From null at suse.de Tue Sep 1 16:30:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 16:30:42 -0000 Subject: SUSE-SU-2026:3910-1: important: Security update for python-sqlparse Message-ID: <178828024251.9039.17916954668008642822@7fc30b86c5e3> # Security update for python-sqlparse Announcement ID: SUSE-SU-2026:3910-1 Release Date: 2026-09-01T10:04:38Z Rating: important References: * bsc#1275459 * bsc#1275460 * bsc#1275461 * bsc#1275466 Cross-References: * CVE-2026-54284 * CVE-2026-59893 * CVE-2026-59894 * CVE-2026-71491 CVSS scores: * CVE-2026-54284 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54284 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54284 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59893 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59893 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59894 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59894 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59894 ( NVD ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-71491 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-71491 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-71491 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves four vulnerabilities can now be installed. ## Description: This update for python-sqlparse fixes the following issues: * CVE-2026-54284: TokenList.**init** materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger (bsc#1275459). * CVE-2026-59893: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (bsc#1275461). * CVE-2026-59894: Generated Python and PHP snippets allow SQL string breakout through unescaped backslashes (bsc#1275460). * CVE-2026-71491: quadratic O(n2) DoS in group_comments (bsc#1275466). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3910=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3910=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3910=1 ## Package List: * Public Cloud Module 15-SP4 (noarch) * python311-sqlparse-0.4.4-150400.6.16.1 * openSUSE Leap 15.4 (noarch) * python311-sqlparse-0.4.4-150400.6.16.1 * Public Cloud Module 15-SP5 (noarch) * python311-sqlparse-0.4.4-150400.6.16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54284.html * https://www.suse.com/security/cve/CVE-2026-59893.html * https://www.suse.com/security/cve/CVE-2026-59894.html * https://www.suse.com/security/cve/CVE-2026-71491.html * https://bugzilla.suse.com/show_bug.cgi?id=1275459 * https://bugzilla.suse.com/show_bug.cgi?id=1275460 * https://bugzilla.suse.com/show_bug.cgi?id=1275461 * https://bugzilla.suse.com/show_bug.cgi?id=1275466 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 16:32:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 16:32:01 -0000 Subject: SUSE-SU-2026:3908-1: moderate: Security update for busybox Message-ID: <178828032194.9039.3539575091689031143@7fc30b86c5e3> # Security update for busybox Announcement ID: SUSE-SU-2026:3908-1 Release Date: 2026-09-01T09:43:09Z Rating: moderate References: * bsc#1217586 * bsc#1271544 * bsc#1271545 * bsc#1271547 * bsc#1271548 Cross-References: * CVE-2023-42366 * CVE-2026-38752 * CVE-2026-38753 * CVE-2026-38754 * CVE-2026-38755 CVSS scores: * CVE-2023-42366 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-42366 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-38752 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-38752 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-38752 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-38752 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-38753 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-38753 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-38753 ( NVD ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-38753 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-38754 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-38754 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-38754 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-38754 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-38755 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-38755 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-38755 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-38755 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.4 An update that solves five vulnerabilities can now be installed. ## Description: This update for busybox fixes the following issues: * CVE-2023-42366: heap buffer overflow in the `next_token` function of `editors/awk.c` (bsc#1217586). * CVE-2026-38752: stack buffer overflow in the `evaluate()` function of `editors/awk.c` (bsc#1271544). * CVE-2026-38753: use-after-free in the `awk_sub()` function of `editors/awk.c` (bsc#1271545). * CVE-2026-38754: heap buffer overflow in `ifsbreakup()` function of `shell/ash.c` (bsc#1271547). * CVE-2026-38755: heap buffer overflow in `evalcommand()` function of `shell/ash.c` (bsc#1271548). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3908=1 ## Package List: * openSUSE Leap 15.4 (noarch) * busybox-syslogd-1.35.0-150400.4.9.1 * busybox-procps-1.35.0-150400.4.9.1 * busybox-util-linux-1.35.0-150400.4.9.1 * busybox-misc-1.35.0-150400.4.9.1 * busybox-patch-1.35.0-150400.4.9.1 * busybox-xz-1.35.0-150400.4.9.1 * busybox-adduser-1.35.0-150400.4.9.1 * busybox-unzip-1.35.0-150400.4.9.1 * busybox-man-1.35.0-150400.4.9.1 * busybox-kmod-1.35.0-150400.4.9.1 * busybox-links-1.35.0-150400.4.9.1 * busybox-vi-1.35.0-150400.4.9.1 * busybox-psmisc-1.35.0-150400.4.9.1 * busybox-grep-1.35.0-150400.4.9.1 * busybox-dos2unix-1.35.0-150400.4.9.1 * busybox-gawk-1.35.0-150400.4.9.1 * busybox-findutils-1.35.0-150400.4.9.1 * busybox-tftp-1.35.0-150400.4.9.1 * busybox-which-1.35.0-150400.4.9.1 * busybox-iproute2-1.35.0-150400.4.9.1 * busybox-whois-1.35.0-150400.4.9.1 * busybox-ncurses-utils-1.35.0-150400.4.9.1 * busybox-sysvinit-tools-1.35.0-150400.4.9.1 * busybox-iputils-1.35.0-150400.4.9.1 * busybox-net-tools-1.35.0-150400.4.9.1 * busybox-bc-1.35.0-150400.4.9.1 * busybox-diffutils-1.35.0-150400.4.9.1 * busybox-policycoreutils-1.35.0-150400.4.9.1 * busybox-gzip-1.35.0-150400.4.9.1 * busybox-wget-1.35.0-150400.4.9.1 * busybox-vlan-1.35.0-150400.4.9.1 * busybox-tar-1.35.0-150400.4.9.1 * busybox-traceroute-1.35.0-150400.4.9.1 * busybox-netcat-1.35.0-150400.4.9.1 * busybox-tunctl-1.35.0-150400.4.9.1 * busybox-selinux-tools-1.35.0-150400.4.9.1 * busybox-sed-1.35.0-150400.4.9.1 * busybox-bzip2-1.35.0-150400.4.9.1 * busybox-ed-1.35.0-150400.4.9.1 * busybox-telnet-1.35.0-150400.4.9.1 * busybox-sharutils-1.35.0-150400.4.9.1 * busybox-sh-1.35.0-150400.4.9.1 * busybox-attr-1.35.0-150400.4.9.1 * busybox-sendmail-1.35.0-150400.4.9.1 * busybox-hostname-1.35.0-150400.4.9.1 * busybox-time-1.35.0-150400.4.9.1 * busybox-coreutils-1.35.0-150400.4.9.1 * busybox-bind-utils-1.35.0-150400.4.9.1 * busybox-less-1.35.0-150400.4.9.1 * busybox-cpio-1.35.0-150400.4.9.1 * busybox-kbd-1.35.0-150400.4.9.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * busybox-static-1.35.0-150400.3.20.1 * busybox-1.35.0-150400.3.20.1 * busybox-testsuite-1.35.0-150400.3.20.1 * openSUSE Leap 15.4 (aarch64 i586 x86_64) * busybox-warewulf3-1.35.0-150400.3.20.1 ## References: * https://www.suse.com/security/cve/CVE-2023-42366.html * https://www.suse.com/security/cve/CVE-2026-38752.html * https://www.suse.com/security/cve/CVE-2026-38753.html * https://www.suse.com/security/cve/CVE-2026-38754.html * https://www.suse.com/security/cve/CVE-2026-38755.html * https://bugzilla.suse.com/show_bug.cgi?id=1217586 * https://bugzilla.suse.com/show_bug.cgi?id=1271544 * https://bugzilla.suse.com/show_bug.cgi?id=1271545 * https://bugzilla.suse.com/show_bug.cgi?id=1271547 * https://bugzilla.suse.com/show_bug.cgi?id=1271548 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 16:33:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 16:33:01 -0000 Subject: SUSE-SU-2026:3907-1: important: Security update for python-sqlparse Message-ID: <178828038190.9039.2430532863471386529@7fc30b86c5e3> # Security update for python-sqlparse Announcement ID: SUSE-SU-2026:3907-1 Release Date: 2026-09-01T09:10:51Z Rating: important References: * bsc#1275459 * bsc#1275460 * bsc#1275461 * bsc#1275466 Cross-References: * CVE-2026-54284 * CVE-2026-59893 * CVE-2026-59894 * CVE-2026-71491 CVSS scores: * CVE-2026-54284 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54284 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54284 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59893 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59893 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59894 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59894 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59894 ( NVD ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-71491 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-71491 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-71491 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.6 * Public Cloud Module 15-SP6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for python-sqlparse fixes the following issues: * CVE-2026-54284: high algorithm complexity when parsing SQL payloads with hundreds of nesting levels can lead to denial of service via excessive resource consumption (bsc#1275459). * CVE-2026-59893: quadratic complexity when processing unmatched dollar-quoted literal and multiline-comment delimiters can lead to denial of service (bsc#1275461). * CVE-2026-59894: improper backlash escaping allows for injection of Python or PHP code via a crafted SQL input (bsc#1275460). * CVE-2026-71491: quadratic complexity in `group_comments` when processing comment-only statements can lead to denial of services (bsc#1275466). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3907=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3907=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3907=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3907=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3907=1 ## Package List: * Public Cloud Module 15-SP6 (noarch) * python311-sqlparse-0.4.4-150600.3.9.1 * Python 3 Module 15-SP7 (noarch) * python311-sqlparse-0.4.4-150600.3.9.1 * openSUSE Leap 15.6 (noarch) * python311-sqlparse-0.4.4-150600.3.9.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python311-sqlparse-0.4.4-150600.3.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python311-sqlparse-0.4.4-150600.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54284.html * https://www.suse.com/security/cve/CVE-2026-59893.html * https://www.suse.com/security/cve/CVE-2026-59894.html * https://www.suse.com/security/cve/CVE-2026-71491.html * https://bugzilla.suse.com/show_bug.cgi?id=1275459 * https://bugzilla.suse.com/show_bug.cgi?id=1275460 * https://bugzilla.suse.com/show_bug.cgi?id=1275461 * https://bugzilla.suse.com/show_bug.cgi?id=1275466 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 16:34:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 16:34:01 -0000 Subject: SUSE-SU-2026:3906-1: important: Security update for python3-sqlparse Message-ID: <178828044151.9039.1743769136137484364@7fc30b86c5e3> # Security update for python3-sqlparse Announcement ID: SUSE-SU-2026:3906-1 Release Date: 2026-09-01T09:10:23Z Rating: important References: * bsc#1275459 * bsc#1275460 * bsc#1275461 * bsc#1275466 Cross-References: * CVE-2026-54284 * CVE-2026-59893 * CVE-2026-59894 * CVE-2026-71491 CVSS scores: * CVE-2026-54284 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54284 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54284 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59893 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59893 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59894 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59894 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59894 ( NVD ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-71491 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-71491 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-71491 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for python3-sqlparse fixes the following issues: * CVE-2026-54284: high algorithm complexity when parsing SQL payloads with hundreds of nesting levels can lead to denial of service via excessive resource consumption (bsc#1275459). * CVE-2026-59893: quadratic complexity when processing unmatched dollar-quoted literal and multiline-comment delimiters can lead to denial of service (bsc#1275461). * CVE-2026-59894: improper backlash escaping allows for injection of Python or PHP code via a crafted SQL input (bsc#1275460). * CVE-2026-71491: quadratic complexity in `group_comments` when processing comment-only statements can lead to denial of services (bsc#1275466). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3906=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3906=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3906=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3906=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3906=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3906=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3906=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3906=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3906=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3906=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3906=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-3906=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python3-sqlparse-0.4.2-150300.23.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python3-sqlparse-0.4.2-150300.23.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python3-sqlparse-0.4.2-150300.23.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python3-sqlparse-0.4.2-150300.23.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * python3-sqlparse-0.4.2-150300.23.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python3-sqlparse-0.4.2-150300.23.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python3-sqlparse-0.4.2-150300.23.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python3-sqlparse-0.4.2-150300.23.1 * openSUSE Leap 15.3 (noarch) * python3-sqlparse-0.4.2-150300.23.1 * Basesystem Module 15-SP7 (noarch) * python3-sqlparse-0.4.2-150300.23.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python3-sqlparse-0.4.2-150300.23.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python3-sqlparse-0.4.2-150300.23.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54284.html * https://www.suse.com/security/cve/CVE-2026-59893.html * https://www.suse.com/security/cve/CVE-2026-59894.html * https://www.suse.com/security/cve/CVE-2026-71491.html * https://bugzilla.suse.com/show_bug.cgi?id=1275459 * https://bugzilla.suse.com/show_bug.cgi?id=1275460 * https://bugzilla.suse.com/show_bug.cgi?id=1275461 * https://bugzilla.suse.com/show_bug.cgi?id=1275466 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 16:35:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 16:35:00 -0000 Subject: SUSE-SU-2026:3905-1: critical: Security update for libapr-util1 Message-ID: <178828050066.9039.16717640957410124718@7fc30b86c5e3> # Security update for libapr-util1 Announcement ID: SUSE-SU-2026:3905-1 Release Date: 2026-09-01T08:36:08Z Rating: critical References: * bsc#1274235 * bsc#1274237 * bsc#1274850 * bsc#1274854 Cross-References: * CVE-2025-49506 * CVE-2026-32327 * CVE-2026-34191 * CVE-2026-34502 CVSS scores: * CVE-2025-49506 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-49506 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-32327 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-32327 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-34191 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34191 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34502 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34502 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves four vulnerabilities can now be installed. ## Description: This update for libapr-util1 fixes the following issues: * CVE-2025-49506: leaking content via side channel timing attack (bsc#1274237). * CVE-2026-32327: XML stack recursion crash (bsc#1274235). * CVE-2026-34191: SQL Injection via apr_dbd_oracle (bsc#1274850). * CVE-2026-34502: heap buffer overflow in APR memcached client (bsc#1274854). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3905=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3905=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le) * libapr-util1-debuginfo-1.5.3-8.36.1 * libapr-util1-devel-1.5.3-8.36.1 * libapr-util1-dbd-sqlite3-1.5.3-8.36.1 * libapr-util1-dbd-sqlite3-debuginfo-1.5.3-8.36.1 * libapr-util1-debugsource-1.5.3-8.36.1 * libapr-util1-1.5.3-8.36.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x) * libapr-util1-debugsource-1.5.3-8.34.1 * libapr-util1-dbd-sqlite3-debuginfo-1.5.3-8.34.1 * libapr-util1-devel-1.5.3-8.34.1 * libapr-util1-1.5.3-8.34.1 * libapr-util1-dbd-sqlite3-1.5.3-8.34.1 * libapr-util1-debuginfo-1.5.3-8.34.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (x86_64) * libapr-util1-devel-1.5.3-8.22.1 * libapr-util1-dbd-sqlite3-1.5.3-8.22.1 * libapr-util1-debuginfo-1.5.3-8.22.1 * libapr-util1-1.5.3-8.22.1 * libapr-util1-debugsource-1.5.3-8.22.1 * libapr-util1-dbd-sqlite3-debuginfo-1.5.3-8.22.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libapr-util1-devel-1.5.3-8.22.1 * libapr-util1-dbd-sqlite3-1.5.3-8.22.1 * libapr-util1-debuginfo-1.5.3-8.22.1 * libapr-util1-1.5.3-8.22.1 * libapr-util1-debugsource-1.5.3-8.22.1 * libapr-util1-dbd-sqlite3-debuginfo-1.5.3-8.22.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49506.html * https://www.suse.com/security/cve/CVE-2026-32327.html * https://www.suse.com/security/cve/CVE-2026-34191.html * https://www.suse.com/security/cve/CVE-2026-34502.html * https://bugzilla.suse.com/show_bug.cgi?id=1274235 * https://bugzilla.suse.com/show_bug.cgi?id=1274237 * https://bugzilla.suse.com/show_bug.cgi?id=1274850 * https://bugzilla.suse.com/show_bug.cgi?id=1274854 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:31:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:31:04 -0000 Subject: SUSE-SU-2026:23390-1: important: Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829466458.2603.9491243103050225744@2eb657abeeed> # Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23390-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-598=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-41-default-8-1.1 * kernel-livepatch-6_4_0-41-default-debuginfo-8-1.1 * kernel-livepatch-MICRO-6-0_Update_18-debugsource-8-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:32:20 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:32:20 -0000 Subject: SUSE-SU-2026:23389-1: important: Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829474040.2603.18236514128134383952@2eb657abeeed> # Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23389-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-597=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-40-default-9-1.1 * kernel-livepatch-MICRO-6-0_Update_17-debugsource-9-1.1 * kernel-livepatch-6_4_0-40-default-debuginfo-9-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:33:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:33:37 -0000 Subject: SUSE-SU-2026:23388-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829481723.2603.11791333523173463262@2eb657abeeed> # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23388-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-596=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-39-default-debuginfo-10-1.1 * kernel-livepatch-6_4_0-39-default-10-1.1 * kernel-livepatch-MICRO-6-0_Update_16-debugsource-10-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:34:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:34:42 -0000 Subject: SUSE-SU-2026:23387-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829488295.2603.2210161625445479105@2eb657abeeed> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23387-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-595=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_14-debugsource-11-1.2 * kernel-livepatch-6_4_0-38-default-11-1.2 * kernel-livepatch-6_4_0-38-default-debuginfo-11-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:35:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:35:49 -0000 Subject: SUSE-SU-2026:23386-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829494919.2603.16298580299374780755@2eb657abeeed> # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23386-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-594=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_13-debugsource-13-1.1 * kernel-livepatch-6_4_0-36-default-debuginfo-13-1.1 * kernel-livepatch-6_4_0-36-default-13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:36:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:36:54 -0000 Subject: SUSE-SU-2026:23385-1: important: Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829501440.2603.1781176738723181202@2eb657abeeed> # Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23385-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-35.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-593=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-35-default-15-1.1 * kernel-livepatch-6_4_0-35-default-debuginfo-15-1.1 * kernel-livepatch-MICRO-6-0_Update_12-debugsource-15-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:38:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:38:03 -0000 Subject: SUSE-SU-2026:23384-1: important: Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829508341.2603.16286324559620015364@2eb657abeeed> # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23384-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-592=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_11-debugsource-15-1.1 * kernel-livepatch-6_4_0-34-default-15-1.1 * kernel-livepatch-6_4_0-34-default-debuginfo-15-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:39:08 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:39:08 -0000 Subject: SUSE-SU-2026:23383-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829514882.2603.14064443014168287528@2eb657abeeed> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23383-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-591=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-32-default-debuginfo-16-1.1 * kernel-livepatch-6_4_0-32-default-16-1.1 * kernel-livepatch-MICRO-6-0_Update_10-debugsource-16-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:39:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:39:51 -0000 Subject: SUSE-SU-2026:23382-1: important: Security update for the Linux Kernel RT (Live Patch 27 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829519147.2603.11378804793391536513@2eb657abeeed> # Security update for the Linux Kernel RT (Live Patch 27 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23382-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1270023 * bsc#1270024 * bsc#1271543 * bsc#1271867 Cross-References: * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-50.2 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-590=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_27-debugsource-2-1.1 * kernel-livepatch-6_4_0-50-rt-debuginfo-2-1.1 * kernel-livepatch-6_4_0-50-rt-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:40:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:40:37 -0000 Subject: SUSE-SU-2026:23381-1: important: Security update for the Linux Kernel RT (Live Patch 26 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829523761.2603.8271142857625300136@2eb657abeeed> # Security update for the Linux Kernel RT (Live Patch 26 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23381-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271370 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-46242 * CVE-2026-52956 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-53366 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-49.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-589=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-49-rt-2-1.1 * kernel-livepatch-6_4_0-49-rt-debuginfo-2-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_26-debugsource-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:41:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:41:32 -0000 Subject: SUSE-SU-2026:23380-1: important: Security update for the Linux Kernel RT (Live Patch 25 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829529229.2603.17352644398273277149@2eb657abeeed> # Security update for the Linux Kernel RT (Live Patch 25 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23380-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1268281 * bsc#1269034 * bsc#1269822 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-53133 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves nine vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-48.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-588=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-48-rt-3-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_25-debugsource-3-1.1 * kernel-livepatch-6_4_0-48-rt-debuginfo-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:42:26 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:42:26 -0000 Subject: SUSE-SU-2026:23379-1: important: Security update for the Linux Kernel RT (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829534616.2603.15733190470188002924@2eb657abeeed> # Security update for the Linux Kernel RT (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23379-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1267362 * bsc#1268281 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-43109 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 13 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-47.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-587=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-47-rt-4-1.1 * kernel-livepatch-6_4_0-47-rt-debuginfo-4-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_24-debugsource-4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:43:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:43:30 -0000 Subject: SUSE-SU-2026:23378-1: important: Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829541066.2603.16749051647069949330@2eb657abeeed> # Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23378-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 18 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-586=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-46-rt-5-1.1 * kernel-livepatch-6_4_0-46-rt-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_23-debugsource-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:44:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:44:30 -0000 Subject: SUSE-SU-2026:23377-1: important: Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829547040.2603.13283958004637273170@2eb657abeeed> # Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23377-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 18 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-585=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_22-debugsource-5-1.2 * kernel-livepatch-6_4_0-45-rt-debuginfo-5-1.2 * kernel-livepatch-6_4_0-45-rt-5-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:45:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:45:34 -0000 Subject: SUSE-SU-2026:23376-1: important: Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829553408.2603.17198681475323300245@2eb657abeeed> # Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23376-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-584=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-43-rt-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_21-debugsource-5-1.1 * kernel-livepatch-6_4_0-43-rt-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:46:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:46:34 -0000 Subject: SUSE-SU-2026:23375-1: important: Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829559446.2603.5029963749018302319@2eb657abeeed> # Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23375-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-582=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_20-debugsource-6-1.1 * kernel-livepatch-6_4_0-42-rt-debuginfo-6-1.1 * kernel-livepatch-6_4_0-42-rt-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:47:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:47:34 -0000 Subject: SUSE-SU-2026:23374-1: important: Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829565489.2603.542588306621380396@2eb657abeeed> # Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23374-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-581=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-41-rt-debuginfo-8-1.1 * kernel-livepatch-6_4_0-41-rt-8-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_19-debugsource-8-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:48:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:48:37 -0000 Subject: SUSE-SU-2026:23373-1: important: Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829571762.2603.17180783499891803904@2eb657abeeed> # Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23373-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-580=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-40-rt-9-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_18-debugsource-9-1.1 * kernel-livepatch-6_4_0-40-rt-debuginfo-9-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:49:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:49:42 -0000 Subject: SUSE-SU-2026:23372-1: important: Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829578294.2603.2808429645374591798@2eb657abeeed> # Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23372-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-579=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-39-rt-debuginfo-10-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_15-debugsource-10-1.1 * kernel-livepatch-6_4_0-39-rt-10-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:50:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:50:49 -0000 Subject: SUSE-SU-2026:23371-1: important: Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829584976.2603.8286188706733642895@2eb657abeeed> # Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23371-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-37.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-578=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-37-rt-debuginfo-11-1.1 * kernel-livepatch-6_4_0-37-rt-11-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_13-debugsource-11-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:51:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:51:59 -0000 Subject: SUSE-SU-2026:23370-1: important: Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829591941.2603.9634254082240787479@2eb657abeeed> # Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23370-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-577=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-36-rt-15-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_12-debugsource-15-1.1 * kernel-livepatch-6_4_0-36-rt-debuginfo-15-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:53:05 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:53:05 -0000 Subject: SUSE-SU-2026:23369-1: important: Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829598582.2603.13907400983749952554@2eb657abeeed> # Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23369-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-576=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-35-rt-16-1.1 * kernel-livepatch-6_4_0-35-rt-debuginfo-16-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_11-debugsource-16-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:54:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:54:12 -0000 Subject: SUSE-SU-2026:23368-1: important: Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829605248.2603.1675444632234792578@2eb657abeeed> # Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23368-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-575=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_10-debugsource-20-1.1 * kernel-livepatch-6_4_0-34-rt-debuginfo-20-1.1 * kernel-livepatch-6_4_0-34-rt-20-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:55:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:55:14 -0000 Subject: SUSE-SU-2026:23367-1: important: Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829611420.2603.11551456625128730464@2eb657abeeed> # Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23367-1 Release Date: 2026-08-31T15:12:59Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-583=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-43-default-debuginfo-5-1.1 * kernel-livepatch-6_4_0-43-default-5-1.1 * kernel-livepatch-MICRO-6-0_Update_20-debugsource-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:56:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:56:15 -0000 Subject: SUSE-SU-2026:23366-1: important: Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178829617531.2603.11890657440144090060@2eb657abeeed> # Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23366-1 Release Date: 2026-08-31T15:12:59Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-574=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-42-default-6-1.1 * kernel-livepatch-6_4_0-42-default-debuginfo-6-1.1 * kernel-livepatch-MICRO-6-0_Update_19-debugsource-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:56:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:56:59 -0000 Subject: SUSE-SU-2026:3918-1: moderate: Security update for cups-filters Message-ID: <178829621933.2603.12473377546235852179@2eb657abeeed> # Security update for cups-filters Announcement ID: SUSE-SU-2026:3918-1 Release Date: 2026-09-01T14:58:38Z Rating: moderate References: * bsc#1273145 * bsc#1273146 Cross-References: * CVE-2026-64611 * CVE-2026-64612 CVSS scores: * CVE-2026-64611 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64611 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64611 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64612 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64612 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64612 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for cups-filters fixes the following issues: * CVE-2026-64611: user who controls an IEEE-1284 device ID consumed by `cfIEEE1284GetMakeModel` can drive `cfIEEE1284NormalizeMakeModel` into an infinite loop (bsc#1273145). * CVE-2026-64612: authenticated client that can submit an image print job can abort the CUPS filter process by supplying a malformed PNG (bsc#1273146). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3918=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * cups-filters-debugsource-1.0.58-19.38.1 * cups-filters-debuginfo-1.0.58-19.38.1 * cups-filters-foomatic-rip-1.0.58-19.38.1 * cups-filters-cups-browsed-1.0.58-19.38.1 * cups-filters-1.0.58-19.38.1 * cups-filters-foomatic-rip-debuginfo-1.0.58-19.38.1 * cups-filters-ghostscript-debuginfo-1.0.58-19.38.1 * cups-filters-ghostscript-1.0.58-19.38.1 * cups-filters-cups-browsed-debuginfo-1.0.58-19.38.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64611.html * https://www.suse.com/security/cve/CVE-2026-64612.html * https://bugzilla.suse.com/show_bug.cgi?id=1273145 * https://bugzilla.suse.com/show_bug.cgi?id=1273146 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:57:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:57:37 -0000 Subject: SUSE-SU-2026:3917-1: important: Security update for ucode-intel Message-ID: <178829625789.2603.727202643502656164@2eb657abeeed> # Security update for ucode-intel Announcement ID: SUSE-SU-2026:3917-1 Release Date: 2026-09-01T14:58:30Z Rating: important References: * bsc#1274785 Cross-References: * CVE-2025-31936 * CVE-2025-31938 * CVE-2025-35973 * CVE-2026-20707 * CVE-2026-20713 * CVE-2026-20716 * CVE-2026-20760 * CVE-2026-20901 * CVE-2026-20917 CVSS scores: * CVE-2025-31936 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31936 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2025-31936 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31938 ( SUSE ): 4.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31938 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2025-31938 ( NVD ): 4.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35973 ( SUSE ): 4.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35973 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N * CVE-2025-35973 ( NVD ): 4.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20707 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20707 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-20707 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20713 ( SUSE ): 4.5 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20713 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N * CVE-2026-20713 ( NVD ): 4.5 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( SUSE ): 7.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-20716 ( NVD ): 7.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20760 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20760 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20760 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20901 ( NVD ): 4.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20901 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N * CVE-2026-20917 ( SUSE ): 4.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20917 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2026-20917 ( NVD ): 4.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves nine vulnerabilities can now be installed. ## Description: This update for ucode-intel fixes the following issues: * Intel CPU Microcode was updated to the 20260812 release (bsc#1274785) * Removed MTL/06-aa-04/c0 due to functional issues observed when loading the MCU in some platforms. * Intel CPU Microcode was updated to the 20260811 release (bsc#1274785) * Security updates for INTEL-SA-01379 / CVE-2025-31936 * Security updates for INTEL-SA-01404 / CVE-2025-31938 * Security updates for INTEL-SA-01423 / CVE-2026-20917 * Security updates for INTEL-SA-01428 / CVE-2025-35973 * Security updates for INTEL-SA-01435 / CVE-2026-20716 * Security updates for INTEL-SA-01441 / CVE-2026-20760 * Security updates for INTEL-SA-01442 / CVE-2026-20713 / CVE-2026-20901 * Security updates for INTEL-SA-01443 / CVE-2026-20707 * Update for functional issues. ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3917=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3917=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (x86_64) * ucode-intel-debugsource-20260812-164.1 * ucode-intel-20260812-164.1 * ucode-intel-debuginfo-20260812-164.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * ucode-intel-debugsource-20260812-164.1 * ucode-intel-20260812-164.1 * ucode-intel-debuginfo-20260812-164.1 ## References: * https://www.suse.com/security/cve/CVE-2025-31936.html * https://www.suse.com/security/cve/CVE-2025-31938.html * https://www.suse.com/security/cve/CVE-2025-35973.html * https://www.suse.com/security/cve/CVE-2026-20707.html * https://www.suse.com/security/cve/CVE-2026-20713.html * https://www.suse.com/security/cve/CVE-2026-20716.html * https://www.suse.com/security/cve/CVE-2026-20760.html * https://www.suse.com/security/cve/CVE-2026-20901.html * https://www.suse.com/security/cve/CVE-2026-20917.html * https://bugzilla.suse.com/show_bug.cgi?id=1274785 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:58:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:58:33 -0000 Subject: SUSE-SU-2026:3916-1: important: Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid Message-ID: <178829631340.2603.14410705147436284216@2eb657abeeed> # Security update for terraform-provider-aws, terraform-provider-azurerm, terraform-provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provid Announcement ID: SUSE-SU-2026:3916-1 Release Date: 2026-09-01T14:58:22Z Rating: important References: * bsc#1271995 * bsc#1272078 * bsc#1272090 * bsc#1276978 * bsc#1276987 Cross-References: * CVE-2026-56852 * CVE-2026-71556 * CVE-2026-71557 CVSS scores: * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-71556 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L * CVE-2026-71556 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L * CVE-2026-71557 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-71557 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves three vulnerabilities and has two security fixes can now be installed. ## Description: This update for terraform-provider-aws, terraform-provider-azurerm, terraform- provider-external, terraform-provider-google, terraform-provider-helm, terraform-provider-kubernetes, terraform-provider-local, terraform-provider- null, terraform-provider-random, terraform-provider-tls fixes the following issues: * CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of truncated/invalid UTF-8 input can lead to infinite loop (bsc#1271995, bsc#1272078, bsc#1272090). * CVE-2026-71556: github.com/go-git/go-git/v5: symlink traversal issue in worktree operations allows for arbitrary file reads/writes (bsc#1276978). * CVE-2026-71557: github.com/go-git/go-git/v5: improper reference name sanitization before construction of on-disk paths under the reference storage directory can lead to arbitrary file writes (bsc#1276987). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3916=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3916=1 ## Package List: * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * terraform-provider-kubernetes-1.13.2-150200.6.18.2 * terraform-provider-aws-3.11.0-150200.6.24.2 * terraform-provider-tls-3.0.0-150200.5.21.2 * terraform-provider-google-3.43.0-150200.6.18.2 * terraform-provider-local-2.0.0-150200.6.25.1 * terraform-provider-azurerm-2.32.0-150200.6.18.2 * terraform-provider-external-2.0.0-150200.6.18.2 * terraform-provider-helm-2.9.0-150200.6.29.2 * terraform-provider-random-3.0.0-150200.6.21.2 * terraform-provider-null-3.0.0-150200.6.24.2 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * terraform-provider-aws-3.11.0-150200.6.24.2 * terraform-provider-kubernetes-1.13.2-150200.6.18.2 * terraform-provider-tls-3.0.0-150200.5.21.2 * terraform-provider-google-3.43.0-150200.6.18.2 * terraform-provider-local-2.0.0-150200.6.25.1 * terraform-provider-azurerm-2.32.0-150200.6.18.2 * terraform-provider-external-2.0.0-150200.6.18.2 * terraform-provider-helm-2.9.0-150200.6.29.2 * terraform-provider-random-3.0.0-150200.6.21.2 * terraform-provider-null-3.0.0-150200.6.24.2 ## References: * https://www.suse.com/security/cve/CVE-2026-56852.html * https://www.suse.com/security/cve/CVE-2026-71556.html * https://www.suse.com/security/cve/CVE-2026-71557.html * https://bugzilla.suse.com/show_bug.cgi?id=1271995 * https://bugzilla.suse.com/show_bug.cgi?id=1272078 * https://bugzilla.suse.com/show_bug.cgi?id=1272090 * https://bugzilla.suse.com/show_bug.cgi?id=1276978 * https://bugzilla.suse.com/show_bug.cgi?id=1276987 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:59:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:59:12 -0000 Subject: SUSE-SU-2026:3915-1: important: Security update for apache2-mod_auth_openidc Message-ID: <178829635286.2603.17752097520897180132@2eb657abeeed> # Security update for apache2-mod_auth_openidc Announcement ID: SUSE-SU-2026:3915-1 Release Date: 2026-09-01T14:57:09Z Rating: important References: * bsc#1276217 Cross-References: * CVE-2026-54789 CVSS scores: * CVE-2026-54789 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54789 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for apache2-mod_auth_openidc fixes the following issue: * CVE-2026-54789: out-of-bounds read and one-byte out-of-bounds write in the state-cookie parser of `mod_auth_openidc` (bsc#1276217). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3915=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3915=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * apache2-mod_auth_openidc-debuginfo-2.4.0-7.25.1 * apache2-mod_auth_openidc-2.4.0-7.25.1 * apache2-mod_auth_openidc-debugsource-2.4.0-7.25.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * apache2-mod_auth_openidc-2.4.0-7.25.1 * apache2-mod_auth_openidc-debuginfo-2.4.0-7.25.1 * apache2-mod_auth_openidc-debugsource-2.4.0-7.25.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54789.html * https://bugzilla.suse.com/show_bug.cgi?id=1276217 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 1 20:59:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 01 Sep 2026 20:59:54 -0000 Subject: SUSE-SU-2026:3914-1: important: Security update for yast2-auth-client Message-ID: <178829639422.2603.17184187359383765061@2eb657abeeed> # Security update for yast2-auth-client Announcement ID: SUSE-SU-2026:3914-1 Release Date: 2026-09-01T14:56:55Z Rating: important References: * bsc#1272775 * bsc#1274612 * bsc#1274806 Cross-References: * CVE-2026-59681 CVSS scores: * CVE-2026-59681 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59681 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59681 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability and has two security fixes can now be installed. ## Description: This update for yast2-auth-client fixes the following issue: Update to version 4.7.1. * CVE-2026-59681: OS command injection via unsanitized Organizational Unit/dnsHostName in AD join (AutoYaST-reachable) (bsc#1272775). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3914=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * yast2-auth-client-4.7.1-150700.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59681.html * https://bugzilla.suse.com/show_bug.cgi?id=1272775 * https://bugzilla.suse.com/show_bug.cgi?id=1274612 * https://bugzilla.suse.com/show_bug.cgi?id=1274806 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 2 12:31:48 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 02 Sep 2026 12:31:48 -0000 Subject: SUSE-SU-2026:23411-1: critical: Security update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen Message-ID: <178835230826.3792.833776797457992702@feb3610e450a> # Security update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen Announcement ID: SUSE-SU-2026:23411-1 Release Date: 2026-08-31T15:29:17Z Rating: critical References: * bsc#1262698 * bsc#1262701 * bsc#1266262 * bsc#1266263 * bsc#1271649 * bsc#1272772 * bsc#1272773 * bsc#1272774 * bsc#1274867 Cross-References: * CVE-2026-16349 * CVE-2026-16350 * CVE-2026-16351 * CVE-2026-16352 * CVE-2026-16353 * CVE-2026-16354 * CVE-2026-16355 * CVE-2026-16356 * CVE-2026-16357 * CVE-2026-16358 * CVE-2026-16359 * CVE-2026-16360 * CVE-2026-16362 * CVE-2026-16363 * CVE-2026-16364 * CVE-2026-16365 * CVE-2026-16366 * CVE-2026-16367 * CVE-2026-16368 * CVE-2026-16369 * CVE-2026-16370 * CVE-2026-16371 * CVE-2026-16372 * CVE-2026-16373 * CVE-2026-16374 * CVE-2026-16375 * CVE-2026-16376 * CVE-2026-16377 * CVE-2026-16378 * CVE-2026-16379 * CVE-2026-16380 * CVE-2026-16381 * CVE-2026-16382 * CVE-2026-16383 * CVE-2026-16384 * CVE-2026-16385 * CVE-2026-16386 * CVE-2026-16387 * CVE-2026-16388 * CVE-2026-16389 * CVE-2026-16390 * CVE-2026-16391 * CVE-2026-16392 * CVE-2026-16393 * CVE-2026-16394 * CVE-2026-16395 * CVE-2026-16396 * CVE-2026-16397 * CVE-2026-16398 * CVE-2026-16399 * CVE-2026-16400 * CVE-2026-16401 * CVE-2026-16402 * CVE-2026-16403 * CVE-2026-16404 * CVE-2026-16405 * CVE-2026-16406 * CVE-2026-16407 * CVE-2026-16408 * CVE-2026-16409 * CVE-2026-16410 * CVE-2026-16411 * CVE-2026-16412 * CVE-2026-74934 * CVE-2026-74935 * CVE-2026-74936 * CVE-2026-74937 * CVE-2026-74938 * CVE-2026-74939 * CVE-2026-74940 * CVE-2026-74941 * CVE-2026-74942 * CVE-2026-74943 * CVE-2026-74944 * CVE-2026-74945 * CVE-2026-74946 * CVE-2026-74947 * CVE-2026-74948 * CVE-2026-74949 * CVE-2026-74950 * CVE-2026-74953 * CVE-2026-74954 * CVE-2026-74955 * CVE-2026-74956 * CVE-2026-74957 * CVE-2026-74958 * CVE-2026-74959 * CVE-2026-74960 * CVE-2026-74961 * CVE-2026-74962 * CVE-2026-74963 * CVE-2026-74964 * CVE-2026-74965 * CVE-2026-74966 * CVE-2026-74967 * CVE-2026-74968 * CVE-2026-74969 * CVE-2026-74970 * CVE-2026-74971 * CVE-2026-74972 * CVE-2026-74973 * CVE-2026-74974 * CVE-2026-74976 * CVE-2026-74977 * CVE-2026-74978 * CVE-2026-74979 * CVE-2026-74981 * CVE-2026-74982 * CVE-2026-74983 * CVE-2026-74984 * CVE-2026-74985 * CVE-2026-74986 * CVE-2026-74987 * CVE-2026-74988 * CVE-2026-74990 CVSS scores: * CVE-2026-16349 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-16349 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16350 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16350 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16351 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-16351 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16352 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16352 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16353 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16353 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16354 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16356 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16357 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16358 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16359 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16360 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16362 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16363 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16364 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16365 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16366 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16367 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-16368 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16369 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16370 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16371 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16372 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16374 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16375 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16376 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16377 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16378 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16379 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16380 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16381 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16382 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16384 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16385 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16386 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16387 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16388 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16389 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16390 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16391 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16392 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-16393 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-16394 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16395 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16396 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16397 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-16398 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16399 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16400 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16401 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16403 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-16404 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N * CVE-2026-16405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16406 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16407 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16408 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16409 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16410 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16411 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16412 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74934 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74934 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74935 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74935 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74936 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74936 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74936 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74937 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74938 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74938 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74939 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74940 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74940 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74941 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74942 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74943 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74943 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74944 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74944 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74945 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-74946 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74947 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74948 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-74949 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74950 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74953 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-74955 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74956 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74957 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74958 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-74959 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74960 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74961 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74962 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74963 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-74963 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74964 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74965 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74966 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-74967 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74968 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74969 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74970 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74971 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-74972 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-74973 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74974 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74976 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-74977 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74978 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74979 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74981 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74982 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74983 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74984 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74985 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74986 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74987 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74988 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74990 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74990 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves 115 vulnerabilities can now be installed. ## Description: This update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.1.0 ESR. * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935 Privilege escalation in the DOM: Networking component * CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937 Use-after-free in the JavaScript: GC component * CVE-2026-74938 Mitigation bypass in the JavaScript: GC component * CVE-2026-74939 Privilege escalation in the DOM: Navigation component * CVE-2026-74940 Use-after-free in the Graphics: Text component * CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942 Privilege escalation in the Remote Settings Client component * CVE-2026-74943 Use-after-free in the Graphics: ImageLib component * CVE-2026-74944 Use-after-free in the DOM: Core & HTML component * CVE-2026-74945 Information disclosure in the Graphics: Text component * CVE-2026-74946 Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947 Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948 Information disclosure in the Graphics component * CVE-2026-74949 Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950 Privilege escalation in the Downloads API component * CVE-2026-74953 Privilege escalation in the Networking: Cookies component * CVE-2026-74954 Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955 Privilege escalation in the Request Handling component * CVE-2026-74956 Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957 Mitigation bypass in the Safe Browsing component * CVE-2026-74958 Information disclosure in the WebRTC component * CVE-2026-74959 Mitigation bypass in the Storage: Cache API component * CVE-2026-74960 Site isolation issue in the WebExtensions component * CVE-2026-74961 Side-channel in the Web Audio component * CVE-2026-74962 Site isolation issue in the Networking: Cookies component * CVE-2026-74963 Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964 Integer overflow in the Graphics component * CVE-2026-74965 Privilege escalation in the Shell Integration component * CVE-2026-74966 Information disclosure in the Form Autofill component * CVE-2026-74967 Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968 Site isolation issue in the Graphics: WebRender component * CVE-2026-74969 Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970 Site isolation issue in the Graphics component * CVE-2026-74971 Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972 Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973 Race condition, use-after-free in the Graphics component * CVE-2026-74974 Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977 Integer overflow in the Graphics component * CVE-2026-74978 Clickjacking issue in the Widget component * CVE-2026-74979 Mitigation bypass in the Add-ons Manager component * CVE-2026-74981 Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982 Denial-of-service in the Widget component * CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984 Race condition in the JavaScript Engine component * CVE-2026-74985 Privilege escalation in the Enterprise Policies component * CVE-2026-74986 Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987 Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988 Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990 Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Firefox Extended Support Release 153.0esr ESR * New: ## General * Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. * Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. * The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. * Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. * Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs * Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. * Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. * Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. * Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. * A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy * Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. * Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. * Firefox now uses Safe Browsing V5 for phishing and malware protection. * Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. * Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations * Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. * A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility * Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Linux * Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. * Firefox no longer requires a restart after package manager updates and uses less memory on Linux. * Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. * WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. * Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. * Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. * Enterprise policy documentation has moved to https://firefox-admin- docs.mozilla.org/. * Fixed: Various security fixes. * MFSA 2026-68 (bsc#1271649): * CVE-2026-16349 Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350 Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362 Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351 Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352 Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363 JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364 Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365 Privilege escalation in the DOM: Workers component * CVE-2026-16366 Privilege escalation in the DOM: Navigation component * CVE-2026-16353 Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354 Information disclosure in the Graphics: ImageLib component * CVE-2026-16367 Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368 Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369 Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356 Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357 Incorrect boundary conditions in the Graphics component * CVE-2026-16370 Mitigation bypass in the DOM: Networking component * CVE-2026-16371 Privilege escalation in the DOM: Navigation component * CVE-2026-16372 Privilege escalation in the DOM: Content Processes component * CVE-2026-16373 Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374 Information disclosure in the Framework component in DevTools * CVE-2026-16375 Site isolation issue in the Networking: HTTP component * CVE-2026-16376 Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377 Mitigation bypass in the PDF Viewer component * CVE-2026-16378 Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379 Privilege escalation in the DOM: Content Processes component * CVE-2026-16358 Site isolation issue in the Graphics: WebRender component * CVE-2026-16380 Mitigation bypass in the Networking component * CVE-2026-16381 Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382 Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383 Mitigation bypass in the DOM: Networking component * CVE-2026-16384 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387 Site isolation issue in the Networking component * CVE-2026-16388 Sandbox escape in the DOM: Networking component * CVE-2026-16389 Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390 Mitigation bypass in the Enterprise Policies component * CVE-2026-16391 Information disclosure in the Storage: IndexedDB component * CVE-2026-16392 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393 Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359 Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394 Mitigation bypass in the DOM: Security component * CVE-2026-16395 Integer overflow in the Audio/Video component * CVE-2026-16396 Privilege escalation in WebExtensions * CVE-2026-16397 Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398 Site isolation issue in the Graphics component * CVE-2026-16399 Site isolation issue in the DOM: Navigation component * CVE-2026-16400 Information disclosure in the DOM: Security component * CVE-2026-16401 Privilege escalation in the Data Loss Prevention component * CVE-2026-16402 Integer overflow in the Graphics: ImageLib component * CVE-2026-16403 Spoofing issue in the Address Bar component * CVE-2026-16404 Spoofing issue in Firefox for Android * CVE-2026-16405 Information disclosure in the Networking: WebSockets component * CVE-2026-16406 Mitigation bypass in the Networking component * CVE-2026-16407 Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408 Integer overflow in the Audio/Video: Playback component * CVE-2026-16409 Invalid pointer in the Security: PSM component * CVE-2026-16410 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411 Memory safety bugs fixed in Firefox 153 * CVE-2026-16412 Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360 Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 Changes in mozilla-nss: * Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). * Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). * Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). * Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). * Add zeroization for ML-KEM, ported from upstream (bsc#1272774). * Add zeroization for ML-DSA (bsc#1272774). * Add ML-DSA robustness and test fixes. * Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Update fuzz/config/tstclnt_arguments.py. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren?t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ?Community ? Network Security Services (NSS)?. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. * update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix "testing if key corruption is detected in attribute" failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl * update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o * update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. * update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. * update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). * update to NSS 3.120.1 * no upstream releasenotes * update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. * update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs * update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. * Adjusted for changed naming scheme of tarballs for this release by upstream * update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* * update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch * update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don?t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function * update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions * update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. * update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions * update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool * update to NSS 3.113 * Fix alias for mac workers on try. * Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. Changes in mozilla-nspr: * update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig * update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 * update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. * update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char * update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support "%e" format specifier Changes in rust-cbindgen: * Update to version v0.29.4+git0: * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields * Update to version 0.29.2+git0: * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * Explicitly request serde's std features to avoid issues with newer toml versions. * enum: Track dependencies properly in enumerations. * Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove "display" feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with "void" default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * tests: Fix symbol file and tests. * tests: Run rustfmt. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1570=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le x86_64) * libfreebl3-debuginfo-3.125-160000.1.1 * mozilla-nss-tools-3.125-160000.1.1 * libfreebl3-3.125-160000.1.1 * mozilla-nss-tools-debuginfo-3.125-160000.1.1 * mozilla-nspr-4.39-160000.1.1 * libsoftokn3-debuginfo-3.125-160000.1.1 * libsoftokn3-3.125-160000.1.1 * mozilla-nspr-debuginfo-4.39-160000.1.1 * mozilla-nss-certs-3.125-160000.1.1 * mozilla-nspr-debugsource-4.39-160000.1.1 * mozilla-nss-debugsource-3.125-160000.1.1 * mozilla-nss-3.125-160000.1.1 * mozilla-nss-debuginfo-3.125-160000.1.1 * mozilla-nss-certs-debuginfo-3.125-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16349.html * https://www.suse.com/security/cve/CVE-2026-16350.html * https://www.suse.com/security/cve/CVE-2026-16351.html * https://www.suse.com/security/cve/CVE-2026-16352.html * https://www.suse.com/security/cve/CVE-2026-16353.html * https://www.suse.com/security/cve/CVE-2026-16354.html * https://www.suse.com/security/cve/CVE-2026-16355.html * https://www.suse.com/security/cve/CVE-2026-16356.html * https://www.suse.com/security/cve/CVE-2026-16357.html * https://www.suse.com/security/cve/CVE-2026-16358.html * https://www.suse.com/security/cve/CVE-2026-16359.html * https://www.suse.com/security/cve/CVE-2026-16360.html * https://www.suse.com/security/cve/CVE-2026-16362.html * https://www.suse.com/security/cve/CVE-2026-16363.html * https://www.suse.com/security/cve/CVE-2026-16364.html * https://www.suse.com/security/cve/CVE-2026-16365.html * https://www.suse.com/security/cve/CVE-2026-16366.html * https://www.suse.com/security/cve/CVE-2026-16367.html * https://www.suse.com/security/cve/CVE-2026-16368.html * https://www.suse.com/security/cve/CVE-2026-16369.html * https://www.suse.com/security/cve/CVE-2026-16370.html * https://www.suse.com/security/cve/CVE-2026-16371.html * https://www.suse.com/security/cve/CVE-2026-16372.html * https://www.suse.com/security/cve/CVE-2026-16373.html * https://www.suse.com/security/cve/CVE-2026-16374.html * https://www.suse.com/security/cve/CVE-2026-16375.html * https://www.suse.com/security/cve/CVE-2026-16376.html * https://www.suse.com/security/cve/CVE-2026-16377.html * https://www.suse.com/security/cve/CVE-2026-16378.html * https://www.suse.com/security/cve/CVE-2026-16379.html * https://www.suse.com/security/cve/CVE-2026-16380.html * https://www.suse.com/security/cve/CVE-2026-16381.html * https://www.suse.com/security/cve/CVE-2026-16382.html * https://www.suse.com/security/cve/CVE-2026-16383.html * https://www.suse.com/security/cve/CVE-2026-16384.html * https://www.suse.com/security/cve/CVE-2026-16385.html * https://www.suse.com/security/cve/CVE-2026-16386.html * https://www.suse.com/security/cve/CVE-2026-16387.html * https://www.suse.com/security/cve/CVE-2026-16388.html * https://www.suse.com/security/cve/CVE-2026-16389.html * https://www.suse.com/security/cve/CVE-2026-16390.html * https://www.suse.com/security/cve/CVE-2026-16391.html * https://www.suse.com/security/cve/CVE-2026-16392.html * https://www.suse.com/security/cve/CVE-2026-16393.html * https://www.suse.com/security/cve/CVE-2026-16394.html * https://www.suse.com/security/cve/CVE-2026-16395.html * https://www.suse.com/security/cve/CVE-2026-16396.html * https://www.suse.com/security/cve/CVE-2026-16397.html * https://www.suse.com/security/cve/CVE-2026-16398.html * https://www.suse.com/security/cve/CVE-2026-16399.html * https://www.suse.com/security/cve/CVE-2026-16400.html * https://www.suse.com/security/cve/CVE-2026-16401.html * https://www.suse.com/security/cve/CVE-2026-16402.html * https://www.suse.com/security/cve/CVE-2026-16403.html * https://www.suse.com/security/cve/CVE-2026-16404.html * https://www.suse.com/security/cve/CVE-2026-16405.html * https://www.suse.com/security/cve/CVE-2026-16406.html * https://www.suse.com/security/cve/CVE-2026-16407.html * https://www.suse.com/security/cve/CVE-2026-16408.html * https://www.suse.com/security/cve/CVE-2026-16409.html * https://www.suse.com/security/cve/CVE-2026-16410.html * https://www.suse.com/security/cve/CVE-2026-16411.html * https://www.suse.com/security/cve/CVE-2026-16412.html * https://www.suse.com/security/cve/CVE-2026-74934.html * https://www.suse.com/security/cve/CVE-2026-74935.html * https://www.suse.com/security/cve/CVE-2026-74936.html * https://www.suse.com/security/cve/CVE-2026-74937.html * https://www.suse.com/security/cve/CVE-2026-74938.html * https://www.suse.com/security/cve/CVE-2026-74939.html * https://www.suse.com/security/cve/CVE-2026-74940.html * https://www.suse.com/security/cve/CVE-2026-74941.html * https://www.suse.com/security/cve/CVE-2026-74942.html * https://www.suse.com/security/cve/CVE-2026-74943.html * https://www.suse.com/security/cve/CVE-2026-74944.html * https://www.suse.com/security/cve/CVE-2026-74945.html * https://www.suse.com/security/cve/CVE-2026-74946.html * https://www.suse.com/security/cve/CVE-2026-74947.html * https://www.suse.com/security/cve/CVE-2026-74948.html * https://www.suse.com/security/cve/CVE-2026-74949.html * https://www.suse.com/security/cve/CVE-2026-74950.html * https://www.suse.com/security/cve/CVE-2026-74953.html * https://www.suse.com/security/cve/CVE-2026-74954.html * https://www.suse.com/security/cve/CVE-2026-74955.html * https://www.suse.com/security/cve/CVE-2026-74956.html * https://www.suse.com/security/cve/CVE-2026-74957.html * https://www.suse.com/security/cve/CVE-2026-74958.html * https://www.suse.com/security/cve/CVE-2026-74959.html * https://www.suse.com/security/cve/CVE-2026-74960.html * https://www.suse.com/security/cve/CVE-2026-74961.html * https://www.suse.com/security/cve/CVE-2026-74962.html * https://www.suse.com/security/cve/CVE-2026-74963.html * https://www.suse.com/security/cve/CVE-2026-74964.html * https://www.suse.com/security/cve/CVE-2026-74965.html * https://www.suse.com/security/cve/CVE-2026-74966.html * https://www.suse.com/security/cve/CVE-2026-74967.html * https://www.suse.com/security/cve/CVE-2026-74968.html * https://www.suse.com/security/cve/CVE-2026-74969.html * https://www.suse.com/security/cve/CVE-2026-74970.html * https://www.suse.com/security/cve/CVE-2026-74971.html * https://www.suse.com/security/cve/CVE-2026-74972.html * https://www.suse.com/security/cve/CVE-2026-74973.html * https://www.suse.com/security/cve/CVE-2026-74974.html * https://www.suse.com/security/cve/CVE-2026-74976.html * https://www.suse.com/security/cve/CVE-2026-74977.html * https://www.suse.com/security/cve/CVE-2026-74978.html * https://www.suse.com/security/cve/CVE-2026-74979.html * https://www.suse.com/security/cve/CVE-2026-74981.html * https://www.suse.com/security/cve/CVE-2026-74982.html * https://www.suse.com/security/cve/CVE-2026-74983.html * https://www.suse.com/security/cve/CVE-2026-74984.html * https://www.suse.com/security/cve/CVE-2026-74985.html * https://www.suse.com/security/cve/CVE-2026-74986.html * https://www.suse.com/security/cve/CVE-2026-74987.html * https://www.suse.com/security/cve/CVE-2026-74988.html * https://www.suse.com/security/cve/CVE-2026-74990.html * https://bugzilla.suse.com/show_bug.cgi?id=1262698 * https://bugzilla.suse.com/show_bug.cgi?id=1262701 * https://bugzilla.suse.com/show_bug.cgi?id=1266262 * https://bugzilla.suse.com/show_bug.cgi?id=1266263 * https://bugzilla.suse.com/show_bug.cgi?id=1271649 * https://bugzilla.suse.com/show_bug.cgi?id=1272772 * https://bugzilla.suse.com/show_bug.cgi?id=1272773 * https://bugzilla.suse.com/show_bug.cgi?id=1272774 * https://bugzilla.suse.com/show_bug.cgi?id=1274867 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 2 12:33:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 02 Sep 2026 12:33:40 -0000 Subject: SUSE-SU-2026:23407-1: moderate: Security update for libgpg-error Message-ID: <178835242098.3792.14081287312361940678@feb3610e450a> # Security update for libgpg-error Announcement ID: SUSE-SU-2026:23407-1 Release Date: 2026-08-31T05:56:31Z Rating: moderate References: * bsc#1263078 Affected Products: * SUSE Linux Micro 6.2 An update that has one fix can now be installed. ## Description: This update for libgpg-error fixes the following issue: * Out-of-bounds read in `_gpgrt_vfnameconcat` of `stringutils.c` when the `GPGRT_FCONCAT_SYSCONF` flag is used (bsc#1263078). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1562=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libgpg-error0-debuginfo-1.58-160000.2.1 * libgpg-error-debugsource-1.58-160000.2.1 * libgpg-error0-1.58-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1263078 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 2 12:34:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 02 Sep 2026 12:34:47 -0000 Subject: SUSE-SU-2026:23405-1: important: Security update for udisks2 Message-ID: <178835248789.3792.15263716319617461121@feb3610e450a> # Security update for udisks2 Announcement ID: SUSE-SU-2026:23405-1 Release Date: 2026-08-30T15:19:49Z Rating: important References: * bsc#1274430 Cross-References: * CVE-2026-7867 CVSS scores: * CVE-2026-7867 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-7867 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for udisks2 fixes the following issue: * CVE-2026-7867: insufficient authorization checks on the `as-user` option in the `org.freedesktop.UDisks2.Filesystem.Mount()` D-Bus method can lead to local privilege escalation (bsc#1274430). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1560=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libudisks2-0_btrfs-2.10.1-160000.4.1 * udisks2-debuginfo-2.10.1-160000.4.1 * libudisks2-0-2.10.1-160000.4.1 * udisks2-debugsource-2.10.1-160000.4.1 * libudisks2-0_btrfs-debuginfo-2.10.1-160000.4.1 * libudisks2-0_lvm2-2.10.1-160000.4.1 * libudisks2-0-debuginfo-2.10.1-160000.4.1 * udisks2-2.10.1-160000.4.1 * libudisks2-0_lvm2-debuginfo-2.10.1-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-7867.html * https://bugzilla.suse.com/show_bug.cgi?id=1274430 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 2 12:35:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 02 Sep 2026 12:35:29 -0000 Subject: SUSE-SU-2026:23404-1: moderate: Security update for python-cryptography Message-ID: <178835252928.3792.3651716728720716990@feb3610e450a> # Security update for python-cryptography Announcement ID: SUSE-SU-2026:23404-1 Release Date: 2026-08-30T14:36:28Z Rating: moderate References: * bsc#1273516 * bsc#1273549 * bsc#1273551 Cross-References: * CVE-2026-69247 * CVE-2026-69248 * CVE-2026-69249 CVSS scores: * CVE-2026-69247 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-69247 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-69247 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-69248 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-69248 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-69248 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-69249 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-69249 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-69249 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-cryptography fixes the following issues: * CVE-2026-69247: PKCS#7 `EnvelopedData` decryption exposes a Bleichenbacher oracle through distinguishable errors and timing (bsc#1273551). * CVE-2026-69248: verifier accepts wildcard DNS names allowing escape from `permittedSubtrees` (bsc#1273549). * CVE-2026-69249: duplicate self-signed intermediates can cause exponential path-building (bsc#1273516). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1541=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * python313-cryptography-debuginfo-44.0.3-160000.5.1 * python313-cryptography-44.0.3-160000.5.1 * python-cryptography-debugsource-44.0.3-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-69247.html * https://www.suse.com/security/cve/CVE-2026-69248.html * https://www.suse.com/security/cve/CVE-2026-69249.html * https://bugzilla.suse.com/show_bug.cgi?id=1273516 * https://bugzilla.suse.com/show_bug.cgi?id=1273549 * https://bugzilla.suse.com/show_bug.cgi?id=1273551 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 2 12:37:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 02 Sep 2026 12:37:18 -0000 Subject: SUSE-SU-2026:23400-1: moderate: Security update for dhcpcd Message-ID: <178835263853.3792.10865345090286962896@feb3610e450a> # Security update for dhcpcd Announcement ID: SUSE-SU-2026:23400-1 Release Date: 2026-08-30T14:33:33Z Rating: moderate References: * bsc#1268968 * bsc#1268974 * bsc#1268976 * bsc#1268980 Cross-References: * CVE-2026-56113 * CVE-2026-56115 * CVE-2026-56116 * CVE-2026-56117 CVSS scores: * CVE-2026-56113 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56113 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56113 ( NVD ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56113 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56113 ( NVD ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56115 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56115 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56115 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56115 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56116 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56116 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56116 ( NVD ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56116 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56117 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56117 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56117 ( NVD ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56117 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56117 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves four vulnerabilities can now be installed. ## Description: This update for dhcpcd fixes the following issues: Update to 10.5.0. Security issues fixed: * CVE-2026-56113: crafted DHCPv6 RENEW reply can lead to a denial of service (bsc#1268980). * CVE-2026-56115: crafted DHCPv6 ADVERTISE message can cause a one-byte stack out-of-bounds write (bsc#1268976). * CVE-2026-56116: crafted Router Advertisements containing Route Information options with a zero lifetime can lead to a memory leak (bsc#1268974). * CVE-2026-56117: crafted privileged command sent over a writable control socket can lead to a heap use-after-free (bsc#1268968). Changes for dhcpcd: * 10.5.0: * Add missing SPDX-License tags * Format code with clang-format v19 * privsep: Change IPC to use SOCK_STREAM * BPF: Split OS specific code out into own files and add libpcap support * hooks: Escape interface names and use printf * Delete DHCPv6 IA FD from the loop before closing it * eloop: Use kqueue or epoll to wait for a fd to become ready * Darwin: Add initial support for macOS * Import latest pidfile from NetBSD * BPF: Improve headers * compat: Add support for getprogname(3) * route: Rework rt structure so sockaddrs are pointers * dhcp-common: Escape ifname for lease file * privsep: smaller buffer size without INET6 * script: add ifxname as the escaped string * time.h always pulls in struct timespec * route: Use HAVE_RT_MISSFILTER rather than a generic BSD define * privsep: Test defines for all ioctls * if: if_init inits the interface from the kernel * privsep: Add ps_root_gethostname * DHCP: Don't really expire the lease when testing * DHCP: Don't add a trailing : on vendor if no machine arch * privsep: guard setproctitle and only use compat on linux * options: Remove some const to fix compile warnings * privsep: Don't open PF_INET socket for each ioctl * sun: Enable building for privsep * script: Use correct buffer length variable * privsep: Remove PS_BUFLEN * privsep: Simplify readerror * timezone: disallow directory traversal * privsep: ps_root_readfile should return the real file size * linux: Ensure NLA data boundaries are valid * options: Fix userclass boundary * ND6: fix OOB reject mask for an undefined option. * DHCP6: Ensure IA_PD Prefix Lenth is valid * ND: Enforce require and reject policy * ARP: check we have enough to read the frame header * hooks: Quote assignment of compat vars correctly * udev: Ensure we have a subsystem, action and ifname * Fix CI build * DHCP: Santize messages from servers for output * ARP: Iterate over states safely as the cb could remove ours * privsep: Check data is terminated when a string * auth: clear keys with memset_explicit * auth: Ensure remaining dlen matches hash digest length * hooks: don't read past truncated ip6 address starting fe * ipv6: Only regen temp addrs with sufficent pltime * eloop: Improve timespecdiff * eloop: Fix compile warning where UTIME_MAX is a calculation * vsio: Allow zero length options * DHCP6: Fix configuring the suffix to delegated prefixes * IPv6: Fix numerous issues extending temporary address times * capsicum: Avoid some overflow issues in privsep sysctl * script: Fix buffer over and under flows in script_buftoenv * IPv4: uset old_ia when adding an address causes early removal * dhcp: add configurable backoff parameters for DHCPv4 * options: Introdce policy groups * Build all the targets on macos * control: remove unprivileged socket * DHCP: deconfigure even when state is NULL or NONE ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1548=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * dhcpcd-debugsource-10.5.0-160000.1.1 * dhcpcd-debuginfo-10.5.0-160000.1.1 * dhcpcd-10.5.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56113.html * https://www.suse.com/security/cve/CVE-2026-56115.html * https://www.suse.com/security/cve/CVE-2026-56116.html * https://www.suse.com/security/cve/CVE-2026-56117.html * https://bugzilla.suse.com/show_bug.cgi?id=1268968 * https://bugzilla.suse.com/show_bug.cgi?id=1268974 * https://bugzilla.suse.com/show_bug.cgi?id=1268976 * https://bugzilla.suse.com/show_bug.cgi?id=1268980 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 2 12:40:24 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 02 Sep 2026 12:40:24 -0000 Subject: SUSE-SU-2026:23393-1: important: Security update for vim Message-ID: <178835282455.3792.9090351225380773585@feb3610e450a> # Security update for vim Announcement ID: SUSE-SU-2026:23393-1 Release Date: 2026-08-28T08:28:19Z Rating: important References: * bsc#1268162 * bsc#1271684 * bsc#1275011 * bsc#1275012 * bsc#1275013 * bsc#1275014 * bsc#1275015 * bsc#1275016 * bsc#1275017 * bsc#1275018 Cross-References: * CVE-2026-73070 * CVE-2026-73071 * CVE-2026-73072 * CVE-2026-73074 * CVE-2026-73075 * CVE-2026-73076 * CVE-2026-73077 * CVE-2026-73078 CVSS scores: * CVE-2026-73070 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-73070 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-73070 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73071 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-73071 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-73071 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-73072 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73072 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-73072 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73074 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-73074 ( NVD ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73075 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-73075 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-73075 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73076 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73076 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-73076 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73077 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-73077 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73078 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73078 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-73078 ( NVD ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.2 An update that solves eight vulnerabilities and has two fixes can now be installed. ## Description: This update for vim fixes the following issues: Updated to version 9.2.0957. Security issues fixed: * CVE-2026-73070: stack buffer overflow in the socket server can lead to denial of service (bsc#1275018). * CVE-2026-73071: use-after-free in JSON decoding can lead to process crash (bsc#1275017). * CVE-2026-73072: heap buffer overflow when loading a spell file can lead to crash or potential code execution (bsc#1275016). * CVE-2026-73074: heap buffer overflow in text property handling can lead to a crash or potential code execution (bsc#1275015). * CVE-2026-73075: out-of-bounds access in popup opacity handling can lead to a conditional memory write (bsc#1275014). * CVE-2026-73076: arbitrary command execution via the vimball record file (bsc#1275013). * CVE-2026-73077: arbitrary code execution due to insecure shell command handling (bsc#1275012). * CVE-2026-73078: arbitrary code execution via crafted netrw menu entries (bsc#1275011). Other updates and bugfixes: * Version 9.2.0957. * tests: Test_fuzzy_completion_bufname_fullpath() creates unnecessary dir (9.2.0781). * tests: missing cleanup in test_mksession.vim (9.2.0782). * tests: personal spell files leak into later tests (9.2.0783). * crash when borrowing statusline highlight in silent Ex mode (9.2.0784). * WinResized not triggered when the whole Vim is resized (9.2.0785). * filetype: containerfile is not recognized (9.2.0786). * regexp: code 0x1ecb duplicated for equivalence class (9.2.0787). * filetype: hip files are not recognized (9.2.0788). * 'statuslineopt' status line too high after a window is minimized (9.2.0789). * 'completeslash' breaks :find completion with 'findfunc' (9.2.0790). * wincol() counts from right side for 'rightleft' (9.2.0791). * runtime(netrw): explore without optional dir broken (9.2.0792). * if session restored a tiny window, restore fails (9.2.0793). * extend() and extendnew() don't handle NULL expr2 properly (9.2.0794). * popup menu shadow is not cleared when the menu shrinks (9.2.0795). * Visual block reselection wrong with 'virtualedit' (9.2.0796). * memory leak in get_qfline_items() on alloc failure (9.2.0797). * memory leak in compile_expr6() on alloc failure (9.2.0798). * memory leak in compile_def_function_body() on alloc failure (9.2.0799). * memory leak in call_func() on alloc failure (9.2.0800). * memory leak in f_getreginfo() on alloc failure (9.2.0801). * memory leak with list_append_dict/dict_add_list on alloc failure (9.2.0802). * memory leak on alloc failure with taglist/gettagstack() (9.2.0803). * wincol() is wrong for a double-wide character with 'rightleft' (9.2.0804). * screenpos() "curscol" is wrong with 'rightleft' (9.2.0805). * 'showcmd' may show internal command keys (9.2.0806). * MS-Windows: ellipsis character is garbled (9.2.0807). * getregionpos: double-free on alloc failure (9.2.0808). * getframelayout() uses wrong function to free lists (9.2.0809). * add_llist_tags() uses wrong function to free dict (9.2.0810). * mksession writes terminal command unquoted (9.2.0811). * :argdelete with pattern leads to wrong argidx() (9.2.0812). * dict_add_func() may corrupt funcref count on failure (9.2.0813). * Vim9: E1041 when reloading an autoload script with exported variables (9.2.0814). * deeply nested regexp patterns may cause stack overflow (9.2.0815). * GTK4: memory leak in gui_gtk_set_dnd_targets() (9.2.0816). * crash when building a stacktrace during an autocommand (9.2.0817). * tests: client-server test fails without X11 server (9.2.0818). * MS-Windows: sixel image shown as raw text in the console (9.2.0819). * GUI: hidden popup image is displayed and not erased (9.2.0820). * filetype: msmtp system-wide rc file not detected (9.2.0821). * GTK4: crash menu id is null in gui_mch_destroy_menu() (9.2.0822). * tests: Test_clientserver_servlist_list may fail (9.2.0823). * Makefile: make tags depends on configure (9.2.0824). * regexp: submatch in a look-behind is empty with the NFA engine (9.2.0825). * highlighting for broken terminals can be improved (9.2.0826). * :startinsert enters Insert mode in a non-modifiable buffer (9.2.0827). * GTK4: hardware rendering can be improved (9.2.0828). * sessions do not preserve script version for expression options (9.2.0829). * the completion menu is not used on terminals without colors (9.2.0830). * diff highlighting hard to read with syntax enabled (9.2.0831). * socketserver: remote commands can be processed in reverse order (9.2.0832). * GTK4: menu mnemonics do not work properly (9.2.0833). * cleared last search pattern is restored from viminfo (9.2.0834). * features in version.c are not sorted (9.2.0835). * filetype: .git-blame-ignore-revs file is not recognized (9.2.0836). * using wrong colors in hl_blend_attr() (9.2.0837). * searchcount() returns wrong cached maxcount (9.2.0838). * [security]: arbitrary code execution via keyword lookup (9.2.0839). * [security]: code injection in netrw via bookmarks (9.2.0840). * [security]: heap overflow when adding > 65535 text properties (9.2.0841). * [security]: stack buffer overflow in socket server (9.2.0842). * [security]: popup: opacity mask indexed out of bounds (9.2.0843). * [security]: use-after-free on json decode error (9.2.0844). * [security]: arbitrary Ex command execution during C omni-completion (9.2.0845). * [security]: heap buffer overflow in set_sofo() (9.2.0846). * [security]: vimball: code execution via .VimballRecord file (9.2.0847). * tagfunc "cmd" with a generic Ex command corrupts the tag entry (9.2.0848). * filetype: osquery config files are not recognized (9.2.0849). * MS-Windows: commands from a client can be lost (9.2.0850). * focus autocommands triggered inconsistently (9.2.0851). * GTK: ligatures not correctly displayed (9.2.0852). * popup: popup images do not support scaling (9.2.0853). * memory leak when reading a spell file with SN_SAL and SN_SOFO (9.2.0854). * 'showcmd' not redrawn with empty mapping triggered on timeout (9.2.0855). * GTK4: undercurl rendering is inefficient (9.2.0856). * popup: opacity popup over a terminal is not cleared when closed (9.2.0857). * MS-Windows GUI: white flash when VimEnter is slow (9.2.0858). * GTK2: link error (9.2.0859). * filetype: xilinx design constraint files are not recognized (9.2.0860). * GTK4: bleed region updates in jumps (9.2.0861). * missing test change from v9.2.0857 (9.2.0862). * MS-Windows GUI: window contents can be missing when VimEnter is slow (9.2.0863). * using some dead code in Wayland feature (9.2.0864). * GTK4: non-hardware accelerated UI is too slow (9.2.0865). * MS-Windows: ":language messages" only works once (9.2.0866). * MS-Windows: messages are not in the display language (9.2.0867). * GTK: window Manager hint prevents giving focus to dialog (9.2.0868). * buf_copy_options() can lose the P_INSECURE flag (9.2.0869). * filetype: marko files are not recognized (9.2.0870). * screen line is lost when splitting a 'winfixheight' window (9.2.0871). * popup with opacity does not use the font of the highlight group (9.2.0872). * :redrawstatus does not update the ruler of the last window (9.2.0873). * fold size is compared against 'foldminlines' of the wrong window (9.2.0874). * GTK4: GUI does not support command-line arguments (9.2.0875). * GTK4: compile error with disabled netbeans feat (9.2.0876). * Vim9: crash when a closure assigns to a variable declared in a loop (9.2.0877). * Vim9: cannot use a script variable of an enclosing block in a lambda (9.2.0878). * popup: "maxwidth" is not respected when 'wrap' is off (9.2.0879). * scroll: window scrolls when using the autocommand window (9.2.0880). * 'smoothscroll' position is lost when the window height changes (9.2.0881). * :bwipe crashes if WinLeave wipes all other buffers (9.2.0882). * scroll: 'smoothscroll' position is lost when using "|" (9.2.0883). * scroll: unreachable 'smoothscroll' code in cursor_correct() (9.2.0884). * scroll: 'smoothscroll' position is lost when the window is squeezed (9.2.0885). * :set completion works for an invalid sub-option name (9.2.0886). * scroll: jump-scrolling when moving the cursor onto a wrapping line (9.2.0887). * mapping: modifier is not recognized after a partial mapping (9.2.0888). * VMS: spurious "INVALID DECC FEATURE VALUE" message at every startup (9.2.0889). * test: test for patch v9.2.0888 can be clarified (9.2.0890). * MS-Windows: filename-modifier ":8:t" causes underflow (9.2.0891). * highlight: wrong column highlighted with 'cursorcolumn' (9.2.0892). * MS-Windows: "*.vim" also matches files with a longer extension (9.2.0893). * filetype: ed script files not recognised (9.2.0894). * test: Test_aucmd_win_scroll_multibyte() is flaky in the GUI (9.2.0895). * scroll: 'smoothscroll' position is lost when splitting a window (9.2.0896). * GTK3 X11 redraws are not coalesced (9.2.0897). * printing support is lacking (9.2.0898). * command output temporary files may collide (9.2.0899). * FocusGained still triggered when closing dialog (9.2.0900). * textprop: wrong cursor line with truncated virtual text (9.2.0901). * Vim9: iterating over a tuple leaks memory (9.2.0902). * Vim9: cannot use an exported function of an autoload import (9.2.0903). * "zb" scrolls incorrectly with cursor just above fold (9.2.0904). * MS-Windows: ghost cursor with ligatures (9.2.0905). * slow transstr() with long strings (9.2.0906). * popup: virtual text is not redrawn when a text property changes (9.2.0907). * cannot use a {} block in a nested :autocmd (9.2.0908). * insert completion is slow to collect many matches (9.2.0909). * runtime(vim): update syntax, contain Ex commands (9.2.0910). * makefiles do not build hardcopy_postscript.c (9.2.0911). * hardcopy: prototypes are hand-written instead of generated (9.2.0912). * statusline: cell below the vertical separator keeps the old highlight (9.2.0913). * diff: undo after :diffget into an empty buffer leaves a line behind (9.2.0914). * tests: two terminal tests in test_popupwin fail on FreeBSD (9.2.0915). * configure: honor `--disable-hardcopy-pango` with GTK UI (9.2.0916). * :quitall not allowed in the command-line window (9.2.0917). * screen: fill char with a zero low byte is stored as a NUL cell (9.2.0918). * screen: the wrong array is copied into ScreenCols on a resize (9.2.0919). * filetype: json-ld files are not recognized (9.2.0920). * test: terminal tests fail on FreeBSD (9.2.0921). * Wayland: modeless selection not redrawn (9.2.0922). * tabpage: closing a tab page loses the alternate tab page (9.2.0923). * tests: Test_termwinscroll() fails on FreeBSD (9.2.0924). * crash when getcompletiontype() gets a NULL string (9.2.0925). * filetype: business Central files are not recognized (9.2.0926). * curswant not set on 8g8 (9.2.0927). * MinGW: tests hang when Vim is built with coverage enabled (9.2.0928). * incorrect completion for 'pumopt' and 'pumborder' (9.2.0929). * floating point exception when displaying pum (9.2.0930). * the GTK4 GUI is still experimental and untested by CI (9.2.0931). * NFA engine fallback can double free the compiled program (9.2.0932). * u_read_undo() leaks the file name when the undo file owner differs (9.2.0933). * filetype: hlsl files are not recognized (9.2.0934). * reading an undo file is slow with many undo headers (9.2.0935). * stringifying a list or dict can free the item being iterated (9.2.0936). * sort() with a numeric option converts each item on every comparison (9.2.0937). * cursorbind: cursor in the other window is not updated after undo (9.2.0938). * mbyte: wrong cell count for an overlong UTF-8 sequence (9.2.0939). * GTK4: columns are lost when a scrollbar appears (9.2.0940). * tests: clipboard tests fail in the GUI when the terminal has no clipboard (9.2.0941). * test: test_mksession_winpos() fails on GTK4 UI (9.2.0942). * test: test_hardcopy fails on GTK4 UI (9.2.0943). * test: tests fail when checking for GTK4 feature (9.2.0944). * sort() with a numeric option can be improved (9.2.0945). * GTK2/3: mouse move starts Visual selection after a dialog (9.2.0946). * GTK4: screen is cleared when moving the mouse after startup (9.2.0947). * GTK4: mouse move starts Visual selection after a dialog (9.2.0948). * GDK_KEY_VoidSymbol might be undefined (9.2.0949). * transstr() can be improved (after 9.2.0906) (9.2.0950). * GTK3: cursor does no longer blink (9.2.0951). * locking a container while stringifying can be improved (9.2.0952). * insert completion code can be improved (9.2.0953). * u_read_undo() can be improved (after 9.2.0935) (9.2.0954). * tests: terminal tests are flaky (9.2.0955). * GTK4: crash when the window is resized while redrawing (9.2.0956). * filetype: ArgoCD config file is not recognized (9.2.0957). * Allow `wrap` and `linebreak` to be set from a modeline (bsc#1268162). * Point `SYS_VIMRC_FILE` at `$VIMRUNTIME/suse.vimrc` rather than `/etc/vimrc`, which we no longer own (bsc#1268162). * Update `suse.vimrc`: source `/etc/vimrc` at the end of the file, so that a local system vimrc still overrides the distribution defaults. * Guard `suse.vimrc` against re-entry to prevent an infinite sourcing loop (bsc#1271684). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1530=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * vim-debugsource-9.2.0957-160000.1.1 * vim-small-debuginfo-9.2.0957-160000.1.1 * vim-debuginfo-9.2.0957-160000.1.1 * vim-small-9.2.0957-160000.1.1 * SUSE Linux Micro 6.2 (noarch) * vim-data-common-9.2.0957-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-73070.html * https://www.suse.com/security/cve/CVE-2026-73071.html * https://www.suse.com/security/cve/CVE-2026-73072.html * https://www.suse.com/security/cve/CVE-2026-73074.html * https://www.suse.com/security/cve/CVE-2026-73075.html * https://www.suse.com/security/cve/CVE-2026-73076.html * https://www.suse.com/security/cve/CVE-2026-73077.html * https://www.suse.com/security/cve/CVE-2026-73078.html * https://bugzilla.suse.com/show_bug.cgi?id=1268162 * https://bugzilla.suse.com/show_bug.cgi?id=1271684 * https://bugzilla.suse.com/show_bug.cgi?id=1275011 * https://bugzilla.suse.com/show_bug.cgi?id=1275012 * https://bugzilla.suse.com/show_bug.cgi?id=1275013 * https://bugzilla.suse.com/show_bug.cgi?id=1275014 * https://bugzilla.suse.com/show_bug.cgi?id=1275015 * https://bugzilla.suse.com/show_bug.cgi?id=1275016 * https://bugzilla.suse.com/show_bug.cgi?id=1275017 * https://bugzilla.suse.com/show_bug.cgi?id=1275018 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 2 12:41:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 02 Sep 2026 12:41:04 -0000 Subject: SUSE-SU-2026:23392-1: moderate: Security update for gzip Message-ID: <178835286448.3792.11162807341005962739@feb3610e450a> # Security update for gzip Announcement ID: SUSE-SU-2026:23392-1 Release Date: 2026-08-27T12:52:38Z Rating: moderate References: * bsc#1269623 * bsc#1272554 Cross-References: * CVE-2026-41992 CVSS scores: * CVE-2026-41992 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41992 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-41992 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41992 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability and has one fix can now be installed. ## Description: This update for gzip fixes the following issues: * CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623, bsc#1272554). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1529=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * gzip-1.13-160000.4.1 * gzip-debugsource-1.13-160000.4.1 * gzip-debuginfo-1.13-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41992.html * https://bugzilla.suse.com/show_bug.cgi?id=1269623 * https://bugzilla.suse.com/show_bug.cgi?id=1272554 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 2 12:41:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 02 Sep 2026 12:41:55 -0000 Subject: SUSE-SU-2026:23391-1: important: Security update for vim Message-ID: <178835291548.3792.9681724494484206965@feb3610e450a> # Security update for vim Announcement ID: SUSE-SU-2026:23391-1 Release Date: 2026-08-28T08:34:30Z Rating: important References: * bsc#1268162 * bsc#1271684 * bsc#1275011 * bsc#1275012 * bsc#1275013 * bsc#1275014 * bsc#1275015 * bsc#1275016 * bsc#1275017 * bsc#1275018 Cross-References: * CVE-2026-73070 * CVE-2026-73071 * CVE-2026-73072 * CVE-2026-73074 * CVE-2026-73075 * CVE-2026-73076 * CVE-2026-73077 * CVE-2026-73078 CVSS scores: * CVE-2026-73070 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-73070 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-73070 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73071 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-73071 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-73071 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-73072 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73072 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-73072 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73074 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-73074 ( NVD ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73075 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-73075 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-73075 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73076 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73076 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-73076 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73077 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-73077 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73078 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73078 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-73078 ( NVD ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that solves eight vulnerabilities and has two fixes can now be installed. ## Description: This update for vim fixes the following issues: Updated to version 9.2.0957. Security issues fixed: * CVE-2026-73070: stack buffer overflow in the socket server can lead to denial of service (bsc#1275018). * CVE-2026-73071: use-after-free in JSON decoding can lead to process crash (bsc#1275017). * CVE-2026-73072: heap buffer overflow when loading a spell file can lead to crash or potential code execution (bsc#1275016). * CVE-2026-73074: heap buffer overflow in text property handling can lead to a crash or potential code execution (bsc#1275015). * CVE-2026-73075: out-of-bounds access in popup opacity handling can lead to a conditional memory write (bsc#1275014). * CVE-2026-73076: arbitrary command execution via the vimball record file (bsc#1275013). * CVE-2026-73077: arbitrary code execution due to insecure shell command handling (bsc#1275012). * CVE-2026-73078: arbitrary code execution via crafted netrw menu entries (bsc#1275011). Other updates and bugfixes: * Version 9.2.0957. * tests: Test_fuzzy_completion_bufname_fullpath() creates unnecessary dir (9.2.0781). * tests: missing cleanup in test_mksession.vim (9.2.0782). * tests: personal spell files leak into later tests (9.2.0783). * crash when borrowing statusline highlight in silent Ex mode (9.2.0784). * WinResized not triggered when the whole Vim is resized (9.2.0785). * filetype: containerfile is not recognized (9.2.0786). * regexp: code 0x1ecb duplicated for equivalence class (9.2.0787). * filetype: hip files are not recognized (9.2.0788). * 'statuslineopt' status line too high after a window is minimized (9.2.0789). * 'completeslash' breaks :find completion with 'findfunc' (9.2.0790). * wincol() counts from right side for 'rightleft' (9.2.0791). * runtime(netrw): explore without optional dir broken (9.2.0792). * if session restored a tiny window, restore fails (9.2.0793). * extend() and extendnew() don't handle NULL expr2 properly (9.2.0794). * popup menu shadow is not cleared when the menu shrinks (9.2.0795). * Visual block reselection wrong with 'virtualedit' (9.2.0796). * memory leak in get_qfline_items() on alloc failure (9.2.0797). * memory leak in compile_expr6() on alloc failure (9.2.0798). * memory leak in compile_def_function_body() on alloc failure (9.2.0799). * memory leak in call_func() on alloc failure (9.2.0800). * memory leak in f_getreginfo() on alloc failure (9.2.0801). * memory leak with list_append_dict/dict_add_list on alloc failure (9.2.0802). * memory leak on alloc failure with taglist/gettagstack() (9.2.0803). * wincol() is wrong for a double-wide character with 'rightleft' (9.2.0804). * screenpos() "curscol" is wrong with 'rightleft' (9.2.0805). * 'showcmd' may show internal command keys (9.2.0806). * MS-Windows: ellipsis character is garbled (9.2.0807). * getregionpos: double-free on alloc failure (9.2.0808). * getframelayout() uses wrong function to free lists (9.2.0809). * add_llist_tags() uses wrong function to free dict (9.2.0810). * mksession writes terminal command unquoted (9.2.0811). * :argdelete with pattern leads to wrong argidx() (9.2.0812). * dict_add_func() may corrupt funcref count on failure (9.2.0813). * Vim9: E1041 when reloading an autoload script with exported variables (9.2.0814). * deeply nested regexp patterns may cause stack overflow (9.2.0815). * GTK4: memory leak in gui_gtk_set_dnd_targets() (9.2.0816). * crash when building a stacktrace during an autocommand (9.2.0817). * tests: client-server test fails without X11 server (9.2.0818). * MS-Windows: sixel image shown as raw text in the console (9.2.0819). * GUI: hidden popup image is displayed and not erased (9.2.0820). * filetype: msmtp system-wide rc file not detected (9.2.0821). * GTK4: crash menu id is null in gui_mch_destroy_menu() (9.2.0822). * tests: Test_clientserver_servlist_list may fail (9.2.0823). * Makefile: make tags depends on configure (9.2.0824). * regexp: submatch in a look-behind is empty with the NFA engine (9.2.0825). * highlighting for broken terminals can be improved (9.2.0826). * :startinsert enters Insert mode in a non-modifiable buffer (9.2.0827). * GTK4: hardware rendering can be improved (9.2.0828). * sessions do not preserve script version for expression options (9.2.0829). * the completion menu is not used on terminals without colors (9.2.0830). * diff highlighting hard to read with syntax enabled (9.2.0831). * socketserver: remote commands can be processed in reverse order (9.2.0832). * GTK4: menu mnemonics do not work properly (9.2.0833). * cleared last search pattern is restored from viminfo (9.2.0834). * features in version.c are not sorted (9.2.0835). * filetype: .git-blame-ignore-revs file is not recognized (9.2.0836). * using wrong colors in hl_blend_attr() (9.2.0837). * searchcount() returns wrong cached maxcount (9.2.0838). * [security]: arbitrary code execution via keyword lookup (9.2.0839). * [security]: code injection in netrw via bookmarks (9.2.0840). * [security]: heap overflow when adding > 65535 text properties (9.2.0841). * [security]: stack buffer overflow in socket server (9.2.0842). * [security]: popup: opacity mask indexed out of bounds (9.2.0843). * [security]: use-after-free on json decode error (9.2.0844). * [security]: arbitrary Ex command execution during C omni-completion (9.2.0845). * [security]: heap buffer overflow in set_sofo() (9.2.0846). * [security]: vimball: code execution via .VimballRecord file (9.2.0847). * tagfunc "cmd" with a generic Ex command corrupts the tag entry (9.2.0848). * filetype: osquery config files are not recognized (9.2.0849). * MS-Windows: commands from a client can be lost (9.2.0850). * focus autocommands triggered inconsistently (9.2.0851). * GTK: ligatures not correctly displayed (9.2.0852). * popup: popup images do not support scaling (9.2.0853). * memory leak when reading a spell file with SN_SAL and SN_SOFO (9.2.0854). * 'showcmd' not redrawn with empty mapping triggered on timeout (9.2.0855). * GTK4: undercurl rendering is inefficient (9.2.0856). * popup: opacity popup over a terminal is not cleared when closed (9.2.0857). * MS-Windows GUI: white flash when VimEnter is slow (9.2.0858). * GTK2: link error (9.2.0859). * filetype: xilinx design constraint files are not recognized (9.2.0860). * GTK4: bleed region updates in jumps (9.2.0861). * missing test change from v9.2.0857 (9.2.0862). * MS-Windows GUI: window contents can be missing when VimEnter is slow (9.2.0863). * using some dead code in Wayland feature (9.2.0864). * GTK4: non-hardware accelerated UI is too slow (9.2.0865). * MS-Windows: ":language messages" only works once (9.2.0866). * MS-Windows: messages are not in the display language (9.2.0867). * GTK: window Manager hint prevents giving focus to dialog (9.2.0868). * buf_copy_options() can lose the P_INSECURE flag (9.2.0869). * filetype: marko files are not recognized (9.2.0870). * screen line is lost when splitting a 'winfixheight' window (9.2.0871). * popup with opacity does not use the font of the highlight group (9.2.0872). * :redrawstatus does not update the ruler of the last window (9.2.0873). * fold size is compared against 'foldminlines' of the wrong window (9.2.0874). * GTK4: GUI does not support command-line arguments (9.2.0875). * GTK4: compile error with disabled netbeans feat (9.2.0876). * Vim9: crash when a closure assigns to a variable declared in a loop (9.2.0877). * Vim9: cannot use a script variable of an enclosing block in a lambda (9.2.0878). * popup: "maxwidth" is not respected when 'wrap' is off (9.2.0879). * scroll: window scrolls when using the autocommand window (9.2.0880). * 'smoothscroll' position is lost when the window height changes (9.2.0881). * :bwipe crashes if WinLeave wipes all other buffers (9.2.0882). * scroll: 'smoothscroll' position is lost when using "|" (9.2.0883). * scroll: unreachable 'smoothscroll' code in cursor_correct() (9.2.0884). * scroll: 'smoothscroll' position is lost when the window is squeezed (9.2.0885). * :set completion works for an invalid sub-option name (9.2.0886). * scroll: jump-scrolling when moving the cursor onto a wrapping line (9.2.0887). * mapping: modifier is not recognized after a partial mapping (9.2.0888). * VMS: spurious "INVALID DECC FEATURE VALUE" message at every startup (9.2.0889). * test: test for patch v9.2.0888 can be clarified (9.2.0890). * MS-Windows: filename-modifier ":8:t" causes underflow (9.2.0891). * highlight: wrong column highlighted with 'cursorcolumn' (9.2.0892). * MS-Windows: "*.vim" also matches files with a longer extension (9.2.0893). * filetype: ed script files not recognised (9.2.0894). * test: Test_aucmd_win_scroll_multibyte() is flaky in the GUI (9.2.0895). * scroll: 'smoothscroll' position is lost when splitting a window (9.2.0896). * GTK3 X11 redraws are not coalesced (9.2.0897). * printing support is lacking (9.2.0898). * command output temporary files may collide (9.2.0899). * FocusGained still triggered when closing dialog (9.2.0900). * textprop: wrong cursor line with truncated virtual text (9.2.0901). * Vim9: iterating over a tuple leaks memory (9.2.0902). * Vim9: cannot use an exported function of an autoload import (9.2.0903). * "zb" scrolls incorrectly with cursor just above fold (9.2.0904). * MS-Windows: ghost cursor with ligatures (9.2.0905). * slow transstr() with long strings (9.2.0906). * popup: virtual text is not redrawn when a text property changes (9.2.0907). * cannot use a {} block in a nested :autocmd (9.2.0908). * insert completion is slow to collect many matches (9.2.0909). * runtime(vim): update syntax, contain Ex commands (9.2.0910). * makefiles do not build hardcopy_postscript.c (9.2.0911). * hardcopy: prototypes are hand-written instead of generated (9.2.0912). * statusline: cell below the vertical separator keeps the old highlight (9.2.0913). * diff: undo after :diffget into an empty buffer leaves a line behind (9.2.0914). * tests: two terminal tests in test_popupwin fail on FreeBSD (9.2.0915). * configure: honor `--disable-hardcopy-pango` with GTK UI (9.2.0916). * :quitall not allowed in the command-line window (9.2.0917). * screen: fill char with a zero low byte is stored as a NUL cell (9.2.0918). * screen: the wrong array is copied into ScreenCols on a resize (9.2.0919). * filetype: json-ld files are not recognized (9.2.0920). * test: terminal tests fail on FreeBSD (9.2.0921). * Wayland: modeless selection not redrawn (9.2.0922). * tabpage: closing a tab page loses the alternate tab page (9.2.0923). * tests: Test_termwinscroll() fails on FreeBSD (9.2.0924). * crash when getcompletiontype() gets a NULL string (9.2.0925). * filetype: business Central files are not recognized (9.2.0926). * curswant not set on 8g8 (9.2.0927). * MinGW: tests hang when Vim is built with coverage enabled (9.2.0928). * incorrect completion for 'pumopt' and 'pumborder' (9.2.0929). * floating point exception when displaying pum (9.2.0930). * the GTK4 GUI is still experimental and untested by CI (9.2.0931). * NFA engine fallback can double free the compiled program (9.2.0932). * u_read_undo() leaks the file name when the undo file owner differs (9.2.0933). * filetype: hlsl files are not recognized (9.2.0934). * reading an undo file is slow with many undo headers (9.2.0935). * stringifying a list or dict can free the item being iterated (9.2.0936). * sort() with a numeric option converts each item on every comparison (9.2.0937). * cursorbind: cursor in the other window is not updated after undo (9.2.0938). * mbyte: wrong cell count for an overlong UTF-8 sequence (9.2.0939). * GTK4: columns are lost when a scrollbar appears (9.2.0940). * tests: clipboard tests fail in the GUI when the terminal has no clipboard (9.2.0941). * test: test_mksession_winpos() fails on GTK4 UI (9.2.0942). * test: test_hardcopy fails on GTK4 UI (9.2.0943). * test: tests fail when checking for GTK4 feature (9.2.0944). * sort() with a numeric option can be improved (9.2.0945). * GTK2/3: mouse move starts Visual selection after a dialog (9.2.0946). * GTK4: screen is cleared when moving the mouse after startup (9.2.0947). * GTK4: mouse move starts Visual selection after a dialog (9.2.0948). * GDK_KEY_VoidSymbol might be undefined (9.2.0949). * transstr() can be improved (after 9.2.0906) (9.2.0950). * GTK3: cursor does no longer blink (9.2.0951). * locking a container while stringifying can be improved (9.2.0952). * insert completion code can be improved (9.2.0953). * u_read_undo() can be improved (after 9.2.0935) (9.2.0954). * tests: terminal tests are flaky (9.2.0955). * GTK4: crash when the window is resized while redrawing (9.2.0956). * filetype: ArgoCD config file is not recognized (9.2.0957). * Allow `wrap` and `linebreak` to be set from a modeline (bsc#1268162). * Point `SYS_VIMRC_FILE` at `$VIMRUNTIME/suse.vimrc` rather than `/etc/vimrc`, which we no longer own (bsc#1268162). * Update `suse.vimrc`: source `/etc/vimrc` at the end of the file, so that a local system vimrc still overrides the distribution defaults. * Guard `suse.vimrc` against re-entry to prevent an infinite sourcing loop (bsc#1271684). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1530=1 ## Package List: * SUSE Linux Micro Extras 6.2 (aarch64 ppc64le s390x x86_64) * vim-debuginfo-9.2.0957-160000.1.1 * vim-debugsource-9.2.0957-160000.1.1 * xxd-9.2.0957-160000.1.1 * xxd-debuginfo-9.2.0957-160000.1.1 * vim-9.2.0957-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-73070.html * https://www.suse.com/security/cve/CVE-2026-73071.html * https://www.suse.com/security/cve/CVE-2026-73072.html * https://www.suse.com/security/cve/CVE-2026-73074.html * https://www.suse.com/security/cve/CVE-2026-73075.html * https://www.suse.com/security/cve/CVE-2026-73076.html * https://www.suse.com/security/cve/CVE-2026-73077.html * https://www.suse.com/security/cve/CVE-2026-73078.html * https://bugzilla.suse.com/show_bug.cgi?id=1268162 * https://bugzilla.suse.com/show_bug.cgi?id=1271684 * https://bugzilla.suse.com/show_bug.cgi?id=1275011 * https://bugzilla.suse.com/show_bug.cgi?id=1275012 * https://bugzilla.suse.com/show_bug.cgi?id=1275013 * https://bugzilla.suse.com/show_bug.cgi?id=1275014 * https://bugzilla.suse.com/show_bug.cgi?id=1275015 * https://bugzilla.suse.com/show_bug.cgi?id=1275016 * https://bugzilla.suse.com/show_bug.cgi?id=1275017 * https://bugzilla.suse.com/show_bug.cgi?id=1275018 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 2 12:42:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 02 Sep 2026 12:42:36 -0000 Subject: SUSE-SU-2026:3921-1: moderate: Security update for libgcrypt Message-ID: <178835295615.3792.5002652544998235610@feb3610e450a> # Security update for libgcrypt Announcement ID: SUSE-SU-2026:3921-1 Release Date: 2026-09-02T07:32:30Z Rating: moderate References: * bsc#1262684 Cross-References: * CVE-2026-41989 CVSS scores: * CVE-2026-41989 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41989 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-41989 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for libgcrypt fixes the following issue: * CVE-2026-41989: crafted ECDH ciphertext can lead denial of service (bsc#1262684). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3921=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3921=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3921=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3921=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3921=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libgcrypt20-hmac-1.9.4-150400.6.14.1 * libgcrypt20-debuginfo-1.9.4-150400.6.14.1 * libgcrypt-debugsource-1.9.4-150400.6.14.1 * libgcrypt20-1.9.4-150400.6.14.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libgcrypt20-hmac-1.9.4-150400.6.14.1 * libgcrypt20-debuginfo-1.9.4-150400.6.14.1 * libgcrypt-debugsource-1.9.4-150400.6.14.1 * libgcrypt20-1.9.4-150400.6.14.1 * openSUSE Leap 15.4 (x86_64) * libgcrypt20-32bit-1.9.4-150400.6.14.1 * libgcrypt20-hmac-32bit-1.9.4-150400.6.14.1 * libgcrypt-devel-32bit-debuginfo-1.9.4-150400.6.14.1 * libgcrypt20-32bit-debuginfo-1.9.4-150400.6.14.1 * libgcrypt-devel-32bit-1.9.4-150400.6.14.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libgcrypt-debugsource-1.9.4-150400.6.14.1 * libgcrypt20-hmac-1.9.4-150400.6.14.1 * libgcrypt-cavs-1.9.4-150400.6.14.1 * libgcrypt-cavs-debuginfo-1.9.4-150400.6.14.1 * libgcrypt-devel-1.9.4-150400.6.14.1 * libgcrypt20-debuginfo-1.9.4-150400.6.14.1 * libgcrypt-devel-debuginfo-1.9.4-150400.6.14.1 * libgcrypt20-1.9.4-150400.6.14.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libgcrypt-devel-64bit-1.9.4-150400.6.14.1 * libgcrypt-devel-64bit-debuginfo-1.9.4-150400.6.14.1 * libgcrypt20-hmac-64bit-1.9.4-150400.6.14.1 * libgcrypt20-64bit-debuginfo-1.9.4-150400.6.14.1 * libgcrypt20-64bit-1.9.4-150400.6.14.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libgcrypt20-hmac-1.9.4-150400.6.14.1 * libgcrypt20-debuginfo-1.9.4-150400.6.14.1 * libgcrypt-debugsource-1.9.4-150400.6.14.1 * libgcrypt20-1.9.4-150400.6.14.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libgcrypt20-hmac-1.9.4-150400.6.14.1 * libgcrypt20-debuginfo-1.9.4-150400.6.14.1 * libgcrypt-debugsource-1.9.4-150400.6.14.1 * libgcrypt20-1.9.4-150400.6.14.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41989.html * https://bugzilla.suse.com/show_bug.cgi?id=1262684 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 2 12:43:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 02 Sep 2026 12:43:51 -0000 Subject: SUSE-SU-2026:3919-1: critical: Security update for dovecot22 Message-ID: <178835303143.3792.245840537186211224@feb3610e450a> # Security update for dovecot22 Announcement ID: SUSE-SU-2026:3919-1 Release Date: 2026-09-02T07:31:58Z Rating: critical References: * bsc#1276792 * bsc#1276795 * bsc#1276799 * bsc#1276800 * bsc#1276802 * bsc#1276804 * bsc#1276809 * bsc#1276811 * bsc#1276812 * bsc#1276815 * bsc#1276817 * bsc#1276827 * bsc#1276833 * bsc#1276835 * bsc#1276837 Cross-References: * CVE-2026-27852 * CVE-2026-33604 * CVE-2026-33605 * CVE-2026-33606 * CVE-2026-33607 * CVE-2026-40014 * CVE-2026-40015 * CVE-2026-40019 * CVE-2026-40203 * CVE-2026-42007 * CVE-2026-42391 * CVE-2026-42393 * CVE-2026-52687 * CVE-2026-73209 CVSS scores: * CVE-2026-27852 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27852 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33604 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33604 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-33604 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-33605 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33605 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33605 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33606 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33606 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N * CVE-2026-33606 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N * CVE-2026-33607 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-33607 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33607 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40014 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40014 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-40014 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-40015 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-40015 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40015 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40019 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40019 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40019 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40203 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-40203 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-40203 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42007 ( SUSE ): 8.5 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-42007 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-42007 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-42391 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42391 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42391 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42393 ( SUSE ): 2.3 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-42393 ( SUSE ): 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42393 ( NVD ): 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-52687 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52687 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52687 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73209 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:L/SI:N/SA:N * CVE-2026-73209 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73209 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 14 vulnerabilities and has one security fix can now be installed. ## Description: This update for dovecot22 fixes the following issues: Security issues fixed: * CVE-2026-27852: DoS by sending mail with bad header (bsc#1276799). * CVE-2026-33604: SMTP smuggling via missing dot-stuffing after bare carriage return (bsc#1276802). * CVE-2026-33605: `managesieve-login`: pre-auth crash (bsc#1276809). * CVE-2026-33606: `dsync`: mail content can cause `dsync` protocol injection (bsc#1276800). * CVE-2026-33607: IMAP `LIST` `match_sub()` exponential backtracking leading to CPU denial of service (bsc#1276795). * CVE-2026-40014: CPU DoS via crafted references header (bsc#1276804). * CVE-2026-40015: `imap-hibernate` can be crashed (bsc#1276812). * CVE-2026-40019: `managesieve-login` pre-auth infinite loop (bsc#1276811). * CVE-2026-40203: IMAP compression can reveal whether a small synced email body matches sender-chosen text (bsc#1276815). * CVE-2026-42007: `sieve` `editheader` RCE (bsc#1276817). * CVE-2026-42391: `imap`: pre-login memory/CPU growth with `ID` command (bsc#1276835). * CVE-2026-42393: `doveadm_password` or api key length can be leaked with timing comparisons (bsc#1276827). * CVE-2026-52687: `imap`: `COMPRESS ZSTD` can cause excessive memory usage (bsc#1276837). * CVE-2026-73209: `imap-login` crash due to self-recursion on zero-output decompress chunks (bsc#1276833). * multiple security fixes (bsc#1276792). Other updates and bugfixes: * Non-CVE hardening taken from the same upstream release: * `sieve`: requiring the same extension repeatedly grew the default argument override chain, which is walked recursively - a crafted script could overflow the stack * `sieve`: `${unicode:...}` hex values could overflow an `unsigned int` and wrap back into the valid Unicode range; the hex parser also read one byte past the end of the buffer * `sieve` variables: the `${1234...}` numeric index overflowed a `signed int` * `sieve enotify`: a single script could emit an unlimited number of notification messages; limited to 10 as upstream does ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3919=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3919=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * dovecot22-backend-pgsql-2.2.31-19.40.1 * dovecot22-devel-2.2.31-19.40.1 * dovecot22-backend-sqlite-debuginfo-2.2.31-19.40.1 * dovecot22-backend-mysql-debuginfo-2.2.31-19.40.1 * dovecot22-debugsource-2.2.31-19.40.1 * dovecot22-backend-mysql-2.2.31-19.40.1 * dovecot22-debuginfo-2.2.31-19.40.1 * dovecot22-backend-pgsql-debuginfo-2.2.31-19.40.1 * dovecot22-2.2.31-19.40.1 * dovecot22-backend-sqlite-2.2.31-19.40.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * dovecot22-backend-pgsql-2.2.31-19.40.1 * dovecot22-devel-2.2.31-19.40.1 * dovecot22-backend-sqlite-debuginfo-2.2.31-19.40.1 * dovecot22-backend-mysql-debuginfo-2.2.31-19.40.1 * dovecot22-debugsource-2.2.31-19.40.1 * dovecot22-backend-mysql-2.2.31-19.40.1 * dovecot22-debuginfo-2.2.31-19.40.1 * dovecot22-backend-pgsql-debuginfo-2.2.31-19.40.1 * dovecot22-2.2.31-19.40.1 * dovecot22-backend-sqlite-2.2.31-19.40.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27852.html * https://www.suse.com/security/cve/CVE-2026-33604.html * https://www.suse.com/security/cve/CVE-2026-33605.html * https://www.suse.com/security/cve/CVE-2026-33606.html * https://www.suse.com/security/cve/CVE-2026-33607.html * https://www.suse.com/security/cve/CVE-2026-40014.html * https://www.suse.com/security/cve/CVE-2026-40015.html * https://www.suse.com/security/cve/CVE-2026-40019.html * https://www.suse.com/security/cve/CVE-2026-40203.html * https://www.suse.com/security/cve/CVE-2026-42007.html * https://www.suse.com/security/cve/CVE-2026-42391.html * https://www.suse.com/security/cve/CVE-2026-42393.html * https://www.suse.com/security/cve/CVE-2026-52687.html * https://www.suse.com/security/cve/CVE-2026-73209.html * https://bugzilla.suse.com/show_bug.cgi?id=1276792 * https://bugzilla.suse.com/show_bug.cgi?id=1276795 * https://bugzilla.suse.com/show_bug.cgi?id=1276799 * https://bugzilla.suse.com/show_bug.cgi?id=1276800 * https://bugzilla.suse.com/show_bug.cgi?id=1276802 * https://bugzilla.suse.com/show_bug.cgi?id=1276804 * https://bugzilla.suse.com/show_bug.cgi?id=1276809 * https://bugzilla.suse.com/show_bug.cgi?id=1276811 * https://bugzilla.suse.com/show_bug.cgi?id=1276812 * https://bugzilla.suse.com/show_bug.cgi?id=1276815 * https://bugzilla.suse.com/show_bug.cgi?id=1276817 * https://bugzilla.suse.com/show_bug.cgi?id=1276827 * https://bugzilla.suse.com/show_bug.cgi?id=1276833 * https://bugzilla.suse.com/show_bug.cgi?id=1276835 * https://bugzilla.suse.com/show_bug.cgi?id=1276837 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 2 20:30:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 02 Sep 2026 20:30:34 -0000 Subject: SUSE-SU-2026:3925-1: low: Security update for bzip2 Message-ID: <178838103406.4197.13967556407897435048@6bd16ccd9111> # Security update for bzip2 Announcement ID: SUSE-SU-2026:3925-1 Release Date: 2026-09-02T14:55:35Z Rating: low References: * bsc#1266786 Cross-References: * CVE-2026-42250 CVSS scores: * CVE-2026-42250 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42250 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-42250 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for bzip2 fixes the following issue: * CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3925=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libbz2-1-debuginfo-32bit-1.0.6-30.17.1 * bzip2-debuginfo-1.0.6-30.17.1 * libbz2-1-1.0.6-30.17.1 * bzip2-debugsource-1.0.6-30.17.1 * libbz2-1-32bit-1.0.6-30.17.1 * bzip2-1.0.6-30.17.1 * libbz2-devel-1.0.6-30.17.1 * libbz2-1-debuginfo-1.0.6-30.17.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * bzip2-doc-1.0.6-30.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42250.html * https://bugzilla.suse.com/show_bug.cgi?id=1266786 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 2 20:31:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 02 Sep 2026 20:31:15 -0000 Subject: SUSE-SU-2026:3924-1: moderate: Security update for texlive Message-ID: <178838107544.4197.6694854907472372140@6bd16ccd9111> # Security update for texlive Announcement ID: SUSE-SU-2026:3924-1 Release Date: 2026-09-02T14:55:26Z Rating: moderate References: * bsc#1272432 Cross-References: * CVE-2026-63729 CVSS scores: * CVE-2026-63729 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-63729 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-63729 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-63729 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for texlive fixes the following issue: * CVE-2026-63729: heap use-after-free in the SyncTeX parser can lead to application crash or arbitrary code execution when malformed `.synctex` or `.synctex.gz` files are processed(bsc#1272432). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3924=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libkpathsea6-debuginfo-6.2.0dev-22.14.1 * libkpathsea6-6.2.0dev-22.14.1 * texlive-ptexenc-devel-1.3.2dev-22.14.1 * texlive-bin-devel-2013.20130620-22.14.1 * texlive-kpathsea-devel-6.2.0dev-22.14.1 ## References: * https://www.suse.com/security/cve/CVE-2026-63729.html * https://bugzilla.suse.com/show_bug.cgi?id=1272432 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:31:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:31:01 -0000 Subject: SUSE-SU-2026:3955-1: important: Security update for kubevirt, virt-pr-helper-container Message-ID: <178843866197.2657.6183703651982489747@f2d94a75072c> # Security update for kubevirt, virt-pr-helper-container Announcement ID: SUSE-SU-2026:3955-1 Release Date: 2026-09-03T07:54:42Z Rating: important References: * bsc#1276520 Affected Products: * Containers Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has one security fix can now be installed. ## Description: This update for kubevirt, virt-pr-helper-container fixes the following issues: Changes in kubevirt: * Package the persistent-reservation helper's entrypoint script (bsc#1276520): virt-operator runs the pr-helper container with the command /entrypoint.sh, which symlinks the multipath socket into place and then execs qemu-pr- helper. Only multipath.conf was installed, so the container could not start and persistent reservation was unavailable. The script is upstream in cmd/pr-helper/entrypoint.sh. * Re-vendor google.golang.org/grpc v1.79.3 -> v1.82.1: GO-2026-6061 (GHSA- hrxh-6v49-42gf, no CVE id assigned yet) fixes flaws in the xDS RBAC authorization engine, which kubevirt does not vendor, and in the HTTP/2 transport server implementation (internal/transport), which kubevirt vendors and uses for the virt-handler and virt-launcher gRPC servers. Ride-along minimum-version bumps: google.golang.org/protobuf v1.36.10 -> v1.36.11, google.golang.org/genproto/googleapis/rpc to the 20260414 snapshot. * Run the Go unit tests of the pkg/ tree in %check (new bcond "check", default on; --without check disables). Two packages are excluded with reasons in the spec: the fuzz-seed suite and the virtctl root test fail identically on the unpatched source tree. * Sync all remaining fixes from the upstream release-1.7 branch head (upstream has cut no 1.7.5 tag since v1.7.4, 2026-06-01): * data race on the shared error variable in the abortChangeVMIs goroutine * virt-operator error paths: fix a nil-pointer dereference on shadowed variables and log resource names instead of full object dumps * add the --with-kubevirt-control-plane-label flag to csv-generator and manifest-templator * virtctl image-upload retried with the same upload token after it expired, so every remaining retry failed with 401; refresh the token between retries * virsh domcapabilities omitted features implicitly enabled by the base CPU model, leaving host-model-required-features node labels incomplete * validate existence and CSI support of PVC volumes before volume migration; incomplete MigratedVolumes entries silently broke the migration flow (file instead of block disk on the target) * test companion of the PVC validation fix * a migration whose target pod dies after proxy setup but before QEMU migration starts was never finalized, leaving the VMI migration state pending forever * set terminationGracePeriodSeconds 10 in the testing disks-images-provider manifest so pod teardown does not wait out a 30s grace period blocked on a foreground sleep * fix the Cirros boot order test on IPv6-only clusters * remove e2e tests that are redundant with unit coverage * the migration controller garbage-collected migration objects but left their old virt-launcher pods behind; clean both up together * virt-launcher stopped processing libvirt events while a domain was paused due to an I/O error; lifecycle events (migration started/ finished on the target), agent-sourced status (interfaces, OS info, fsFreeze) were dropped, and the domain state update itself only propagated if GetDiskErrors returned a faulty disk, leaving the VMI status stale until unpause. Backport of upstream commit 9f14a3450109 (PR#16778, released in v1.8.0), adapted to the 1.7 code base. Changes in virt-pr-helper-container: * Ship the pr-helper entrypoint script (bsc#1276520): virt-operator starts the pr-helper container with the command /entrypoint.sh, which symlinks the multipath socket into place and then execs qemu-pr-helper. The image contained only the bare binary, so enabling the PersistentReservation feature gate put every virt-handler pod into CrashLoopBackOff. Add entrypoint.sh (verbatim upstream cmd/pr-helper/entrypoint.sh) and hand the entrypoint to it. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3955=1 ## Package List: * Containers Module 15-SP7 (aarch64 x86_64) * kubevirt-virtctl-1.7.4-150700.3.39.1 * kubevirt-virtctl-debuginfo-1.7.4-150700.3.39.1 * kubevirt-manifests-1.7.4-150700.3.39.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1276520 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:31:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:31:40 -0000 Subject: SUSE-SU-2026:3954-1: important: Security update for cosign Message-ID: <178843870008.2657.15497411322824583921@f2d94a75072c> # Security update for cosign Announcement ID: SUSE-SU-2026:3954-1 Release Date: 2026-09-03T07:47:55Z Rating: important References: Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for cosign rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3954=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3954=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3954=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3954=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3954=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3954=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3954=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3954=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3954=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3954=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3954=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3954=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.1.2-150400.3.54.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * cosign-debuginfo-3.1.2-150400.3.54.1 * cosign-3.1.2-150400.3.54.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * cosign-debuginfo-3.1.2-150400.3.54.1 * cosign-3.1.2-150400.3.54.1 * Basesystem Module 15-SP7 (noarch) * cosign-zsh-completion-3.1.2-150400.3.54.1 * cosign-bash-completion-3.1.2-150400.3.54.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cosign-debuginfo-3.1.2-150400.3.54.1 * cosign-3.1.2-150400.3.54.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * cosign-3.1.2-150400.3.54.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * cosign-debuginfo-3.1.2-150400.3.54.1 * cosign-3.1.2-150400.3.54.1 * openSUSE Leap 15.4 (noarch) * cosign-fish-completion-3.1.2-150400.3.54.1 * cosign-zsh-completion-3.1.2-150400.3.54.1 * cosign-bash-completion-3.1.2-150400.3.54.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * cosign-3.1.2-150400.3.54.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * cosign-3.1.2-150400.3.54.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * cosign-3.1.2-150400.3.54.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * cosign-3.1.2-150400.3.54.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * cosign-3.1.2-150400.3.54.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * cosign-3.1.2-150400.3.54.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:32:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:32:35 -0000 Subject: SUSE-SU-2026:3953-1: important: Security update for apache2-mod_auth_openidc Message-ID: <178843875582.2657.12019275883012483560@f2d94a75072c> # Security update for apache2-mod_auth_openidc Announcement ID: SUSE-SU-2026:3953-1 Release Date: 2026-09-03T07:45:36Z Rating: important References: * bsc#1276217 Cross-References: * CVE-2026-54789 CVSS scores: * CVE-2026-54789 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54789 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for apache2-mod_auth_openidc fixes the following issue: * CVE-2026-54789: out-of-bounds read and one-byte out-of-bounds write in the state-cookie parser of `mod_auth_openidc` (bsc#1276217). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3953=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3953=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3953=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3953=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3953=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3953=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3953=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3953=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * apache2-mod_auth_openidc-debugsource-2.4.17.1-150100.3.40.1 * apache2-mod_auth_openidc-2.4.17.1-150100.3.40.1 * apache2-mod_auth_openidc-debuginfo-2.4.17.1-150100.3.40.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * apache2-mod_auth_openidc-debugsource-2.4.17.1-150100.3.40.1 * apache2-mod_auth_openidc-2.4.17.1-150100.3.40.1 * apache2-mod_auth_openidc-debuginfo-2.4.17.1-150100.3.40.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * apache2-mod_auth_openidc-debugsource-2.4.17.1-150100.3.40.1 * apache2-mod_auth_openidc-2.4.17.1-150100.3.40.1 * apache2-mod_auth_openidc-debuginfo-2.4.17.1-150100.3.40.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * apache2-mod_auth_openidc-2.4.17.1-150100.3.40.1 * apache2-mod_auth_openidc-debugsource-2.4.17.1-150100.3.40.1 * apache2-mod_auth_openidc-debuginfo-2.4.17.1-150100.3.40.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * apache2-mod_auth_openidc-2.4.17.1-150100.3.40.1 * apache2-mod_auth_openidc-debugsource-2.4.17.1-150100.3.40.1 * apache2-mod_auth_openidc-debuginfo-2.4.17.1-150100.3.40.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * apache2-mod_auth_openidc-debugsource-2.4.17.1-150100.3.40.1 * apache2-mod_auth_openidc-2.4.17.1-150100.3.40.1 * apache2-mod_auth_openidc-debuginfo-2.4.17.1-150100.3.40.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * apache2-mod_auth_openidc-2.4.17.1-150100.3.40.1 * apache2-mod_auth_openidc-debugsource-2.4.17.1-150100.3.40.1 * apache2-mod_auth_openidc-debuginfo-2.4.17.1-150100.3.40.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * apache2-mod_auth_openidc-2.4.17.1-150100.3.40.1 * apache2-mod_auth_openidc-debugsource-2.4.17.1-150100.3.40.1 * apache2-mod_auth_openidc-debuginfo-2.4.17.1-150100.3.40.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54789.html * https://bugzilla.suse.com/show_bug.cgi?id=1276217 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:33:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:33:15 -0000 Subject: SUSE-SU-2026:3952-1: important: Security update for apache2-mod_auth_openidc Message-ID: <178843879511.2657.13706959670804930116@f2d94a75072c> # Security update for apache2-mod_auth_openidc Announcement ID: SUSE-SU-2026:3952-1 Release Date: 2026-09-03T07:43:50Z Rating: important References: * bsc#1276217 Cross-References: * CVE-2026-54789 CVSS scores: * CVE-2026-54789 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54789 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for apache2-mod_auth_openidc fixes the following issue: * CVE-2026-54789: out-of-bounds read and one-byte out-of-bounds write in the state-cookie parser of `mod_auth_openidc` (bsc#1276217). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3952=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3952=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3952=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3952=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * apache2-mod_auth_openidc-debuginfo-2.4.17.1-150600.16.20.1 * apache2-mod_auth_openidc-2.4.17.1-150600.16.20.1 * apache2-mod_auth_openidc-debugsource-2.4.17.1-150600.16.20.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * apache2-mod_auth_openidc-debuginfo-2.4.17.1-150600.16.20.1 * apache2-mod_auth_openidc-2.4.17.1-150600.16.20.1 * apache2-mod_auth_openidc-debugsource-2.4.17.1-150600.16.20.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * apache2-mod_auth_openidc-debuginfo-2.4.17.1-150600.16.20.1 * apache2-mod_auth_openidc-2.4.17.1-150600.16.20.1 * apache2-mod_auth_openidc-debugsource-2.4.17.1-150600.16.20.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * apache2-mod_auth_openidc-debuginfo-2.4.17.1-150600.16.20.1 * apache2-mod_auth_openidc-2.4.17.1-150600.16.20.1 * apache2-mod_auth_openidc-debugsource-2.4.17.1-150600.16.20.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54789.html * https://bugzilla.suse.com/show_bug.cgi?id=1276217 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:34:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:34:12 -0000 Subject: SUSE-SU-2026:3951-1: moderate: Security update for erlang Message-ID: <178843885260.2657.7737907599481603816@f2d94a75072c> # Security update for erlang Announcement ID: SUSE-SU-2026:3951-1 Release Date: 2026-09-03T07:43:15Z Rating: moderate References: * bsc#1262503 Cross-References: * CVE-2026-32147 CVSS scores: * CVE-2026-32147 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-32147 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-32147 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-32147 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Affected Products: * openSUSE Leap 15.3 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for erlang fixes the following issue: * CVE-2026-32147: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in SFTP chroot (bsc#1262503). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3951=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-3951=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * erlang-diameter-23.3.4.19-150300.3.42.1 * erlang-doc-23.3.4.19-150300.3.42.1 * erlang-reltool-src-23.3.4.19-150300.3.42.1 * erlang-diameter-src-23.3.4.19-150300.3.42.1 * erlang-wx-src-23.3.4.19-150300.3.42.1 * erlang-wx-23.3.4.19-150300.3.42.1 * erlang-debugsource-23.3.4.19-150300.3.42.1 * erlang-dialyzer-debuginfo-23.3.4.19-150300.3.42.1 * erlang-observer-23.3.4.19-150300.3.42.1 * erlang-23.3.4.19-150300.3.42.1 * erlang-jinterface-23.3.4.19-150300.3.42.1 * erlang-jinterface-src-23.3.4.19-150300.3.42.1 * erlang-epmd-23.3.4.19-150300.3.42.1 * erlang-src-23.3.4.19-150300.3.42.1 * erlang-debuginfo-23.3.4.19-150300.3.42.1 * erlang-dialyzer-src-23.3.4.19-150300.3.42.1 * erlang-et-src-23.3.4.19-150300.3.42.1 * erlang-debugger-src-23.3.4.19-150300.3.42.1 * erlang-wx-debuginfo-23.3.4.19-150300.3.42.1 * erlang-epmd-debuginfo-23.3.4.19-150300.3.42.1 * erlang-dialyzer-23.3.4.19-150300.3.42.1 * erlang-observer-src-23.3.4.19-150300.3.42.1 * erlang-debugger-23.3.4.19-150300.3.42.1 * erlang-reltool-23.3.4.19-150300.3.42.1 * erlang-et-23.3.4.19-150300.3.42.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * erlang-epmd-23.3.4.19-150300.3.42.1 * erlang-23.3.4.19-150300.3.42.1 * erlang-epmd-debuginfo-23.3.4.19-150300.3.42.1 * erlang-debuginfo-23.3.4.19-150300.3.42.1 * erlang-debugsource-23.3.4.19-150300.3.42.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32147.html * https://bugzilla.suse.com/show_bug.cgi?id=1262503 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:35:08 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:35:08 -0000 Subject: SUSE-SU-2026:3950-1: moderate: Security update for quagga Message-ID: <178843890838.2657.3902440328711949673@f2d94a75072c> # Security update for quagga Announcement ID: SUSE-SU-2026:3950-1 Release Date: 2026-09-03T07:42:27Z Rating: moderate References: * bsc#1263974 Cross-References: * CVE-2026-37458 CVSS scores: * CVE-2026-37458 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-37458 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-37458 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for quagga fixes the following issue: * CVE-2026-37458: missing input validation in the `MP_REACH_NLRI` component allows authenticated attackers to cause a DoS via a crafted UPDATE message (bsc#1263974). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3950=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libfpm_pb0-1.1.1-150400.12.11.1 * libospf0-1.1.1-150400.12.11.1 * quagga-debuginfo-1.1.1-150400.12.11.1 * quagga-devel-1.1.1-150400.12.11.1 * quagga-1.1.1-150400.12.11.1 * libzebra1-1.1.1-150400.12.11.1 * libospf0-debuginfo-1.1.1-150400.12.11.1 * libzebra1-debuginfo-1.1.1-150400.12.11.1 * libquagga_pb0-1.1.1-150400.12.11.1 * quagga-debugsource-1.1.1-150400.12.11.1 * libquagga_pb0-debuginfo-1.1.1-150400.12.11.1 * libospfapiclient0-debuginfo-1.1.1-150400.12.11.1 * libfpm_pb0-debuginfo-1.1.1-150400.12.11.1 * libospfapiclient0-1.1.1-150400.12.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-37458.html * https://bugzilla.suse.com/show_bug.cgi?id=1263974 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:36:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:36:04 -0000 Subject: SUSE-SU-2026:3949-1: important: Security update for yast2-users Message-ID: <178843896431.2657.15382959252313598920@f2d94a75072c> # Security update for yast2-users Announcement ID: SUSE-SU-2026:3949-1 Release Date: 2026-09-03T07:42:03Z Rating: important References: * bsc#1272839 Cross-References: * CVE-2026-59680 CVSS scores: * CVE-2026-59680 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59680 ( NVD ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59680 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for yast2-users fixes the following issue: Update to version 4.7.2. * CVE-2026-59680: OS command injection via LDAP-supplied `shadowLastChange`/`shadowExpire` attribute (bsc#1272839). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP7 zypper in -t patch SUSE-SLE-INSTALLER-15-SP7-2026-3949=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3949=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 zypper in -t patch SUSE-SLE-INSTALLER-15-SP7-2026-3949=1 * SUSE Linux Enterprise High Performance Computing 15 SP7 zypper in -t patch SUSE-SLE-INSTALLER-15-SP7-2026-3949=1 * SUSE Linux Enterprise Desktop 15 SP7 zypper in -t patch SUSE-SLE-INSTALLER-15-SP7-2026-3949=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * yast2-users-debuginfo-4.7.2-150700.3.8.1 * yast2-users-4.7.2-150700.3.8.1 * yast2-users-debugsource-4.7.2-150700.3.8.1 * SUSE Linux Enterprise Server 15 SP7 (aarch64 ppc64le s390x x86_64) * yast2-users-4.7.2-150700.3.8.1 * SUSE Linux Enterprise High Performance Computing 15 SP7 (aarch64 x86_64) * yast2-users-4.7.2-150700.3.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 (ppc64le x86_64) * yast2-users-4.7.2-150700.3.8.1 * SUSE Linux Enterprise Desktop 15 SP7 (x86_64) * yast2-users-4.7.2-150700.3.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59680.html * https://bugzilla.suse.com/show_bug.cgi?id=1272839 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:36:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:36:43 -0000 Subject: SUSE-SU-2026:3948-1: important: Security update for yast2-users Message-ID: <178843900331.2657.17926431058304650943@f2d94a75072c> # Security update for yast2-users Announcement ID: SUSE-SU-2026:3948-1 Release Date: 2026-09-03T07:41:33Z Rating: important References: * bsc#1272839 Cross-References: * CVE-2026-59680 CVSS scores: * CVE-2026-59680 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59680 ( NVD ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59680 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for yast2-users fixes the following issue: Update to version 4.6.7. * CVE-2026-59680: OS command injection via LDAP-supplied `shadowLastChange`/`shadowExpire` attribute (bsc#1272839). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3948=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3948=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3948=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * yast2-users-4.6.7-150600.3.6.1 * yast2-users-debugsource-4.6.7-150600.3.6.1 * yast2-users-debuginfo-4.6.7-150600.3.6.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * yast2-users-4.6.7-150600.3.6.1 * yast2-users-debugsource-4.6.7-150600.3.6.1 * yast2-users-debuginfo-4.6.7-150600.3.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * yast2-users-4.6.7-150600.3.6.1 * yast2-users-debugsource-4.6.7-150600.3.6.1 * yast2-users-debuginfo-4.6.7-150600.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59680.html * https://bugzilla.suse.com/show_bug.cgi?id=1272839 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:37:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:37:41 -0000 Subject: SUSE-SU-2026:3947-1: important: Security update for yast2-users Message-ID: <178843906121.2657.13059146938717787474@f2d94a75072c> # Security update for yast2-users Announcement ID: SUSE-SU-2026:3947-1 Release Date: 2026-09-03T07:41:06Z Rating: important References: * bsc#1272839 Cross-References: * CVE-2026-59680 CVSS scores: * CVE-2026-59680 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59680 ( NVD ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59680 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for yast2-users fixes the following issue: Update to version 4.5.8. * CVE-2026-59680: OS command injection via LDAP-supplied `shadowLastChange`/`shadowExpire` attribute (bsc#1272839). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3947=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3947=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3947=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3947=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3947=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * yast2-users-4.5.8-150500.3.11.1 * yast2-users-debuginfo-4.5.8-150500.3.11.1 * yast2-users-debugsource-4.5.8-150500.3.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * yast2-users-4.5.8-150500.3.11.1 * yast2-users-debuginfo-4.5.8-150500.3.11.1 * yast2-users-debugsource-4.5.8-150500.3.11.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * yast2-users-4.5.8-150500.3.11.1 * yast2-users-debuginfo-4.5.8-150500.3.11.1 * yast2-users-debugsource-4.5.8-150500.3.11.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * yast2-users-4.5.8-150500.3.11.1 * yast2-users-debuginfo-4.5.8-150500.3.11.1 * yast2-users-debugsource-4.5.8-150500.3.11.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * yast2-users-4.5.8-150500.3.11.1 * yast2-users-debuginfo-4.5.8-150500.3.11.1 * yast2-users-debugsource-4.5.8-150500.3.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59680.html * https://bugzilla.suse.com/show_bug.cgi?id=1272839 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:38:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:38:36 -0000 Subject: SUSE-SU-2026:3946-1: important: Security update for yast2-users Message-ID: <178843911670.2657.13363643582431835130@f2d94a75072c> # Security update for yast2-users Announcement ID: SUSE-SU-2026:3946-1 Release Date: 2026-09-03T07:40:21Z Rating: important References: * bsc#1272839 Cross-References: * CVE-2026-59680 CVSS scores: * CVE-2026-59680 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59680 ( NVD ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59680 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for yast2-users fixes the following issue: Update to version 4.4.17. * CVE-2026-59680: OS command injection via LDAP-supplied `shadowLastChange`/`shadowExpire` attribute (bsc#1272839). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3946=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3946=1 * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3946=1 * SUSE Linux Enterprise Server 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3946=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3946=1 SUSE-SLE-Product- SLES_SAP-15-SP4-2026-3946=1 * SUSE Linux Enterprise High Performance Computing 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3946=1 * SUSE Linux Enterprise Desktop 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3946=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3946=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-3946=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3946=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3946=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * yast2-users-4.4.17-150400.3.21.1 * yast2-users-debugsource-4.4.17-150400.3.21.1 * yast2-users-debuginfo-4.4.17-150400.3.21.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * yast2-users-debuginfo-4.4.17-150400.3.21.1 * yast2-users-4.4.17-150400.3.21.1 * yast2-users-debugsource-4.4.17-150400.3.21.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * yast2-users-4.4.17-150400.3.21.1 * yast2-users-debugsource-4.4.17-150400.3.21.1 * yast2-users-debuginfo-4.4.17-150400.3.21.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * yast2-users-4.4.17-150400.3.21.1 * yast2-users-debugsource-4.4.17-150400.3.21.1 * yast2-users-debuginfo-4.4.17-150400.3.21.1 * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * yast2-users-4.4.17-150400.3.21.1 * SUSE Linux Enterprise Server 15 SP4 (aarch64 ppc64le s390x x86_64) * yast2-users-4.4.17-150400.3.21.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * yast2-users-debuginfo-4.4.17-150400.3.21.1 * yast2-users-4.4.17-150400.3.21.1 * yast2-users-debugsource-4.4.17-150400.3.21.1 * SUSE Linux Enterprise High Performance Computing 15 SP4 (aarch64 x86_64) * yast2-users-4.4.17-150400.3.21.1 * SUSE Linux Enterprise Desktop 15 SP4 (x86_64) * yast2-users-4.4.17-150400.3.21.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * yast2-users-4.4.17-150400.3.21.1 * SUSE Manager Proxy 4.3 (x86_64) * yast2-users-4.4.17-150400.3.21.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59680.html * https://bugzilla.suse.com/show_bug.cgi?id=1272839 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:39:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:39:41 -0000 Subject: SUSE-SU-2026:3945-1: important: Security update for yast2-users Message-ID: <178843918165.2657.7425804439408430450@f2d94a75072c> # Security update for yast2-users Announcement ID: SUSE-SU-2026:3945-1 Release Date: 2026-09-03T07:38:59Z Rating: important References: * bsc#1272839 Cross-References: * CVE-2026-59680 CVSS scores: * CVE-2026-59680 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59680 ( NVD ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59680 ( NVD ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for yast2-users fixes the following issue: Update to version 3.2.20. * CVE-2026-59680: OS command injection via LDAP-supplied `shadowLastChange`/`shadowExpire` attribute (bsc#1272839). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3945=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3945=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * yast2-users-debugsource-3.2.20-3.3.1 * yast2-users-3.2.20-3.3.1 * yast2-users-debuginfo-3.2.20-3.3.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * yast2-users-debugsource-3.2.20-3.3.1 * yast2-users-3.2.20-3.3.1 * yast2-users-debuginfo-3.2.20-3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59680.html * https://bugzilla.suse.com/show_bug.cgi?id=1272839 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:40:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:40:52 -0000 Subject: SUSE-SU-2026:3944-1: important: Security update for postgresql14 Message-ID: <178843925227.2657.6514239653555050069@f2d94a75072c> # Security update for postgresql14 Announcement ID: SUSE-SU-2026:3944-1 Release Date: 2026-09-03T07:38:15Z Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275053 * bsc#1275054 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275061 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14673 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14662 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14664 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14666 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14668 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14669 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14673 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14673 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14678 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14679 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14680 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15741 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15741 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15742 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16241 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18024 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18408 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19385 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6464 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6469 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6470 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6471 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * Legacy Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for postgresql14 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). * CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). * CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql14: * Update to version 14.24: * https://www.postgresql.org/docs/14/release-14-24.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3944=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3944=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-3944=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3944=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3944=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * postgresql14-server-devel-debuginfo-14.24-150600.16.36.1 * postgresql14-llvmjit-14.24-150600.16.36.1 * postgresql14-test-14.24-150600.16.36.1 * postgresql14-devel-debuginfo-14.24-150600.16.36.1 * postgresql14-plperl-debuginfo-14.24-150600.16.36.1 * postgresql14-contrib-14.24-150600.16.36.1 * postgresql14-server-14.24-150600.16.36.1 * postgresql14-plpython-debuginfo-14.24-150600.16.36.1 * postgresql14-plperl-14.24-150600.16.36.1 * postgresql14-debuginfo-14.24-150600.16.36.1 * postgresql14-pltcl-debuginfo-14.24-150600.16.36.1 * postgresql14-plpython-14.24-150600.16.36.1 * postgresql14-server-debuginfo-14.24-150600.16.36.1 * postgresql14-14.24-150600.16.36.1 * postgresql14-devel-14.24-150600.16.36.1 * postgresql14-pltcl-14.24-150600.16.36.1 * postgresql14-contrib-debuginfo-14.24-150600.16.36.1 * postgresql14-llvmjit-debuginfo-14.24-150600.16.36.1 * postgresql14-server-devel-14.24-150600.16.36.1 * postgresql14-llvmjit-devel-14.24-150600.16.36.1 * postgresql14-debugsource-14.24-150600.16.36.1 * openSUSE Leap 15.6 (noarch) * postgresql14-docs-14.24-150600.16.36.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * postgresql14-plpython-14.24-150600.16.36.1 * postgresql14-plpython-debuginfo-14.24-150600.16.36.1 * postgresql14-server-devel-debuginfo-14.24-150600.16.36.1 * postgresql14-server-debuginfo-14.24-150600.16.36.1 * postgresql14-14.24-150600.16.36.1 * postgresql14-devel-14.24-150600.16.36.1 * postgresql14-plperl-14.24-150600.16.36.1 * postgresql14-pltcl-14.24-150600.16.36.1 * postgresql14-server-devel-14.24-150600.16.36.1 * postgresql14-devel-debuginfo-14.24-150600.16.36.1 * postgresql14-plperl-debuginfo-14.24-150600.16.36.1 * postgresql14-contrib-14.24-150600.16.36.1 * postgresql14-server-14.24-150600.16.36.1 * postgresql14-pltcl-debuginfo-14.24-150600.16.36.1 * postgresql14-debuginfo-14.24-150600.16.36.1 * postgresql14-contrib-debuginfo-14.24-150600.16.36.1 * postgresql14-debugsource-14.24-150600.16.36.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * postgresql14-docs-14.24-150600.16.36.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * postgresql14-plpython-14.24-150600.16.36.1 * postgresql14-server-devel-debuginfo-14.24-150600.16.36.1 * postgresql14-plpython-debuginfo-14.24-150600.16.36.1 * postgresql14-server-debuginfo-14.24-150600.16.36.1 * postgresql14-14.24-150600.16.36.1 * postgresql14-devel-14.24-150600.16.36.1 * postgresql14-contrib-debuginfo-14.24-150600.16.36.1 * postgresql14-plperl-14.24-150600.16.36.1 * postgresql14-pltcl-14.24-150600.16.36.1 * postgresql14-devel-debuginfo-14.24-150600.16.36.1 * postgresql14-plperl-debuginfo-14.24-150600.16.36.1 * postgresql14-contrib-14.24-150600.16.36.1 * postgresql14-server-14.24-150600.16.36.1 * postgresql14-debuginfo-14.24-150600.16.36.1 * postgresql14-pltcl-debuginfo-14.24-150600.16.36.1 * postgresql14-server-devel-14.24-150600.16.36.1 * postgresql14-debugsource-14.24-150600.16.36.1 * Legacy Module 15-SP7 (noarch) * postgresql14-docs-14.24-150600.16.36.1 * Legacy Module 15-SP7 (ppc64le s390x x86_64) * postgresql14-test-14.24-150600.16.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * postgresql14-plpython-debuginfo-14.24-150600.16.36.1 * postgresql14-plpython-14.24-150600.16.36.1 * postgresql14-server-devel-debuginfo-14.24-150600.16.36.1 * postgresql14-server-debuginfo-14.24-150600.16.36.1 * postgresql14-14.24-150600.16.36.1 * postgresql14-devel-14.24-150600.16.36.1 * postgresql14-contrib-debuginfo-14.24-150600.16.36.1 * postgresql14-plperl-14.24-150600.16.36.1 * postgresql14-pltcl-14.24-150600.16.36.1 * postgresql14-devel-debuginfo-14.24-150600.16.36.1 * postgresql14-plperl-debuginfo-14.24-150600.16.36.1 * postgresql14-contrib-14.24-150600.16.36.1 * postgresql14-debuginfo-14.24-150600.16.36.1 * postgresql14-server-14.24-150600.16.36.1 * postgresql14-pltcl-debuginfo-14.24-150600.16.36.1 * postgresql14-server-devel-14.24-150600.16.36.1 * postgresql14-debugsource-14.24-150600.16.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * postgresql14-docs-14.24-150600.16.36.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * postgresql14-llvmjit-14.24-150600.16.36.1 * postgresql14-test-14.24-150600.16.36.1 * postgresql14-llvmjit-debuginfo-14.24-150600.16.36.1 * postgresql14-debuginfo-14.24-150600.16.36.1 * postgresql14-debugsource-14.24-150600.16.36.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14673.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html * https://bugzilla.suse.com/show_bug.cgi?id=1275001 * https://bugzilla.suse.com/show_bug.cgi?id=1275002 * https://bugzilla.suse.com/show_bug.cgi?id=1275042 * https://bugzilla.suse.com/show_bug.cgi?id=1275043 * https://bugzilla.suse.com/show_bug.cgi?id=1275044 * https://bugzilla.suse.com/show_bug.cgi?id=1275046 * https://bugzilla.suse.com/show_bug.cgi?id=1275047 * https://bugzilla.suse.com/show_bug.cgi?id=1275048 * https://bugzilla.suse.com/show_bug.cgi?id=1275049 * https://bugzilla.suse.com/show_bug.cgi?id=1275050 * https://bugzilla.suse.com/show_bug.cgi?id=1275051 * https://bugzilla.suse.com/show_bug.cgi?id=1275053 * https://bugzilla.suse.com/show_bug.cgi?id=1275054 * https://bugzilla.suse.com/show_bug.cgi?id=1275056 * https://bugzilla.suse.com/show_bug.cgi?id=1275057 * https://bugzilla.suse.com/show_bug.cgi?id=1275058 * https://bugzilla.suse.com/show_bug.cgi?id=1275059 * https://bugzilla.suse.com/show_bug.cgi?id=1275061 * https://bugzilla.suse.com/show_bug.cgi?id=1275063 * https://bugzilla.suse.com/show_bug.cgi?id=1275064 * https://bugzilla.suse.com/show_bug.cgi?id=1275065 * https://bugzilla.suse.com/show_bug.cgi?id=1275066 * https://bugzilla.suse.com/show_bug.cgi?id=1275067 * https://bugzilla.suse.com/show_bug.cgi?id=1275068 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:42:20 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:42:20 -0000 Subject: SUSE-SU-2026:3943-1: important: Security update for postgresql16 Message-ID: <178843934053.2657.6825579676243982742@f2d94a75072c> # Security update for postgresql16 Announcement ID: SUSE-SU-2026:3943-1 Release Date: 2026-09-03T07:36:59Z Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275053 * bsc#1275054 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275061 * bsc#1275062 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14672 * CVE-2026-14673 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14662 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14664 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14666 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14668 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14669 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14672 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14672 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14673 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14673 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14678 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14679 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14680 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15741 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15741 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15742 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16241 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18024 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18408 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19385 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6464 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6469 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6470 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6471 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for postgresql16 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). * CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). * CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). * CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql16: * Update to version 16.15: * https://www.postgresql.org/docs/16/release-16-15.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3943=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3943=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3943=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3943=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3943=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3943=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3943=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3943=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * postgresql16-contrib-16.15-150200.5.49.1 * postgresql16-debuginfo-16.15-150200.5.49.1 * postgresql16-plperl-16.15-150200.5.49.1 * postgresql16-pltcl-16.15-150200.5.49.1 * postgresql16-plpython-debuginfo-16.15-150200.5.49.1 * postgresql16-server-devel-debuginfo-16.15-150200.5.49.1 * postgresql16-server-devel-16.15-150200.5.49.1 * postgresql16-devel-debuginfo-16.15-150200.5.49.1 * postgresql16-plperl-debuginfo-16.15-150200.5.49.1 * postgresql16-server-debuginfo-16.15-150200.5.49.1 * postgresql16-plpython-16.15-150200.5.49.1 * postgresql16-server-16.15-150200.5.49.1 * postgresql16-16.15-150200.5.49.1 * postgresql16-pltcl-debuginfo-16.15-150200.5.49.1 * postgresql16-contrib-debuginfo-16.15-150200.5.49.1 * postgresql16-devel-16.15-150200.5.49.1 * postgresql16-debugsource-16.15-150200.5.49.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * postgresql16-docs-16.15-150200.5.49.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * postgresql16-contrib-16.15-150200.5.49.1 * postgresql16-debuginfo-16.15-150200.5.49.1 * postgresql16-plperl-16.15-150200.5.49.1 * postgresql16-pltcl-16.15-150200.5.49.1 * postgresql16-plpython-debuginfo-16.15-150200.5.49.1 * postgresql16-server-debuginfo-16.15-150200.5.49.1 * postgresql16-server-devel-debuginfo-16.15-150200.5.49.1 * postgresql16-plperl-debuginfo-16.15-150200.5.49.1 * postgresql16-devel-debuginfo-16.15-150200.5.49.1 * postgresql16-plpython-16.15-150200.5.49.1 * postgresql16-server-devel-16.15-150200.5.49.1 * postgresql16-server-16.15-150200.5.49.1 * postgresql16-16.15-150200.5.49.1 * postgresql16-devel-16.15-150200.5.49.1 * postgresql16-pltcl-debuginfo-16.15-150200.5.49.1 * postgresql16-contrib-debuginfo-16.15-150200.5.49.1 * postgresql16-debugsource-16.15-150200.5.49.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * postgresql16-docs-16.15-150200.5.49.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * postgresql16-contrib-16.15-150200.5.49.1 * postgresql16-debuginfo-16.15-150200.5.49.1 * postgresql16-plperl-16.15-150200.5.49.1 * postgresql16-pltcl-16.15-150200.5.49.1 * postgresql16-plpython-debuginfo-16.15-150200.5.49.1 * postgresql16-plpython-16.15-150200.5.49.1 * postgresql16-server-devel-16.15-150200.5.49.1 * postgresql16-plperl-debuginfo-16.15-150200.5.49.1 * postgresql16-server-debuginfo-16.15-150200.5.49.1 * postgresql16-server-devel-debuginfo-16.15-150200.5.49.1 * postgresql16-devel-debuginfo-16.15-150200.5.49.1 * postgresql16-server-16.15-150200.5.49.1 * postgresql16-16.15-150200.5.49.1 * postgresql16-pltcl-debuginfo-16.15-150200.5.49.1 * postgresql16-contrib-debuginfo-16.15-150200.5.49.1 * postgresql16-devel-16.15-150200.5.49.1 * postgresql16-debugsource-16.15-150200.5.49.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * postgresql16-docs-16.15-150200.5.49.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * postgresql16-contrib-16.15-150200.5.49.1 * postgresql16-debuginfo-16.15-150200.5.49.1 * postgresql16-plperl-16.15-150200.5.49.1 * postgresql16-pltcl-16.15-150200.5.49.1 * postgresql16-plpython-debuginfo-16.15-150200.5.49.1 * postgresql16-server-debuginfo-16.15-150200.5.49.1 * postgresql16-server-devel-16.15-150200.5.49.1 * postgresql16-devel-debuginfo-16.15-150200.5.49.1 * postgresql16-plpython-16.15-150200.5.49.1 * postgresql16-server-devel-debuginfo-16.15-150200.5.49.1 * postgresql16-plperl-debuginfo-16.15-150200.5.49.1 * postgresql16-server-16.15-150200.5.49.1 * postgresql16-16.15-150200.5.49.1 * postgresql16-devel-16.15-150200.5.49.1 * postgresql16-pltcl-debuginfo-16.15-150200.5.49.1 * postgresql16-contrib-debuginfo-16.15-150200.5.49.1 * postgresql16-debugsource-16.15-150200.5.49.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * postgresql16-docs-16.15-150200.5.49.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * postgresql16-contrib-16.15-150200.5.49.1 * postgresql16-debuginfo-16.15-150200.5.49.1 * postgresql16-plperl-16.15-150200.5.49.1 * postgresql16-pltcl-16.15-150200.5.49.1 * postgresql16-plpython-debuginfo-16.15-150200.5.49.1 * postgresql16-plpython-16.15-150200.5.49.1 * postgresql16-server-debuginfo-16.15-150200.5.49.1 * postgresql16-devel-debuginfo-16.15-150200.5.49.1 * postgresql16-plperl-debuginfo-16.15-150200.5.49.1 * postgresql16-server-devel-16.15-150200.5.49.1 * postgresql16-server-devel-debuginfo-16.15-150200.5.49.1 * postgresql16-server-16.15-150200.5.49.1 * postgresql16-16.15-150200.5.49.1 * postgresql16-devel-16.15-150200.5.49.1 * postgresql16-pltcl-debuginfo-16.15-150200.5.49.1 * postgresql16-contrib-debuginfo-16.15-150200.5.49.1 * postgresql16-debugsource-16.15-150200.5.49.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * postgresql16-docs-16.15-150200.5.49.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * postgresql16-contrib-16.15-150200.5.49.1 * postgresql16-debuginfo-16.15-150200.5.49.1 * postgresql16-plperl-16.15-150200.5.49.1 * postgresql16-pltcl-16.15-150200.5.49.1 * postgresql16-plpython-debuginfo-16.15-150200.5.49.1 * postgresql16-server-devel-debuginfo-16.15-150200.5.49.1 * postgresql16-plpython-16.15-150200.5.49.1 * postgresql16-plperl-debuginfo-16.15-150200.5.49.1 * postgresql16-devel-debuginfo-16.15-150200.5.49.1 * postgresql16-server-devel-16.15-150200.5.49.1 * postgresql16-server-debuginfo-16.15-150200.5.49.1 * postgresql16-server-16.15-150200.5.49.1 * postgresql16-16.15-150200.5.49.1 * postgresql16-devel-16.15-150200.5.49.1 * postgresql16-pltcl-debuginfo-16.15-150200.5.49.1 * postgresql16-contrib-debuginfo-16.15-150200.5.49.1 * postgresql16-debugsource-16.15-150200.5.49.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * postgresql16-docs-16.15-150200.5.49.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * postgresql16-contrib-16.15-150200.5.49.1 * postgresql16-debuginfo-16.15-150200.5.49.1 * postgresql16-plperl-16.15-150200.5.49.1 * postgresql16-pltcl-16.15-150200.5.49.1 * postgresql16-plpython-debuginfo-16.15-150200.5.49.1 * postgresql16-server-devel-debuginfo-16.15-150200.5.49.1 * postgresql16-server-debuginfo-16.15-150200.5.49.1 * postgresql16-devel-debuginfo-16.15-150200.5.49.1 * postgresql16-plperl-debuginfo-16.15-150200.5.49.1 * postgresql16-plpython-16.15-150200.5.49.1 * postgresql16-server-devel-16.15-150200.5.49.1 * postgresql16-server-16.15-150200.5.49.1 * postgresql16-16.15-150200.5.49.1 * postgresql16-pltcl-debuginfo-16.15-150200.5.49.1 * postgresql16-contrib-debuginfo-16.15-150200.5.49.1 * postgresql16-devel-16.15-150200.5.49.1 * postgresql16-debugsource-16.15-150200.5.49.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * postgresql16-docs-16.15-150200.5.49.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * postgresql16-contrib-16.15-150200.5.49.1 * postgresql16-debuginfo-16.15-150200.5.49.1 * postgresql16-plperl-16.15-150200.5.49.1 * postgresql16-pltcl-16.15-150200.5.49.1 * postgresql16-plpython-debuginfo-16.15-150200.5.49.1 * postgresql16-server-devel-debuginfo-16.15-150200.5.49.1 * postgresql16-server-devel-16.15-150200.5.49.1 * postgresql16-plpython-16.15-150200.5.49.1 * postgresql16-plperl-debuginfo-16.15-150200.5.49.1 * postgresql16-devel-debuginfo-16.15-150200.5.49.1 * postgresql16-server-debuginfo-16.15-150200.5.49.1 * postgresql16-server-16.15-150200.5.49.1 * postgresql16-16.15-150200.5.49.1 * postgresql16-pltcl-debuginfo-16.15-150200.5.49.1 * postgresql16-contrib-debuginfo-16.15-150200.5.49.1 * postgresql16-devel-16.15-150200.5.49.1 * postgresql16-debugsource-16.15-150200.5.49.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * postgresql16-docs-16.15-150200.5.49.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14672.html * https://www.suse.com/security/cve/CVE-2026-14673.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html * https://bugzilla.suse.com/show_bug.cgi?id=1275001 * https://bugzilla.suse.com/show_bug.cgi?id=1275002 * https://bugzilla.suse.com/show_bug.cgi?id=1275042 * https://bugzilla.suse.com/show_bug.cgi?id=1275043 * https://bugzilla.suse.com/show_bug.cgi?id=1275044 * https://bugzilla.suse.com/show_bug.cgi?id=1275046 * https://bugzilla.suse.com/show_bug.cgi?id=1275047 * https://bugzilla.suse.com/show_bug.cgi?id=1275048 * https://bugzilla.suse.com/show_bug.cgi?id=1275049 * https://bugzilla.suse.com/show_bug.cgi?id=1275050 * https://bugzilla.suse.com/show_bug.cgi?id=1275051 * https://bugzilla.suse.com/show_bug.cgi?id=1275053 * https://bugzilla.suse.com/show_bug.cgi?id=1275054 * https://bugzilla.suse.com/show_bug.cgi?id=1275056 * https://bugzilla.suse.com/show_bug.cgi?id=1275057 * https://bugzilla.suse.com/show_bug.cgi?id=1275058 * https://bugzilla.suse.com/show_bug.cgi?id=1275059 * https://bugzilla.suse.com/show_bug.cgi?id=1275061 * https://bugzilla.suse.com/show_bug.cgi?id=1275062 * https://bugzilla.suse.com/show_bug.cgi?id=1275063 * https://bugzilla.suse.com/show_bug.cgi?id=1275064 * https://bugzilla.suse.com/show_bug.cgi?id=1275065 * https://bugzilla.suse.com/show_bug.cgi?id=1275066 * https://bugzilla.suse.com/show_bug.cgi?id=1275067 * https://bugzilla.suse.com/show_bug.cgi?id=1275068 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:43:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:43:35 -0000 Subject: SUSE-SU-2026:3942-1: important: Security update for postgresql18 Message-ID: <178843941568.2657.17207687366128724834@f2d94a75072c> # Security update for postgresql18 Announcement ID: SUSE-SU-2026:3942-1 Release Date: 2026-09-03T07:35:10Z Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275052 * bsc#1275053 * bsc#1275054 * bsc#1275055 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275060 * bsc#1275061 * bsc#1275062 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14672 * CVE-2026-14673 * CVE-2026-14676 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-14681 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16238 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14662 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14664 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14666 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14668 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14669 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14672 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14672 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14673 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14673 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14676 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14676 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14678 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14679 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14680 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14681 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14681 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-15741 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15741 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15742 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16238 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16238 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16241 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18024 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18408 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19385 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6464 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6469 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6470 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6471 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 28 vulnerabilities can now be installed. ## Description: This update for postgresql18 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). * CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). * CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). * CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). * CVE-2026-14676: `pg_stat_statements` heap buffer overflow executes arbitrary code (bsc#1275060). * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). * CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). * CVE-2026-16238: type confusion in `pg_restore_attribute_stats()` executes arbitrary code (bsc#1275052). * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql18: * Update to version 18.6: * https://www.postgresql.org/docs/18/release-18-6.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3942=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3942=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libecpg6-debuginfo-18.6-8.17.1 * libpq5-debuginfo-18.6-8.17.1 * libecpg6-18.6-8.17.1 * libpq5-18.6-8.17.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libecpg6-debuginfo-32bit-18.6-8.17.1 * libecpg6-32bit-18.6-8.17.1 * libpq5-debuginfo-32bit-18.6-8.17.1 * libpq5-32bit-18.6-8.17.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libpq5-debuginfo-32bit-18.6-8.17.1 * libpq5-debuginfo-18.6-8.17.1 * libecpg6-debuginfo-32bit-18.6-8.17.1 * libecpg6-debuginfo-18.6-8.17.1 * libpq5-32bit-18.6-8.17.1 * libecpg6-18.6-8.17.1 * libecpg6-32bit-18.6-8.17.1 * libpq5-18.6-8.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14672.html * https://www.suse.com/security/cve/CVE-2026-14673.html * https://www.suse.com/security/cve/CVE-2026-14676.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-14681.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16238.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html * https://bugzilla.suse.com/show_bug.cgi?id=1275001 * https://bugzilla.suse.com/show_bug.cgi?id=1275002 * https://bugzilla.suse.com/show_bug.cgi?id=1275042 * https://bugzilla.suse.com/show_bug.cgi?id=1275043 * https://bugzilla.suse.com/show_bug.cgi?id=1275044 * https://bugzilla.suse.com/show_bug.cgi?id=1275046 * https://bugzilla.suse.com/show_bug.cgi?id=1275047 * https://bugzilla.suse.com/show_bug.cgi?id=1275048 * https://bugzilla.suse.com/show_bug.cgi?id=1275049 * https://bugzilla.suse.com/show_bug.cgi?id=1275050 * https://bugzilla.suse.com/show_bug.cgi?id=1275051 * https://bugzilla.suse.com/show_bug.cgi?id=1275052 * https://bugzilla.suse.com/show_bug.cgi?id=1275053 * https://bugzilla.suse.com/show_bug.cgi?id=1275054 * https://bugzilla.suse.com/show_bug.cgi?id=1275055 * https://bugzilla.suse.com/show_bug.cgi?id=1275056 * https://bugzilla.suse.com/show_bug.cgi?id=1275057 * https://bugzilla.suse.com/show_bug.cgi?id=1275058 * https://bugzilla.suse.com/show_bug.cgi?id=1275059 * https://bugzilla.suse.com/show_bug.cgi?id=1275060 * https://bugzilla.suse.com/show_bug.cgi?id=1275061 * https://bugzilla.suse.com/show_bug.cgi?id=1275062 * https://bugzilla.suse.com/show_bug.cgi?id=1275063 * https://bugzilla.suse.com/show_bug.cgi?id=1275064 * https://bugzilla.suse.com/show_bug.cgi?id=1275065 * https://bugzilla.suse.com/show_bug.cgi?id=1275066 * https://bugzilla.suse.com/show_bug.cgi?id=1275067 * https://bugzilla.suse.com/show_bug.cgi?id=1275068 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:44:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:44:44 -0000 Subject: SUSE-SU-2026:3941-1: important: Security update for postgresql14 Message-ID: <178843948485.2657.8762984434119375725@f2d94a75072c> # Security update for postgresql14 Announcement ID: SUSE-SU-2026:3941-1 Release Date: 2026-09-03T07:34:36Z Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275053 * bsc#1275054 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275061 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14673 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14662 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14664 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14666 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14668 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14669 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14673 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14673 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14678 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14679 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14680 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15741 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15741 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15742 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16241 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18024 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18408 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19385 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6464 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6469 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6470 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6471 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for postgresql14 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). * CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). * CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql14: * Update to version 14.24: * https://www.postgresql.org/docs/14/release-14-24.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3941=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3941=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3941=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3941=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3941=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3941=1 ## Package List: * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * postgresql14-server-devel-14.24-150200.5.77.1 * postgresql14-server-debuginfo-14.24-150200.5.77.1 * postgresql14-debuginfo-14.24-150200.5.77.1 * postgresql14-plpython-debuginfo-14.24-150200.5.77.1 * postgresql14-contrib-14.24-150200.5.77.1 * postgresql14-devel-14.24-150200.5.77.1 * postgresql14-plpython-14.24-150200.5.77.1 * postgresql14-debugsource-14.24-150200.5.77.1 * postgresql14-server-14.24-150200.5.77.1 * postgresql14-contrib-debuginfo-14.24-150200.5.77.1 * postgresql14-plperl-debuginfo-14.24-150200.5.77.1 * postgresql14-devel-debuginfo-14.24-150200.5.77.1 * postgresql14-server-devel-debuginfo-14.24-150200.5.77.1 * postgresql14-plperl-14.24-150200.5.77.1 * postgresql14-14.24-150200.5.77.1 * postgresql14-pltcl-debuginfo-14.24-150200.5.77.1 * postgresql14-pltcl-14.24-150200.5.77.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * postgresql14-docs-14.24-150200.5.77.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * postgresql14-server-devel-14.24-150200.5.77.1 * postgresql14-server-debuginfo-14.24-150200.5.77.1 * postgresql14-debuginfo-14.24-150200.5.77.1 * postgresql14-plpython-debuginfo-14.24-150200.5.77.1 * postgresql14-contrib-14.24-150200.5.77.1 * postgresql14-debugsource-14.24-150200.5.77.1 * postgresql14-devel-14.24-150200.5.77.1 * postgresql14-server-14.24-150200.5.77.1 * postgresql14-contrib-debuginfo-14.24-150200.5.77.1 * postgresql14-plperl-debuginfo-14.24-150200.5.77.1 * postgresql14-devel-debuginfo-14.24-150200.5.77.1 * postgresql14-server-devel-debuginfo-14.24-150200.5.77.1 * postgresql14-plperl-14.24-150200.5.77.1 * postgresql14-plpython-14.24-150200.5.77.1 * postgresql14-pltcl-debuginfo-14.24-150200.5.77.1 * postgresql14-14.24-150200.5.77.1 * postgresql14-pltcl-14.24-150200.5.77.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * postgresql14-docs-14.24-150200.5.77.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * postgresql14-server-debuginfo-14.24-150200.5.77.1 * postgresql14-plperl-debuginfo-14.24-150200.5.77.1 * postgresql14-pltcl-debuginfo-14.24-150200.5.77.1 * postgresql14-plpython-debuginfo-14.24-150200.5.77.1 * postgresql14-debugsource-14.24-150200.5.77.1 * postgresql14-14.24-150200.5.77.1 * postgresql14-server-devel-14.24-150200.5.77.1 * postgresql14-llvmjit-debuginfo-14.24-150200.5.77.1 * postgresql14-devel-14.24-150200.5.77.1 * postgresql14-plperl-14.24-150200.5.77.1 * postgresql14-plpython-14.24-150200.5.77.1 * postgresql14-pltcl-14.24-150200.5.77.1 * postgresql14-debuginfo-14.24-150200.5.77.1 * postgresql14-llvmjit-devel-14.24-150200.5.77.1 * postgresql14-contrib-14.24-150200.5.77.1 * postgresql14-server-14.24-150200.5.77.1 * postgresql14-contrib-debuginfo-14.24-150200.5.77.1 * postgresql14-devel-debuginfo-14.24-150200.5.77.1 * postgresql14-llvmjit-14.24-150200.5.77.1 * postgresql14-server-devel-debuginfo-14.24-150200.5.77.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * postgresql14-docs-14.24-150200.5.77.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * postgresql14-server-devel-14.24-150200.5.77.1 * postgresql14-server-debuginfo-14.24-150200.5.77.1 * postgresql14-debuginfo-14.24-150200.5.77.1 * postgresql14-plpython-debuginfo-14.24-150200.5.77.1 * postgresql14-contrib-14.24-150200.5.77.1 * postgresql14-devel-14.24-150200.5.77.1 * postgresql14-debugsource-14.24-150200.5.77.1 * postgresql14-server-14.24-150200.5.77.1 * postgresql14-contrib-debuginfo-14.24-150200.5.77.1 * postgresql14-plperl-debuginfo-14.24-150200.5.77.1 * postgresql14-devel-debuginfo-14.24-150200.5.77.1 * postgresql14-server-devel-debuginfo-14.24-150200.5.77.1 * postgresql14-plperl-14.24-150200.5.77.1 * postgresql14-plpython-14.24-150200.5.77.1 * postgresql14-pltcl-debuginfo-14.24-150200.5.77.1 * postgresql14-14.24-150200.5.77.1 * postgresql14-pltcl-14.24-150200.5.77.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * postgresql14-docs-14.24-150200.5.77.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * postgresql14-server-devel-14.24-150200.5.77.1 * postgresql14-server-debuginfo-14.24-150200.5.77.1 * postgresql14-debuginfo-14.24-150200.5.77.1 * postgresql14-plpython-debuginfo-14.24-150200.5.77.1 * postgresql14-contrib-14.24-150200.5.77.1 * postgresql14-devel-14.24-150200.5.77.1 * postgresql14-debugsource-14.24-150200.5.77.1 * postgresql14-server-14.24-150200.5.77.1 * postgresql14-contrib-debuginfo-14.24-150200.5.77.1 * postgresql14-plperl-debuginfo-14.24-150200.5.77.1 * postgresql14-devel-debuginfo-14.24-150200.5.77.1 * postgresql14-server-devel-debuginfo-14.24-150200.5.77.1 * postgresql14-plperl-14.24-150200.5.77.1 * postgresql14-plpython-14.24-150200.5.77.1 * postgresql14-pltcl-debuginfo-14.24-150200.5.77.1 * postgresql14-14.24-150200.5.77.1 * postgresql14-pltcl-14.24-150200.5.77.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * postgresql14-docs-14.24-150200.5.77.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * postgresql14-server-debuginfo-14.24-150200.5.77.1 * postgresql14-plperl-debuginfo-14.24-150200.5.77.1 * postgresql14-pltcl-debuginfo-14.24-150200.5.77.1 * postgresql14-plpython-debuginfo-14.24-150200.5.77.1 * postgresql14-debugsource-14.24-150200.5.77.1 * postgresql14-14.24-150200.5.77.1 * postgresql14-server-devel-14.24-150200.5.77.1 * postgresql14-llvmjit-debuginfo-14.24-150200.5.77.1 * postgresql14-devel-14.24-150200.5.77.1 * postgresql14-plperl-14.24-150200.5.77.1 * postgresql14-plpython-14.24-150200.5.77.1 * postgresql14-pltcl-14.24-150200.5.77.1 * postgresql14-debuginfo-14.24-150200.5.77.1 * postgresql14-llvmjit-devel-14.24-150200.5.77.1 * postgresql14-contrib-14.24-150200.5.77.1 * postgresql14-server-14.24-150200.5.77.1 * postgresql14-contrib-debuginfo-14.24-150200.5.77.1 * postgresql14-devel-debuginfo-14.24-150200.5.77.1 * postgresql14-llvmjit-14.24-150200.5.77.1 * postgresql14-server-devel-debuginfo-14.24-150200.5.77.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * postgresql14-docs-14.24-150200.5.77.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14673.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html * https://bugzilla.suse.com/show_bug.cgi?id=1275001 * https://bugzilla.suse.com/show_bug.cgi?id=1275002 * https://bugzilla.suse.com/show_bug.cgi?id=1275042 * https://bugzilla.suse.com/show_bug.cgi?id=1275043 * https://bugzilla.suse.com/show_bug.cgi?id=1275044 * https://bugzilla.suse.com/show_bug.cgi?id=1275046 * https://bugzilla.suse.com/show_bug.cgi?id=1275047 * https://bugzilla.suse.com/show_bug.cgi?id=1275048 * https://bugzilla.suse.com/show_bug.cgi?id=1275049 * https://bugzilla.suse.com/show_bug.cgi?id=1275050 * https://bugzilla.suse.com/show_bug.cgi?id=1275051 * https://bugzilla.suse.com/show_bug.cgi?id=1275053 * https://bugzilla.suse.com/show_bug.cgi?id=1275054 * https://bugzilla.suse.com/show_bug.cgi?id=1275056 * https://bugzilla.suse.com/show_bug.cgi?id=1275057 * https://bugzilla.suse.com/show_bug.cgi?id=1275058 * https://bugzilla.suse.com/show_bug.cgi?id=1275059 * https://bugzilla.suse.com/show_bug.cgi?id=1275061 * https://bugzilla.suse.com/show_bug.cgi?id=1275063 * https://bugzilla.suse.com/show_bug.cgi?id=1275064 * https://bugzilla.suse.com/show_bug.cgi?id=1275065 * https://bugzilla.suse.com/show_bug.cgi?id=1275066 * https://bugzilla.suse.com/show_bug.cgi?id=1275067 * https://bugzilla.suse.com/show_bug.cgi?id=1275068 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:45:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:45:53 -0000 Subject: SUSE-SU-2026:3940-1: important: Security update for postgresql15 Message-ID: <178843955342.2657.9117774650930180294@f2d94a75072c> # Security update for postgresql15 Announcement ID: SUSE-SU-2026:3940-1 Release Date: 2026-09-03T07:32:49Z Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275053 * bsc#1275054 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275061 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14673 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14662 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14664 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14666 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14668 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14669 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14673 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14673 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14678 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14679 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14680 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15741 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15741 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15742 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16241 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18024 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18408 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19385 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6464 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6469 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6470 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6471 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for postgresql15 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). * CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). * CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql15: * Update to version 15.19: * https://www.postgresql.org/docs/15/release-15-19.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3940=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3940=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * postgresql15-plperl-debuginfo-15.19-3.61.1 * postgresql15-plpython-debuginfo-15.19-3.61.1 * postgresql15-server-15.19-3.61.1 * postgresql15-server-debuginfo-15.19-3.61.1 * postgresql15-devel-15.19-3.61.1 * postgresql15-contrib-15.19-3.61.1 * postgresql15-pltcl-15.19-3.61.1 * postgresql15-server-devel-debuginfo-15.19-3.61.1 * postgresql15-server-devel-15.19-3.61.1 * postgresql15-plperl-15.19-3.61.1 * postgresql15-devel-debuginfo-15.19-3.61.1 * postgresql15-contrib-debuginfo-15.19-3.61.1 * postgresql15-plpython-15.19-3.61.1 * postgresql15-pltcl-debuginfo-15.19-3.61.1 * postgresql15-debugsource-15.19-3.61.1 * postgresql15-15.19-3.61.1 * postgresql15-debuginfo-15.19-3.61.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * postgresql15-docs-15.19-3.61.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * postgresql15-plperl-debuginfo-15.19-3.61.1 * postgresql15-plpython-debuginfo-15.19-3.61.1 * postgresql15-server-debuginfo-15.19-3.61.1 * postgresql15-server-15.19-3.61.1 * postgresql15-devel-15.19-3.61.1 * postgresql15-pltcl-15.19-3.61.1 * postgresql15-server-devel-debuginfo-15.19-3.61.1 * postgresql15-contrib-15.19-3.61.1 * postgresql15-server-devel-15.19-3.61.1 * postgresql15-plperl-15.19-3.61.1 * postgresql15-contrib-debuginfo-15.19-3.61.1 * postgresql15-devel-debuginfo-15.19-3.61.1 * postgresql15-plpython-15.19-3.61.1 * postgresql15-pltcl-debuginfo-15.19-3.61.1 * postgresql15-debugsource-15.19-3.61.1 * postgresql15-15.19-3.61.1 * postgresql15-debuginfo-15.19-3.61.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * postgresql15-docs-15.19-3.61.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14673.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html * https://bugzilla.suse.com/show_bug.cgi?id=1275001 * https://bugzilla.suse.com/show_bug.cgi?id=1275002 * https://bugzilla.suse.com/show_bug.cgi?id=1275042 * https://bugzilla.suse.com/show_bug.cgi?id=1275043 * https://bugzilla.suse.com/show_bug.cgi?id=1275044 * https://bugzilla.suse.com/show_bug.cgi?id=1275046 * https://bugzilla.suse.com/show_bug.cgi?id=1275047 * https://bugzilla.suse.com/show_bug.cgi?id=1275048 * https://bugzilla.suse.com/show_bug.cgi?id=1275049 * https://bugzilla.suse.com/show_bug.cgi?id=1275050 * https://bugzilla.suse.com/show_bug.cgi?id=1275051 * https://bugzilla.suse.com/show_bug.cgi?id=1275053 * https://bugzilla.suse.com/show_bug.cgi?id=1275054 * https://bugzilla.suse.com/show_bug.cgi?id=1275056 * https://bugzilla.suse.com/show_bug.cgi?id=1275057 * https://bugzilla.suse.com/show_bug.cgi?id=1275058 * https://bugzilla.suse.com/show_bug.cgi?id=1275059 * https://bugzilla.suse.com/show_bug.cgi?id=1275061 * https://bugzilla.suse.com/show_bug.cgi?id=1275063 * https://bugzilla.suse.com/show_bug.cgi?id=1275064 * https://bugzilla.suse.com/show_bug.cgi?id=1275065 * https://bugzilla.suse.com/show_bug.cgi?id=1275066 * https://bugzilla.suse.com/show_bug.cgi?id=1275067 * https://bugzilla.suse.com/show_bug.cgi?id=1275068 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:46:39 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:46:39 -0000 Subject: SUSE-SU-2026:3939-1: moderate: Security update for libvirt Message-ID: <178843959988.2657.2078581641665420037@f2d94a75072c> # Security update for libvirt Announcement ID: SUSE-SU-2026:3939-1 Release Date: 2026-09-03T07:32:06Z Rating: moderate References: * bsc#1266364 * bsc#1274576 * bsc#1274946 * bsc#1275264 * bsc#1275265 * bsc#1275863 * jsc#PED-16192 Cross-References: * CVE-2026-18917 * CVE-2026-61477 * CVE-2026-63622 * CVE-2026-63623 * CVE-2026-77159 CVSS scores: * CVE-2026-18917 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-18917 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-61477 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-61477 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61477 ( NVD ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-63622 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63622 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63622 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63623 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-63623 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-63623 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves five vulnerabilities, contains one feature and has one security fix can now be installed. ## Description: This update for libvirt fixes the following issues: * CVE-2026-18917: remote: Fix integer overflow in RPC handler for virNodeGetFreePages (bsc#1275863) * CVE-2026-63622: util: virFileChownFiles: do not follow symlinks (bsc#1275264) * CVE-2026-63623: storage: create images with a private umask during qemu-img create/convert (bsc#12075265) * CVE-2026-77159: qemu: tpm: Avoid following symlinks when chown'ing log file (bsc#1274946) * CVE-2026-61477: Reject line breaks in network config (bsc#1274576) * qemu: Fix invocation of numa-preplace when hugepages requested, but page size not specified (bsc#1266364) * Add ClearwaterForest CPU model (jsc#PED-16192) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3939=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3939=1 ## Package List: * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libvirt-daemon-driver-storage-iscsi-direct-11.0.0-150700.4.27.1 * libvirt-daemon-proxy-11.0.0-150700.4.27.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-driver-qemu-11.0.0-150700.4.27.1 * libvirt-daemon-driver-storage-disk-11.0.0-150700.4.27.1 * libvirt-daemon-driver-storage-scsi-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-driver-secret-11.0.0-150700.4.27.1 * libvirt-nss-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-common-11.0.0-150700.4.27.1 * libvirt-daemon-driver-nodedev-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-driver-interface-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-driver-storage-11.0.0-150700.4.27.1 * libvirt-daemon-lock-11.0.0-150700.4.27.1 * libvirt-daemon-plugin-sanlock-11.0.0-150700.4.27.1 * libvirt-daemon-driver-nwfilter-11.0.0-150700.4.27.1 * libvirt-daemon-config-network-11.0.0-150700.4.27.1 * libvirt-devel-11.0.0-150700.4.27.1 * libvirt-daemon-hooks-11.0.0-150700.4.27.1 * libvirt-daemon-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-common-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-driver-storage-core-11.0.0-150700.4.27.1 * libvirt-daemon-plugin-sanlock-debuginfo-11.0.0-150700.4.27.1 * libvirt-debugsource-11.0.0-150700.4.27.1 * libvirt-daemon-driver-storage-iscsi-11.0.0-150700.4.27.1 * libvirt-11.0.0-150700.4.27.1 * libvirt-nss-11.0.0-150700.4.27.1 * libvirt-client-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-driver-storage-logical-11.0.0-150700.4.27.1 * libvirt-daemon-driver-nodedev-11.0.0-150700.4.27.1 * libvirt-daemon-log-11.0.0-150700.4.27.1 * libvirt-daemon-11.0.0-150700.4.27.1 * libvirt-client-11.0.0-150700.4.27.1 * libvirt-daemon-log-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-driver-storage-logical-debuginfo-11.0.0-150700.4.27.1 * libvirt-client-qemu-11.0.0-150700.4.27.1 * libvirt-daemon-driver-storage-mpath-11.0.0-150700.4.27.1 * libvirt-daemon-driver-storage-mpath-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-proxy-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-driver-nwfilter-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-driver-interface-11.0.0-150700.4.27.1 * libvirt-daemon-plugin-lockd-11.0.0-150700.4.27.1 * libvirt-daemon-config-nwfilter-11.0.0-150700.4.27.1 * libvirt-daemon-qemu-11.0.0-150700.4.27.1 * libvirt-daemon-driver-storage-core-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-plugin-lockd-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-driver-network-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-driver-storage-scsi-11.0.0-150700.4.27.1 * libvirt-daemon-driver-storage-disk-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-driver-qemu-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-driver-secret-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-lock-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-driver-network-11.0.0-150700.4.27.1 * Server Applications Module 15-SP7 (x86_64) * libvirt-daemon-xen-11.0.0-150700.4.27.1 * libvirt-daemon-driver-libxl-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-driver-libxl-11.0.0-150700.4.27.1 * Server Applications Module 15-SP7 (noarch) * libvirt-doc-11.0.0-150700.4.27.1 * Server Applications Module 15-SP7 (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-debuginfo-11.0.0-150700.4.27.1 * libvirt-daemon-driver-storage-rbd-11.0.0-150700.4.27.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libvirt-libs-11.0.0-150700.4.27.1 * libvirt-libs-debuginfo-11.0.0-150700.4.27.1 * libvirt-debugsource-11.0.0-150700.4.27.1 ## References: * https://www.suse.com/security/cve/CVE-2026-18917.html * https://www.suse.com/security/cve/CVE-2026-61477.html * https://www.suse.com/security/cve/CVE-2026-63622.html * https://www.suse.com/security/cve/CVE-2026-63623.html * https://www.suse.com/security/cve/CVE-2026-77159.html * https://bugzilla.suse.com/show_bug.cgi?id=1266364 * https://bugzilla.suse.com/show_bug.cgi?id=1274576 * https://bugzilla.suse.com/show_bug.cgi?id=1274946 * https://bugzilla.suse.com/show_bug.cgi?id=1275264 * https://bugzilla.suse.com/show_bug.cgi?id=1275265 * https://bugzilla.suse.com/show_bug.cgi?id=1275863 * https://jira.suse.com/browse/PED-16192 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:47:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:47:25 -0000 Subject: SUSE-SU-2026:3938-1: critical: Security update for apr-util Message-ID: <178843964562.2657.7511561084969246009@f2d94a75072c> # Security update for apr-util Announcement ID: SUSE-SU-2026:3938-1 Release Date: 2026-09-03T07:30:49Z Rating: critical References: * bsc#1207866 * bsc#1274235 * bsc#1274237 * bsc#1274850 * bsc#1274852 * bsc#1274854 Cross-References: * CVE-2022-25147 * CVE-2025-49506 * CVE-2026-32327 * CVE-2026-34191 * CVE-2026-34501 * CVE-2026-34502 CVSS scores: * CVE-2022-25147 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2022-25147 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-49506 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-49506 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-32327 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-32327 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-34191 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34191 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34501 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-34501 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34502 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34502 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for apr-util fixes the following issues: * CVE-2022-25147: buffer overflow possible with specially crafted input (bsc#1207866). * CVE-2025-49506: leaking content via side channel timing attack (bsc#1274237). * CVE-2026-32327: XML stack recursion crash (bsc#1274235). * CVE-2026-34191: SQL Injection via apr_dbd_oracle (bsc#1274850). * CVE-2026-34501: heap buffer overflow in redis client (bsc#1274852). * CVE-2026-34502: heap buffer overflow in APR memcached client (bsc#1274854). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3938=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3938=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3938=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3938=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3938=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libapr-util1-dbd-mysql-1.6.1-150600.27.3.1 * libapr-util1-dbd-pgsql-1.6.1-150600.27.3.1 * libapr-util1-dbd-mysql-debuginfo-1.6.1-150600.27.3.1 * libapr-util1-dbd-pgsql-debuginfo-1.6.1-150600.27.3.1 * libapr-util1-dbd-sqlite3-1.6.1-150600.27.3.1 * apr-util-debugsource-1.6.1-150600.27.3.1 * libapr-util1-debuginfo-1.6.1-150600.27.3.1 * apr-util-debuginfo-1.6.1-150600.27.3.1 * apr-util-devel-1.6.1-150600.27.3.1 * libapr-util1-1.6.1-150600.27.3.1 * libapr-util1-dbd-sqlite3-debuginfo-1.6.1-150600.27.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libapr-util1-dbd-mysql-1.6.1-150600.27.3.1 * libapr-util1-dbd-pgsql-1.6.1-150600.27.3.1 * libapr-util1-dbd-mysql-debuginfo-1.6.1-150600.27.3.1 * libapr-util1-dbd-pgsql-debuginfo-1.6.1-150600.27.3.1 * libapr-util1-dbd-sqlite3-1.6.1-150600.27.3.1 * apr-util-debugsource-1.6.1-150600.27.3.1 * libapr-util1-debuginfo-1.6.1-150600.27.3.1 * apr-util-debuginfo-1.6.1-150600.27.3.1 * apr-util-devel-1.6.1-150600.27.3.1 * libapr-util1-1.6.1-150600.27.3.1 * libapr-util1-dbd-sqlite3-debuginfo-1.6.1-150600.27.3.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libapr-util1-dbd-mysql-1.6.1-150600.27.3.1 * libapr-util1-dbd-pgsql-1.6.1-150600.27.3.1 * libapr-util1-dbd-mysql-debuginfo-1.6.1-150600.27.3.1 * libapr-util1-dbd-pgsql-debuginfo-1.6.1-150600.27.3.1 * apr-util-debugsource-1.6.1-150600.27.3.1 * libapr-util1-dbd-sqlite3-1.6.1-150600.27.3.1 * apr-util-debuginfo-1.6.1-150600.27.3.1 * libapr-util1-dbd-sqlite3-debuginfo-1.6.1-150600.27.3.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libapr-util1-dbd-mysql-1.6.1-150600.27.3.1 * libapr-util1-dbd-pgsql-1.6.1-150600.27.3.1 * libapr-util1-dbm-db-debuginfo-1.6.1-150600.27.3.1 * libapr-util1-dbd-mysql-debuginfo-1.6.1-150600.27.3.1 * libapr-util1-dbd-pgsql-debuginfo-1.6.1-150600.27.3.1 * libapr-util1-dbd-sqlite3-1.6.1-150600.27.3.1 * apr-util-debugsource-1.6.1-150600.27.3.1 * libapr-util1-debuginfo-1.6.1-150600.27.3.1 * apr-util-debuginfo-1.6.1-150600.27.3.1 * apr-util-devel-1.6.1-150600.27.3.1 * libapr-util1-dbm-db-1.6.1-150600.27.3.1 * libapr-util1-1.6.1-150600.27.3.1 * libapr-util1-dbd-sqlite3-debuginfo-1.6.1-150600.27.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * apr-util-debugsource-1.6.1-150600.27.3.1 * apr-util-debuginfo-1.6.1-150600.27.3.1 * apr-util-devel-1.6.1-150600.27.3.1 * libapr-util1-1.6.1-150600.27.3.1 * libapr-util1-debuginfo-1.6.1-150600.27.3.1 ## References: * https://www.suse.com/security/cve/CVE-2022-25147.html * https://www.suse.com/security/cve/CVE-2025-49506.html * https://www.suse.com/security/cve/CVE-2026-32327.html * https://www.suse.com/security/cve/CVE-2026-34191.html * https://www.suse.com/security/cve/CVE-2026-34501.html * https://www.suse.com/security/cve/CVE-2026-34502.html * https://bugzilla.suse.com/show_bug.cgi?id=1207866 * https://bugzilla.suse.com/show_bug.cgi?id=1274235 * https://bugzilla.suse.com/show_bug.cgi?id=1274237 * https://bugzilla.suse.com/show_bug.cgi?id=1274850 * https://bugzilla.suse.com/show_bug.cgi?id=1274852 * https://bugzilla.suse.com/show_bug.cgi?id=1274854 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:48:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:48:27 -0000 Subject: SUSE-SU-2026:3937-1: critical: Security update for apr-util Message-ID: <178843970769.2657.7504299214794860560@f2d94a75072c> # Security update for apr-util Announcement ID: SUSE-SU-2026:3937-1 Release Date: 2026-09-03T07:29:34Z Rating: critical References: * bsc#1207866 * bsc#1274235 * bsc#1274237 * bsc#1274850 * bsc#1274852 * bsc#1274854 Cross-References: * CVE-2022-25147 * CVE-2025-49506 * CVE-2026-32327 * CVE-2026-34191 * CVE-2026-34501 * CVE-2026-34502 CVSS scores: * CVE-2022-25147 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2022-25147 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-49506 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-49506 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-32327 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-32327 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-34191 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34191 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34501 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-34501 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34502 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34502 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for apr-util fixes the following issues: * CVE-2022-25147: buffer overflow possible with specially crafted input (bsc#1207866). * CVE-2025-49506: leaking content via side channel timing attack (bsc#1274237). * CVE-2026-32327: XML stack recursion crash (bsc#1274235). * CVE-2026-34191: SQL Injection via apr_dbd_oracle (bsc#1274850). * CVE-2026-34501: heap buffer overflow in redis client (bsc#1274852). * CVE-2026-34502: heap buffer overflow in APR memcached client (bsc#1274854). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3937=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3937=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3937=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3937=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3937=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3937=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3937=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3937=1 * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-3937=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * libapr-util1-dbm-db-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-sqlite3-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-debuginfo-1.6.1-150300.18.8.1 * apr-util-devel-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-1.6.1-150300.18.8.1 * libapr-util1-dbd-sqlite3-1.6.1-150300.18.8.1 * apr-util-debuginfo-1.6.1-150300.18.8.1 * apr-util-debugsource-1.6.1-150300.18.8.1 * libapr-util1-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbm-db-1.6.1-150300.18.8.1 * libapr-util1-1.6.1-150300.18.8.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libapr-util1-dbd-sqlite3-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-debuginfo-1.6.1-150300.18.8.1 * apr-util-devel-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-1.6.1-150300.18.8.1 * libapr-util1-dbd-sqlite3-1.6.1-150300.18.8.1 * apr-util-debuginfo-1.6.1-150300.18.8.1 * apr-util-debugsource-1.6.1-150300.18.8.1 * libapr-util1-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-1.6.1-150300.18.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libapr-util1-dbd-sqlite3-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-debuginfo-1.6.1-150300.18.8.1 * apr-util-devel-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-1.6.1-150300.18.8.1 * libapr-util1-dbd-sqlite3-1.6.1-150300.18.8.1 * apr-util-debuginfo-1.6.1-150300.18.8.1 * apr-util-debugsource-1.6.1-150300.18.8.1 * libapr-util1-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-1.6.1-150300.18.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libapr-util1-dbd-sqlite3-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-debuginfo-1.6.1-150300.18.8.1 * apr-util-devel-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-1.6.1-150300.18.8.1 * libapr-util1-dbd-sqlite3-1.6.1-150300.18.8.1 * apr-util-debuginfo-1.6.1-150300.18.8.1 * apr-util-debugsource-1.6.1-150300.18.8.1 * libapr-util1-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-1.6.1-150300.18.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libapr-util1-dbd-sqlite3-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-debuginfo-1.6.1-150300.18.8.1 * apr-util-devel-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-1.6.1-150300.18.8.1 * libapr-util1-dbd-sqlite3-1.6.1-150300.18.8.1 * apr-util-debuginfo-1.6.1-150300.18.8.1 * apr-util-debugsource-1.6.1-150300.18.8.1 * libapr-util1-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-1.6.1-150300.18.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libapr-util1-dbd-sqlite3-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-debuginfo-1.6.1-150300.18.8.1 * apr-util-devel-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-1.6.1-150300.18.8.1 * libapr-util1-dbd-sqlite3-1.6.1-150300.18.8.1 * apr-util-debuginfo-1.6.1-150300.18.8.1 * apr-util-debugsource-1.6.1-150300.18.8.1 * libapr-util1-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-1.6.1-150300.18.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libapr-util1-dbd-sqlite3-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-debuginfo-1.6.1-150300.18.8.1 * apr-util-devel-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-1.6.1-150300.18.8.1 * libapr-util1-dbd-sqlite3-1.6.1-150300.18.8.1 * apr-util-debuginfo-1.6.1-150300.18.8.1 * apr-util-debugsource-1.6.1-150300.18.8.1 * libapr-util1-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-1.6.1-150300.18.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libapr-util1-dbd-sqlite3-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-debuginfo-1.6.1-150300.18.8.1 * apr-util-devel-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-1.6.1-150300.18.8.1 * libapr-util1-dbd-sqlite3-1.6.1-150300.18.8.1 * apr-util-debuginfo-1.6.1-150300.18.8.1 * apr-util-debugsource-1.6.1-150300.18.8.1 * libapr-util1-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-1.6.1-150300.18.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libapr-util1-dbd-sqlite3-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-1.6.1-150300.18.8.1 * libapr-util1-dbd-pgsql-debuginfo-1.6.1-150300.18.8.1 * apr-util-devel-1.6.1-150300.18.8.1 * libapr-util1-dbd-mysql-1.6.1-150300.18.8.1 * libapr-util1-dbd-sqlite3-1.6.1-150300.18.8.1 * apr-util-debuginfo-1.6.1-150300.18.8.1 * apr-util-debugsource-1.6.1-150300.18.8.1 * libapr-util1-debuginfo-1.6.1-150300.18.8.1 * libapr-util1-1.6.1-150300.18.8.1 ## References: * https://www.suse.com/security/cve/CVE-2022-25147.html * https://www.suse.com/security/cve/CVE-2025-49506.html * https://www.suse.com/security/cve/CVE-2026-32327.html * https://www.suse.com/security/cve/CVE-2026-34191.html * https://www.suse.com/security/cve/CVE-2026-34501.html * https://www.suse.com/security/cve/CVE-2026-34502.html * https://bugzilla.suse.com/show_bug.cgi?id=1207866 * https://bugzilla.suse.com/show_bug.cgi?id=1274235 * https://bugzilla.suse.com/show_bug.cgi?id=1274237 * https://bugzilla.suse.com/show_bug.cgi?id=1274850 * https://bugzilla.suse.com/show_bug.cgi?id=1274852 * https://bugzilla.suse.com/show_bug.cgi?id=1274854 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:49:26 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:49:26 -0000 Subject: SUSE-SU-2026:3936-1: important: Security update for libsoup2 Message-ID: <178843976692.2657.6720214200272144190@f2d94a75072c> # Security update for libsoup2 Announcement ID: SUSE-SU-2026:3936-1 Release Date: 2026-09-03T07:27:45Z Rating: important References: * bsc#1241686 * bsc#1241688 * bsc#1254876 * bsc#1272196 Cross-References: * CVE-2025-14523 * CVE-2025-46420 * CVE-2025-46421 * CVE-2026-12548 CVSS scores: * CVE-2025-14523 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-14523 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2025-14523 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2025-46420 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-46420 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-46420 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2025-46421 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-46421 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-12548 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12548 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12548 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves four vulnerabilities can now be installed. ## Description: This update for libsoup2 fixes the following issues: * CVE-2026-12548: out-of-bounds read in multipart body parser due to an integer truncation (bsc#1272196). Changes for libsoup2: * tld-test: update after changes in the public suffix list: "*.bd" is no longer in the public suffix list so let's use ".jm" instead. * Increase test timeout for all arches except x86_64 and run tests again should they fail the first time, the testsuite is flaky. * Increase test timeout on s390x. The http2-body-stream test can be slow and sometimes times out in our builds. * fix an intermittent test failure (glgo#GNOME/libsoup#399). * Fix build with libxml2-2.12.0 and clang-17. * Add upstream bug fixes: * lib: Add g_task_set_source_tag() everywhere * lib: Add names to various GSources * Drop no longer valid translation-update-upstream BuildRequires and macro. * Use ldconfig_scriptlets macro for post(un) handling. * Update to version 2.74.3: * Add missing g-i annotations to `soup_address_get_sockaddr()` and `soup_socket_read_until()`. * Add missing `extern` when building on Windows. * Update libxml2 fallback for meson wrap. * Improvements when using libsoup with meson wraps. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3936=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3936=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3936=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3936=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3936=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3936=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3936=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3936=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3936=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3936=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3936=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3936=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3936=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3936=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libsoup-2_4-1-debuginfo-2.74.3-150400.3.40.1 * typelib-1_0-Soup-2_4-2.74.3-150400.3.40.1 * libsoup2-devel-2.74.3-150400.3.40.1 * libsoup-2_4-1-2.74.3-150400.3.40.1 * libsoup2-debugsource-2.74.3-150400.3.40.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * libsoup2-lang-2.74.3-150400.3.40.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libsoup-2_4-1-debuginfo-2.74.3-150400.3.40.1 * typelib-1_0-Soup-2_4-2.74.3-150400.3.40.1 * libsoup2-devel-2.74.3-150400.3.40.1 * libsoup-2_4-1-2.74.3-150400.3.40.1 * libsoup2-debugsource-2.74.3-150400.3.40.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * libsoup2-lang-2.74.3-150400.3.40.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libsoup-2_4-1-debuginfo-2.74.3-150400.3.40.1 * typelib-1_0-Soup-2_4-2.74.3-150400.3.40.1 * libsoup2-devel-2.74.3-150400.3.40.1 * libsoup-2_4-1-2.74.3-150400.3.40.1 * libsoup2-debugsource-2.74.3-150400.3.40.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * libsoup2-lang-2.74.3-150400.3.40.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libsoup2-debugsource-2.74.3-150400.3.40.1 * libsoup-2_4-1-debuginfo-2.74.3-150400.3.40.1 * libsoup-2_4-1-2.74.3-150400.3.40.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libsoup2-debugsource-2.74.3-150400.3.40.1 * libsoup-2_4-1-debuginfo-2.74.3-150400.3.40.1 * libsoup-2_4-1-2.74.3-150400.3.40.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libsoup-2_4-1-debuginfo-2.74.3-150400.3.40.1 * typelib-1_0-Soup-2_4-2.74.3-150400.3.40.1 * libsoup2-devel-2.74.3-150400.3.40.1 * libsoup-2_4-1-2.74.3-150400.3.40.1 * libsoup2-debugsource-2.74.3-150400.3.40.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * libsoup2-lang-2.74.3-150400.3.40.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libsoup-2_4-1-debuginfo-2.74.3-150400.3.40.1 * typelib-1_0-Soup-2_4-2.74.3-150400.3.40.1 * libsoup2-devel-2.74.3-150400.3.40.1 * libsoup-2_4-1-2.74.3-150400.3.40.1 * libsoup2-debugsource-2.74.3-150400.3.40.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * libsoup2-lang-2.74.3-150400.3.40.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libsoup-2_4-1-debuginfo-2.74.3-150400.3.40.1 * typelib-1_0-Soup-2_4-2.74.3-150400.3.40.1 * libsoup2-devel-2.74.3-150400.3.40.1 * libsoup-2_4-1-2.74.3-150400.3.40.1 * libsoup2-debugsource-2.74.3-150400.3.40.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libsoup-2_4-1-64bit-2.74.3-150400.3.40.1 * libsoup-2_4-1-64bit-debuginfo-2.74.3-150400.3.40.1 * libsoup2-devel-64bit-2.74.3-150400.3.40.1 * openSUSE Leap 15.4 (x86_64) * libsoup-2_4-1-32bit-2.74.3-150400.3.40.1 * libsoup-2_4-1-32bit-debuginfo-2.74.3-150400.3.40.1 * libsoup2-devel-32bit-2.74.3-150400.3.40.1 * openSUSE Leap 15.4 (noarch) * libsoup2-lang-2.74.3-150400.3.40.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libsoup-2_4-1-debuginfo-2.74.3-150400.3.40.1 * typelib-1_0-Soup-2_4-2.74.3-150400.3.40.1 * libsoup2-devel-2.74.3-150400.3.40.1 * libsoup-2_4-1-2.74.3-150400.3.40.1 * libsoup2-debugsource-2.74.3-150400.3.40.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * libsoup2-lang-2.74.3-150400.3.40.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libsoup-2_4-1-debuginfo-2.74.3-150400.3.40.1 * typelib-1_0-Soup-2_4-2.74.3-150400.3.40.1 * libsoup2-devel-2.74.3-150400.3.40.1 * libsoup-2_4-1-2.74.3-150400.3.40.1 * libsoup2-debugsource-2.74.3-150400.3.40.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * libsoup2-lang-2.74.3-150400.3.40.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libsoup2-debugsource-2.74.3-150400.3.40.1 * libsoup-2_4-1-debuginfo-2.74.3-150400.3.40.1 * libsoup-2_4-1-2.74.3-150400.3.40.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libsoup2-debugsource-2.74.3-150400.3.40.1 * libsoup-2_4-1-debuginfo-2.74.3-150400.3.40.1 * libsoup-2_4-1-2.74.3-150400.3.40.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libsoup-2_4-1-debuginfo-2.74.3-150400.3.40.1 * typelib-1_0-Soup-2_4-2.74.3-150400.3.40.1 * libsoup2-devel-2.74.3-150400.3.40.1 * libsoup-2_4-1-2.74.3-150400.3.40.1 * libsoup2-debugsource-2.74.3-150400.3.40.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * libsoup2-lang-2.74.3-150400.3.40.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libsoup2-debugsource-2.74.3-150400.3.40.1 * libsoup-2_4-1-debuginfo-2.74.3-150400.3.40.1 * libsoup-2_4-1-2.74.3-150400.3.40.1 ## References: * https://www.suse.com/security/cve/CVE-2025-14523.html * https://www.suse.com/security/cve/CVE-2025-46420.html * https://www.suse.com/security/cve/CVE-2025-46421.html * https://www.suse.com/security/cve/CVE-2026-12548.html * https://bugzilla.suse.com/show_bug.cgi?id=1241686 * https://bugzilla.suse.com/show_bug.cgi?id=1241688 * https://bugzilla.suse.com/show_bug.cgi?id=1254876 * https://bugzilla.suse.com/show_bug.cgi?id=1272196 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:50:23 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:50:23 -0000 Subject: SUSE-SU-2026:3935-1: moderate: Security update for cups-filters Message-ID: <178843982370.2657.16123603063796566309@f2d94a75072c> # Security update for cups-filters Announcement ID: SUSE-SU-2026:3935-1 Release Date: 2026-09-03T07:24:47Z Rating: moderate References: * bsc#1273145 * bsc#1273146 Cross-References: * CVE-2026-64611 * CVE-2026-64612 CVSS scores: * CVE-2026-64611 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64611 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64611 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64612 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64612 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64612 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for cups-filters fixes the following issues: * CVE-2026-64611: user who controls an IEEE-1284 device ID consumed by `cfIEEE1284GetMakeModel` can drive `cfIEEE1284NormalizeMakeModel` into an infinite loop (bsc#1273145). * CVE-2026-64612: authenticated client that can submit an image print job can abort the CUPS filter process by supplying a malformed PNG (bsc#1273146). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3935=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cups-filters-1.25.0-150200.3.31.1 * cups-filters-debugsource-1.25.0-150200.3.31.1 * cups-filters-devel-1.25.0-150200.3.31.1 * cups-filters-debuginfo-1.25.0-150200.3.31.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64611.html * https://www.suse.com/security/cve/CVE-2026-64612.html * https://bugzilla.suse.com/show_bug.cgi?id=1273145 * https://bugzilla.suse.com/show_bug.cgi?id=1273146 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:51:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:51:09 -0000 Subject: SUSE-SU-2026:3934-1: important: Security update for ffmpeg Message-ID: <178843986941.2657.10668172812505767606@f2d94a75072c> # Security update for ffmpeg Announcement ID: SUSE-SU-2026:3934-1 Release Date: 2026-09-03T07:24:14Z Rating: important References: * bsc#1272755 * bsc#1272757 * bsc#1272759 * bsc#1272761 * bsc#1272762 * bsc#1272763 Cross-References: * CVE-2026-64833 * CVE-2026-64834 * CVE-2026-65703 * CVE-2026-65705 * CVE-2026-65706 * CVE-2026-66036 CVSS scores: * CVE-2026-64833 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64833 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-64833 ( NVD ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-64833 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-64834 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64834 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64834 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-64834 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-65703 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-65703 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-65703 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-65703 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-65705 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-65705 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-65705 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-65705 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-65706 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-65706 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-65706 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-65706 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66036 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-66036 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-66036 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66036 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66036 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for ffmpeg fixes the following issues: * CVE-2026-64833: out-of-bounds read in the S/PDIF muxer via a crafted DTS stream with a `core_size` value larger than the actual packet length (bsc#1272755). * CVE-2026-64834: infinite loop in the RTP/ASF demuxer via a crafted RTP/ASF stream (bsc#1272757). * CVE-2026-65703: out-of-bounds write in the TDSC video decoder via a crafted AVI file that changes frame dimensions across TDSF frames(bsc#1272759). * CVE-2026-65705: out-of-bounds write in the `vf_floodfill` video filter via a dynamically sized video stream with filtergraph reinitialization disabled via `-reinit_filter 0` (bsc#1272761). * CVE-2026-65706: out-of-bounds write in the `vf_swaprect` video filter via a crafted NV12 video frame with odd width dimensions(bsc#1272762). * CVE-2026-66036: out-of-bounds write in the `vf_hqdn3d` filter via a crafted video whose frame resolution increases between frames when filtergraph reinitialization is disabled via the `-reinit_filter 0` option (bsc#1272763). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3934=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3934=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-3934=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3934=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3934=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3934=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3934=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3934=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3934=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3934=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3934=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-3934=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3934=1 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libavcodec57-3.4.2-150200.11.79.1 * libswscale4-debuginfo-3.4.2-150200.11.79.1 * libswresample-devel-3.4.2-150200.11.79.1 * libavutil55-3.4.2-150200.11.79.1 * ffmpeg-debugsource-3.4.2-150200.11.79.1 * libswresample2-3.4.2-150200.11.79.1 * libavcodec57-debuginfo-3.4.2-150200.11.79.1 * libswscale4-3.4.2-150200.11.79.1 * libswresample2-debuginfo-3.4.2-150200.11.79.1 * libpostproc54-debuginfo-3.4.2-150200.11.79.1 * libswscale-devel-3.4.2-150200.11.79.1 * ffmpeg-debuginfo-3.4.2-150200.11.79.1 * libpostproc54-3.4.2-150200.11.79.1 * libavutil55-debuginfo-3.4.2-150200.11.79.1 * libavutil-devel-3.4.2-150200.11.79.1 * libpostproc-devel-3.4.2-150200.11.79.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libswresample-devel-3.4.2-150200.11.79.1 * libavutil55-3.4.2-150200.11.79.1 * libswresample2-3.4.2-150200.11.79.1 * libpostproc54-debuginfo-3.4.2-150200.11.79.1 * libavformat57-debuginfo-3.4.2-150200.11.79.1 * ffmpeg-debuginfo-3.4.2-150200.11.79.1 * libavutil55-debuginfo-3.4.2-150200.11.79.1 * libavutil-devel-3.4.2-150200.11.79.1 * libswresample2-debuginfo-3.4.2-150200.11.79.1 * libswscale4-3.4.2-150200.11.79.1 * libavformat57-3.4.2-150200.11.79.1 * libavcodec57-3.4.2-150200.11.79.1 * libswscale4-debuginfo-3.4.2-150200.11.79.1 * libavcodec57-debuginfo-3.4.2-150200.11.79.1 * libswscale-devel-3.4.2-150200.11.79.1 * libpostproc54-3.4.2-150200.11.79.1 * libpostproc-devel-3.4.2-150200.11.79.1 * ffmpeg-debugsource-3.4.2-150200.11.79.1 * libavresample3-debuginfo-3.4.2-150200.11.79.1 * libavresample3-3.4.2-150200.11.79.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libswresample-devel-3.4.2-150200.11.79.1 * libavutil55-3.4.2-150200.11.79.1 * libswresample2-3.4.2-150200.11.79.1 * libpostproc54-debuginfo-3.4.2-150200.11.79.1 * ffmpeg-debuginfo-3.4.2-150200.11.79.1 * libavformat57-debuginfo-3.4.2-150200.11.79.1 * libavutil55-debuginfo-3.4.2-150200.11.79.1 * libavutil-devel-3.4.2-150200.11.79.1 * libswresample2-debuginfo-3.4.2-150200.11.79.1 * libswscale4-3.4.2-150200.11.79.1 * libavformat57-3.4.2-150200.11.79.1 * libavcodec57-3.4.2-150200.11.79.1 * libswscale4-debuginfo-3.4.2-150200.11.79.1 * libavcodec57-debuginfo-3.4.2-150200.11.79.1 * libswscale-devel-3.4.2-150200.11.79.1 * libpostproc54-3.4.2-150200.11.79.1 * libpostproc-devel-3.4.2-150200.11.79.1 * ffmpeg-debugsource-3.4.2-150200.11.79.1 * libavresample3-debuginfo-3.4.2-150200.11.79.1 * libavresample3-3.4.2-150200.11.79.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * libavdevice57-debuginfo-3.4.2-150200.11.79.1 * ffmpeg-debugsource-3.4.2-150200.11.79.1 * libavdevice57-3.4.2-150200.11.79.1 * libavresample3-debuginfo-3.4.2-150200.11.79.1 * libavfilter6-debuginfo-3.4.2-150200.11.79.1 * libavformat57-debuginfo-3.4.2-150200.11.79.1 * ffmpeg-3.4.2-150200.11.79.1 * ffmpeg-debuginfo-3.4.2-150200.11.79.1 * libavfilter6-3.4.2-150200.11.79.1 * libavresample3-3.4.2-150200.11.79.1 * libavformat57-3.4.2-150200.11.79.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libswscale4-debuginfo-3.4.2-150200.11.79.1 * libavcodec57-3.4.2-150200.11.79.1 * libswresample-devel-3.4.2-150200.11.79.1 * ffmpeg-debuginfo-3.4.2-150200.11.79.1 * ffmpeg-debugsource-3.4.2-150200.11.79.1 * libavutil55-3.4.2-150200.11.79.1 * libswresample2-3.4.2-150200.11.79.1 * libavcodec57-debuginfo-3.4.2-150200.11.79.1 * libswscale4-3.4.2-150200.11.79.1 * libpostproc-devel-3.4.2-150200.11.79.1 * libpostproc54-debuginfo-3.4.2-150200.11.79.1 * libavformat57-3.4.2-150200.11.79.1 * libswscale-devel-3.4.2-150200.11.79.1 * libavformat57-debuginfo-3.4.2-150200.11.79.1 * libpostproc54-3.4.2-150200.11.79.1 * libavutil55-debuginfo-3.4.2-150200.11.79.1 * libavutil-devel-3.4.2-150200.11.79.1 * libswresample2-debuginfo-3.4.2-150200.11.79.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libswresample-devel-3.4.2-150200.11.79.1 * libavutil55-3.4.2-150200.11.79.1 * libswresample2-3.4.2-150200.11.79.1 * libpostproc54-debuginfo-3.4.2-150200.11.79.1 * libavformat57-debuginfo-3.4.2-150200.11.79.1 * ffmpeg-debuginfo-3.4.2-150200.11.79.1 * libavutil55-debuginfo-3.4.2-150200.11.79.1 * libavutil-devel-3.4.2-150200.11.79.1 * libswresample2-debuginfo-3.4.2-150200.11.79.1 * libswscale4-3.4.2-150200.11.79.1 * libavformat57-3.4.2-150200.11.79.1 * libswscale4-debuginfo-3.4.2-150200.11.79.1 * libavcodec57-3.4.2-150200.11.79.1 * libavcodec57-debuginfo-3.4.2-150200.11.79.1 * libswscale-devel-3.4.2-150200.11.79.1 * libpostproc54-3.4.2-150200.11.79.1 * libpostproc-devel-3.4.2-150200.11.79.1 * ffmpeg-debugsource-3.4.2-150200.11.79.1 * libavresample3-debuginfo-3.4.2-150200.11.79.1 * libavresample3-3.4.2-150200.11.79.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libswscale4-debuginfo-3.4.2-150200.11.79.1 * libswresample-devel-3.4.2-150200.11.79.1 * libavcodec57-3.4.2-150200.11.79.1 * ffmpeg-debugsource-3.4.2-150200.11.79.1 * libavutil55-3.4.2-150200.11.79.1 * libswresample2-3.4.2-150200.11.79.1 * libavcodec57-debuginfo-3.4.2-150200.11.79.1 * libswscale4-3.4.2-150200.11.79.1 * libpostproc-devel-3.4.2-150200.11.79.1 * libpostproc54-debuginfo-3.4.2-150200.11.79.1 * libswscale-devel-3.4.2-150200.11.79.1 * ffmpeg-debuginfo-3.4.2-150200.11.79.1 * libpostproc54-3.4.2-150200.11.79.1 * libavutil55-debuginfo-3.4.2-150200.11.79.1 * libavutil-devel-3.4.2-150200.11.79.1 * libswresample2-debuginfo-3.4.2-150200.11.79.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libswscale4-debuginfo-3.4.2-150200.11.79.1 * libswresample-devel-3.4.2-150200.11.79.1 * libavcodec57-3.4.2-150200.11.79.1 * ffmpeg-debuginfo-3.4.2-150200.11.79.1 * ffmpeg-debugsource-3.4.2-150200.11.79.1 * libavutil55-3.4.2-150200.11.79.1 * libswresample2-3.4.2-150200.11.79.1 * libavcodec57-debuginfo-3.4.2-150200.11.79.1 * libswscale4-3.4.2-150200.11.79.1 * libavformat57-debuginfo-3.4.2-150200.11.79.1 * libswresample2-debuginfo-3.4.2-150200.11.79.1 * libpostproc54-debuginfo-3.4.2-150200.11.79.1 * libswscale-devel-3.4.2-150200.11.79.1 * libavformat57-3.4.2-150200.11.79.1 * libpostproc54-3.4.2-150200.11.79.1 * libavutil55-debuginfo-3.4.2-150200.11.79.1 * libavutil-devel-3.4.2-150200.11.79.1 * libpostproc-devel-3.4.2-150200.11.79.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * ffmpeg-debuginfo-3.4.2-150200.11.79.1 * ffmpeg-debugsource-3.4.2-150200.11.79.1 * libavresample3-debuginfo-3.4.2-150200.11.79.1 * libavformat57-debuginfo-3.4.2-150200.11.79.1 * libavcodec-devel-3.4.2-150200.11.79.1 * libavresample-devel-3.4.2-150200.11.79.1 * libavformat-devel-3.4.2-150200.11.79.1 * libavformat57-3.4.2-150200.11.79.1 * libavresample3-3.4.2-150200.11.79.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libswscale4-debuginfo-3.4.2-150200.11.79.1 * libswresample-devel-3.4.2-150200.11.79.1 * libavcodec57-3.4.2-150200.11.79.1 * libavutil55-3.4.2-150200.11.79.1 * ffmpeg-debugsource-3.4.2-150200.11.79.1 * libswresample2-3.4.2-150200.11.79.1 * libavcodec57-debuginfo-3.4.2-150200.11.79.1 * libswscale4-3.4.2-150200.11.79.1 * libswresample2-debuginfo-3.4.2-150200.11.79.1 * libpostproc54-debuginfo-3.4.2-150200.11.79.1 * libswscale-devel-3.4.2-150200.11.79.1 * ffmpeg-debuginfo-3.4.2-150200.11.79.1 * libpostproc54-3.4.2-150200.11.79.1 * libavutil55-debuginfo-3.4.2-150200.11.79.1 * libavutil-devel-3.4.2-150200.11.79.1 * libpostproc-devel-3.4.2-150200.11.79.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libswresample-devel-3.4.2-150200.11.79.1 * libavutil55-3.4.2-150200.11.79.1 * libswresample2-3.4.2-150200.11.79.1 * libpostproc54-debuginfo-3.4.2-150200.11.79.1 * ffmpeg-debuginfo-3.4.2-150200.11.79.1 * libavformat57-debuginfo-3.4.2-150200.11.79.1 * libavutil55-debuginfo-3.4.2-150200.11.79.1 * libavutil-devel-3.4.2-150200.11.79.1 * libswresample2-debuginfo-3.4.2-150200.11.79.1 * libswscale4-3.4.2-150200.11.79.1 * libavformat57-3.4.2-150200.11.79.1 * libswscale4-debuginfo-3.4.2-150200.11.79.1 * libavcodec57-3.4.2-150200.11.79.1 * libavcodec57-debuginfo-3.4.2-150200.11.79.1 * libswscale-devel-3.4.2-150200.11.79.1 * libpostproc54-3.4.2-150200.11.79.1 * libpostproc-devel-3.4.2-150200.11.79.1 * ffmpeg-debugsource-3.4.2-150200.11.79.1 * libavresample3-debuginfo-3.4.2-150200.11.79.1 * libavresample3-3.4.2-150200.11.79.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libavcodec57-3.4.2-150200.11.79.1 * libswresample-devel-3.4.2-150200.11.79.1 * libswscale4-debuginfo-3.4.2-150200.11.79.1 * libavutil55-3.4.2-150200.11.79.1 * ffmpeg-debugsource-3.4.2-150200.11.79.1 * libswresample2-3.4.2-150200.11.79.1 * libavcodec57-debuginfo-3.4.2-150200.11.79.1 * libswscale4-3.4.2-150200.11.79.1 * libavformat57-debuginfo-3.4.2-150200.11.79.1 * libswresample2-debuginfo-3.4.2-150200.11.79.1 * libpostproc54-debuginfo-3.4.2-150200.11.79.1 * libavformat57-3.4.2-150200.11.79.1 * libswscale-devel-3.4.2-150200.11.79.1 * ffmpeg-debuginfo-3.4.2-150200.11.79.1 * libpostproc54-3.4.2-150200.11.79.1 * libavutil55-debuginfo-3.4.2-150200.11.79.1 * libavutil-devel-3.4.2-150200.11.79.1 * libpostproc-devel-3.4.2-150200.11.79.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libavcodec57-3.4.2-150200.11.79.1 * libswresample-devel-3.4.2-150200.11.79.1 * libswscale4-debuginfo-3.4.2-150200.11.79.1 * ffmpeg-debuginfo-3.4.2-150200.11.79.1 * libavutil55-3.4.2-150200.11.79.1 * ffmpeg-debugsource-3.4.2-150200.11.79.1 * libswresample2-3.4.2-150200.11.79.1 * libavcodec57-debuginfo-3.4.2-150200.11.79.1 * libswscale4-3.4.2-150200.11.79.1 * libavformat57-debuginfo-3.4.2-150200.11.79.1 * libswresample2-debuginfo-3.4.2-150200.11.79.1 * libpostproc54-debuginfo-3.4.2-150200.11.79.1 * libswscale-devel-3.4.2-150200.11.79.1 * libavformat57-3.4.2-150200.11.79.1 * libpostproc54-3.4.2-150200.11.79.1 * libavutil55-debuginfo-3.4.2-150200.11.79.1 * libavutil-devel-3.4.2-150200.11.79.1 * libpostproc-devel-3.4.2-150200.11.79.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64833.html * https://www.suse.com/security/cve/CVE-2026-64834.html * https://www.suse.com/security/cve/CVE-2026-65703.html * https://www.suse.com/security/cve/CVE-2026-65705.html * https://www.suse.com/security/cve/CVE-2026-65706.html * https://www.suse.com/security/cve/CVE-2026-66036.html * https://bugzilla.suse.com/show_bug.cgi?id=1272755 * https://bugzilla.suse.com/show_bug.cgi?id=1272757 * https://bugzilla.suse.com/show_bug.cgi?id=1272759 * https://bugzilla.suse.com/show_bug.cgi?id=1272761 * https://bugzilla.suse.com/show_bug.cgi?id=1272762 * https://bugzilla.suse.com/show_bug.cgi?id=1272763 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:51:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:51:53 -0000 Subject: SUSE-SU-2026:3933-1: moderate: Security update for busybox Message-ID: <178843991387.2657.13879536751123202481@f2d94a75072c> # Security update for busybox Announcement ID: SUSE-SU-2026:3933-1 Release Date: 2026-09-03T07:21:45Z Rating: moderate References: * bsc#1217586 * bsc#1271544 * bsc#1271545 * bsc#1271547 * bsc#1271548 Cross-References: * CVE-2023-42366 * CVE-2026-38752 * CVE-2026-38753 * CVE-2026-38754 * CVE-2026-38755 CVSS scores: * CVE-2023-42366 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-42366 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-38752 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-38752 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-38752 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-38752 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-38753 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-38753 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-38753 ( NVD ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-38753 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-38754 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-38754 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-38754 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-38754 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-38755 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-38755 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-38755 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-38755 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves five vulnerabilities can now be installed. ## Description: This update for busybox fixes the following issues: * CVE-2023-42366: heap buffer overflow in the `next_token` function of `editors/awk.c` (bsc#1217586). * CVE-2026-38752: stack buffer overflow in the `evaluate()` function of `editors/awk.c` (bsc#1271544). * CVE-2026-38753: use-after-free in the `awk_sub()` function of `editors/awk.c` (bsc#1271545). * CVE-2026-38754: heap buffer overflow in `ifsbreakup()` function of `shell/ash.c` (bsc#1271547). * CVE-2026-38755: heap buffer overflow in `evalcommand()` function of `shell/ash.c` (bsc#1271548). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3933=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * busybox-1.37.0-150700.18.21.1 * busybox-static-1.37.0-150700.18.21.1 ## References: * https://www.suse.com/security/cve/CVE-2023-42366.html * https://www.suse.com/security/cve/CVE-2026-38752.html * https://www.suse.com/security/cve/CVE-2026-38753.html * https://www.suse.com/security/cve/CVE-2026-38754.html * https://www.suse.com/security/cve/CVE-2026-38755.html * https://bugzilla.suse.com/show_bug.cgi?id=1217586 * https://bugzilla.suse.com/show_bug.cgi?id=1271544 * https://bugzilla.suse.com/show_bug.cgi?id=1271545 * https://bugzilla.suse.com/show_bug.cgi?id=1271547 * https://bugzilla.suse.com/show_bug.cgi?id=1271548 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:52:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:52:32 -0000 Subject: SUSE-SU-2026:3932-1: important: Security update for python-msgpack Message-ID: <178843995288.2657.6687903292428374809@f2d94a75072c> # Security update for python-msgpack Announcement ID: SUSE-SU-2026:3932-1 Release Date: 2026-09-03T07:21:03Z Rating: important References: * bsc#1269947 Cross-References: * CVE-2026-57585 CVSS scores: * CVE-2026-57585 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-57585 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python-msgpack fixes the following issue: * CVE-2026-57585: reusing an Unpacker instance after an error has been caught can lead to an out-of-bounds read (bsc#1269947). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3932=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3932=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3932=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3932=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3932=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3932=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3932=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3932=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3932=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python311-msgpack-1.0.7-150400.10.9.1 * python-msgpack-debugsource-1.0.7-150400.10.9.1 * python311-msgpack-debuginfo-1.0.7-150400.10.9.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python311-msgpack-debuginfo-1.0.7-150400.10.9.1 * python-msgpack-debugsource-1.0.7-150400.10.9.1 * python311-msgpack-1.0.7-150400.10.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python311-msgpack-1.0.7-150400.10.9.1 * python-msgpack-debugsource-1.0.7-150400.10.9.1 * python311-msgpack-debuginfo-1.0.7-150400.10.9.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python311-msgpack-1.0.7-150400.10.9.1 * python-msgpack-debugsource-1.0.7-150400.10.9.1 * python311-msgpack-debuginfo-1.0.7-150400.10.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python311-msgpack-debuginfo-1.0.7-150400.10.9.1 * python-msgpack-debugsource-1.0.7-150400.10.9.1 * python311-msgpack-1.0.7-150400.10.9.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-msgpack-debuginfo-1.0.7-150400.10.9.1 * python-msgpack-debugsource-1.0.7-150400.10.9.1 * python311-msgpack-1.0.7-150400.10.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python311-msgpack-debuginfo-1.0.7-150400.10.9.1 * python-msgpack-debugsource-1.0.7-150400.10.9.1 * python311-msgpack-1.0.7-150400.10.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python311-msgpack-debuginfo-1.0.7-150400.10.9.1 * python-msgpack-debugsource-1.0.7-150400.10.9.1 * python311-msgpack-1.0.7-150400.10.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python311-msgpack-1.0.7-150400.10.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-57585.html * https://bugzilla.suse.com/show_bug.cgi?id=1269947 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:53:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:53:29 -0000 Subject: SUSE-SU-2026:3931-1: important: Security update for dracut Message-ID: <178844000994.2657.9410995470987925277@f2d94a75072c> # Security update for dracut Announcement ID: SUSE-SU-2026:3931-1 Release Date: 2026-09-03T07:19:34Z Rating: important References: * bsc#1268322 * bsc#1273580 Cross-References: * CVE-2026-16445 * CVE-2026-6893 CVSS scores: * CVE-2026-16445 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16445 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for dracut fixes the following issues: * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). * CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580). Changes for dracut: * Update to version 059+suse.576.g72b98359a: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2026-3931=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3931=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * dracut-fips-059+suse.576.g72b98359a-150700.3.23.1 * dracut-debuginfo-059+suse.576.g72b98359a-150700.3.23.1 * dracut-ima-059+suse.576.g72b98359a-150700.3.23.1 * dracut-debugsource-059+suse.576.g72b98359a-150700.3.23.1 * dracut-059+suse.576.g72b98359a-150700.3.23.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (ppc64le x86_64) * dracut-debugsource-059+suse.576.g72b98359a-150700.3.23.1 * dracut-mkinitrd-deprecated-059+suse.576.g72b98359a-150700.3.23.1 * dracut-debuginfo-059+suse.576.g72b98359a-150700.3.23.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16445.html * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 * https://bugzilla.suse.com/show_bug.cgi?id=1273580 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:54:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:54:55 -0000 Subject: SUSE-SU-2026:3930-1: important: Security update for nodejs20 Message-ID: <178844009516.2657.503886012805906603@f2d94a75072c> # Security update for nodejs20 Announcement ID: SUSE-SU-2026:3930-1 Release Date: 2026-09-03T07:19:03Z Rating: important References: * bsc#1236258 * bsc#1256848 * bsc#1259853 * bsc#1262274 * bsc#1266318 * bsc#1268097 * bsc#1268477 * bsc#1268479 * bsc#1268481 * bsc#1268482 * bsc#1268554 * bsc#1268555 * bsc#1268592 * bsc#1268593 * bsc#1268598 * bsc#1268605 * bsc#1268606 * bsc#1268608 * bsc#1268609 * bsc#1268611 * bsc#1268618 * bsc#1269825 * bsc#1272882 * bsc#1272941 * bsc#1272942 * bsc#1272943 * bsc#1272944 * bsc#1272945 * bsc#1272947 * bsc#1272948 * bsc#1272949 * bsc#1272950 * bsc#1272951 * bsc#1273591 * bsc#1273593 * bsc#1277587 Cross-References: * CVE-2025-22150 * CVE-2026-11525 * CVE-2026-12151 * CVE-2026-16728 * CVE-2026-16729 * CVE-2026-22036 * CVE-2026-27135 * CVE-2026-40170 * CVE-2026-42338 * CVE-2026-48615 * CVE-2026-48617 * CVE-2026-48618 * CVE-2026-48619 * CVE-2026-48928 * CVE-2026-48930 * CVE-2026-48931 * CVE-2026-48933 * CVE-2026-48934 * CVE-2026-48935 * CVE-2026-48937 * CVE-2026-54272 * CVE-2026-56846 * CVE-2026-56847 * CVE-2026-56848 * CVE-2026-56850 * CVE-2026-58039 * CVE-2026-58040 * CVE-2026-58042 * CVE-2026-58043 * CVE-2026-58044 * CVE-2026-58045 * CVE-2026-6733 * CVE-2026-69192 * CVE-2026-9496 * CVE-2026-9679 CVSS scores: * CVE-2025-22150 ( SUSE ): 7.4 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-22150 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-22150 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-11525 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-11525 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-12151 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16728 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-16728 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-16728 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16729 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-16729 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-16729 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-22036 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22036 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22036 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-22036 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27135 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40170 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42338 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42338 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42338 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42338 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42338 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-48615 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48615 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48615 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48615 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48617 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48617 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N * CVE-2026-48617 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-48617 ( NVD ): 1.8 CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N * CVE-2026-48618 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48618 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-48618 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-48618 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48618 ( NVD ): 7.7 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-48619 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48619 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48619 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48928 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48928 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-48928 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48928 ( NVD ): 4.2 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48930 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48930 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-48930 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48930 ( NVD ): 5.6 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-48931 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48931 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48931 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48931 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48933 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48933 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48933 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48933 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48934 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48934 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48934 ( NVD ): 4.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-48935 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48935 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48935 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48937 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48937 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48937 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-54272 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N * CVE-2026-54272 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-54272 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56846 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56846 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56847 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-56847 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-56847 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N * CVE-2026-56847 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-56848 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56848 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56848 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56850 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56850 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-56850 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-56850 ( NVD ): 4.1 CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-58039 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-58039 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-58039 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-58040 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-58040 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-58040 ( NVD ): 6.3 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-58042 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58042 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58042 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58043 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2026-58043 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-58043 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-58043 ( NVD ): 7.5 CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-58044 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-58044 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-58044 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-58045 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58045 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58045 ( NVD ): 6.2 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6733 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-6733 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-69192 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-69192 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-9496 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9496 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-9496 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9679 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-9679 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 35 vulnerabilities and has one security fix can now be installed. ## Description: This update for nodejs20 fixes the following issues: * CVE-2025-22150: undici: predictable random values used when defining the boundary for a `multipart`/`form-data` request (bsc#1236258). * CVE-2026-6733: undici: response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery (bsc#1268479). * CVE-2026-9496: pacote: excessive CPU consumption in `addGitSha` when processing a specially crafted `spec.rawSpec` value can lead to DoS (bsc#1266318). * CVE-2026-9679: undici: HTTP header injection via `Set-Cookie` percent- decoding (bsc#1268477). * CVE-2026-11525: undici: weakening of cookie `SameSite` policy due to incorrect parsing of `Set-Cookie` header (bsc#1268481). * CVE-2026-12151: undici: denial of service due to unbounded memory growth via WebSocket frames (bsc#1268482). * CVE-2026-16728: undici: downstream response desynchronization via retry interceptor (bsc#1273593). * CVE-2026-16729: undici: `setCookie` function does not fully sanitize cookie attributes (bsc#1273591). * CVE-2026-22036: undici: unbounded decompression chain in HTTP responses via `Content-Encoding` may lead to resource exhaustion (bsc#1256848). * CVE-2026-27135: nghttp2: assertion failure due to missing state validation can lead to DoS (bsc#1259853). * CVE-2026-40170: ngtcp2: qlog `parameters_set` stack buffer overflow (bsc#1262274). * CVE-2026-42338: ip-address: cross-site scripting via improper HTML escaping of untrusted input (bsc#1268097). * CVE-2026-48615: proxy credentials leaked in `ERR_PROXY_TUNNEL` error message (bsc#1268598). * CVE-2026-48617: permission model enforcement bypass via `process.report.writeReport()` path misvalidation (bsc#1268554). * CVE-2026-48618: unicode dot separator handling can lead to tls wildcard- depth authentication bypass due to resolver and verifier hostname normalization mismatch (bsc#1268593). * CVE-2026-48619: unbounded memory growth in `node:http2` clients via attacker-controlled `ORIGIN` frames (bsc#1268618). * CVE-2026-48928: uppercase sni context matching can lead to mtls authorization bypass due to case-sensitive hostname matching (bsc#1268605). * CVE-2026-48930: `embedded-nul` hostnames can lead to silent authority rebinding due to `c-string` truncation in resolver bindings (bsc#1268606). * CVE-2026-48931: HTTP response queue poisoning via TOCTOU race condition in `http.Agent` (bsc#1268611). * CVE-2026-48933: WebCrypto AES integer overflow leads to remote process abort (bsc#1268592). * CVE-2026-48934: TLS host identity verification bypass via session reuse with different servername leads to unauthorized connections (bsc#1268608). * CVE-2026-48935: permission model bypass via `FileHandle.utimes()` in the `promises` API (bsc#1268609). * CVE-2026-48937: servers keep accepting data even after sending a `GOAWAY` frame (bsc#1268555). * CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust- boundary checks (bsc#1272882). * CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941). * CVE-2026-56847: permission model allows trace events to write outside the allowlist (bsc#1272949). * CVE-2026-56848: HTTP/2 re-entrant send can cause heap use-after-free (bsc#1272942). * CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944). * CVE-2026-58039: permission model allows process reports to write outside the allowlist (bsc#1272950). * CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945). * CVE-2026-58042: `dns.resolveAny()` can abort on DNS responses with many `A` records (bsc#1272947). * CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943). * CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951). * CVE-2026-58045: `node:zlib` sync APIs can crash on spoofed `TypedArray` length (bsc#1272948). * CVE-2026-69192: ip-address: `Address4` decodes leading-zero octets as decimal while resolvers decode them as octal, which allows for SSRF and trust-boundary bypass (bsc#1277587). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3930=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3930=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3930=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3930=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3930=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * nodejs20-20.20.2-150500.11.30.1 * npm20-20.20.2-150500.11.30.1 * nodejs20-debuginfo-20.20.2-150500.11.30.1 * nodejs20-devel-20.20.2-150500.11.30.1 * nodejs20-debugsource-20.20.2-150500.11.30.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * nodejs20-docs-20.20.2-150500.11.30.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * nodejs20-20.20.2-150500.11.30.1 * npm20-20.20.2-150500.11.30.1 * nodejs20-debuginfo-20.20.2-150500.11.30.1 * nodejs20-devel-20.20.2-150500.11.30.1 * nodejs20-debugsource-20.20.2-150500.11.30.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * nodejs20-docs-20.20.2-150500.11.30.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * nodejs20-20.20.2-150500.11.30.1 * npm20-20.20.2-150500.11.30.1 * nodejs20-debuginfo-20.20.2-150500.11.30.1 * nodejs20-devel-20.20.2-150500.11.30.1 * nodejs20-debugsource-20.20.2-150500.11.30.1 * corepack20-20.20.2-150500.11.30.1 * openSUSE Leap 15.5 (noarch) * nodejs20-docs-20.20.2-150500.11.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * nodejs20-20.20.2-150500.11.30.1 * npm20-20.20.2-150500.11.30.1 * nodejs20-debuginfo-20.20.2-150500.11.30.1 * nodejs20-devel-20.20.2-150500.11.30.1 * nodejs20-debugsource-20.20.2-150500.11.30.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * nodejs20-docs-20.20.2-150500.11.30.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * nodejs20-20.20.2-150500.11.30.1 * npm20-20.20.2-150500.11.30.1 * nodejs20-debuginfo-20.20.2-150500.11.30.1 * nodejs20-devel-20.20.2-150500.11.30.1 * nodejs20-debugsource-20.20.2-150500.11.30.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * nodejs20-docs-20.20.2-150500.11.30.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22150.html * https://www.suse.com/security/cve/CVE-2026-11525.html * https://www.suse.com/security/cve/CVE-2026-12151.html * https://www.suse.com/security/cve/CVE-2026-16728.html * https://www.suse.com/security/cve/CVE-2026-16729.html * https://www.suse.com/security/cve/CVE-2026-22036.html * https://www.suse.com/security/cve/CVE-2026-27135.html * https://www.suse.com/security/cve/CVE-2026-40170.html * https://www.suse.com/security/cve/CVE-2026-42338.html * https://www.suse.com/security/cve/CVE-2026-48615.html * https://www.suse.com/security/cve/CVE-2026-48617.html * https://www.suse.com/security/cve/CVE-2026-48618.html * https://www.suse.com/security/cve/CVE-2026-48619.html * https://www.suse.com/security/cve/CVE-2026-48928.html * https://www.suse.com/security/cve/CVE-2026-48930.html * https://www.suse.com/security/cve/CVE-2026-48931.html * https://www.suse.com/security/cve/CVE-2026-48933.html * https://www.suse.com/security/cve/CVE-2026-48934.html * https://www.suse.com/security/cve/CVE-2026-48935.html * https://www.suse.com/security/cve/CVE-2026-48937.html * https://www.suse.com/security/cve/CVE-2026-54272.html * https://www.suse.com/security/cve/CVE-2026-56846.html * https://www.suse.com/security/cve/CVE-2026-56847.html * https://www.suse.com/security/cve/CVE-2026-56848.html * https://www.suse.com/security/cve/CVE-2026-56850.html * https://www.suse.com/security/cve/CVE-2026-58039.html * https://www.suse.com/security/cve/CVE-2026-58040.html * https://www.suse.com/security/cve/CVE-2026-58042.html * https://www.suse.com/security/cve/CVE-2026-58043.html * https://www.suse.com/security/cve/CVE-2026-58044.html * https://www.suse.com/security/cve/CVE-2026-58045.html * https://www.suse.com/security/cve/CVE-2026-6733.html * https://www.suse.com/security/cve/CVE-2026-69192.html * https://www.suse.com/security/cve/CVE-2026-9496.html * https://www.suse.com/security/cve/CVE-2026-9679.html * https://bugzilla.suse.com/show_bug.cgi?id=1236258 * https://bugzilla.suse.com/show_bug.cgi?id=1256848 * https://bugzilla.suse.com/show_bug.cgi?id=1259853 * https://bugzilla.suse.com/show_bug.cgi?id=1262274 * https://bugzilla.suse.com/show_bug.cgi?id=1266318 * https://bugzilla.suse.com/show_bug.cgi?id=1268097 * https://bugzilla.suse.com/show_bug.cgi?id=1268477 * https://bugzilla.suse.com/show_bug.cgi?id=1268479 * https://bugzilla.suse.com/show_bug.cgi?id=1268481 * https://bugzilla.suse.com/show_bug.cgi?id=1268482 * https://bugzilla.suse.com/show_bug.cgi?id=1268554 * https://bugzilla.suse.com/show_bug.cgi?id=1268555 * https://bugzilla.suse.com/show_bug.cgi?id=1268592 * https://bugzilla.suse.com/show_bug.cgi?id=1268593 * https://bugzilla.suse.com/show_bug.cgi?id=1268598 * https://bugzilla.suse.com/show_bug.cgi?id=1268605 * https://bugzilla.suse.com/show_bug.cgi?id=1268606 * https://bugzilla.suse.com/show_bug.cgi?id=1268608 * https://bugzilla.suse.com/show_bug.cgi?id=1268609 * https://bugzilla.suse.com/show_bug.cgi?id=1268611 * https://bugzilla.suse.com/show_bug.cgi?id=1268618 * https://bugzilla.suse.com/show_bug.cgi?id=1269825 * https://bugzilla.suse.com/show_bug.cgi?id=1272882 * https://bugzilla.suse.com/show_bug.cgi?id=1272941 * https://bugzilla.suse.com/show_bug.cgi?id=1272942 * https://bugzilla.suse.com/show_bug.cgi?id=1272943 * https://bugzilla.suse.com/show_bug.cgi?id=1272944 * https://bugzilla.suse.com/show_bug.cgi?id=1272945 * https://bugzilla.suse.com/show_bug.cgi?id=1272947 * https://bugzilla.suse.com/show_bug.cgi?id=1272948 * https://bugzilla.suse.com/show_bug.cgi?id=1272949 * https://bugzilla.suse.com/show_bug.cgi?id=1272950 * https://bugzilla.suse.com/show_bug.cgi?id=1272951 * https://bugzilla.suse.com/show_bug.cgi?id=1273591 * https://bugzilla.suse.com/show_bug.cgi?id=1273593 * https://bugzilla.suse.com/show_bug.cgi?id=1277587 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:56:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:56:37 -0000 Subject: SUSE-SU-2026:3929-1: important: Security update for nodejs20 Message-ID: <178844019766.2657.10272830214324210036@f2d94a75072c> # Security update for nodejs20 Announcement ID: SUSE-SU-2026:3929-1 Release Date: 2026-09-03T07:18:06Z Rating: important References: * bsc#1236258 * bsc#1256848 * bsc#1259853 * bsc#1262274 * bsc#1266318 * bsc#1268097 * bsc#1268477 * bsc#1268479 * bsc#1268481 * bsc#1268482 * bsc#1268554 * bsc#1268555 * bsc#1268592 * bsc#1268593 * bsc#1268598 * bsc#1268605 * bsc#1268606 * bsc#1268608 * bsc#1268609 * bsc#1268611 * bsc#1268618 * bsc#1269825 * bsc#1272882 * bsc#1272941 * bsc#1272942 * bsc#1272943 * bsc#1272944 * bsc#1272945 * bsc#1272947 * bsc#1272948 * bsc#1272949 * bsc#1272950 * bsc#1272951 * bsc#1273591 * bsc#1273593 * bsc#1277587 Cross-References: * CVE-2025-22150 * CVE-2026-11525 * CVE-2026-12151 * CVE-2026-16728 * CVE-2026-16729 * CVE-2026-22036 * CVE-2026-27135 * CVE-2026-40170 * CVE-2026-42338 * CVE-2026-48615 * CVE-2026-48617 * CVE-2026-48618 * CVE-2026-48619 * CVE-2026-48928 * CVE-2026-48930 * CVE-2026-48931 * CVE-2026-48933 * CVE-2026-48934 * CVE-2026-48935 * CVE-2026-48937 * CVE-2026-54272 * CVE-2026-56846 * CVE-2026-56847 * CVE-2026-56848 * CVE-2026-56850 * CVE-2026-58039 * CVE-2026-58040 * CVE-2026-58042 * CVE-2026-58043 * CVE-2026-58044 * CVE-2026-58045 * CVE-2026-6733 * CVE-2026-69192 * CVE-2026-9496 * CVE-2026-9679 CVSS scores: * CVE-2025-22150 ( SUSE ): 7.4 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-22150 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-22150 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-11525 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-11525 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-12151 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16728 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-16728 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-16728 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16729 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-16729 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-16729 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-22036 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22036 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22036 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-22036 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27135 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40170 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40170 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42338 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42338 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42338 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-42338 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42338 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-48615 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48615 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48615 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48615 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48617 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48617 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N * CVE-2026-48617 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N * CVE-2026-48617 ( NVD ): 1.8 CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:N * CVE-2026-48618 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48618 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-48618 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-48618 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48618 ( NVD ): 7.7 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-48619 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48619 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48619 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48928 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48928 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-48928 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48928 ( NVD ): 4.2 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48930 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48930 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-48930 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48930 ( NVD ): 5.6 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-48931 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48931 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48931 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48931 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48933 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48933 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48933 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48933 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48934 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48934 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48934 ( NVD ): 4.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-48935 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48935 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48935 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48937 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48937 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48937 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-54272 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N * CVE-2026-54272 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-54272 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56846 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56846 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56847 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-56847 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-56847 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N * CVE-2026-56847 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-56848 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56848 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56848 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56850 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56850 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-56850 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-56850 ( NVD ): 4.1 CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-58039 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-58039 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-58039 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-58040 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-58040 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-58040 ( NVD ): 6.3 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-58042 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58042 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58042 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58043 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2026-58043 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-58043 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-58043 ( NVD ): 7.5 CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-58044 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-58044 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-58044 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-58045 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58045 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58045 ( NVD ): 6.2 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6733 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-6733 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-69192 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-69192 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-9496 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-9496 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-9496 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9679 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-9679 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 35 vulnerabilities and has one security fix can now be installed. ## Description: This update for nodejs20 fixes the following issues: * CVE-2025-22150: undici: predictable random values used when defining the boundary for a `multipart`/`form-data` request (bsc#1236258). * CVE-2026-6733: undici: response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery (bsc#1268479). * CVE-2026-9496: pacote: excessive CPU consumption in `addGitSha` when processing a specially crafted `spec.rawSpec` value can lead to DoS (bsc#1266318). * CVE-2026-9679: undici: HTTP header injection via `Set-Cookie` percent- decoding (bsc#1268477). * CVE-2026-11525: undici: weakening of cookie `SameSite` policy due to incorrect parsing of `Set-Cookie` header (bsc#1268481). * CVE-2026-12151: undici: denial of service due to unbounded memory growth via WebSocket frames (bsc#1268482). * CVE-2026-16728: undici: downstream response desynchronization via retry interceptor (bsc#1273593). * CVE-2026-16729: undici: `setCookie` function does not fully sanitize cookie attributes (bsc#1273591). * CVE-2026-22036: undici: unbounded decompression chain in HTTP responses via `Content-Encoding` may lead to resource exhaustion (bsc#1256848). * CVE-2026-27135: nghttp2: assertion failure due to missing state validation can lead to DoS (bsc#1259853). * CVE-2026-40170: ngtcp2: qlog `parameters_set` stack buffer overflow (bsc#1262274). * CVE-2026-42338: ip-address: cross-site scripting via improper HTML escaping of untrusted input (bsc#1268097). * CVE-2026-48615: proxy credentials leaked in `ERR_PROXY_TUNNEL` error message (bsc#1268598). * CVE-2026-48617: permission model enforcement bypass via `process.report.writeReport()` path misvalidation (bsc#1268554). * CVE-2026-48618: unicode dot separator handling can lead to tls wildcard- depth authentication bypass due to resolver and verifier hostname normalization mismatch (bsc#1268593). * CVE-2026-48619: unbounded memory growth in `node:http2` clients via attacker-controlled `ORIGIN` frames (bsc#1268618). * CVE-2026-48928: uppercase sni context matching can lead to mtls authorization bypass due to case-sensitive hostname matching (bsc#1268605). * CVE-2026-48930: `embedded-nul` hostnames can lead to silent authority rebinding due to `c-string` truncation in resolver bindings (bsc#1268606). * CVE-2026-48931: HTTP response queue poisoning via TOCTOU race condition in `http.Agent` (bsc#1268611). * CVE-2026-48933: WebCrypto AES integer overflow leads to remote process abort (bsc#1268592). * CVE-2026-48934: TLS host identity verification bypass via session reuse with different servername leads to unauthorized connections (bsc#1268608). * CVE-2026-48935: permission model bypass via `FileHandle.utimes()` in the `promises` API (bsc#1268609). * CVE-2026-48937: servers keep accepting data even after sending a `GOAWAY` frame (bsc#1268555). * CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust- boundary checks (bsc#1272882). * CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941). * CVE-2026-56847: permission model allows trace events to write outside the allowlist (bsc#1272949). * CVE-2026-56848: HTTP/2 re-entrant send can cause heap use-after-free (bsc#1272942). * CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944). * CVE-2026-58039: permission model allows process reports to write outside the allowlist (bsc#1272950). * CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945). * CVE-2026-58042: `dns.resolveAny()` can abort on DNS responses with many `A` records (bsc#1272947). * CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943). * CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951). * CVE-2026-58045: `node:zlib` sync APIs can crash on spoofed `TypedArray` length (bsc#1272948). * CVE-2026-69192: ip-address: `Address4` decodes leading-zero octets as decimal while resolvers decode them as octal, which allows for SSRF and trust-boundary bypass (bsc#1277587). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3929=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3929=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3929=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * nodejs20-docs-20.20.2-150600.3.21.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * nodejs20-debugsource-20.20.2-150600.3.21.1 * nodejs20-debuginfo-20.20.2-150600.3.21.1 * nodejs20-devel-20.20.2-150600.3.21.1 * nodejs20-20.20.2-150600.3.21.1 * npm20-20.20.2-150600.3.21.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * nodejs20-debugsource-20.20.2-150600.3.21.1 * nodejs20-debuginfo-20.20.2-150600.3.21.1 * nodejs20-devel-20.20.2-150600.3.21.1 * nodejs20-20.20.2-150600.3.21.1 * npm20-20.20.2-150600.3.21.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * nodejs20-docs-20.20.2-150600.3.21.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * nodejs20-debugsource-20.20.2-150600.3.21.1 * nodejs20-debuginfo-20.20.2-150600.3.21.1 * nodejs20-devel-20.20.2-150600.3.21.1 * nodejs20-20.20.2-150600.3.21.1 * npm20-20.20.2-150600.3.21.1 * corepack20-20.20.2-150600.3.21.1 * openSUSE Leap 15.6 (noarch) * nodejs20-docs-20.20.2-150600.3.21.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22150.html * https://www.suse.com/security/cve/CVE-2026-11525.html * https://www.suse.com/security/cve/CVE-2026-12151.html * https://www.suse.com/security/cve/CVE-2026-16728.html * https://www.suse.com/security/cve/CVE-2026-16729.html * https://www.suse.com/security/cve/CVE-2026-22036.html * https://www.suse.com/security/cve/CVE-2026-27135.html * https://www.suse.com/security/cve/CVE-2026-40170.html * https://www.suse.com/security/cve/CVE-2026-42338.html * https://www.suse.com/security/cve/CVE-2026-48615.html * https://www.suse.com/security/cve/CVE-2026-48617.html * https://www.suse.com/security/cve/CVE-2026-48618.html * https://www.suse.com/security/cve/CVE-2026-48619.html * https://www.suse.com/security/cve/CVE-2026-48928.html * https://www.suse.com/security/cve/CVE-2026-48930.html * https://www.suse.com/security/cve/CVE-2026-48931.html * https://www.suse.com/security/cve/CVE-2026-48933.html * https://www.suse.com/security/cve/CVE-2026-48934.html * https://www.suse.com/security/cve/CVE-2026-48935.html * https://www.suse.com/security/cve/CVE-2026-48937.html * https://www.suse.com/security/cve/CVE-2026-54272.html * https://www.suse.com/security/cve/CVE-2026-56846.html * https://www.suse.com/security/cve/CVE-2026-56847.html * https://www.suse.com/security/cve/CVE-2026-56848.html * https://www.suse.com/security/cve/CVE-2026-56850.html * https://www.suse.com/security/cve/CVE-2026-58039.html * https://www.suse.com/security/cve/CVE-2026-58040.html * https://www.suse.com/security/cve/CVE-2026-58042.html * https://www.suse.com/security/cve/CVE-2026-58043.html * https://www.suse.com/security/cve/CVE-2026-58044.html * https://www.suse.com/security/cve/CVE-2026-58045.html * https://www.suse.com/security/cve/CVE-2026-6733.html * https://www.suse.com/security/cve/CVE-2026-69192.html * https://www.suse.com/security/cve/CVE-2026-9496.html * https://www.suse.com/security/cve/CVE-2026-9679.html * https://bugzilla.suse.com/show_bug.cgi?id=1236258 * https://bugzilla.suse.com/show_bug.cgi?id=1256848 * https://bugzilla.suse.com/show_bug.cgi?id=1259853 * https://bugzilla.suse.com/show_bug.cgi?id=1262274 * https://bugzilla.suse.com/show_bug.cgi?id=1266318 * https://bugzilla.suse.com/show_bug.cgi?id=1268097 * https://bugzilla.suse.com/show_bug.cgi?id=1268477 * https://bugzilla.suse.com/show_bug.cgi?id=1268479 * https://bugzilla.suse.com/show_bug.cgi?id=1268481 * https://bugzilla.suse.com/show_bug.cgi?id=1268482 * https://bugzilla.suse.com/show_bug.cgi?id=1268554 * https://bugzilla.suse.com/show_bug.cgi?id=1268555 * https://bugzilla.suse.com/show_bug.cgi?id=1268592 * https://bugzilla.suse.com/show_bug.cgi?id=1268593 * https://bugzilla.suse.com/show_bug.cgi?id=1268598 * https://bugzilla.suse.com/show_bug.cgi?id=1268605 * https://bugzilla.suse.com/show_bug.cgi?id=1268606 * https://bugzilla.suse.com/show_bug.cgi?id=1268608 * https://bugzilla.suse.com/show_bug.cgi?id=1268609 * https://bugzilla.suse.com/show_bug.cgi?id=1268611 * https://bugzilla.suse.com/show_bug.cgi?id=1268618 * https://bugzilla.suse.com/show_bug.cgi?id=1269825 * https://bugzilla.suse.com/show_bug.cgi?id=1272882 * https://bugzilla.suse.com/show_bug.cgi?id=1272941 * https://bugzilla.suse.com/show_bug.cgi?id=1272942 * https://bugzilla.suse.com/show_bug.cgi?id=1272943 * https://bugzilla.suse.com/show_bug.cgi?id=1272944 * https://bugzilla.suse.com/show_bug.cgi?id=1272945 * https://bugzilla.suse.com/show_bug.cgi?id=1272947 * https://bugzilla.suse.com/show_bug.cgi?id=1272948 * https://bugzilla.suse.com/show_bug.cgi?id=1272949 * https://bugzilla.suse.com/show_bug.cgi?id=1272950 * https://bugzilla.suse.com/show_bug.cgi?id=1272951 * https://bugzilla.suse.com/show_bug.cgi?id=1273591 * https://bugzilla.suse.com/show_bug.cgi?id=1273593 * https://bugzilla.suse.com/show_bug.cgi?id=1277587 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 12:57:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 12:57:33 -0000 Subject: SUSE-SU-2026:3928-1: moderate: Security update for apptainer Message-ID: <178844025360.2657.10917851897232093012@f2d94a75072c> # Security update for apptainer Announcement ID: SUSE-SU-2026:3928-1 Release Date: 2026-09-03T07:17:31Z Rating: moderate References: * bsc#1276731 Cross-References: * CVE-2026-41178 CVSS scores: * CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * HPC Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for apptainer fixes the following issue: * CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276731). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * HPC Module 15-SP7 zypper in -t patch SUSE-SLE-Module-HPC-15-SP7-2026-3928=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3928=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3928=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 x86_64) * apptainer-1.5.3-150600.4.40.1 * apptainer-suid-1.5.3-150600.4.40.1 * openSUSE Leap 15.6 (aarch64 x86_64) * apptainer-1.5.3-150600.4.40.1 * apptainer-suid-1.5.3-150600.4.40.1 * apptainer-suid-debuginfo-1.5.3-150600.4.40.1 * apptainer-debuginfo-1.5.3-150600.4.40.1 * openSUSE Leap 15.6 (noarch) * apptainer-sle15_7-1.5.3-150600.4.40.1 * apptainer-leap-1.5.3-150600.4.40.1 * apptainer-sle16-1.5.3-150600.4.40.1 * apptainer-sle15_6-1.5.3-150600.4.40.1 * HPC Module 15-SP7 (aarch64 x86_64) * apptainer-1.5.3-150600.4.40.1 * apptainer-debuginfo-1.5.3-150600.4.40.1 * HPC Module 15-SP7 (noarch) * apptainer-sle15_7-1.5.3-150600.4.40.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41178.html * https://bugzilla.suse.com/show_bug.cgi?id=1276731 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 20:31:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 20:31:06 -0000 Subject: SUSE-SU-2026:3964-1: low: Security update for lcms2 Message-ID: <178846746675.5830.8422066247712228227@6bd16ccd9111> # Security update for lcms2 Announcement ID: SUSE-SU-2026:3964-1 Release Date: 2026-09-03T13:34:11Z Rating: low References: * bsc#1264994 Cross-References: * CVE-2026-41254 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for lcms2 fixes the following issue: * CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3964=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * liblcms2-2-32bit-2.7-9.13.1 * liblcms2-2-debuginfo-32bit-2.7-9.13.1 * lcms2-debugsource-2.7-9.13.1 * liblcms2-2-2.7-9.13.1 * lcms2-debuginfo-2.7-9.13.1 * liblcms2-2-debuginfo-2.7-9.13.1 * lcms2-2.7-9.13.1 * liblcms2-devel-2.7-9.13.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://bugzilla.suse.com/show_bug.cgi?id=1264994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 20:32:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 20:32:14 -0000 Subject: SUSE-SU-2026:3963-1: important: Security update for postgresql16 Message-ID: <178846753446.5830.16291829461311357708@6bd16ccd9111> # Security update for postgresql16 Announcement ID: SUSE-SU-2026:3963-1 Release Date: 2026-09-03T13:34:02Z Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275053 * bsc#1275054 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275061 * bsc#1275062 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14672 * CVE-2026-14673 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14662 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14664 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14666 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14668 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14669 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14672 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14672 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14673 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14673 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14678 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14679 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14680 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15741 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15741 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15742 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16241 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18024 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18408 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19385 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6464 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6469 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6470 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6471 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * Legacy Module 15-SP7 * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for postgresql16 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). * CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). * CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). * CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql16: * Update to version 16.15: * https://www.postgresql.org/docs/16/release-16-15.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3963=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3963=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-3963=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3963=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3963=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3963=1 ## Package List: * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * postgresql16-16.15-150600.16.38.1 * postgresql16-server-debuginfo-16.15-150600.16.38.1 * postgresql16-server-devel-16.15-150600.16.38.1 * postgresql16-server-16.15-150600.16.38.1 * postgresql16-debugsource-16.15-150600.16.38.1 * postgresql16-debuginfo-16.15-150600.16.38.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * postgresql16-16.15-150600.16.38.1 * postgresql16-server-debuginfo-16.15-150600.16.38.1 * postgresql16-llvmjit-debuginfo-16.15-150600.16.38.1 * postgresql16-plpython-16.15-150600.16.38.1 * postgresql16-debuginfo-16.15-150600.16.38.1 * postgresql16-pltcl-debuginfo-16.15-150600.16.38.1 * postgresql16-server-devel-16.15-150600.16.38.1 * postgresql16-server-devel-debuginfo-16.15-150600.16.38.1 * postgresql16-llvmjit-16.15-150600.16.38.1 * postgresql16-server-16.15-150600.16.38.1 * postgresql16-debugsource-16.15-150600.16.38.1 * postgresql16-pltcl-16.15-150600.16.38.1 * postgresql16-llvmjit-devel-16.15-150600.16.38.1 * postgresql16-plperl-16.15-150600.16.38.1 * postgresql16-test-16.15-150600.16.38.1 * postgresql16-contrib-debuginfo-16.15-150600.16.38.1 * postgresql16-devel-16.15-150600.16.38.1 * postgresql16-plperl-debuginfo-16.15-150600.16.38.1 * postgresql16-plpython-debuginfo-16.15-150600.16.38.1 * postgresql16-contrib-16.15-150600.16.38.1 * postgresql16-devel-debuginfo-16.15-150600.16.38.1 * openSUSE Leap 15.6 (noarch) * postgresql16-docs-16.15-150600.16.38.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * postgresql16-16.15-150600.16.38.1 * postgresql16-pltcl-16.15-150600.16.38.1 * postgresql16-plperl-16.15-150600.16.38.1 * postgresql16-server-debuginfo-16.15-150600.16.38.1 * postgresql16-server-devel-16.15-150600.16.38.1 * postgresql16-server-devel-debuginfo-16.15-150600.16.38.1 * postgresql16-debugsource-16.15-150600.16.38.1 * postgresql16-plpython-16.15-150600.16.38.1 * postgresql16-server-16.15-150600.16.38.1 * postgresql16-debuginfo-16.15-150600.16.38.1 * postgresql16-pltcl-debuginfo-16.15-150600.16.38.1 * postgresql16-contrib-debuginfo-16.15-150600.16.38.1 * postgresql16-devel-16.15-150600.16.38.1 * postgresql16-plperl-debuginfo-16.15-150600.16.38.1 * postgresql16-plpython-debuginfo-16.15-150600.16.38.1 * postgresql16-contrib-16.15-150600.16.38.1 * postgresql16-devel-debuginfo-16.15-150600.16.38.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * postgresql16-docs-16.15-150600.16.38.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * postgresql16-llvmjit-devel-16.15-150600.16.38.1 * postgresql16-test-16.15-150600.16.38.1 * postgresql16-llvmjit-debuginfo-16.15-150600.16.38.1 * postgresql16-debugsource-16.15-150600.16.38.1 * postgresql16-debuginfo-16.15-150600.16.38.1 * postgresql16-llvmjit-16.15-150600.16.38.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * postgresql16-16.15-150600.16.38.1 * postgresql16-pltcl-16.15-150600.16.38.1 * postgresql16-plperl-16.15-150600.16.38.1 * postgresql16-server-debuginfo-16.15-150600.16.38.1 * postgresql16-server-devel-16.15-150600.16.38.1 * postgresql16-server-devel-debuginfo-16.15-150600.16.38.1 * postgresql16-debugsource-16.15-150600.16.38.1 * postgresql16-plpython-16.15-150600.16.38.1 * postgresql16-server-16.15-150600.16.38.1 * postgresql16-debuginfo-16.15-150600.16.38.1 * postgresql16-pltcl-debuginfo-16.15-150600.16.38.1 * postgresql16-contrib-debuginfo-16.15-150600.16.38.1 * postgresql16-devel-16.15-150600.16.38.1 * postgresql16-plperl-debuginfo-16.15-150600.16.38.1 * postgresql16-plpython-debuginfo-16.15-150600.16.38.1 * postgresql16-contrib-16.15-150600.16.38.1 * postgresql16-devel-debuginfo-16.15-150600.16.38.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * postgresql16-docs-16.15-150600.16.38.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * postgresql16-debugsource-16.15-150600.16.38.1 * postgresql16-debuginfo-16.15-150600.16.38.1 * postgresql16-contrib-debuginfo-16.15-150600.16.38.1 * postgresql16-devel-16.15-150600.16.38.1 * postgresql16-contrib-16.15-150600.16.38.1 * postgresql16-devel-debuginfo-16.15-150600.16.38.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14672.html * https://www.suse.com/security/cve/CVE-2026-14673.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html * https://bugzilla.suse.com/show_bug.cgi?id=1275001 * https://bugzilla.suse.com/show_bug.cgi?id=1275002 * https://bugzilla.suse.com/show_bug.cgi?id=1275042 * https://bugzilla.suse.com/show_bug.cgi?id=1275043 * https://bugzilla.suse.com/show_bug.cgi?id=1275044 * https://bugzilla.suse.com/show_bug.cgi?id=1275046 * https://bugzilla.suse.com/show_bug.cgi?id=1275047 * https://bugzilla.suse.com/show_bug.cgi?id=1275048 * https://bugzilla.suse.com/show_bug.cgi?id=1275049 * https://bugzilla.suse.com/show_bug.cgi?id=1275050 * https://bugzilla.suse.com/show_bug.cgi?id=1275051 * https://bugzilla.suse.com/show_bug.cgi?id=1275053 * https://bugzilla.suse.com/show_bug.cgi?id=1275054 * https://bugzilla.suse.com/show_bug.cgi?id=1275056 * https://bugzilla.suse.com/show_bug.cgi?id=1275057 * https://bugzilla.suse.com/show_bug.cgi?id=1275058 * https://bugzilla.suse.com/show_bug.cgi?id=1275059 * https://bugzilla.suse.com/show_bug.cgi?id=1275061 * https://bugzilla.suse.com/show_bug.cgi?id=1275062 * https://bugzilla.suse.com/show_bug.cgi?id=1275063 * https://bugzilla.suse.com/show_bug.cgi?id=1275064 * https://bugzilla.suse.com/show_bug.cgi?id=1275065 * https://bugzilla.suse.com/show_bug.cgi?id=1275066 * https://bugzilla.suse.com/show_bug.cgi?id=1275067 * https://bugzilla.suse.com/show_bug.cgi?id=1275068 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 20:33:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 20:33:10 -0000 Subject: SUSE-SU-2026:3962-1: moderate: Security update for terraform-provider-susepubliccloud Message-ID: <178846759013.5830.14520538099285538911@6bd16ccd9111> # Security update for terraform-provider-susepubliccloud Announcement ID: SUSE-SU-2026:3962-1 Release Date: 2026-09-03T13:33:16Z Rating: moderate References: * bsc#1271995 Cross-References: * CVE-2026-56852 CVSS scores: * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for terraform-provider-susepubliccloud fixes the following issue: * CVE-2026-56852: golang.org/x/text/unicode/norm: improper handling of truncated/invalid UTF-8 input can lead to infinite loop (bsc#1271995). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-3962=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-3962=1 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * terraform-provider-susepubliccloud-0.0.1-150100.3.20.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * terraform-provider-susepubliccloud-0.0.1-150100.3.20.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1271995 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 20:33:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 20:33:53 -0000 Subject: SUSE-SU-2026:3961-1: moderate: Security update for suseconnect-ng Message-ID: <178846763386.5830.11887175419409507698@6bd16ccd9111> # Security update for suseconnect-ng Announcement ID: SUSE-SU-2026:3961-1 Release Date: 2026-09-03T13:32:45Z Rating: moderate References: * bsc#1159776 * bsc#1267478 * bsc#1268596 * bsc#1268900 * bsc#1270392 Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has five security fixes can now be installed. ## Description: This update for suseconnect-ng fixes the following issue: * Update version to 1.23.0: * Use product identifier for product migrations. (bsc#1268596) * Switch to using go1.26-openssl as the default Go version to install to support building the package (jsc#SCC-843, bsc#1268900). * Fix flag parsing so that unknown flags or options are flagged as an error and the usage message is displayed. (bsc#1159776) * InstallReleasePackage interactive/noninteractive handling should be consistent with DistUpgrade (bsc#1267478). * Add new optional rpm_packages collector, disabled by default, to collect list of installed SUSE vendored RPM packages. (jsc#TEL-298) * Allow deregsiter when subscribed regcode has expired (bsc#1270392, jsc#865) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3961=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3961=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * suseconnect-ruby-bindings-1.23.0-150600.3.24.1 * suseconnect-ng-1.23.0-150600.3.24.1 * mcp-server-suseconnect-1.23.0-150600.3.24.1 * libsuseconnect-1.23.0-150600.3.24.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * suseconnect-ruby-bindings-1.23.0-150600.3.24.1 * suseconnect-ng-1.23.0-150600.3.24.1 * libsuseconnect-1.23.0-150600.3.24.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1159776 * https://bugzilla.suse.com/show_bug.cgi?id=1267478 * https://bugzilla.suse.com/show_bug.cgi?id=1268596 * https://bugzilla.suse.com/show_bug.cgi?id=1268900 * https://bugzilla.suse.com/show_bug.cgi?id=1270392 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 20:34:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 20:34:49 -0000 Subject: SUSE-SU-2026:3960-1: moderate: Security update for file-roller Message-ID: <178846768906.5830.16491371088016992014@6bd16ccd9111> # Security update for file-roller Announcement ID: SUSE-SU-2026:3960-1 Release Date: 2026-09-03T13:32:33Z Rating: moderate References: * bsc#1276442 Cross-References: * CVE-2026-78322 CVSS scores: * CVE-2026-78322 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-78322 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for file-roller fixes the following issue: * CVE-2026-78322: stack buffer overflow in parse_progress_line for 7z and RAR handlers (bsc#1276442). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3960=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * file-roller-debuginfo-3.20.3-15.12.1 * file-roller-debugsource-3.20.3-15.12.1 * nautilus-file-roller-3.20.3-15.12.1 * nautilus-file-roller-debuginfo-3.20.3-15.12.1 * file-roller-3.20.3-15.12.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * file-roller-lang-3.20.3-15.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-78322.html * https://bugzilla.suse.com/show_bug.cgi?id=1276442 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 20:35:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 20:35:30 -0000 Subject: SUSE-SU-2026:3959-1: moderate: Security update for cpio Message-ID: <178846773042.5830.5713569437712525048@6bd16ccd9111> # Security update for cpio Announcement ID: SUSE-SU-2026:3959-1 Release Date: 2026-09-03T13:32:22Z Rating: moderate References: * bsc#1274856 * bsc#1274857 * bsc#1274858 Cross-References: * CVE-2026-66484 * CVE-2026-66485 * CVE-2026-66486 CVSS scores: * CVE-2026-66484 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-66484 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66485 ( SUSE ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-66485 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66486 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-66486 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for cpio fixes the following issues: * CVE-2026-66484: path traversal allows creating hard links outside intended directory via malicious tar archives (bsc#1274856). * CVE-2026-66485: denial of service via uncontrolled memory allocation from crafted archives (bsc#1274857). * CVE-2026-66486: terminal control sequence injection via crafted archive member names (bsc#1274858). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3959=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * cpio-debugsource-2.11-36.25.1 * cpio-debuginfo-2.11-36.25.1 * cpio-2.11-36.25.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * cpio-lang-2.11-36.25.1 ## References: * https://www.suse.com/security/cve/CVE-2026-66484.html * https://www.suse.com/security/cve/CVE-2026-66485.html * https://www.suse.com/security/cve/CVE-2026-66486.html * https://bugzilla.suse.com/show_bug.cgi?id=1274856 * https://bugzilla.suse.com/show_bug.cgi?id=1274857 * https://bugzilla.suse.com/show_bug.cgi?id=1274858 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 3 20:36:17 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 03 Sep 2026 20:36:17 -0000 Subject: SUSE-SU-2026:3958-1: moderate: Security update for curl Message-ID: <178846777755.5830.4286774822717606031@6bd16ccd9111> # Security update for curl Announcement ID: SUSE-SU-2026:3958-1 Release Date: 2026-09-03T13:32:14Z Rating: moderate References: * bsc#1262633 * bsc#1263440 * bsc#1264971 * bsc#1268412 * bsc#1277476 * bsc#1277479 * bsc#1277480 Cross-References: * CVE-2026-13608 * CVE-2026-5773 * CVE-2026-7168 * CVE-2026-80229 * CVE-2026-80230 * CVE-2026-8926 CVSS scores: * CVE-2026-13608 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-13608 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-5773 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-5773 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-5773 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-5773 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-7168 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-7168 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-7168 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-7168 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-80229 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-80229 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-80230 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-80230 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-8926 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8926 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-8926 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves six vulnerabilities and has one security fix can now be installed. ## Description: This update for curl fixes the following issues: * CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). * CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). * CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). * CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). * CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). * CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). Changes for curl: * Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3958=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-3958=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3958=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3958=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3958=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-3958=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * curl-debuginfo-8.14.1-150400.5.91.1 * curl-debugsource-8.14.1-150400.5.91.1 * libcurl4-8.14.1-150400.5.91.1 * curl-8.14.1-150400.5.91.1 * libcurl4-debuginfo-8.14.1-150400.5.91.1 * openSUSE Leap 15.4 (x86_64) * libcurl4-32bit-8.14.1-150400.5.91.1 * libcurl-devel-32bit-8.14.1-150400.5.91.1 * libcurl4-32bit-debuginfo-8.14.1-150400.5.91.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libcurl-mini4-8.14.1-150400.5.91.1 * curl-debuginfo-8.14.1-150400.5.91.1 * curl-debugsource-8.14.1-150400.5.91.1 * libcurl4-8.14.1-150400.5.91.1 * curl-8.14.1-150400.5.91.1 * libcurl-mini4-debuginfo-8.14.1-150400.5.91.1 * curl-mini-debugsource-8.14.1-150400.5.91.1 * libcurl-devel-8.14.1-150400.5.91.1 * libcurl4-debuginfo-8.14.1-150400.5.91.1 * openSUSE Leap 15.4 (noarch) * curl-fish-completion-8.14.1-150400.5.91.1 * curl-zsh-completion-8.14.1-150400.5.91.1 * libcurl-devel-doc-8.14.1-150400.5.91.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libcurl4-64bit-debuginfo-8.14.1-150400.5.91.1 * libcurl-devel-64bit-8.14.1-150400.5.91.1 * libcurl4-64bit-8.14.1-150400.5.91.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * curl-debuginfo-8.14.1-150400.5.91.1 * curl-debugsource-8.14.1-150400.5.91.1 * libcurl4-8.14.1-150400.5.91.1 * curl-8.14.1-150400.5.91.1 * libcurl4-debuginfo-8.14.1-150400.5.91.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * curl-debuginfo-8.14.1-150400.5.91.1 * curl-debugsource-8.14.1-150400.5.91.1 * libcurl4-8.14.1-150400.5.91.1 * curl-8.14.1-150400.5.91.1 * libcurl4-debuginfo-8.14.1-150400.5.91.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * curl-debuginfo-8.14.1-150400.5.91.1 * curl-debugsource-8.14.1-150400.5.91.1 * libcurl4-8.14.1-150400.5.91.1 * curl-8.14.1-150400.5.91.1 * libcurl4-debuginfo-8.14.1-150400.5.91.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * curl-debuginfo-8.14.1-150400.5.91.1 * curl-debugsource-8.14.1-150400.5.91.1 * libcurl4-8.14.1-150400.5.91.1 * curl-8.14.1-150400.5.91.1 * libcurl4-debuginfo-8.14.1-150400.5.91.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13608.html * https://www.suse.com/security/cve/CVE-2026-5773.html * https://www.suse.com/security/cve/CVE-2026-7168.html * https://www.suse.com/security/cve/CVE-2026-80229.html * https://www.suse.com/security/cve/CVE-2026-80230.html * https://www.suse.com/security/cve/CVE-2026-8926.html * https://bugzilla.suse.com/show_bug.cgi?id=1262633 * https://bugzilla.suse.com/show_bug.cgi?id=1263440 * https://bugzilla.suse.com/show_bug.cgi?id=1264971 * https://bugzilla.suse.com/show_bug.cgi?id=1268412 * https://bugzilla.suse.com/show_bug.cgi?id=1277476 * https://bugzilla.suse.com/show_bug.cgi?id=1277479 * https://bugzilla.suse.com/show_bug.cgi?id=1277480 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:30:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:30:37 -0000 Subject: SUSE-SU-2026:23451-1: moderate: Security update for rpcbind Message-ID: <178852503746.6827.11511475057394574056@316acd70164b> # Security update for rpcbind Announcement ID: SUSE-SU-2026:23451-1 Release Date: 2026-09-03T08:09:32Z Rating: moderate References: * bsc#1272340 Cross-References: * CVE-2026-16461 CVSS scores: * CVE-2026-16461 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-16461 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for rpcbind fixes the following issue: * CVE-2026-16461: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting (bsc#1272340). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-879=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * rpcbind-debugsource-1.2.9-2.1 * rpcbind-1.2.9-2.1 * rpcbind-debuginfo-1.2.9-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16461.html * https://bugzilla.suse.com/show_bug.cgi?id=1272340 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:31:23 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:31:23 -0000 Subject: SUSE-SU-2026:23450-1: moderate: Security update for libusb-1_0 Message-ID: <178852508386.6827.11556240227531671396@316acd70164b> # Security update for libusb-1_0 Announcement ID: SUSE-SU-2026:23450-1 Release Date: 2026-09-03T08:09:32Z Rating: moderate References: * bsc#1266664 * bsc#1266667 Cross-References: * CVE-2026-23679 * CVE-2026-47104 CVSS scores: * CVE-2026-23679 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23679 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23679 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23679 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23679 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-47104 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47104 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47104 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47104 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for libusb-1_0 fixes the following issues: * CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). * CVE-2026-47104: one-byte out-of-bounds read in `parse_iad_array()` allows attackers to trigger a denial of service via a malformed USB descriptor (bsc#1266667). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-877=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libusb-1_0-0-1.0.27-2.1 * libusb-1_0-debugsource-1.0.27-2.1 * libusb-1_0-0-debuginfo-1.0.27-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23679.html * https://www.suse.com/security/cve/CVE-2026-47104.html * https://bugzilla.suse.com/show_bug.cgi?id=1266664 * https://bugzilla.suse.com/show_bug.cgi?id=1266667 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:32:08 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:32:08 -0000 Subject: SUSE-SU-2026:23449-1: important: Security update for ucode-intel Message-ID: <178852512855.6827.9232874180744195060@316acd70164b> # Security update for ucode-intel Announcement ID: SUSE-SU-2026:23449-1 Release Date: 2026-09-03T08:09:32Z Rating: important References: * bsc#1274785 Cross-References: * CVE-2025-31936 * CVE-2025-31938 * CVE-2025-35973 * CVE-2026-20707 * CVE-2026-20713 * CVE-2026-20716 * CVE-2026-20760 * CVE-2026-20901 * CVE-2026-20917 CVSS scores: * CVE-2025-31936 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31936 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2025-31936 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31938 ( SUSE ): 4.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31938 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2025-31938 ( NVD ): 4.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35973 ( SUSE ): 4.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35973 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N * CVE-2025-35973 ( NVD ): 4.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20707 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20707 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-20707 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20713 ( SUSE ): 4.5 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20713 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N * CVE-2026-20713 ( NVD ): 4.5 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( SUSE ): 7.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-20716 ( NVD ): 7.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20760 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20760 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20760 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20901 ( NVD ): 4.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20901 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N * CVE-2026-20917 ( SUSE ): 4.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20917 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2026-20917 ( NVD ): 4.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.0 An update that solves nine vulnerabilities can now be installed. ## Description: This update for ucode-intel fixes the following issues: * Intel CPU Microcode was updated to the 20260812 release (bsc#1274785) * Removed MTL/06-aa-04/c0 due to functional issues observed when loading the MCU in some platforms. * Intel CPU Microcode was updated to the 20260811 release (bsc#1274785) * Security updates for INTEL-SA-01379 / CVE-2025-31936 * Security updates for INTEL-SA-01404 / CVE-2025-31938 * Security updates for INTEL-SA-01423 / CVE-2026-20917 * Security updates for INTEL-SA-01428 / CVE-2025-35973 * Security updates for INTEL-SA-01435 / CVE-2026-20716 * Security updates for INTEL-SA-01441 / CVE-2026-20760 * Security updates for INTEL-SA-01442 / CVE-2026-20713 / CVE-2026-20901 * Security updates for INTEL-SA-01443 / CVE-2026-20707 * Update for functional issues. ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-878=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * ucode-intel-20260812-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-31936.html * https://www.suse.com/security/cve/CVE-2025-31938.html * https://www.suse.com/security/cve/CVE-2025-35973.html * https://www.suse.com/security/cve/CVE-2026-20707.html * https://www.suse.com/security/cve/CVE-2026-20713.html * https://www.suse.com/security/cve/CVE-2026-20716.html * https://www.suse.com/security/cve/CVE-2026-20760.html * https://www.suse.com/security/cve/CVE-2026-20901.html * https://www.suse.com/security/cve/CVE-2026-20917.html * https://bugzilla.suse.com/show_bug.cgi?id=1274785 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:33:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:33:43 -0000 Subject: SUSE-SU-2026:23446-1: moderate: Security update for busybox Message-ID: <178852522340.6827.6922392771574451636@316acd70164b> # Security update for busybox Announcement ID: SUSE-SU-2026:23446-1 Release Date: 2026-09-02T09:39:33Z Rating: moderate References: * bsc#1217586 * bsc#1271544 * bsc#1271545 * bsc#1271547 * bsc#1271548 Cross-References: * CVE-2023-42366 * CVE-2026-38752 * CVE-2026-38753 * CVE-2026-38754 * CVE-2026-38755 CVSS scores: * CVE-2023-42366 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2023-42366 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-38752 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-38752 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-38752 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-38752 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-38753 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-38753 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-38753 ( NVD ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-38753 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-38754 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-38754 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-38754 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-38754 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-38755 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-38755 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-38755 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-38755 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for busybox fixes the following issues: * CVE-2023-42366: heap buffer overflow in the `next_token` function of `editors/awk.c` (bsc#1217586). * CVE-2026-38752: stack buffer overflow in the `evaluate()` function of `editors/awk.c` (bsc#1271544). * CVE-2026-38753: use-after-free in the `awk_sub()` function of `editors/awk.c` (bsc#1271545). * CVE-2026-38754: heap buffer overflow in `ifsbreakup()` function of `shell/ash.c` (bsc#1271547). * CVE-2026-38755: heap buffer overflow in `evalcommand()` function of `shell/ash.c` (bsc#1271548). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-875=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * busybox-1.36.1-5.1 ## References: * https://www.suse.com/security/cve/CVE-2023-42366.html * https://www.suse.com/security/cve/CVE-2026-38752.html * https://www.suse.com/security/cve/CVE-2026-38753.html * https://www.suse.com/security/cve/CVE-2026-38754.html * https://www.suse.com/security/cve/CVE-2026-38755.html * https://bugzilla.suse.com/show_bug.cgi?id=1217586 * https://bugzilla.suse.com/show_bug.cgi?id=1271544 * https://bugzilla.suse.com/show_bug.cgi?id=1271545 * https://bugzilla.suse.com/show_bug.cgi?id=1271547 * https://bugzilla.suse.com/show_bug.cgi?id=1271548 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:34:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:34:29 -0000 Subject: SUSE-SU-2026:23445-1: important: Security update for libvirt Message-ID: <178852526904.6827.3398112608676513496@316acd70164b> # Security update for libvirt Announcement ID: SUSE-SU-2026:23445-1 Release Date: 2026-09-02T09:39:32Z Rating: important References: * bsc#1258345 * bsc#1274576 * bsc#1274946 * bsc#1275264 * bsc#1275265 * bsc#1275863 Cross-References: * CVE-2026-18917 * CVE-2026-61477 * CVE-2026-63622 * CVE-2026-63623 * CVE-2026-77159 CVSS scores: * CVE-2026-18917 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-18917 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-61477 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-61477 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61477 ( NVD ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-63622 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63622 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63622 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63623 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-63623 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-63623 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for libvirt fixes the following issues: * CVE-2026-18917: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow (bsc#1275863). * CVE-2026-61477: newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection (bsc#1274576). * CVE-2026-63622: `swtpm` privilege escalation via symlink following (bsc#1275264). * CVE-2026-63623: information disclosure via world-readable storage volume images during clone/convert (bsc#1275265). * CVE-2026-77159: root `chown()` on `swtpm` logfile follows symlinks (bsc#1274946). Changes for libvirt: * rpc: avoid leak of GSource in use for interrupting main loop bsc#1258345 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-874=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libvirt-daemon-plugin-lockd-debuginfo-10.0.0-5.1 * libvirt-daemon-proxy-debuginfo-10.0.0-5.1 * libvirt-daemon-10.0.0-5.1 * libvirt-daemon-config-network-10.0.0-5.1 * libvirt-daemon-driver-nodedev-10.0.0-5.1 * libvirt-client-qemu-10.0.0-5.1 * libvirt-daemon-qemu-10.0.0-5.1 * libvirt-daemon-log-10.0.0-5.1 * libvirt-daemon-driver-storage-core-10.0.0-5.1 * libvirt-daemon-driver-nwfilter-debuginfo-10.0.0-5.1 * libvirt-daemon-driver-storage-mpath-debuginfo-10.0.0-5.1 * libvirt-daemon-driver-secret-10.0.0-5.1 * libvirt-daemon-log-debuginfo-10.0.0-5.1 * libvirt-daemon-debuginfo-10.0.0-5.1 * libvirt-daemon-driver-storage-mpath-10.0.0-5.1 * libvirt-daemon-common-debuginfo-10.0.0-5.1 * libvirt-daemon-driver-network-debuginfo-10.0.0-5.1 * libvirt-daemon-driver-storage-scsi-debuginfo-10.0.0-5.1 * libvirt-daemon-driver-storage-disk-10.0.0-5.1 * libvirt-client-debuginfo-10.0.0-5.1 * libvirt-daemon-driver-nwfilter-10.0.0-5.1 * libvirt-nss-debuginfo-10.0.0-5.1 * libvirt-daemon-driver-nodedev-debuginfo-10.0.0-5.1 * libvirt-daemon-hooks-10.0.0-5.1 * libvirt-daemon-driver-storage-iscsi-direct-10.0.0-5.1 * libvirt-daemon-driver-storage-logical-debuginfo-10.0.0-5.1 * libvirt-daemon-driver-storage-10.0.0-5.1 * libvirt-daemon-plugin-lockd-10.0.0-5.1 * libvirt-nss-10.0.0-5.1 * libvirt-daemon-driver-storage-logical-10.0.0-5.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-10.0.0-5.1 * libvirt-libs-10.0.0-5.1 * libvirt-daemon-driver-qemu-10.0.0-5.1 * libvirt-daemon-driver-storage-core-debuginfo-10.0.0-5.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-10.0.0-5.1 * libvirt-daemon-lock-10.0.0-5.1 * libvirt-daemon-common-10.0.0-5.1 * libvirt-debugsource-10.0.0-5.1 * libvirt-daemon-driver-storage-scsi-10.0.0-5.1 * libvirt-client-10.0.0-5.1 * libvirt-daemon-driver-qemu-debuginfo-10.0.0-5.1 * libvirt-daemon-driver-storage-iscsi-10.0.0-5.1 * libvirt-daemon-driver-network-10.0.0-5.1 * libvirt-libs-debuginfo-10.0.0-5.1 * libvirt-daemon-lock-debuginfo-10.0.0-5.1 * libvirt-daemon-driver-storage-disk-debuginfo-10.0.0-5.1 * libvirt-daemon-driver-secret-debuginfo-10.0.0-5.1 * libvirt-daemon-proxy-10.0.0-5.1 * SUSE Linux Micro 6.0 (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-debuginfo-10.0.0-5.1 * libvirt-daemon-driver-storage-rbd-10.0.0-5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-18917.html * https://www.suse.com/security/cve/CVE-2026-61477.html * https://www.suse.com/security/cve/CVE-2026-63622.html * https://www.suse.com/security/cve/CVE-2026-63623.html * https://www.suse.com/security/cve/CVE-2026-77159.html * https://bugzilla.suse.com/show_bug.cgi?id=1258345 * https://bugzilla.suse.com/show_bug.cgi?id=1274576 * https://bugzilla.suse.com/show_bug.cgi?id=1274946 * https://bugzilla.suse.com/show_bug.cgi?id=1275264 * https://bugzilla.suse.com/show_bug.cgi?id=1275265 * https://bugzilla.suse.com/show_bug.cgi?id=1275863 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:35:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:35:09 -0000 Subject: SUSE-SU-2026:23444-1: important: Security update for dracut Message-ID: <178852530989.6827.15804880005089773008@316acd70164b> # Security update for dracut Announcement ID: SUSE-SU-2026:23444-1 Release Date: 2026-09-02T09:29:03Z Rating: important References: * bsc#1268322 * bsc#1273580 Cross-References: * CVE-2026-16445 * CVE-2026-6893 CVSS scores: * CVE-2026-16445 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16445 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for dracut fixes the following issues: * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). * CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580). Changes for dracut: * Update to version 059+suse.615.g018c5a4: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset * fix(network-manager): ensure safe content of /tmp/dhclient."$ifname".dhcpopts ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-876=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * dracut-debugsource-059+suse.615.g018c5a4-1.1 * dracut-debuginfo-059+suse.615.g018c5a4-1.1 * dracut-fips-059+suse.615.g018c5a4-1.1 * dracut-059+suse.615.g018c5a4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16445.html * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 * https://bugzilla.suse.com/show_bug.cgi?id=1273580 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:35:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:35:51 -0000 Subject: SUSE-SU-2026:23443-1: moderate: Security update for lcms2 Message-ID: <178852535138.6827.5055275662933782878@316acd70164b> # Security update for lcms2 Announcement ID: SUSE-SU-2026:23443-1 Release Date: 2026-09-01T12:45:19Z Rating: moderate References: * bsc#1247985 * bsc#1263703 * bsc#1264994 Cross-References: * CVE-2026-41254 * CVE-2026-42798 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42798 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-42798 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities and has one fix can now be installed. ## Description: This update for lcms2 fixes the following issues: * CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994). * CVE-2026-42798: Little CMS (lcms2) 2.16 through 2.18 before 2.19 has an integer overflow in ParseCube in cmscgats.c (bsc#1263703). Changes for lcms2: * Enable threads support (bsc#1247985) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-873=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * liblcms2-2-debuginfo-2.16-2.1 * lcms2-debugsource-2.16-2.1 * liblcms2-2-2.16-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://www.suse.com/security/cve/CVE-2026-42798.html * https://bugzilla.suse.com/show_bug.cgi?id=1247985 * https://bugzilla.suse.com/show_bug.cgi?id=1263703 * https://bugzilla.suse.com/show_bug.cgi?id=1264994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:36:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:36:30 -0000 Subject: SUSE-SU-2026:23442-1: low: Security update for bzip2 Message-ID: <178852539007.6827.1753500414806494528@316acd70164b> # Security update for bzip2 Announcement ID: SUSE-SU-2026:23442-1 Release Date: 2026-09-01T07:05:42Z Rating: low References: * bsc#1266786 Cross-References: * CVE-2026-42250 CVSS scores: * CVE-2026-42250 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42250 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-42250 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for bzip2 fixes the following issue: * CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-872=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libbz2-1-1.0.8-4.1 * bzip2-debugsource-1.0.8-4.1 * bzip2-1.0.8-4.1 * libbz2-1-debuginfo-1.0.8-4.1 * bzip2-debuginfo-1.0.8-4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42250.html * https://bugzilla.suse.com/show_bug.cgi?id=1266786 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:37:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:37:12 -0000 Subject: SUSE-SU-2026:23441-1: moderate: Security update for cpio Message-ID: <178852543266.6827.8040573096420982118@316acd70164b> # Security update for cpio Announcement ID: SUSE-SU-2026:23441-1 Release Date: 2026-08-31T19:28:25Z Rating: moderate References: * bsc#1221712 * bsc#1274856 * bsc#1274857 * bsc#1274858 Cross-References: * CVE-2026-66484 * CVE-2026-66485 * CVE-2026-66486 CVSS scores: * CVE-2026-66484 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-66484 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66485 ( SUSE ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-66485 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66486 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-66486 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.0 An update that solves three vulnerabilities and has one fix can now be installed. ## Description: This update for cpio fixes the following issues: Security issues fixed: * CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). * CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). * CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). Non security issue fixed: * GCC 14: cpio package fails (bsc#1221712). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-871=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * cpio-debugsource-2.15-2.1 * cpio-debuginfo-2.15-2.1 * cpio-2.15-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-66484.html * https://www.suse.com/security/cve/CVE-2026-66485.html * https://www.suse.com/security/cve/CVE-2026-66486.html * https://bugzilla.suse.com/show_bug.cgi?id=1221712 * https://bugzilla.suse.com/show_bug.cgi?id=1274856 * https://bugzilla.suse.com/show_bug.cgi?id=1274857 * https://bugzilla.suse.com/show_bug.cgi?id=1274858 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:37:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:37:56 -0000 Subject: SUSE-SU-2026:23440-1: important: Security update for the Linux Kernel RT (Live Patch 27 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852547621.6827.1869425854947328886@316acd70164b> # Security update for the Linux Kernel RT (Live Patch 27 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23440-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1270023 * bsc#1270024 * bsc#1271543 * bsc#1271867 Cross-References: * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-50.2 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-590=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-50-rt-2-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_27-debugsource-2-1.1 * kernel-livepatch-6_4_0-50-rt-debuginfo-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:38:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:38:43 -0000 Subject: SUSE-SU-2026:23439-1: important: Security update for the Linux Kernel RT (Live Patch 26 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852552322.6827.9446634925667994722@316acd70164b> # Security update for the Linux Kernel RT (Live Patch 26 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23439-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271370 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-46242 * CVE-2026-52956 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-53366 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-49.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-589=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-49-rt-debuginfo-2-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_26-debugsource-2-1.1 * kernel-livepatch-6_4_0-49-rt-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:39:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:39:35 -0000 Subject: SUSE-SU-2026:23438-1: important: Security update for the Linux Kernel RT (Live Patch 25 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852557502.6827.8204623634116347773@316acd70164b> # Security update for the Linux Kernel RT (Live Patch 25 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23438-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1268281 * bsc#1269034 * bsc#1269822 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-53133 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves nine vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-48.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-588=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_25-debugsource-3-1.1 * kernel-livepatch-6_4_0-48-rt-debuginfo-3-1.1 * kernel-livepatch-6_4_0-48-rt-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:40:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:40:30 -0000 Subject: SUSE-SU-2026:23437-1: important: Security update for the Linux Kernel RT (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852563072.6827.4974767100409851751@316acd70164b> # Security update for the Linux Kernel RT (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23437-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1267362 * bsc#1268281 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-43109 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 13 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-47.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-587=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-47-rt-4-1.1 * kernel-livepatch-6_4_0-47-rt-debuginfo-4-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_24-debugsource-4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:41:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:41:32 -0000 Subject: SUSE-SU-2026:23436-1: important: Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852569272.6827.1644053229561092106@316acd70164b> # Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23436-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 18 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-586=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-46-rt-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_23-debugsource-5-1.1 * kernel-livepatch-6_4_0-46-rt-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:42:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:42:34 -0000 Subject: SUSE-SU-2026:23435-1: important: Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852575456.6827.18206175220761499181@316acd70164b> # Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23435-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 18 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-585=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_22-debugsource-5-1.2 * kernel-livepatch-6_4_0-45-rt-debuginfo-5-1.2 * kernel-livepatch-6_4_0-45-rt-5-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:43:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:43:38 -0000 Subject: SUSE-SU-2026:23434-1: important: Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852581884.6827.9369709361534691391@316acd70164b> # Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23434-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-584=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_21-debugsource-5-1.1 * kernel-livepatch-6_4_0-43-rt-debuginfo-5-1.1 * kernel-livepatch-6_4_0-43-rt-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:44:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:44:42 -0000 Subject: SUSE-SU-2026:23433-1: important: Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852588257.6827.10411587422490981657@316acd70164b> # Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23433-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-582=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-42-rt-6-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_20-debugsource-6-1.1 * kernel-livepatch-6_4_0-42-rt-debuginfo-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:45:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:45:45 -0000 Subject: SUSE-SU-2026:23432-1: important: Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852594587.6827.514005180992335679@316acd70164b> # Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23432-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-581=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-41-rt-debuginfo-8-1.1 * kernel-livepatch-6_4_0-41-rt-8-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_19-debugsource-8-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:46:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:46:52 -0000 Subject: SUSE-SU-2026:23431-1: important: Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852601202.6827.6573304780727289834@316acd70164b> # Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23431-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-580=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_18-debugsource-9-1.1 * kernel-livepatch-6_4_0-40-rt-9-1.1 * kernel-livepatch-6_4_0-40-rt-debuginfo-9-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:47:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:47:58 -0000 Subject: SUSE-SU-2026:23430-1: important: Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852607887.6827.7743050460861790358@316acd70164b> # Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23430-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-579=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_15-debugsource-10-1.1 * kernel-livepatch-6_4_0-39-rt-10-1.1 * kernel-livepatch-6_4_0-39-rt-debuginfo-10-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:49:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:49:07 -0000 Subject: SUSE-SU-2026:23429-1: important: Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852614732.6827.16294920959915143171@316acd70164b> # Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23429-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-37.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-578=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-37-rt-11-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_13-debugsource-11-1.1 * kernel-livepatch-6_4_0-37-rt-debuginfo-11-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:50:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:50:16 -0000 Subject: SUSE-SU-2026:23428-1: important: Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852621666.6827.15119436397109465205@316acd70164b> # Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23428-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-577=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-36-rt-debuginfo-15-1.1 * kernel-livepatch-6_4_0-36-rt-15-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_12-debugsource-15-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:51:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:51:30 -0000 Subject: SUSE-SU-2026:23427-1: important: Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852629096.6827.8028682510281857709@316acd70164b> # Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23427-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-576=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-35-rt-16-1.1 * kernel-livepatch-6_4_0-35-rt-debuginfo-16-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_11-debugsource-16-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:52:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:52:40 -0000 Subject: SUSE-SU-2026:23426-1: important: Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852636079.6827.15069117755211358398@316acd70164b> # Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23426-1 Release Date: 2026-08-31T15:30:50Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-575=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-34-rt-debuginfo-20-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_10-debugsource-20-1.1 * kernel-livepatch-6_4_0-34-rt-20-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:53:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:53:45 -0000 Subject: SUSE-SU-2026:23425-1: important: Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852642538.6827.16283251689579785081@316acd70164b> # Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23425-1 Release Date: 2026-08-31T15:29:09Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 20 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-597=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_17-debugsource-9-1.1 * kernel-livepatch-6_4_0-40-default-9-1.1 * kernel-livepatch-6_4_0-40-default-debuginfo-9-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:54:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:54:52 -0000 Subject: SUSE-SU-2026:23424-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852649250.6827.238734460095793348@316acd70164b> # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23424-1 Release Date: 2026-08-31T15:29:09Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-594=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_13-debugsource-13-1.1 * kernel-livepatch-6_4_0-36-default-13-1.1 * kernel-livepatch-6_4_0-36-default-debuginfo-13-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:56:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:56:01 -0000 Subject: SUSE-SU-2026:23423-1: important: Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852656156.6827.10965036512052077359@316acd70164b> # Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23423-1 Release Date: 2026-08-31T15:29:09Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-35.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-593=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_12-debugsource-15-1.1 * kernel-livepatch-6_4_0-35-default-15-1.1 * kernel-livepatch-6_4_0-35-default-debuginfo-15-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:57:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:57:09 -0000 Subject: SUSE-SU-2026:23422-1: important: Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852662938.6827.15712320313936566468@316acd70164b> # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23422-1 Release Date: 2026-08-31T15:25:42Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-592=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_11-debugsource-15-1.1 * kernel-livepatch-6_4_0-34-default-debuginfo-15-1.1 * kernel-livepatch-6_4_0-34-default-15-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:58:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:58:16 -0000 Subject: SUSE-SU-2026:23421-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852669622.6827.14999817298761830374@316acd70164b> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23421-1 Release Date: 2026-08-31T15:24:37Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-595=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-38-default-debuginfo-11-1.2 * kernel-livepatch-MICRO-6-0_Update_14-debugsource-11-1.2 * kernel-livepatch-6_4_0-38-default-11-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 12:59:20 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 12:59:20 -0000 Subject: SUSE-SU-2026:23420-1: important: Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852676054.6827.15977881817516126434@316acd70164b> # Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23420-1 Release Date: 2026-08-31T15:23:52Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-598=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-41-default-debuginfo-8-1.1 * kernel-livepatch-MICRO-6-0_Update_18-debugsource-8-1.1 * kernel-livepatch-6_4_0-41-default-8-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 13:00:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 13:00:30 -0000 Subject: SUSE-SU-2026:23419-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852683093.6827.8813479899570730464@316acd70164b> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23419-1 Release Date: 2026-08-31T15:22:46Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-591=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-32-default-debuginfo-16-1.1 * kernel-livepatch-MICRO-6-0_Update_10-debugsource-16-1.1 * kernel-livepatch-6_4_0-32-default-16-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 13:01:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 13:01:38 -0000 Subject: SUSE-SU-2026:23418-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852689890.6827.16709877202239480523@316acd70164b> # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23418-1 Release Date: 2026-08-31T15:22:16Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 21 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-596=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-39-default-10-1.1 * kernel-livepatch-MICRO-6-0_Update_16-debugsource-10-1.1 * kernel-livepatch-6_4_0-39-default-debuginfo-10-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 13:02:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 13:02:42 -0000 Subject: SUSE-SU-2026:23417-1: important: Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852696227.6827.225401408274682767@316acd70164b> # Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23417-1 Release Date: 2026-08-31T15:18:16Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-583=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-43-default-5-1.1 * kernel-livepatch-6_4_0-43-default-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0_Update_20-debugsource-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 13:03:48 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 13:03:48 -0000 Subject: SUSE-SU-2026:23416-1: important: Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178852702836.6827.1741316243274799152@316acd70164b> # Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23416-1 Release Date: 2026-08-31T15:18:16Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 19 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023) * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-23240: Amend fix ("tls: Fix race condition in tls_sw_cancel_work_tx()") (bsc#1262404). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-574=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-42-default-debuginfo-6-1.1 * kernel-livepatch-6_4_0-42-default-6-1.1 * kernel-livepatch-MICRO-6-0_Update_19-debugsource-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 13:04:26 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 13:04:26 -0000 Subject: SUSE-SU-2026:23415-1: low: Security update for bzip2 Message-ID: <178852706689.6827.15525402218205135218@316acd70164b> # Security update for bzip2 Announcement ID: SUSE-SU-2026:23415-1 Release Date: 2026-09-01T06:55:06Z Rating: low References: * bsc#1266786 Cross-References: * CVE-2026-42250 CVSS scores: * CVE-2026-42250 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42250 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-42250 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for bzip2 fixes the following issue: * CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-697=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libbz2-1-1.0.8-slfo.1.1_2.1 * libbz2-1-debuginfo-1.0.8-slfo.1.1_2.1 * bzip2-1.0.8-slfo.1.1_2.1 * bzip2-debuginfo-1.0.8-slfo.1.1_2.1 * bzip2-debugsource-1.0.8-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42250.html * https://bugzilla.suse.com/show_bug.cgi?id=1266786 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 13:05:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 13:05:11 -0000 Subject: SUSE-SU-2026:23414-1: important: Security update for c-ares Message-ID: <178852711109.6827.17201514071683220122@316acd70164b> # Security update for c-ares Announcement ID: SUSE-SU-2026:23414-1 Release Date: 2026-08-31T19:42:01Z Rating: important References: * bsc#1240955 * bsc#1254738 * bsc#1270416 * bsc#1276290 * bsc#1276291 Cross-References: * CVE-2025-31498 * CVE-2025-62408 * CVE-2026-33630 * CVE-2026-69184 * CVE-2026-69186 CVSS scores: * CVE-2025-31498 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-31498 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2025-31498 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-62408 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-62408 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33630 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33630 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33630 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-69184 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-69186 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for c-ares fixes the following issues: Update to c-ares 1.34.8. * CVE-2025-31498: use-after-free in `read_answers()` when `process_answer()` may re-enqueue a query (bsc#1240955). * CVE-2025-62408: use-after-free due to connection being cleaned up after error (bsc#1254738). * CVE-2026-33630: remotely triggerable use-after-free/double-free in query- completion handling via `ares_getaddrinfo()` over TCP (bsc#1270416). * CVE-2026-69184: CPU exhaustion denial of service via unbounded DNS name compression pointer chains (bsc#1276290). * CVE-2026-69186: memory amplification denial of service via unvalidated DNS header record counts (bsc#1276291). Changes for c-ares: * c-ares 1.34.8: * For details, see https://c-ares.org/changelog.html. * c-ares 1.34.6: * Ignore Windows IDN Search Domains until proper IDN support is added. * Various bug fixes. * c-ares 1.34.4: * Changes: * QNX Port: Port to QNX 8, add primary config reading support, add CI build. PR #934, PR #937, PR #938 * Bugfixes: * Empty TXT records were not being preserved. PR #922 * `docs`: update deprecation notices for `ares_create_query()` and `ares_mkquery()`. PR #910 * `license`: some files weren't properly updated. PR #920 * Fix `bind` local device regression from 1.34.0. PR #929, PR #931, PR #935 * `CMake`: set policy version to prevent deprecation warnings. PR #932 * `CMake`: shared and static library names should be the same on unix platforms like `autotools` uses. PR #933 * Update to latest `autoconf` archive macros for enhanced system compatibility. PR #936 * c-ares 1.34.3: * Build the release package in an automated way so we can provide provenance as per SLSA3. PR #906 * Some upstream servers are non-compliant with EDNS options, resend queries without EDNS. Issue #911 * TSAN warns on missing lock, but lock isn't actually necessary. PR #915 * `ares_getaddrinfo(`) for `AF_UNSPEC` should retry IPv4 if only IPv6 is received. 765d558 * `ares_send()` shouldn't return `ARES_EBADRESP`, its `ARES_EBADQUERY`. 91519e7 * Fix typos in man pages. PR #905 * c-ares 1.34.2: * Features: * `adig`: read arguments from `adigrc`. [PR #856] * Add new pending write callback optimization via `ares_set_pending_write_cb`. [PR #857] * New function `ares_process_fds()`. [PR #875] * Failed servers should be probed rather than redirecting queries which could cause unexpected latency. [PR #877] * `adig`: rework command line arguments to mimic `dig` from `bind`. [PR #890] * Add new method for overriding network functions `ares_set_socket_function_ex()` to properly support all new functionality. [PR #894] * Fix regression with custom socket callbacks due to DNS cookie support. [PR #895] * `ares_socket`: set `IP_BIND_ADDRESS_NO_PORT` on `ares_set_local_ip*` tcp sockets [PR #887] * URI parser/writer for `ares_set_servers_csv()`/`ares_get_servers_csv()`. [PR #882] * Connection handling modularization. [PR #857], [PR #876] * Expose library/utility functions to tools. [PR #860] * Remove `ares__` prefix, just use `ares_` for internal functions. [PR #872] * fix: potential `WIN32_LEAN_AND_MEAN` redefinition. [PR #869] * Fix `googletest` v1.15 compatibility. [PR #874] * Fix `pkgconfig` thread dependencies. [PR #884] * c-ares 1.33.0: * Add DNS cookie support (RFC7873 + RFC9018) to help prevent off-path cache poisoning attacks. [PR #833] * Implement TCP FastOpen (TFO) RFC7413, which will make TCP reconnects 0-RTT on supported systems. [PR #840] * Reorganize source tree. [PR #822] * Refactoring of connection handling to prevent code duplication. [PR #839] * New dynamic array data structure to prevent simple logic flaws in array handling in various code paths. [PR #841] * `ares_destroy()` race condition during shutdown due to missing lock. [PR #831] * c-ares in 1.32: * Add support for DNS `0x20` to help prevent cache poisoning attacks, enabled by specifying `ARES_FLAG_DNS0x20`. Disabled by default. [PR #800] * Rework query timeout logic to automatically adjust timeouts based on network conditions. The timeout specified now is only used as a hint until there is enough history to calculate a more valid timeout. [PR #794] * DNS RR `TXT` strings should not be automatically concatenated as there are use cases outside of RFC 7208. In order to maintain ABI compliance, the ability to retrieve `TXT` strings concatenated is retained as well as a new API to retrieve the individual strings. This restores behavior from c-ares 1.20.0. [PR #801] * Clean up header inclusion logic to make hacking on code easier. [PR #797] * GCC/Clang: Enable even more strict warnings to catch more coding flaws. [253bdee] * Tests: Fix thread race condition in test cases for `EventThread`. [PR #803] * Thread Saftey: `ares_timeout()` was missing lock. [74a64e4] * c-ares 1.31.0: * Enable Query Cache by default. [PR #786] * Enhance Windows DNS configuration change detection to also detect manual DNS configuration changes. [PR #785] * Various legacy MacOS Build fixes. [Issue #782] * Ndots value of zero in `resolv.conf` was not being honored. [852a60a] * Watt-32 build support had been broken for some time. [PR #781] * Distribute `ares_dns_rec_type_tostr` manpage. [PR #778] * c-ares 1.30.0: * Basic support for SIG RR record (RFC 2931 / RFC 2535) [PR #773] * Validation that DNS strings can only consist of printable ascii characters otherwise will trigger a parse failure. [75de16c] and [40fb125] * `QueryCache`: Fix issue where purging on server changes wasn't working. [a6c8fe6] * c-ares 1.29.0: * When using `ARES_OPT_EVENT_THREAD`, automatically reload system configuration when network conditions change. [PR #759] * Apple: reimplement DNS configuration reading to more accurately pull DNS settings. [PR #750] * Add observability into DNS server health via a server state callback, invoked whenever a query finishes. [PR #744] * Add server failover retry behavior, where failed servers are retried with small probability after a minimum delay. [PR #731] * Mark `ares_channel_t *` as `const` in more places in the public API. [PR #758] * Due to a logic flaw, dns name compression writing was not properly implemented which would result in the name prefix not being written for a partial match. This could cause issues in various record types such as `MX` records when using the deprecated API. Regression introduced in 1.28.0. [Issue #757] * Revert OpenBSD `SOCK_DNS` flag, it doesn't do what the docs say it does and causes c-ares to become non-functional. [PR #754] * `ares_getnameinfo()`: loosen validation on `salen` parameter. [Issue #752] * `cmake`: Android requires C99. [PR #748] * `ares_queue_wait_empty()` does not honor `timeout_ms >= 0`. [Issue #742] * c-ares 1.28.1: * Emit warnings when deprecated c-ares functions are used. This can be disabled by passing a compiler definition of `CARES_NO_DEPRECATED`. [PR #732] * Add function `ares_search_dnsrec()` to search for records using the new DNS record data structures. [PR #719] * Rework internals to pass around `ares_dns_record_t` instead of binary data, this introduces new public functions of `ares_query_dnsrec()` and `ares_send_dnsrec()`. [PR #730] * tests: when performing simulated queries, reduce timeouts to make tests run faster. * Replace configuration file parsers with memory-safe parser. [PR #725] * Remove `acountry` completely, the manpage might still get installed otherwise. [Issue #718] * CMake: don't overwrite global required libraries/definitions/includes which could cause build errors for projects chain building c-ares. [Issue #729] * On some platforms, `netinet6/in6.h` is not included by `netinet/in.h` and needs to be included separately. [PR #728] * Fix a potential memory leak in `ares_init()`. [Issue #724] * Some platforms don't have the `isascii()` function. Implement as a macro. [PR #721] * CMake: Fix chain building if `CMAKE` runtime paths not set. * NDots configuration should allow a value of zero. [PR #735] ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-696=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libcares2-debuginfo-1.34.8-slfo.1.1_1.1 * libcares2-1.34.8-slfo.1.1_1.1 * c-ares-debugsource-1.34.8-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-31498.html * https://www.suse.com/security/cve/CVE-2025-62408.html * https://www.suse.com/security/cve/CVE-2026-33630.html * https://www.suse.com/security/cve/CVE-2026-69184.html * https://www.suse.com/security/cve/CVE-2026-69186.html * https://bugzilla.suse.com/show_bug.cgi?id=1240955 * https://bugzilla.suse.com/show_bug.cgi?id=1254738 * https://bugzilla.suse.com/show_bug.cgi?id=1270416 * https://bugzilla.suse.com/show_bug.cgi?id=1276290 * https://bugzilla.suse.com/show_bug.cgi?id=1276291 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 16:30:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 16:30:35 -0000 Subject: SUSE-SU-2026:3978-1: moderate: Security update for python-sqlparse Message-ID: <178853943501.7185.9985254913520074827@316acd70164b> # Security update for python-sqlparse Announcement ID: SUSE-SU-2026:3978-1 Release Date: 2026-09-04T09:19:35Z Rating: moderate References: * bsc#1278097 Cross-References: * CVE-2026-84305 CVSS scores: * CVE-2026-84305 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84305 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-84305 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-sqlparse fixes the following issue: * CVE-2026-84305: Reindentation of tuple lists causes near-cap quadratic CPU consumption (bsc#1278097). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3978=1 ## Package List: * SUSE Package Hub 15 15-SP7 (noarch) * python2-sqlparse-0.2.4-150100.6.14.1 ## References: * https://www.suse.com/security/cve/CVE-2026-84305.html * https://bugzilla.suse.com/show_bug.cgi?id=1278097 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 16:32:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 16:32:14 -0000 Subject: SUSE-SU-2026:3974-1: important: Security update for podman Message-ID: <178853953445.7185.17547650268524186896@316acd70164b> # Security update for podman Announcement ID: SUSE-SU-2026:3974-1 Release Date: 2026-09-04T08:46:23Z Rating: important References: Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that can now be installed. ## Description: This update for podman rebuilds it against the current go security release. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-3974=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3974=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3974=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3974=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3974=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-3974=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-3974=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-3974=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-3974=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * podmansh-4.9.5-150500.3.82.1 * podman-debuginfo-4.9.5-150500.3.82.1 * podman-remote-debuginfo-4.9.5-150500.3.82.1 * podman-4.9.5-150500.3.82.1 * podman-remote-4.9.5-150500.3.82.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * podman-docker-4.9.5-150500.3.82.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * podman-docker-4.9.5-150500.3.82.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * podmansh-4.9.5-150500.3.82.1 * podman-debuginfo-4.9.5-150500.3.82.1 * podman-remote-debuginfo-4.9.5-150500.3.82.1 * podman-4.9.5-150500.3.82.1 * podman-remote-4.9.5-150500.3.82.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * podmansh-4.9.5-150500.3.82.1 * podman-debuginfo-4.9.5-150500.3.82.1 * podman-remote-debuginfo-4.9.5-150500.3.82.1 * podman-4.9.5-150500.3.82.1 * podman-remote-4.9.5-150500.3.82.1 * openSUSE Leap 15.5 (noarch) * podman-docker-4.9.5-150500.3.82.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * podmansh-4.9.5-150500.3.82.1 * podman-debuginfo-4.9.5-150500.3.82.1 * podman-remote-debuginfo-4.9.5-150500.3.82.1 * podman-4.9.5-150500.3.82.1 * podman-remote-4.9.5-150500.3.82.1 * Containers Module 15-SP7 (noarch) * podman-docker-4.9.5-150500.3.82.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * podmansh-4.9.5-150500.3.82.1 * podman-debuginfo-4.9.5-150500.3.82.1 * podman-remote-debuginfo-4.9.5-150500.3.82.1 * podman-4.9.5-150500.3.82.1 * podman-remote-4.9.5-150500.3.82.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * podman-docker-4.9.5-150500.3.82.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * podman-docker-4.9.5-150500.3.82.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * podmansh-4.9.5-150500.3.82.1 * podman-debuginfo-4.9.5-150500.3.82.1 * podman-remote-debuginfo-4.9.5-150500.3.82.1 * podman-4.9.5-150500.3.82.1 * podman-remote-4.9.5-150500.3.82.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * podmansh-4.9.5-150500.3.82.1 * podman-debuginfo-4.9.5-150500.3.82.1 * podman-remote-debuginfo-4.9.5-150500.3.82.1 * podman-4.9.5-150500.3.82.1 * podman-remote-4.9.5-150500.3.82.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * podman-docker-4.9.5-150500.3.82.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * podmansh-4.9.5-150500.3.82.1 * podman-debuginfo-4.9.5-150500.3.82.1 * podman-remote-debuginfo-4.9.5-150500.3.82.1 * podman-4.9.5-150500.3.82.1 * podman-remote-4.9.5-150500.3.82.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * podman-docker-4.9.5-150500.3.82.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * podman-docker-4.9.5-150500.3.82.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * podmansh-4.9.5-150500.3.82.1 * podman-debuginfo-4.9.5-150500.3.82.1 * podman-remote-debuginfo-4.9.5-150500.3.82.1 * podman-4.9.5-150500.3.82.1 * podman-remote-4.9.5-150500.3.82.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 16:33:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 16:33:09 -0000 Subject: SUSE-SU-2026:3973-1: important: Security update for libsoup2 Message-ID: <178853958986.7185.11191479147683616520@316acd70164b> # Security update for libsoup2 Announcement ID: SUSE-SU-2026:3973-1 Release Date: 2026-09-04T08:21:07Z Rating: important References: * bsc#1272196 Cross-References: * CVE-2026-12548 CVSS scores: * CVE-2026-12548 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12548 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12548 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for libsoup2 fixes the following issues: * CVE-2026-12548: out-of-bounds read in multipart body parser due to an integer truncation (bsc#1272196). Changes for libsoup2: * update after changes in the public suffix list: "*.bd" is no longer in the public suffix list so let's use ".jm" instead. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3973=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3973=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3973=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3973=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libsoup-2_4-1-2.74.3-150600.4.39.1 * libsoup2-debugsource-2.74.3-150600.4.39.1 * libsoup2-devel-2.74.3-150600.4.39.1 * libsoup-2_4-1-debuginfo-2.74.3-150600.4.39.1 * typelib-1_0-Soup-2_4-2.74.3-150600.4.39.1 * Basesystem Module 15-SP7 (noarch) * libsoup2-lang-2.74.3-150600.4.39.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libsoup2-devel-64bit-2.74.3-150600.4.39.1 * libsoup-2_4-1-64bit-2.74.3-150600.4.39.1 * libsoup-2_4-1-64bit-debuginfo-2.74.3-150600.4.39.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libsoup-2_4-1-2.74.3-150600.4.39.1 * libsoup2-debugsource-2.74.3-150600.4.39.1 * libsoup2-devel-2.74.3-150600.4.39.1 * libsoup-2_4-1-debuginfo-2.74.3-150600.4.39.1 * typelib-1_0-Soup-2_4-2.74.3-150600.4.39.1 * openSUSE Leap 15.6 (x86_64) * libsoup-2_4-1-32bit-debuginfo-2.74.3-150600.4.39.1 * libsoup2-devel-32bit-2.74.3-150600.4.39.1 * libsoup-2_4-1-32bit-2.74.3-150600.4.39.1 * openSUSE Leap 15.6 (noarch) * libsoup2-lang-2.74.3-150600.4.39.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libsoup-2_4-1-2.74.3-150600.4.39.1 * libsoup2-debugsource-2.74.3-150600.4.39.1 * libsoup2-devel-2.74.3-150600.4.39.1 * libsoup-2_4-1-debuginfo-2.74.3-150600.4.39.1 * typelib-1_0-Soup-2_4-2.74.3-150600.4.39.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * libsoup2-lang-2.74.3-150600.4.39.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libsoup-2_4-1-2.74.3-150600.4.39.1 * libsoup2-debugsource-2.74.3-150600.4.39.1 * libsoup2-devel-2.74.3-150600.4.39.1 * libsoup-2_4-1-debuginfo-2.74.3-150600.4.39.1 * typelib-1_0-Soup-2_4-2.74.3-150600.4.39.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * libsoup2-lang-2.74.3-150600.4.39.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12548.html * https://bugzilla.suse.com/show_bug.cgi?id=1272196 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 16:34:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 16:34:06 -0000 Subject: SUSE-SU-2026:3972-1: moderate: Security update for python-h2 Message-ID: <178853964603.7185.7290472561650589817@316acd70164b> # Security update for python-h2 Announcement ID: SUSE-SU-2026:3972-1 Release Date: 2026-09-04T08:20:45Z Rating: moderate References: * bsc#1274386 Cross-References: * CVE-2026-71554 CVSS scores: * CVE-2026-71554 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-71554 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-h2 fixes the following issue: * CVE-2026-71554: duplicate `Host` headers are accepted and forwarded to consuming applications, which can lead to request smuggling (bsc#1274386). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-3972=1 ## Package List: * Server Applications Module 15-SP7 (noarch) * python3-h2-3.2.0-150200.3.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-71554.html * https://bugzilla.suse.com/show_bug.cgi?id=1274386 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 16:34:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 16:34:44 -0000 Subject: SUSE-SU-2026:3970-1: moderate: Security update for python-h2 Message-ID: <178853968466.7185.14424166158294404328@316acd70164b> # Security update for python-h2 Announcement ID: SUSE-SU-2026:3970-1 Release Date: 2026-09-04T08:20:20Z Rating: moderate References: * bsc#1274386 Cross-References: * CVE-2026-71554 CVSS scores: * CVE-2026-71554 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-71554 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-h2 fixes the following issue: * CVE-2026-71554: duplicate `Host` headers are accepted and forwarded to consuming applications, which can lead to request smuggling (bsc#1274386). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-3970=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3970=1 ## Package List: * openSUSE Leap 15.4 (noarch) * python311-h2-4.1.0-150400.8.9.1 * Python 3 Module 15-SP7 (noarch) * python311-h2-4.1.0-150400.8.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-71554.html * https://bugzilla.suse.com/show_bug.cgi?id=1274386 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 16:35:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 16:35:43 -0000 Subject: SUSE-SU-2026:3969-1: moderate: Security update for python Message-ID: <178853974355.7185.8795642362582790903@316acd70164b> # Security update for python Announcement ID: SUSE-SU-2026:3969-1 Release Date: 2026-09-04T08:20:04Z Rating: moderate References: * bsc#1273091 * bsc#1276903 * bsc#1277271 Cross-References: * CVE-2026-13346 * CVE-2026-1703 * CVE-2026-3219 CVSS scores: * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for python fixes the following issues: Security issues fixed: * CVE-2026-13346: pip: arbitrary file installation via malicious package indexes (bsc#1273091). Non security issue fixed: * Update bundled pip wheels to pip-10.0.1-py2.py3-none-any.whl ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-3969=1 ## Package List: * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * libpython2_7-1_0-debuginfo-2.7.18-150000.126.1 * libpython2_7-1_0-2.7.18-150000.126.1 * python-xml-2.7.18-150000.126.1 * python-debuginfo-2.7.18-150000.126.1 * python-curses-2.7.18-150000.126.1 * python-base-debuginfo-2.7.18-150000.126.1 * python-xml-debuginfo-2.7.18-150000.126.1 * python-gdbm-2.7.18-150000.126.1 * python-curses-debuginfo-2.7.18-150000.126.1 * python-base-2.7.18-150000.126.1 * python-base-debugsource-2.7.18-150000.126.1 * python-debugsource-2.7.18-150000.126.1 * python-2.7.18-150000.126.1 * python-gdbm-debuginfo-2.7.18-150000.126.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13346.html * https://www.suse.com/security/cve/CVE-2026-1703.html * https://www.suse.com/security/cve/CVE-2026-3219.html * https://bugzilla.suse.com/show_bug.cgi?id=1273091 * https://bugzilla.suse.com/show_bug.cgi?id=1276903 * https://bugzilla.suse.com/show_bug.cgi?id=1277271 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 4 16:36:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 04 Sep 2026 16:36:22 -0000 Subject: SUSE-SU-2026:3968-1: low: Security update for libheif Message-ID: <178853978217.7185.12568572406571915938@316acd70164b> # Security update for libheif Announcement ID: SUSE-SU-2026:3968-1 Release Date: 2026-09-04T08:19:34Z Rating: low References: * bsc#1273079 Cross-References: * CVE-2026-62289 CVSS scores: * CVE-2026-62289 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-62289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-62289 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for libheif fixes the following issue: * CVE-2026-62289: integer underflow in Fraction constructor via double clap transform application (bsc#1273079). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-3968=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * gdk-pixbuf-loader-libheif-debuginfo-1.12.0-150400.3.23.2 * libheif1-1.12.0-150400.3.23.2 * libheif-debugsource-1.12.0-150400.3.23.2 * libheif1-debuginfo-1.12.0-150400.3.23.2 * libheif-devel-1.12.0-150400.3.23.2 * gdk-pixbuf-loader-libheif-1.12.0-150400.3.23.2 * openSUSE Leap 15.4 (x86_64) * libheif1-32bit-debuginfo-1.12.0-150400.3.23.2 * libheif1-32bit-1.12.0-150400.3.23.2 * openSUSE Leap 15.4 (aarch64_ilp32) * libheif1-64bit-debuginfo-1.12.0-150400.3.23.2 * libheif1-64bit-1.12.0-150400.3.23.2 ## References: * https://www.suse.com/security/cve/CVE-2026-62289.html * https://bugzilla.suse.com/show_bug.cgi?id=1273079 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:30:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:30:45 -0000 Subject: SUSE-SU-2026:4034-1: important: Security update for openssl-1_1-livepatches Message-ID: <178878424514.9930.456565071941150881@6bd16ccd9111> # Security update for openssl-1_1-livepatches Announcement ID: SUSE-SU-2026:4034-1 Release Date: 2026-09-07T07:54:33Z Rating: important References: * bsc#1274788 * bsc#1275133 Cross-References: * CVE-2026-63072 CVSS scores: * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for openssl-1_1-livepatches fixes the following issue: * CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1275133, bsc#1274788). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-4034=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4034=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (x86_64) * openssl-1_1-livepatches-0.8-150400.3.26.1 * openSUSE Leap 15.4 (x86_64) * openssl-1_1-livepatches-debugsource-0.8-150400.3.26.1 * openssl-1_1-livepatches-0.8-150400.3.26.1 * openssl-1_1-livepatches-debuginfo-0.8-150400.3.26.1 ## References: * https://www.suse.com/security/cve/CVE-2026-63072.html * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1275133 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:31:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:31:44 -0000 Subject: SUSE-SU-2026:4033-1: important: Security update for openssl-1_1 Message-ID: <178878430483.9930.2122995643594477405@6bd16ccd9111> # Security update for openssl-1_1 Announcement ID: SUSE-SU-2026:4033-1 Release Date: 2026-09-07T07:48:33Z Rating: important References: * bsc#1274774 * bsc#1274788 * bsc#1274795 * bsc#1277247 Cross-References: * CVE-2026-54874 * CVE-2026-63072 CVSS scores: * CVE-2026-54874 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-54874 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves two vulnerabilities and has two security fixes can now be installed. ## Description: This update for openssl-1_1 fixes the following issues: August 2026 release. * CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). * CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4033=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4033=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4033=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4033=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4033=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4033=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4033=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4033=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4033=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * openssl-1_1-debuginfo-1.1.1l-150400.7.104.1 * openssl-1_1-debugsource-1.1.1l-150400.7.104.1 * openssl-1_1-1.1.1l-150400.7.104.1 * libopenssl-1_1-devel-1.1.1l-150400.7.104.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.104.1 * libopenssl1_1-hmac-1.1.1l-150400.7.104.1 * libopenssl1_1-1.1.1l-150400.7.104.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libopenssl1_1-32bit-1.1.1l-150400.7.104.1 * libopenssl1_1-32bit-debuginfo-1.1.1l-150400.7.104.1 * libopenssl1_1-hmac-32bit-1.1.1l-150400.7.104.1 * libopenssl-1_1-devel-32bit-1.1.1l-150400.7.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * openssl-1_1-debuginfo-1.1.1l-150400.7.104.1 * openssl-1_1-debugsource-1.1.1l-150400.7.104.1 * openssl-1_1-1.1.1l-150400.7.104.1 * libopenssl-1_1-devel-1.1.1l-150400.7.104.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.104.1 * libopenssl1_1-hmac-1.1.1l-150400.7.104.1 * libopenssl1_1-1.1.1l-150400.7.104.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libopenssl1_1-32bit-debuginfo-1.1.1l-150400.7.104.1 * libopenssl-1_1-devel-32bit-1.1.1l-150400.7.104.1 * libopenssl1_1-hmac-32bit-1.1.1l-150400.7.104.1 * libopenssl1_1-32bit-1.1.1l-150400.7.104.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * openssl-1_1-debuginfo-1.1.1l-150400.7.104.1 * openssl-1_1-debugsource-1.1.1l-150400.7.104.1 * openssl-1_1-1.1.1l-150400.7.104.1 * libopenssl-1_1-devel-1.1.1l-150400.7.104.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.104.1 * libopenssl1_1-hmac-1.1.1l-150400.7.104.1 * libopenssl1_1-1.1.1l-150400.7.104.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libopenssl1_1-32bit-debuginfo-1.1.1l-150400.7.104.1 * libopenssl1_1-hmac-32bit-1.1.1l-150400.7.104.1 * libopenssl-1_1-devel-32bit-1.1.1l-150400.7.104.1 * libopenssl1_1-32bit-1.1.1l-150400.7.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libopenssl1_1-32bit-debuginfo-1.1.1l-150400.7.104.1 * libopenssl1_1-hmac-32bit-1.1.1l-150400.7.104.1 * libopenssl-1_1-devel-32bit-1.1.1l-150400.7.104.1 * libopenssl1_1-32bit-1.1.1l-150400.7.104.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * openssl-1_1-debuginfo-1.1.1l-150400.7.104.1 * openssl-1_1-debugsource-1.1.1l-150400.7.104.1 * openssl-1_1-1.1.1l-150400.7.104.1 * libopenssl-1_1-devel-1.1.1l-150400.7.104.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.104.1 * libopenssl1_1-hmac-1.1.1l-150400.7.104.1 * libopenssl1_1-1.1.1l-150400.7.104.1 * openSUSE Leap 15.4 (x86_64) * libopenssl1_1-32bit-debuginfo-1.1.1l-150400.7.104.1 * libopenssl-1_1-devel-32bit-1.1.1l-150400.7.104.1 * libopenssl1_1-hmac-32bit-1.1.1l-150400.7.104.1 * libopenssl1_1-32bit-1.1.1l-150400.7.104.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * openssl-1_1-debuginfo-1.1.1l-150400.7.104.1 * openssl-1_1-debugsource-1.1.1l-150400.7.104.1 * openssl-1_1-1.1.1l-150400.7.104.1 * libopenssl-1_1-devel-1.1.1l-150400.7.104.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.104.1 * libopenssl1_1-hmac-1.1.1l-150400.7.104.1 * libopenssl1_1-1.1.1l-150400.7.104.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libopenssl1_1-64bit-1.1.1l-150400.7.104.1 * libopenssl-1_1-devel-64bit-1.1.1l-150400.7.104.1 * libopenssl1_1-64bit-debuginfo-1.1.1l-150400.7.104.1 * libopenssl1_1-hmac-64bit-1.1.1l-150400.7.104.1 * openSUSE Leap 15.4 (noarch) * openssl-1_1-doc-1.1.1l-150400.7.104.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * openssl-1_1-debuginfo-1.1.1l-150400.7.104.1 * openssl-1_1-debugsource-1.1.1l-150400.7.104.1 * openssl-1_1-1.1.1l-150400.7.104.1 * libopenssl-1_1-devel-1.1.1l-150400.7.104.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.104.1 * libopenssl1_1-hmac-1.1.1l-150400.7.104.1 * libopenssl1_1-1.1.1l-150400.7.104.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * openssl-1_1-debuginfo-1.1.1l-150400.7.104.1 * openssl-1_1-debugsource-1.1.1l-150400.7.104.1 * openssl-1_1-1.1.1l-150400.7.104.1 * libopenssl-1_1-devel-1.1.1l-150400.7.104.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.104.1 * libopenssl1_1-hmac-1.1.1l-150400.7.104.1 * libopenssl1_1-1.1.1l-150400.7.104.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * openssl-1_1-debuginfo-1.1.1l-150400.7.104.1 * openssl-1_1-debugsource-1.1.1l-150400.7.104.1 * openssl-1_1-1.1.1l-150400.7.104.1 * libopenssl-1_1-devel-1.1.1l-150400.7.104.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.104.1 * libopenssl1_1-hmac-1.1.1l-150400.7.104.1 * libopenssl1_1-1.1.1l-150400.7.104.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * openssl-1_1-debuginfo-1.1.1l-150400.7.104.1 * openssl-1_1-debugsource-1.1.1l-150400.7.104.1 * openssl-1_1-1.1.1l-150400.7.104.1 * libopenssl-1_1-devel-1.1.1l-150400.7.104.1 * libopenssl1_1-debuginfo-1.1.1l-150400.7.104.1 * libopenssl1_1-hmac-1.1.1l-150400.7.104.1 * libopenssl1_1-1.1.1l-150400.7.104.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54874.html * https://www.suse.com/security/cve/CVE-2026-63072.html * https://bugzilla.suse.com/show_bug.cgi?id=1274774 * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1274795 * https://bugzilla.suse.com/show_bug.cgi?id=1277247 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:32:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:32:51 -0000 Subject: SUSE-SU-2026:4032-1: important: Security update for openssl-3 Message-ID: <178878437114.9930.10915565910342418159@6bd16ccd9111> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:4032-1 Release Date: 2026-09-07T07:47:47Z Rating: important References: * bsc#1274774 * bsc#1274788 * bsc#1274790 * bsc#1274795 * bsc#1274797 * bsc#1275837 Cross-References: * CVE-2026-54874 * CVE-2026-63072 * CVE-2026-63074 * CVE-2026-63076 * CVE-2026-75803 CVSS scores: * CVE-2026-54874 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-54874 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63074 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63074 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-75803 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-75803 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves five vulnerabilities and has one security fix can now be installed. ## Description: This update for openssl-3 fixes the following issues: August 2026 release. * CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). * CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). * CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). * CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). * CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4032=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4032=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4032=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4032=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4032=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4032=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4032=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4032=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4032=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libopenssl3-debuginfo-3.0.8-150400.4.98.1 * openssl-3-debugsource-3.0.8-150400.4.98.1 * libopenssl3-3.0.8-150400.4.98.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libopenssl3-debuginfo-3.0.8-150400.4.98.1 * openssl-3-debugsource-3.0.8-150400.4.98.1 * libopenssl3-3.0.8-150400.4.98.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libopenssl3-3.0.8-150400.4.98.1 * openssl-3-debugsource-3.0.8-150400.4.98.1 * libopenssl3-debuginfo-3.0.8-150400.4.98.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libopenssl3-3.0.8-150400.4.98.1 * openssl-3-debugsource-3.0.8-150400.4.98.1 * libopenssl3-debuginfo-3.0.8-150400.4.98.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * openssl-3-debugsource-3.0.8-150400.4.98.1 * libopenssl3-3.0.8-150400.4.98.1 * libopenssl3-debuginfo-3.0.8-150400.4.98.1 * openssl-3-3.0.8-150400.4.98.1 * openssl-3-debuginfo-3.0.8-150400.4.98.1 * libopenssl-3-devel-3.0.8-150400.4.98.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * openssl-3-debugsource-3.0.8-150400.4.98.1 * libopenssl3-3.0.8-150400.4.98.1 * libopenssl3-debuginfo-3.0.8-150400.4.98.1 * openssl-3-3.0.8-150400.4.98.1 * openssl-3-debuginfo-3.0.8-150400.4.98.1 * libopenssl-3-devel-3.0.8-150400.4.98.1 * openSUSE Leap 15.4 (x86_64) * libopenssl3-32bit-3.0.8-150400.4.98.1 * libopenssl3-32bit-debuginfo-3.0.8-150400.4.98.1 * libopenssl-3-devel-32bit-3.0.8-150400.4.98.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libopenssl3-64bit-3.0.8-150400.4.98.1 * libopenssl-3-devel-64bit-3.0.8-150400.4.98.1 * libopenssl3-64bit-debuginfo-3.0.8-150400.4.98.1 * openSUSE Leap 15.4 (noarch) * openssl-3-doc-3.0.8-150400.4.98.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * openssl-3-debugsource-3.0.8-150400.4.98.1 * libopenssl3-debuginfo-3.0.8-150400.4.98.1 * libopenssl3-3.0.8-150400.4.98.1 * openssl-3-3.0.8-150400.4.98.1 * openssl-3-debuginfo-3.0.8-150400.4.98.1 * libopenssl-3-devel-3.0.8-150400.4.98.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * openssl-3-debugsource-3.0.8-150400.4.98.1 * libopenssl3-3.0.8-150400.4.98.1 * libopenssl3-debuginfo-3.0.8-150400.4.98.1 * openssl-3-3.0.8-150400.4.98.1 * openssl-3-debuginfo-3.0.8-150400.4.98.1 * libopenssl-3-devel-3.0.8-150400.4.98.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * openssl-3-debugsource-3.0.8-150400.4.98.1 * libopenssl3-debuginfo-3.0.8-150400.4.98.1 * libopenssl3-3.0.8-150400.4.98.1 * openssl-3-3.0.8-150400.4.98.1 * openssl-3-debuginfo-3.0.8-150400.4.98.1 * libopenssl-3-devel-3.0.8-150400.4.98.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54874.html * https://www.suse.com/security/cve/CVE-2026-63072.html * https://www.suse.com/security/cve/CVE-2026-63074.html * https://www.suse.com/security/cve/CVE-2026-63076.html * https://www.suse.com/security/cve/CVE-2026-75803.html * https://bugzilla.suse.com/show_bug.cgi?id=1274774 * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1274790 * https://bugzilla.suse.com/show_bug.cgi?id=1274795 * https://bugzilla.suse.com/show_bug.cgi?id=1274797 * https://bugzilla.suse.com/show_bug.cgi?id=1275837 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:33:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:33:50 -0000 Subject: SUSE-SU-2026:4031-1: moderate: Security update for python-aiohttp Message-ID: <178878443012.9930.2708909179121003697@6bd16ccd9111> # Security update for python-aiohttp Announcement ID: SUSE-SU-2026:4031-1 Release Date: 2026-09-07T07:46:19Z Rating: moderate References: * bsc#1273125 * bsc#1273552 * bsc#1273553 Cross-References: * CVE-2026-59881 * CVE-2026-69243 * CVE-2026-69244 CVSS scores: * CVE-2026-59881 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59881 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59881 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-69243 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-69243 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-69243 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-69244 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-69244 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-69244 ( NVD ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-aiohttp fixes the following issues: * CVE-2026-59881: excessive resource consumption due to WebSocket client accepting compressed frames without negotiated permessage-deflate (bsc#1273125). * CVE-2026-69243: HTTP request smuggling via the WebSocket upgrade procedure (bsc#1273553). * CVE-2026-69244: out-of-bounds heap read in the C response parser while building an error message for a malformed response (bsc#1273552). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4031=1 * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-4031=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-4031=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-aiohttp-3.9.3-150400.10.46.1 * python-aiohttp-debugsource-3.9.3-150400.10.46.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.46.1 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-aiohttp-3.9.3-150400.10.46.1 * python-aiohttp-debugsource-3.9.3-150400.10.46.1 * python311-aiohttp-debuginfo-3.9.3-150400.10.46.1 * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python311-aiohttp-3.9.3-150400.10.46.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59881.html * https://www.suse.com/security/cve/CVE-2026-69243.html * https://www.suse.com/security/cve/CVE-2026-69244.html * https://bugzilla.suse.com/show_bug.cgi?id=1273125 * https://bugzilla.suse.com/show_bug.cgi?id=1273552 * https://bugzilla.suse.com/show_bug.cgi?id=1273553 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:34:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:34:45 -0000 Subject: SUSE-SU-2026:4030-1: moderate: Security update for python313-pip Message-ID: <178878448575.9930.4126410134428289598@6bd16ccd9111> # Security update for python313-pip Announcement ID: SUSE-SU-2026:4030-1 Release Date: 2026-09-07T07:45:57Z Rating: moderate References: * bsc#1273090 Cross-References: * CVE-2026-13346 CVSS scores: * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N Affected Products: * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python313-pip fixes the following issue: * CVE-2026-13346: incorrect handling of doubly-encoded package URLs from malicious indexes allows files to be installed to arbitrary locations on disk (bsc#1273090). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-4030=1 ## Package List: * Python 3 Module 15-SP7 (noarch) * python313-pip-24.2-150700.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13346.html * https://bugzilla.suse.com/show_bug.cgi?id=1273090 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:35:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:35:25 -0000 Subject: SUSE-SU-2026:4029-1: moderate: Security update for nghttp2 Message-ID: <178878452535.9930.2008752803838061298@6bd16ccd9111> # Security update for nghttp2 Announcement ID: SUSE-SU-2026:4029-1 Release Date: 2026-09-07T07:45:40Z Rating: moderate References: * bsc#1269489 Cross-References: * CVE-2026-58055 CVSS scores: * CVE-2026-58055 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N * CVE-2026-58055 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58055 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for nghttp2 fixes the following issue: * CVE-2026-58055: HTTP/1.1 Upgrade request can lead to HTTP request smuggling and cross-client response-queue poisoning (bsc#1269489). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4029=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libnghttp2-14-debuginfo-1.64.0-150700.3.6.1 * libnghttp2-devel-1.64.0-150700.3.6.1 * libnghttp2-14-1.64.0-150700.3.6.1 * nghttp2-debugsource-1.64.0-150700.3.6.1 * nghttp2-debuginfo-1.64.0-150700.3.6.1 * Basesystem Module 15-SP7 (x86_64) * libnghttp2-14-32bit-1.64.0-150700.3.6.1 * libnghttp2-14-32bit-debuginfo-1.64.0-150700.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58055.html * https://bugzilla.suse.com/show_bug.cgi?id=1269489 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:36:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:36:04 -0000 Subject: SUSE-SU-2026:4028-1: moderate: Security update for httpcomponents-client Message-ID: <178878456492.9930.9018821459543067472@6bd16ccd9111> # Security update for httpcomponents-client Announcement ID: SUSE-SU-2026:4028-1 Release Date: 2026-09-07T07:45:24Z Rating: moderate References: * bsc#1273163 Cross-References: * CVE-2026-64607 CVSS scores: * CVE-2026-64607 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64607 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64607 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for httpcomponents-client fixes the following issue: * CVE-2026-64607: improper release of underlying connection back to connection manager when an invalid or unsupported `Content-Encoding` header value in a response message (bsc#1273163). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-4028=1 ## Package List: * Development Tools Module 15-SP7 (noarch) * httpcomponents-client-4.5.14-150200.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64607.html * https://bugzilla.suse.com/show_bug.cgi?id=1273163 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:36:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:36:44 -0000 Subject: SUSE-SU-2026:4027-1: moderate: Security update for sssd Message-ID: <178878460435.9930.12653196613704113524@6bd16ccd9111> # Security update for sssd Announcement ID: SUSE-SU-2026:4027-1 Release Date: 2026-09-07T07:44:54Z Rating: moderate References: * bsc#1273925 Cross-References: * CVE-2026-68743 CVSS scores: * CVE-2026-68743 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68743 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68743 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68743 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for sssd fixes the following issue: * CVE-2026-68743: oversized length parameters in authentication requests can cause heap out-of-bounds reads (bsc#1273925). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4027=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4027=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4027=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4027=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4027=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libsss_idmap0-2.5.2-150400.4.51.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.51.1 * libsss_nss_idmap0-2.5.2-150400.4.51.1 * sssd-ldap-2.5.2-150400.4.51.1 * sssd-2.5.2-150400.4.51.1 * sssd-common-2.5.2-150400.4.51.1 * libsss_certmap0-2.5.2-150400.4.51.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.51.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.51.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.51.1 * sssd-debugsource-2.5.2-150400.4.51.1 * sssd-common-debuginfo-2.5.2-150400.4.51.1 * sssd-ldap-debuginfo-2.5.2-150400.4.51.1 * sssd-krb5-common-2.5.2-150400.4.51.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libsss_idmap0-2.5.2-150400.4.51.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.51.1 * libsss_nss_idmap0-2.5.2-150400.4.51.1 * sssd-ldap-2.5.2-150400.4.51.1 * sssd-2.5.2-150400.4.51.1 * sssd-common-2.5.2-150400.4.51.1 * libsss_certmap0-2.5.2-150400.4.51.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.51.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.51.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.51.1 * sssd-debugsource-2.5.2-150400.4.51.1 * sssd-common-debuginfo-2.5.2-150400.4.51.1 * sssd-ldap-debuginfo-2.5.2-150400.4.51.1 * sssd-krb5-common-2.5.2-150400.4.51.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libsss_idmap0-debuginfo-2.5.2-150400.4.51.1 * sssd-kcm-2.5.2-150400.4.51.1 * libsss_nss_idmap-devel-2.5.2-150400.4.51.1 * libnfsidmap-sss-debuginfo-2.5.2-150400.4.51.1 * sssd-2.5.2-150400.4.51.1 * python3-sssd-config-debuginfo-2.5.2-150400.4.51.1 * libsss_certmap0-2.5.2-150400.4.51.1 * libsss_simpleifp-devel-2.5.2-150400.4.51.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.51.1 * sssd-dbus-2.5.2-150400.4.51.1 * sssd-debugsource-2.5.2-150400.4.51.1 * python3-sssd-config-2.5.2-150400.4.51.1 * sssd-winbind-idmap-debuginfo-2.5.2-150400.4.51.1 * sssd-kcm-debuginfo-2.5.2-150400.4.51.1 * python3-sss_nss_idmap-debuginfo-2.5.2-150400.4.51.1 * sssd-ldap-debuginfo-2.5.2-150400.4.51.1 * python3-sss_nss_idmap-2.5.2-150400.4.51.1 * sssd-tools-2.5.2-150400.4.51.1 * libsss_idmap0-2.5.2-150400.4.51.1 * libipa_hbac0-2.5.2-150400.4.51.1 * libipa_hbac-devel-2.5.2-150400.4.51.1 * libsss_nss_idmap0-2.5.2-150400.4.51.1 * sssd-proxy-2.5.2-150400.4.51.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.51.1 * sssd-krb5-2.5.2-150400.4.51.1 * libsss_simpleifp0-2.5.2-150400.4.51.1 * libsss_certmap-devel-2.5.2-150400.4.51.1 * sssd-krb5-common-2.5.2-150400.4.51.1 * sssd-ipa-debuginfo-2.5.2-150400.4.51.1 * libsss_idmap-devel-2.5.2-150400.4.51.1 * python3-ipa_hbac-debuginfo-2.5.2-150400.4.51.1 * libipa_hbac0-debuginfo-2.5.2-150400.4.51.1 * sssd-common-2.5.2-150400.4.51.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.51.1 * sssd-ipa-2.5.2-150400.4.51.1 * python3-ipa_hbac-2.5.2-150400.4.51.1 * sssd-common-debuginfo-2.5.2-150400.4.51.1 * libsss_simpleifp0-debuginfo-2.5.2-150400.4.51.1 * sssd-krb5-debuginfo-2.5.2-150400.4.51.1 * sssd-tools-debuginfo-2.5.2-150400.4.51.1 * libnfsidmap-sss-2.5.2-150400.4.51.1 * sssd-proxy-debuginfo-2.5.2-150400.4.51.1 * sssd-ad-2.5.2-150400.4.51.1 * sssd-ldap-2.5.2-150400.4.51.1 * sssd-ad-debuginfo-2.5.2-150400.4.51.1 * python3-sss-murmur-2.5.2-150400.4.51.1 * sssd-winbind-idmap-2.5.2-150400.4.51.1 * sssd-dbus-debuginfo-2.5.2-150400.4.51.1 * python3-sss-murmur-debuginfo-2.5.2-150400.4.51.1 * openSUSE Leap 15.4 (aarch64_ilp32) * sssd-common-64bit-2.5.2-150400.4.51.1 * sssd-common-64bit-debuginfo-2.5.2-150400.4.51.1 * openSUSE Leap 15.4 (x86_64) * sssd-common-32bit-debuginfo-2.5.2-150400.4.51.1 * sssd-common-32bit-2.5.2-150400.4.51.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libsss_idmap0-2.5.2-150400.4.51.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.51.1 * libsss_nss_idmap0-2.5.2-150400.4.51.1 * sssd-ldap-2.5.2-150400.4.51.1 * sssd-2.5.2-150400.4.51.1 * sssd-common-2.5.2-150400.4.51.1 * libsss_certmap0-2.5.2-150400.4.51.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.51.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.51.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.51.1 * sssd-debugsource-2.5.2-150400.4.51.1 * sssd-common-debuginfo-2.5.2-150400.4.51.1 * sssd-ldap-debuginfo-2.5.2-150400.4.51.1 * sssd-krb5-common-2.5.2-150400.4.51.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libsss_idmap0-2.5.2-150400.4.51.1 * libsss_idmap0-debuginfo-2.5.2-150400.4.51.1 * libsss_nss_idmap0-2.5.2-150400.4.51.1 * sssd-ldap-2.5.2-150400.4.51.1 * sssd-2.5.2-150400.4.51.1 * sssd-common-2.5.2-150400.4.51.1 * libsss_certmap0-2.5.2-150400.4.51.1 * libsss_certmap0-debuginfo-2.5.2-150400.4.51.1 * sssd-krb5-common-debuginfo-2.5.2-150400.4.51.1 * libsss_nss_idmap0-debuginfo-2.5.2-150400.4.51.1 * sssd-debugsource-2.5.2-150400.4.51.1 * sssd-common-debuginfo-2.5.2-150400.4.51.1 * sssd-ldap-debuginfo-2.5.2-150400.4.51.1 * sssd-krb5-common-2.5.2-150400.4.51.1 ## References: * https://www.suse.com/security/cve/CVE-2026-68743.html * https://bugzilla.suse.com/show_bug.cgi?id=1273925 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:37:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:37:40 -0000 Subject: SUSE-SU-2026:4026-1: moderate: Security update for fuse-overlayfs Message-ID: <178878466045.9930.11810446048317782199@6bd16ccd9111> # Security update for fuse-overlayfs Announcement ID: SUSE-SU-2026:4026-1 Release Date: 2026-09-07T07:44:33Z Rating: moderate References: * bsc#1273100 Cross-References: * CVE-2026-52791 CVSS scores: * CVE-2026-52791 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-52791 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-52791 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Containers Module 15-SP7 * SUSE Enterprise Storage 7.1 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for fuse-overlayfs fixes the following issue: * CVE-2026-52791: Privilege Escalation Vulnerability via SUID/SGID Bit Preservation (bsc#1273100). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Enterprise Storage 7.1 zypper in -t patch SUSE-Storage-7.1-2026-4026=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4026=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4026=1 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-4026=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4026=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4026=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4026=1 ## Package List: * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * fuse-overlayfs-1.1.2-150100.3.14.1 * fuse-overlayfs-debuginfo-1.1.2-150100.3.14.1 * fuse-overlayfs-debugsource-1.1.2-150100.3.14.1 * SUSE Enterprise Storage 7.1 (aarch64 x86_64) * fuse-overlayfs-1.1.2-150100.3.14.1 * fuse-overlayfs-debuginfo-1.1.2-150100.3.14.1 * fuse-overlayfs-debugsource-1.1.2-150100.3.14.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * fuse-overlayfs-1.1.2-150100.3.14.1 * fuse-overlayfs-debuginfo-1.1.2-150100.3.14.1 * fuse-overlayfs-debugsource-1.1.2-150100.3.14.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * fuse-overlayfs-1.1.2-150100.3.14.1 * fuse-overlayfs-debuginfo-1.1.2-150100.3.14.1 * fuse-overlayfs-debugsource-1.1.2-150100.3.14.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * fuse-overlayfs-1.1.2-150100.3.14.1 * fuse-overlayfs-debuginfo-1.1.2-150100.3.14.1 * fuse-overlayfs-debugsource-1.1.2-150100.3.14.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * fuse-overlayfs-1.1.2-150100.3.14.1 * fuse-overlayfs-debuginfo-1.1.2-150100.3.14.1 * fuse-overlayfs-debugsource-1.1.2-150100.3.14.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * fuse-overlayfs-1.1.2-150100.3.14.1 * fuse-overlayfs-debuginfo-1.1.2-150100.3.14.1 * fuse-overlayfs-debugsource-1.1.2-150100.3.14.1 ## References: * https://www.suse.com/security/cve/CVE-2026-52791.html * https://bugzilla.suse.com/show_bug.cgi?id=1273100 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:38:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:38:19 -0000 Subject: SUSE-SU-2026:4025-1: important: Security update for ucode-intel Message-ID: <178878469952.9930.10875711832410711387@6bd16ccd9111> # Security update for ucode-intel Announcement ID: SUSE-SU-2026:4025-1 Release Date: 2026-09-07T07:43:51Z Rating: important References: * bsc#1274785 Cross-References: * CVE-2025-31936 * CVE-2025-31938 * CVE-2025-35973 * CVE-2026-20707 * CVE-2026-20713 * CVE-2026-20716 * CVE-2026-20760 * CVE-2026-20901 * CVE-2026-20917 CVSS scores: * CVE-2025-31936 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31936 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2025-31936 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31938 ( SUSE ): 4.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31938 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2025-31938 ( NVD ): 4.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35973 ( SUSE ): 4.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35973 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N * CVE-2025-35973 ( NVD ): 4.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20707 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20707 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-20707 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20713 ( SUSE ): 4.5 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20713 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N * CVE-2026-20713 ( NVD ): 4.5 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( SUSE ): 7.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-20716 ( NVD ): 7.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20760 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20760 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20760 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20901 ( NVD ): 4.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20901 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N * CVE-2026-20917 ( SUSE ): 4.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20917 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2026-20917 ( NVD ): 4.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves nine vulnerabilities can now be installed. ## Description: This update for ucode-intel fixes the following issues: * Intel CPU Microcode was updated to the 20260812 release (bsc#1274785) * Removed MTL/06-aa-04/c0 due to functional issues observed when loading the MCU in some platforms. * Intel CPU Microcode was updated to the 20260811 release (bsc#1274785) * Security updates for INTEL-SA-01379 / CVE-2025-31936 * Security updates for INTEL-SA-01404 / CVE-2025-31938 * Security updates for INTEL-SA-01423 / CVE-2026-20917 * Security updates for INTEL-SA-01428 / CVE-2025-35973 * Security updates for INTEL-SA-01435 / CVE-2026-20716 * Security updates for INTEL-SA-01441 / CVE-2026-20760 * Security updates for INTEL-SA-01442 / CVE-2026-20713 / CVE-2026-20901 * Security updates for INTEL-SA-01443 / CVE-2026-20707 * Update for functional issues. ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4025=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4025=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4025=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4025=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4025=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4025=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4025=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4025=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4025=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4025=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4025=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4025=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4025=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4025=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4025=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4025=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * ucode-intel-20260812-150200.68.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * ucode-intel-20260812-150200.68.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * ucode-intel-20260812-150200.68.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * ucode-intel-20260812-150200.68.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * ucode-intel-20260812-150200.68.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * ucode-intel-20260812-150200.68.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * ucode-intel-20260812-150200.68.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * ucode-intel-20260812-150200.68.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * ucode-intel-20260812-150200.68.1 * Basesystem Module 15-SP7 (x86_64) * ucode-intel-20260812-150200.68.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * ucode-intel-20260812-150200.68.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * ucode-intel-20260812-150200.68.1 * SUSE Linux Enterprise Micro 5.4 (x86_64) * ucode-intel-20260812-150200.68.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * ucode-intel-20260812-150200.68.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * ucode-intel-20260812-150200.68.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * ucode-intel-20260812-150200.68.1 ## References: * https://www.suse.com/security/cve/CVE-2025-31936.html * https://www.suse.com/security/cve/CVE-2025-31938.html * https://www.suse.com/security/cve/CVE-2025-35973.html * https://www.suse.com/security/cve/CVE-2026-20707.html * https://www.suse.com/security/cve/CVE-2026-20713.html * https://www.suse.com/security/cve/CVE-2026-20716.html * https://www.suse.com/security/cve/CVE-2026-20760.html * https://www.suse.com/security/cve/CVE-2026-20901.html * https://www.suse.com/security/cve/CVE-2026-20917.html * https://bugzilla.suse.com/show_bug.cgi?id=1274785 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:38:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:38:58 -0000 Subject: SUSE-SU-2026:4024-1: important: Security update for LibVNCServer Message-ID: <178878473837.9930.17871809762324368260@6bd16ccd9111> # Security update for LibVNCServer Announcement ID: SUSE-SU-2026:4024-1 Release Date: 2026-09-07T07:43:10Z Rating: important References: * bsc#1276218 Cross-References: * CVE-2026-50538 CVSS scores: * CVE-2026-50538 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-50538 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for LibVNCServer fixes the following issue: * CVE-2026-50538: a malicious (or man-in-the-middle) VNC server can force a connecting `libvncclient` to write attacker- controlled data past the end of its framebuffer (bsc#1276218). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4024=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4024=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * LibVNCServer-devel-0.9.9-17.50.1 * LibVNCServer-debugsource-0.9.9-17.50.1 * libvncserver0-0.9.9-17.50.1 * libvncclient0-0.9.9-17.50.1 * libvncserver0-debuginfo-0.9.9-17.50.1 * libvncclient0-debuginfo-0.9.9-17.50.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * LibVNCServer-devel-0.9.9-17.50.1 * LibVNCServer-debugsource-0.9.9-17.50.1 * libvncserver0-0.9.9-17.50.1 * libvncclient0-0.9.9-17.50.1 * libvncserver0-debuginfo-0.9.9-17.50.1 * libvncclient0-debuginfo-0.9.9-17.50.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50538.html * https://bugzilla.suse.com/show_bug.cgi?id=1276218 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:39:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:39:37 -0000 Subject: SUSE-SU-2026:4023-1: moderate: Security update for libsoup Message-ID: <178878477770.9930.11365341250891806184@6bd16ccd9111> # Security update for libsoup Announcement ID: SUSE-SU-2026:4023-1 Release Date: 2026-09-07T07:42:56Z Rating: moderate References: * bsc#1272196 Cross-References: * CVE-2026-12548 CVSS scores: * CVE-2026-12548 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12548 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12548 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for libsoup fixes the following issue: * CVE-2026-12548: out-of-bounds read in multipart body parser due to an integer truncation (bsc#1272196). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4023=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4023=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * libsoup-lang-3.4.4-150600.3.50.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libsoup-3_0-0-3.4.4-150600.3.50.1 * typelib-1_0-Soup-3_0-3.4.4-150600.3.50.1 * libsoup-3_0-0-debuginfo-3.4.4-150600.3.50.1 * libsoup-devel-3.4.4-150600.3.50.1 * libsoup-debugsource-3.4.4-150600.3.50.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libsoup-3_0-0-3.4.4-150600.3.50.1 * typelib-1_0-Soup-3_0-3.4.4-150600.3.50.1 * libsoup-devel-3.4.4-150600.3.50.1 * libsoup-debugsource-3.4.4-150600.3.50.1 * libsoup-3_0-0-debuginfo-3.4.4-150600.3.50.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libsoup-3_0-0-64bit-debuginfo-3.4.4-150600.3.50.1 * libsoup-3_0-0-64bit-3.4.4-150600.3.50.1 * libsoup-devel-64bit-3.4.4-150600.3.50.1 * openSUSE Leap 15.6 (noarch) * libsoup-lang-3.4.4-150600.3.50.1 * openSUSE Leap 15.6 (x86_64) * libsoup-3_0-0-32bit-debuginfo-3.4.4-150600.3.50.1 * libsoup-devel-32bit-3.4.4-150600.3.50.1 * libsoup-3_0-0-32bit-3.4.4-150600.3.50.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12548.html * https://bugzilla.suse.com/show_bug.cgi?id=1272196 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:40:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:40:33 -0000 Subject: SUSE-SU-2026:4022-1: important: Security update for LibVNCServer Message-ID: <178878483320.9930.6739880591506536578@6bd16ccd9111> # Security update for LibVNCServer Announcement ID: SUSE-SU-2026:4022-1 Release Date: 2026-09-07T07:42:45Z Rating: important References: * bsc#1276218 Cross-References: * CVE-2026-50538 CVSS scores: * CVE-2026-50538 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-50538 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for LibVNCServer fixes the following issue: * CVE-2026-50538: a malicious (or man-in-the-middle) VNC server can force a connecting `libvncclient` to write attacker- controlled data past the end of its framebuffer (bsc#1276218). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4022=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-4022=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4022=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * LibVNCServer-debugsource-0.9.14-150600.3.12.1 * libvncclient1-0.9.14-150600.3.12.1 * libvncclient1-debuginfo-0.9.14-150600.3.12.1 * libvncserver1-debuginfo-0.9.14-150600.3.12.1 * libvncserver1-0.9.14-150600.3.12.1 * LibVNCServer-devel-0.9.14-150600.3.12.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x) * LibVNCServer-debugsource-0.9.14-150600.3.12.1 * libvncclient1-0.9.14-150600.3.12.1 * libvncclient1-debuginfo-0.9.14-150600.3.12.1 * libvncserver1-debuginfo-0.9.14-150600.3.12.1 * libvncserver1-0.9.14-150600.3.12.1 * LibVNCServer-devel-0.9.14-150600.3.12.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * LibVNCServer-debugsource-0.9.14-150600.3.12.1 * libvncclient1-0.9.14-150600.3.12.1 * libvncclient1-debuginfo-0.9.14-150600.3.12.1 * libvncserver1-debuginfo-0.9.14-150600.3.12.1 * libvncserver1-0.9.14-150600.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50538.html * https://bugzilla.suse.com/show_bug.cgi?id=1276218 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:41:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:41:37 -0000 Subject: SUSE-SU-2026:4021-1: important: Security update for c-ares Message-ID: <178878489724.9930.7284040752516064688@6bd16ccd9111> # Security update for c-ares Announcement ID: SUSE-SU-2026:4021-1 Release Date: 2026-09-07T07:42:27Z Rating: important References: * bsc#1220279 * bsc#1240955 * bsc#1254738 * bsc#1270416 * bsc#1276290 * bsc#1276291 Cross-References: * CVE-2024-25629 * CVE-2025-31498 * CVE-2025-62408 * CVE-2026-33630 * CVE-2026-69184 * CVE-2026-69186 CVSS scores: * CVE-2024-25629 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2024-25629 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2024-25629 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-31498 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-31498 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2025-31498 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-62408 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-62408 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33630 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33630 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33630 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-69184 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-69186 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for c-ares fixes the following issues: * CVE-2024-25629: out of bounds read in ares__read_line() (bsc#1220279). * CVE-2025-31498: use-after-free in read_answers() when process_answer() may re-enqueue a query (bsc#1240955). * CVE-2025-62408: c-ares 1.32.3-1.34.5 use after free() (bsc#1254738). * CVE-2026-33630: Use-after-free / double-free in c-ares query-completion handling, remotely triggerable via ares_getaddrinfo() over TCP (bsc#1270416). * CVE-2026-69184: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains (bsc#1276290). * CVE-2026-69186: Memory-amplification denial of service via unvalidated DNS header record counts (bsc#1276291). Changes for c-ares: * updated to 1.36.8. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4021=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4021=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4021=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4021=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4021=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4021=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4021=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4021=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4021=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4021=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4021=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4021=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4021=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4021=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4021=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4021=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * c-ares-devel-1.34.8-150000.3.29.1 * c-ares-debugsource-1.34.8-150000.3.29.1 * libcares2-1.34.8-150000.3.29.1 * libcares2-debuginfo-1.34.8-150000.3.29.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * c-ares-devel-1.34.8-150000.3.29.1 * c-ares-debugsource-1.34.8-150000.3.29.1 * libcares2-1.34.8-150000.3.29.1 * libcares2-debuginfo-1.34.8-150000.3.29.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * c-ares-debugsource-1.34.8-150000.3.29.1 * libcares2-1.34.8-150000.3.29.1 * c-ares-devel-1.34.8-150000.3.29.1 * libcares2-debuginfo-1.34.8-150000.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * c-ares-devel-1.34.8-150000.3.29.1 * c-ares-debugsource-1.34.8-150000.3.29.1 * libcares2-1.34.8-150000.3.29.1 * libcares2-debuginfo-1.34.8-150000.3.29.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * c-ares-debugsource-1.34.8-150000.3.29.1 * libcares2-1.34.8-150000.3.29.1 * libcares2-debuginfo-1.34.8-150000.3.29.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * c-ares-debugsource-1.34.8-150000.3.29.1 * libcares2-debuginfo-1.34.8-150000.3.29.1 * c-ares-devel-1.34.8-150000.3.29.1 * libcares2-1.34.8-150000.3.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * c-ares-debugsource-1.34.8-150000.3.29.1 * libcares2-1.34.8-150000.3.29.1 * c-ares-devel-1.34.8-150000.3.29.1 * libcares2-debuginfo-1.34.8-150000.3.29.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * c-ares-debugsource-1.34.8-150000.3.29.1 * libcares2-1.34.8-150000.3.29.1 * libcares2-debuginfo-1.34.8-150000.3.29.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * c-ares-debugsource-1.34.8-150000.3.29.1 * libcares2-1.34.8-150000.3.29.1 * libcares2-debuginfo-1.34.8-150000.3.29.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * c-ares-debugsource-1.34.8-150000.3.29.1 * libcares2-debuginfo-1.34.8-150000.3.29.1 * c-ares-devel-1.34.8-150000.3.29.1 * libcares2-1.34.8-150000.3.29.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * c-ares-debugsource-1.34.8-150000.3.29.1 * libcares2-1.34.8-150000.3.29.1 * c-ares-devel-1.34.8-150000.3.29.1 * libcares2-debuginfo-1.34.8-150000.3.29.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * c-ares-devel-1.34.8-150000.3.29.1 * c-ares-debugsource-1.34.8-150000.3.29.1 * libcares2-1.34.8-150000.3.29.1 * libcares2-debuginfo-1.34.8-150000.3.29.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * c-ares-devel-1.34.8-150000.3.29.1 * c-ares-debugsource-1.34.8-150000.3.29.1 * libcares2-1.34.8-150000.3.29.1 * libcares2-debuginfo-1.34.8-150000.3.29.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * c-ares-debugsource-1.34.8-150000.3.29.1 * libcares2-1.34.8-150000.3.29.1 * c-ares-devel-1.34.8-150000.3.29.1 * libcares2-debuginfo-1.34.8-150000.3.29.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * c-ares-debugsource-1.34.8-150000.3.29.1 * libcares2-1.34.8-150000.3.29.1 * libcares2-debuginfo-1.34.8-150000.3.29.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * c-ares-debugsource-1.34.8-150000.3.29.1 * libcares2-1.34.8-150000.3.29.1 * libcares2-debuginfo-1.34.8-150000.3.29.1 ## References: * https://www.suse.com/security/cve/CVE-2024-25629.html * https://www.suse.com/security/cve/CVE-2025-31498.html * https://www.suse.com/security/cve/CVE-2025-62408.html * https://www.suse.com/security/cve/CVE-2026-33630.html * https://www.suse.com/security/cve/CVE-2026-69184.html * https://www.suse.com/security/cve/CVE-2026-69186.html * https://bugzilla.suse.com/show_bug.cgi?id=1220279 * https://bugzilla.suse.com/show_bug.cgi?id=1240955 * https://bugzilla.suse.com/show_bug.cgi?id=1254738 * https://bugzilla.suse.com/show_bug.cgi?id=1270416 * https://bugzilla.suse.com/show_bug.cgi?id=1276290 * https://bugzilla.suse.com/show_bug.cgi?id=1276291 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:42:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:42:16 -0000 Subject: SUSE-SU-2026:4020-1: important: Security update for webkit2gtk3 Message-ID: <178878493650.9930.16781691017480193800@6bd16ccd9111> # Security update for webkit2gtk3 Announcement ID: SUSE-SU-2026:4020-1 Release Date: 2026-09-07T07:40:28Z Rating: important References: * bsc#1275791 Cross-References: * CVE-2026-28984 * CVE-2026-43804 * CVE-2026-64713 * CVE-2026-64719 * CVE-2026-64728 * CVE-2026-64730 * CVE-2026-64757 * CVE-2026-64783 * CVE-2026-64787 CVSS scores: * CVE-2026-28984 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28984 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28984 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-43804 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43804 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43804 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-64713 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64713 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-64713 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-64719 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64719 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-64719 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-64728 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-64728 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-64728 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-64730 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-64730 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-64730 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-64757 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64757 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-64757 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64783 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64783 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-64783 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64787 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64787 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-64787 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves nine vulnerabilities can now be installed. ## Description: This update for webkit2gtk3 fixes the following issues: * CVE-2026-28984,CVE-2026-43804,CVE-2026-64713,CVE-2026-64719,CVE-2026-64728, CVE-2026-64730,CVE-2026-64757,CVE-2026-64783,CVE-2026-64787: WebKitGTK and WPE WebKit Security Advisory WSA-2026-0005 (bsc#1275791). Changes for webkit2gtk3: * Update to version 2.52.6 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4020=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4020=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4020=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-4020=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * webkitgtk-6_0-injected-bundles-debuginfo-2.52.6-150600.12.74.1 * typelib-1_0-WebKit2-4_0-2.52.6-150600.12.74.1 * libjavascriptcoregtk-4_1-0-2.52.6-150600.12.74.1 * typelib-1_0-JavaScriptCore-4_0-2.52.6-150600.12.74.1 * typelib-1_0-JavaScriptCore-6_0-2.52.6-150600.12.74.1 * webkit2gtk3-soup2-debugsource-2.52.6-150600.12.74.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.6-150600.12.74.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.6-150600.12.74.1 * webkit-jsc-4.1-debuginfo-2.52.6-150600.12.74.1 * typelib-1_0-WebKit2-4_1-2.52.6-150600.12.74.1 * libwebkit2gtk-4_1-0-2.52.6-150600.12.74.1 * webkit2gtk4-minibrowser-2.52.6-150600.12.74.1 * webkit2gtk3-soup2-minibrowser-debuginfo-2.52.6-150600.12.74.1 * webkit2gtk4-minibrowser-debuginfo-2.52.6-150600.12.74.1 * typelib-1_0-WebKit-6_0-2.52.6-150600.12.74.1 * webkit-jsc-4-debuginfo-2.52.6-150600.12.74.1 * webkit2gtk3-minibrowser-debuginfo-2.52.6-150600.12.74.1 * webkit2gtk3-minibrowser-2.52.6-150600.12.74.1 * webkit2gtk4-devel-2.52.6-150600.12.74.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.6-150600.12.74.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.6-150600.12.74.1 * libwebkitgtk-6_0-4-2.52.6-150600.12.74.1 * webkit2gtk3-devel-2.52.6-150600.12.74.1 * webkit2gtk-4_0-injected-bundles-2.52.6-150600.12.74.1 * webkit2gtk-4_1-injected-bundles-2.52.6-150600.12.74.1 * webkit-jsc-6.0-debuginfo-2.52.6-150600.12.74.1 * webkit-jsc-4-2.52.6-150600.12.74.1 * libjavascriptcoregtk-6_0-1-2.52.6-150600.12.74.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.6-150600.12.74.1 * libwebkitgtk-6_0-4-debuginfo-2.52.6-150600.12.74.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.6-150600.12.74.1 * webkit2gtk3-soup2-minibrowser-2.52.6-150600.12.74.1 * webkit-jsc-6.0-2.52.6-150600.12.74.1 * libwebkit2gtk-4_0-37-2.52.6-150600.12.74.1 * webkitgtk-6_0-injected-bundles-2.52.6-150600.12.74.1 * webkit2gtk4-debugsource-2.52.6-150600.12.74.1 * webkit2gtk3-debugsource-2.52.6-150600.12.74.1 * webkit-jsc-4.1-2.52.6-150600.12.74.1 * webkit2gtk3-soup2-devel-2.52.6-150600.12.74.1 * libjavascriptcoregtk-4_0-18-2.52.6-150600.12.74.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.6-150600.12.74.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.6-150600.12.74.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.6-150600.12.74.1 * typelib-1_0-WebKitWebProcessExtension-6_0-2.52.6-150600.12.74.1 * typelib-1_0-JavaScriptCore-4_1-2.52.6-150600.12.74.1 * openSUSE Leap 15.6 (x86_64) * libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.52.6-150600.12.74.1 * libwebkit2gtk-4_1-0-32bit-2.52.6-150600.12.74.1 * libjavascriptcoregtk-4_1-0-32bit-2.52.6-150600.12.74.1 * libwebkit2gtk-4_0-37-32bit-debuginfo-2.52.6-150600.12.74.1 * libwebkit2gtk-4_0-37-32bit-2.52.6-150600.12.74.1 * libwebkit2gtk-4_1-0-32bit-debuginfo-2.52.6-150600.12.74.1 * libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.52.6-150600.12.74.1 * libjavascriptcoregtk-4_0-18-32bit-2.52.6-150600.12.74.1 * openSUSE Leap 15.6 (noarch) * WebKitGTK-4.1-lang-2.52.6-150600.12.74.1 * WebKitGTK-4.0-lang-2.52.6-150600.12.74.1 * WebKitGTK-6.0-lang-2.52.6-150600.12.74.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libwebkit2gtk-4_1-0-64bit-2.52.6-150600.12.74.1 * libwebkit2gtk-4_0-37-64bit-debuginfo-2.52.6-150600.12.74.1 * libjavascriptcoregtk-4_0-18-64bit-2.52.6-150600.12.74.1 * libwebkit2gtk-4_1-0-64bit-debuginfo-2.52.6-150600.12.74.1 * libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.52.6-150600.12.74.1 * libwebkit2gtk-4_0-37-64bit-2.52.6-150600.12.74.1 * libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.52.6-150600.12.74.1 * libjavascriptcoregtk-4_1-0-64bit-2.52.6-150600.12.74.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libjavascriptcoregtk-4_1-0-2.52.6-150600.12.74.1 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.6-150600.12.74.1 * typelib-1_0-WebKit2WebExtension-4_1-2.52.6-150600.12.74.1 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.6-150600.12.74.1 * webkit2gtk-4_1-injected-bundles-2.52.6-150600.12.74.1 * webkit2gtk3-devel-2.52.6-150600.12.74.1 * webkit2gtk3-debugsource-2.52.6-150600.12.74.1 * libwebkit2gtk-4_1-0-debuginfo-2.52.6-150600.12.74.1 * typelib-1_0-JavaScriptCore-4_1-2.52.6-150600.12.74.1 * typelib-1_0-WebKit2-4_1-2.52.6-150600.12.74.1 * libwebkit2gtk-4_1-0-2.52.6-150600.12.74.1 * Desktop Applications Module 15-SP7 (noarch) * WebKitGTK-4.1-lang-2.52.6-150600.12.74.1 * Basesystem Module 15-SP7 (noarch) * WebKitGTK-4.0-lang-2.52.6-150600.12.74.1 * WebKitGTK-6.0-lang-2.52.6-150600.12.74.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * webkitgtk-6_0-injected-bundles-debuginfo-2.52.6-150600.12.74.1 * libjavascriptcoregtk-6_0-1-2.52.6-150600.12.74.1 * typelib-1_0-WebKit2-4_0-2.52.6-150600.12.74.1 * typelib-1_0-JavaScriptCore-4_0-2.52.6-150600.12.74.1 * webkit2gtk3-soup2-devel-2.52.6-150600.12.74.1 * webkit2gtk3-soup2-debugsource-2.52.6-150600.12.74.1 * libwebkitgtk-6_0-4-debuginfo-2.52.6-150600.12.74.1 * typelib-1_0-WebKit2WebExtension-4_0-2.52.6-150600.12.74.1 * libwebkit2gtk-4_0-37-2.52.6-150600.12.74.1 * libjavascriptcoregtk-4_0-18-2.52.6-150600.12.74.1 * libwebkitgtk-6_0-4-2.52.6-150600.12.74.1 * webkit2gtk-4_0-injected-bundles-2.52.6-150600.12.74.1 * webkit2gtk4-debugsource-2.52.6-150600.12.74.1 * libwebkit2gtk-4_0-37-debuginfo-2.52.6-150600.12.74.1 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.6-150600.12.74.1 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.6-150600.12.74.1 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.6-150600.12.74.1 * webkitgtk-6_0-injected-bundles-2.52.6-150600.12.74.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * typelib-1_0-WebKit-6_0-2.52.6-150600.12.74.1 * typelib-1_0-JavaScriptCore-6_0-2.52.6-150600.12.74.1 * webkit2gtk4-devel-2.52.6-150600.12.74.1 * webkit2gtk4-debugsource-2.52.6-150600.12.74.1 * typelib-1_0-WebKitWebProcessExtension-6_0-2.52.6-150600.12.74.1 ## References: * https://www.suse.com/security/cve/CVE-2026-28984.html * https://www.suse.com/security/cve/CVE-2026-43804.html * https://www.suse.com/security/cve/CVE-2026-64713.html * https://www.suse.com/security/cve/CVE-2026-64719.html * https://www.suse.com/security/cve/CVE-2026-64728.html * https://www.suse.com/security/cve/CVE-2026-64730.html * https://www.suse.com/security/cve/CVE-2026-64757.html * https://www.suse.com/security/cve/CVE-2026-64783.html * https://www.suse.com/security/cve/CVE-2026-64787.html * https://bugzilla.suse.com/show_bug.cgi?id=1275791 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:43:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:43:12 -0000 Subject: SUSE-SU-2026:4019-1: important: Security update for microcode_ctl Message-ID: <178878499227.9930.4540980805471246861@6bd16ccd9111> # Security update for microcode_ctl Announcement ID: SUSE-SU-2026:4019-1 Release Date: 2026-09-07T07:39:46Z Rating: important References: * bsc#1274785 Cross-References: * CVE-2025-31936 * CVE-2025-31938 * CVE-2025-35973 * CVE-2026-20707 * CVE-2026-20713 * CVE-2026-20716 * CVE-2026-20760 * CVE-2026-20901 * CVE-2026-20917 CVSS scores: * CVE-2025-31936 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31936 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2025-31936 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31938 ( SUSE ): 4.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31938 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2025-31938 ( NVD ): 4.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35973 ( SUSE ): 4.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35973 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N * CVE-2025-35973 ( NVD ): 4.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20707 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20707 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-20707 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20713 ( SUSE ): 4.5 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20713 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N * CVE-2026-20713 ( NVD ): 4.5 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( SUSE ): 7.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-20716 ( NVD ): 7.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20760 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20760 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20760 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20901 ( NVD ): 4.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20901 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N * CVE-2026-20917 ( SUSE ): 4.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20917 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2026-20917 ( NVD ): 4.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 11 SP4 * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE An update that solves nine vulnerabilities can now be installed. ## Description: This update for microcode_ctl fixes the following issues: * Intel CPU Microcode was updated to the 20260812 release (bsc#1274785) * Removed MTL/06-aa-04/c0 due to functional issues observed when loading the MCU in some platforms. * Intel CPU Microcode was updated to the 20260811 release (bsc#1274785) * Security updates for INTEL-SA-01379 / CVE-2025-31936 * Security updates for INTEL-SA-01404 / CVE-2025-31938 * Security updates for INTEL-SA-01423 / CVE-2026-20917 * Security updates for INTEL-SA-01428 / CVE-2025-35973 * Security updates for INTEL-SA-01435 / CVE-2026-20716 * Security updates for INTEL-SA-01441 / CVE-2026-20760 * Security updates for INTEL-SA-01442 / CVE-2026-20713 / CVE-2026-20901 * Security updates for INTEL-SA-01443 / CVE-2026-20707 * Update for functional issues. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2026-4019=1 * SUSE Linux Enterprise Server 11 SP4 zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2026-4019=1 ## Package List: * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE (x86_64) * microcode_ctl-1.17-102.83.98.1 * SUSE Linux Enterprise Server 11 SP4 (x86_64) * microcode_ctl-1.17-102.83.98.1 ## References: * https://www.suse.com/security/cve/CVE-2025-31936.html * https://www.suse.com/security/cve/CVE-2025-31938.html * https://www.suse.com/security/cve/CVE-2025-35973.html * https://www.suse.com/security/cve/CVE-2026-20707.html * https://www.suse.com/security/cve/CVE-2026-20713.html * https://www.suse.com/security/cve/CVE-2026-20716.html * https://www.suse.com/security/cve/CVE-2026-20760.html * https://www.suse.com/security/cve/CVE-2026-20901.html * https://www.suse.com/security/cve/CVE-2026-20917.html * https://bugzilla.suse.com/show_bug.cgi?id=1274785 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:44:23 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:44:23 -0000 Subject: SUSE-SU-2026:4018-1: important: Security update for postgresql15 Message-ID: <178878506353.9930.1021676860421945861@6bd16ccd9111> # Security update for postgresql15 Announcement ID: SUSE-SU-2026:4018-1 Release Date: 2026-09-07T07:39:37Z Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275053 * bsc#1275054 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275061 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14673 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14662 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14664 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14666 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14668 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14669 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14673 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14673 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14678 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14679 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14680 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15741 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15741 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15742 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16241 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18024 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18408 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19385 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6464 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6469 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6470 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6471 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for postgresql15 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). * CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). * CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql15: * Update to version 15.19: * https://www.postgresql.org/docs/15/release-15-19.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4018=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4018=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4018=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4018=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4018=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4018=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4018=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4018=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * postgresql15-plperl-15.19-150200.5.62.1 * postgresql15-plpython-15.19-150200.5.62.1 * postgresql15-server-15.19-150200.5.62.1 * postgresql15-debugsource-15.19-150200.5.62.1 * postgresql15-plpython-debuginfo-15.19-150200.5.62.1 * postgresql15-15.19-150200.5.62.1 * postgresql15-server-devel-debuginfo-15.19-150200.5.62.1 * postgresql15-plperl-debuginfo-15.19-150200.5.62.1 * postgresql15-debuginfo-15.19-150200.5.62.1 * postgresql15-devel-15.19-150200.5.62.1 * postgresql15-server-debuginfo-15.19-150200.5.62.1 * postgresql15-contrib-15.19-150200.5.62.1 * postgresql15-contrib-debuginfo-15.19-150200.5.62.1 * postgresql15-pltcl-debuginfo-15.19-150200.5.62.1 * postgresql15-server-devel-15.19-150200.5.62.1 * postgresql15-devel-debuginfo-15.19-150200.5.62.1 * postgresql15-pltcl-15.19-150200.5.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * postgresql15-docs-15.19-150200.5.62.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * postgresql15-plperl-15.19-150200.5.62.1 * postgresql15-debugsource-15.19-150200.5.62.1 * postgresql15-server-15.19-150200.5.62.1 * postgresql15-15.19-150200.5.62.1 * postgresql15-plpython-15.19-150200.5.62.1 * postgresql15-plpython-debuginfo-15.19-150200.5.62.1 * postgresql15-debuginfo-15.19-150200.5.62.1 * postgresql15-plperl-debuginfo-15.19-150200.5.62.1 * postgresql15-server-devel-debuginfo-15.19-150200.5.62.1 * postgresql15-devel-15.19-150200.5.62.1 * postgresql15-server-debuginfo-15.19-150200.5.62.1 * postgresql15-contrib-15.19-150200.5.62.1 * postgresql15-contrib-debuginfo-15.19-150200.5.62.1 * postgresql15-pltcl-debuginfo-15.19-150200.5.62.1 * postgresql15-server-devel-15.19-150200.5.62.1 * postgresql15-devel-debuginfo-15.19-150200.5.62.1 * postgresql15-pltcl-15.19-150200.5.62.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * postgresql15-docs-15.19-150200.5.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * postgresql15-plperl-15.19-150200.5.62.1 * postgresql15-plpython-15.19-150200.5.62.1 * postgresql15-15.19-150200.5.62.1 * postgresql15-debugsource-15.19-150200.5.62.1 * postgresql15-plpython-debuginfo-15.19-150200.5.62.1 * postgresql15-server-15.19-150200.5.62.1 * postgresql15-debuginfo-15.19-150200.5.62.1 * postgresql15-plperl-debuginfo-15.19-150200.5.62.1 * postgresql15-devel-debuginfo-15.19-150200.5.62.1 * postgresql15-devel-15.19-150200.5.62.1 * postgresql15-server-debuginfo-15.19-150200.5.62.1 * postgresql15-contrib-15.19-150200.5.62.1 * postgresql15-contrib-debuginfo-15.19-150200.5.62.1 * postgresql15-pltcl-debuginfo-15.19-150200.5.62.1 * postgresql15-server-devel-15.19-150200.5.62.1 * postgresql15-server-devel-debuginfo-15.19-150200.5.62.1 * postgresql15-pltcl-15.19-150200.5.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * postgresql15-docs-15.19-150200.5.62.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * postgresql15-plperl-15.19-150200.5.62.1 * postgresql15-15.19-150200.5.62.1 * postgresql15-plpython-15.19-150200.5.62.1 * postgresql15-server-15.19-150200.5.62.1 * postgresql15-plpython-debuginfo-15.19-150200.5.62.1 * postgresql15-debugsource-15.19-150200.5.62.1 * postgresql15-debuginfo-15.19-150200.5.62.1 * postgresql15-plperl-debuginfo-15.19-150200.5.62.1 * postgresql15-devel-debuginfo-15.19-150200.5.62.1 * postgresql15-devel-15.19-150200.5.62.1 * postgresql15-server-debuginfo-15.19-150200.5.62.1 * postgresql15-contrib-15.19-150200.5.62.1 * postgresql15-contrib-debuginfo-15.19-150200.5.62.1 * postgresql15-pltcl-debuginfo-15.19-150200.5.62.1 * postgresql15-server-devel-15.19-150200.5.62.1 * postgresql15-server-devel-debuginfo-15.19-150200.5.62.1 * postgresql15-pltcl-15.19-150200.5.62.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * postgresql15-docs-15.19-150200.5.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * postgresql15-server-15.19-150200.5.62.1 * postgresql15-debugsource-15.19-150200.5.62.1 * postgresql15-plperl-15.19-150200.5.62.1 * postgresql15-15.19-150200.5.62.1 * postgresql15-plpython-debuginfo-15.19-150200.5.62.1 * postgresql15-plpython-15.19-150200.5.62.1 * postgresql15-server-devel-debuginfo-15.19-150200.5.62.1 * postgresql15-debuginfo-15.19-150200.5.62.1 * postgresql15-plperl-debuginfo-15.19-150200.5.62.1 * postgresql15-devel-15.19-150200.5.62.1 * postgresql15-server-debuginfo-15.19-150200.5.62.1 * postgresql15-contrib-15.19-150200.5.62.1 * postgresql15-contrib-debuginfo-15.19-150200.5.62.1 * postgresql15-pltcl-debuginfo-15.19-150200.5.62.1 * postgresql15-server-devel-15.19-150200.5.62.1 * postgresql15-devel-debuginfo-15.19-150200.5.62.1 * postgresql15-pltcl-15.19-150200.5.62.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * postgresql15-docs-15.19-150200.5.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * postgresql15-plpython-15.19-150200.5.62.1 * postgresql15-15.19-150200.5.62.1 * postgresql15-server-15.19-150200.5.62.1 * postgresql15-plperl-15.19-150200.5.62.1 * postgresql15-debugsource-15.19-150200.5.62.1 * postgresql15-plpython-debuginfo-15.19-150200.5.62.1 * postgresql15-debuginfo-15.19-150200.5.62.1 * postgresql15-plperl-debuginfo-15.19-150200.5.62.1 * postgresql15-server-devel-debuginfo-15.19-150200.5.62.1 * postgresql15-devel-15.19-150200.5.62.1 * postgresql15-server-debuginfo-15.19-150200.5.62.1 * postgresql15-contrib-15.19-150200.5.62.1 * postgresql15-contrib-debuginfo-15.19-150200.5.62.1 * postgresql15-pltcl-debuginfo-15.19-150200.5.62.1 * postgresql15-server-devel-15.19-150200.5.62.1 * postgresql15-devel-debuginfo-15.19-150200.5.62.1 * postgresql15-pltcl-15.19-150200.5.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * postgresql15-docs-15.19-150200.5.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * postgresql15-plpython-15.19-150200.5.62.1 * postgresql15-debugsource-15.19-150200.5.62.1 * postgresql15-plperl-15.19-150200.5.62.1 * postgresql15-15.19-150200.5.62.1 * postgresql15-server-15.19-150200.5.62.1 * postgresql15-plpython-debuginfo-15.19-150200.5.62.1 * postgresql15-debuginfo-15.19-150200.5.62.1 * postgresql15-server-devel-debuginfo-15.19-150200.5.62.1 * postgresql15-plperl-debuginfo-15.19-150200.5.62.1 * postgresql15-devel-15.19-150200.5.62.1 * postgresql15-contrib-15.19-150200.5.62.1 * postgresql15-server-debuginfo-15.19-150200.5.62.1 * postgresql15-contrib-debuginfo-15.19-150200.5.62.1 * postgresql15-pltcl-debuginfo-15.19-150200.5.62.1 * postgresql15-server-devel-15.19-150200.5.62.1 * postgresql15-devel-debuginfo-15.19-150200.5.62.1 * postgresql15-pltcl-15.19-150200.5.62.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * postgresql15-docs-15.19-150200.5.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * postgresql15-plpython-15.19-150200.5.62.1 * postgresql15-plperl-15.19-150200.5.62.1 * postgresql15-server-15.19-150200.5.62.1 * postgresql15-15.19-150200.5.62.1 * postgresql15-plpython-debuginfo-15.19-150200.5.62.1 * postgresql15-debugsource-15.19-150200.5.62.1 * postgresql15-debuginfo-15.19-150200.5.62.1 * postgresql15-plperl-debuginfo-15.19-150200.5.62.1 * postgresql15-devel-debuginfo-15.19-150200.5.62.1 * postgresql15-devel-15.19-150200.5.62.1 * postgresql15-contrib-15.19-150200.5.62.1 * postgresql15-server-debuginfo-15.19-150200.5.62.1 * postgresql15-contrib-debuginfo-15.19-150200.5.62.1 * postgresql15-pltcl-debuginfo-15.19-150200.5.62.1 * postgresql15-server-devel-15.19-150200.5.62.1 * postgresql15-server-devel-debuginfo-15.19-150200.5.62.1 * postgresql15-pltcl-15.19-150200.5.62.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * postgresql15-docs-15.19-150200.5.62.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14673.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html * https://bugzilla.suse.com/show_bug.cgi?id=1275001 * https://bugzilla.suse.com/show_bug.cgi?id=1275002 * https://bugzilla.suse.com/show_bug.cgi?id=1275042 * https://bugzilla.suse.com/show_bug.cgi?id=1275043 * https://bugzilla.suse.com/show_bug.cgi?id=1275044 * https://bugzilla.suse.com/show_bug.cgi?id=1275046 * https://bugzilla.suse.com/show_bug.cgi?id=1275047 * https://bugzilla.suse.com/show_bug.cgi?id=1275048 * https://bugzilla.suse.com/show_bug.cgi?id=1275049 * https://bugzilla.suse.com/show_bug.cgi?id=1275050 * https://bugzilla.suse.com/show_bug.cgi?id=1275051 * https://bugzilla.suse.com/show_bug.cgi?id=1275053 * https://bugzilla.suse.com/show_bug.cgi?id=1275054 * https://bugzilla.suse.com/show_bug.cgi?id=1275056 * https://bugzilla.suse.com/show_bug.cgi?id=1275057 * https://bugzilla.suse.com/show_bug.cgi?id=1275058 * https://bugzilla.suse.com/show_bug.cgi?id=1275059 * https://bugzilla.suse.com/show_bug.cgi?id=1275061 * https://bugzilla.suse.com/show_bug.cgi?id=1275063 * https://bugzilla.suse.com/show_bug.cgi?id=1275064 * https://bugzilla.suse.com/show_bug.cgi?id=1275065 * https://bugzilla.suse.com/show_bug.cgi?id=1275066 * https://bugzilla.suse.com/show_bug.cgi?id=1275067 * https://bugzilla.suse.com/show_bug.cgi?id=1275068 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:45:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:45:34 -0000 Subject: SUSE-SU-2026:4017-1: important: Security update for postgresql15 Message-ID: <178878513462.9930.11287802716393098475@6bd16ccd9111> # Security update for postgresql15 Announcement ID: SUSE-SU-2026:4017-1 Release Date: 2026-09-07T07:38:40Z Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275053 * bsc#1275054 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275061 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14673 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14662 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14664 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14666 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14668 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14669 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14673 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14673 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14678 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14679 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14680 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15741 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15741 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15742 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16241 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18024 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18408 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19385 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6464 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6469 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6470 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6471 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * Legacy Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for postgresql15 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). * CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). * CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql15: * Update to version 15.19: * https://www.postgresql.org/docs/15/release-15-19.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-4017=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4017=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4017=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4017=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * postgresql15-server-15.19-150600.16.36.1 * postgresql15-plpython-debuginfo-15.19-150600.16.36.1 * postgresql15-debugsource-15.19-150600.16.36.1 * postgresql15-devel-debuginfo-15.19-150600.16.36.1 * postgresql15-llvmjit-15.19-150600.16.36.1 * postgresql15-devel-15.19-150600.16.36.1 * postgresql15-server-devel-debuginfo-15.19-150600.16.36.1 * postgresql15-pltcl-debuginfo-15.19-150600.16.36.1 * postgresql15-plperl-15.19-150600.16.36.1 * postgresql15-server-devel-15.19-150600.16.36.1 * postgresql15-llvmjit-debuginfo-15.19-150600.16.36.1 * postgresql15-server-debuginfo-15.19-150600.16.36.1 * postgresql15-contrib-15.19-150600.16.36.1 * postgresql15-llvmjit-devel-15.19-150600.16.36.1 * postgresql15-plperl-debuginfo-15.19-150600.16.36.1 * postgresql15-15.19-150600.16.36.1 * postgresql15-pltcl-15.19-150600.16.36.1 * postgresql15-test-15.19-150600.16.36.1 * postgresql15-debuginfo-15.19-150600.16.36.1 * postgresql15-plpython-15.19-150600.16.36.1 * postgresql15-contrib-debuginfo-15.19-150600.16.36.1 * openSUSE Leap 15.6 (noarch) * postgresql15-docs-15.19-150600.16.36.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * postgresql15-plperl-15.19-150600.16.36.1 * postgresql15-contrib-15.19-150600.16.36.1 * postgresql15-server-15.19-150600.16.36.1 * postgresql15-debugsource-15.19-150600.16.36.1 * postgresql15-devel-debuginfo-15.19-150600.16.36.1 * postgresql15-plpython-debuginfo-15.19-150600.16.36.1 * postgresql15-debuginfo-15.19-150600.16.36.1 * postgresql15-server-devel-15.19-150600.16.36.1 * postgresql15-plpython-15.19-150600.16.36.1 * postgresql15-plperl-debuginfo-15.19-150600.16.36.1 * postgresql15-devel-15.19-150600.16.36.1 * postgresql15-15.19-150600.16.36.1 * postgresql15-server-devel-debuginfo-15.19-150600.16.36.1 * postgresql15-server-debuginfo-15.19-150600.16.36.1 * postgresql15-contrib-debuginfo-15.19-150600.16.36.1 * postgresql15-pltcl-15.19-150600.16.36.1 * postgresql15-pltcl-debuginfo-15.19-150600.16.36.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * postgresql15-docs-15.19-150600.16.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * postgresql15-plperl-15.19-150600.16.36.1 * postgresql15-contrib-15.19-150600.16.36.1 * postgresql15-plpython-debuginfo-15.19-150600.16.36.1 * postgresql15-devel-debuginfo-15.19-150600.16.36.1 * postgresql15-debugsource-15.19-150600.16.36.1 * postgresql15-server-15.19-150600.16.36.1 * postgresql15-debuginfo-15.19-150600.16.36.1 * postgresql15-server-devel-15.19-150600.16.36.1 * postgresql15-plpython-15.19-150600.16.36.1 * postgresql15-plperl-debuginfo-15.19-150600.16.36.1 * postgresql15-devel-15.19-150600.16.36.1 * postgresql15-15.19-150600.16.36.1 * postgresql15-server-devel-debuginfo-15.19-150600.16.36.1 * postgresql15-server-debuginfo-15.19-150600.16.36.1 * postgresql15-contrib-debuginfo-15.19-150600.16.36.1 * postgresql15-pltcl-15.19-150600.16.36.1 * postgresql15-pltcl-debuginfo-15.19-150600.16.36.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * postgresql15-docs-15.19-150600.16.36.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * postgresql15-plperl-15.19-150600.16.36.1 * postgresql15-server-15.19-150600.16.36.1 * postgresql15-contrib-15.19-150600.16.36.1 * postgresql15-devel-debuginfo-15.19-150600.16.36.1 * postgresql15-debugsource-15.19-150600.16.36.1 * postgresql15-plpython-debuginfo-15.19-150600.16.36.1 * postgresql15-debuginfo-15.19-150600.16.36.1 * postgresql15-plpython-15.19-150600.16.36.1 * postgresql15-server-devel-15.19-150600.16.36.1 * postgresql15-plperl-debuginfo-15.19-150600.16.36.1 * postgresql15-devel-15.19-150600.16.36.1 * postgresql15-15.19-150600.16.36.1 * postgresql15-server-devel-debuginfo-15.19-150600.16.36.1 * postgresql15-server-debuginfo-15.19-150600.16.36.1 * postgresql15-contrib-debuginfo-15.19-150600.16.36.1 * postgresql15-pltcl-15.19-150600.16.36.1 * postgresql15-pltcl-debuginfo-15.19-150600.16.36.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14673.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html * https://bugzilla.suse.com/show_bug.cgi?id=1275001 * https://bugzilla.suse.com/show_bug.cgi?id=1275002 * https://bugzilla.suse.com/show_bug.cgi?id=1275042 * https://bugzilla.suse.com/show_bug.cgi?id=1275043 * https://bugzilla.suse.com/show_bug.cgi?id=1275044 * https://bugzilla.suse.com/show_bug.cgi?id=1275046 * https://bugzilla.suse.com/show_bug.cgi?id=1275047 * https://bugzilla.suse.com/show_bug.cgi?id=1275048 * https://bugzilla.suse.com/show_bug.cgi?id=1275049 * https://bugzilla.suse.com/show_bug.cgi?id=1275050 * https://bugzilla.suse.com/show_bug.cgi?id=1275051 * https://bugzilla.suse.com/show_bug.cgi?id=1275053 * https://bugzilla.suse.com/show_bug.cgi?id=1275054 * https://bugzilla.suse.com/show_bug.cgi?id=1275056 * https://bugzilla.suse.com/show_bug.cgi?id=1275057 * https://bugzilla.suse.com/show_bug.cgi?id=1275058 * https://bugzilla.suse.com/show_bug.cgi?id=1275059 * https://bugzilla.suse.com/show_bug.cgi?id=1275061 * https://bugzilla.suse.com/show_bug.cgi?id=1275063 * https://bugzilla.suse.com/show_bug.cgi?id=1275064 * https://bugzilla.suse.com/show_bug.cgi?id=1275065 * https://bugzilla.suse.com/show_bug.cgi?id=1275066 * https://bugzilla.suse.com/show_bug.cgi?id=1275067 * https://bugzilla.suse.com/show_bug.cgi?id=1275068 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:47:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:47:03 -0000 Subject: SUSE-SU-2026:4016-1: important: Security update for postgresql17 Message-ID: <178878522396.9930.1916581492764405558@6bd16ccd9111> # Security update for postgresql17 Announcement ID: SUSE-SU-2026:4016-1 Release Date: 2026-09-07T07:38:13Z Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275053 * bsc#1275054 * bsc#1275055 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275062 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14672 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-14681 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14662 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14664 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14666 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14668 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14669 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14672 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14672 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14678 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14679 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14680 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14681 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14681 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-15741 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15741 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15742 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16241 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18024 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18408 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19385 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6464 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6469 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6470 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6471 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for postgresql17 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). * CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). * CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). * CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql17: * Update to version 17.11: * https://www.postgresql.org/docs/17/release-17-11.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4016=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4016=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-4016=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4016=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4016=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4016=1 ## Package List: * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * postgresql17-contrib-debuginfo-17.11-150600.13.32.1 * postgresql17-devel-debuginfo-17.11-150600.13.32.1 * postgresql17-server-17.11-150600.13.32.1 * postgresql17-pltcl-17.11-150600.13.32.1 * postgresql17-server-debuginfo-17.11-150600.13.32.1 * postgresql17-plpython-debuginfo-17.11-150600.13.32.1 * postgresql17-pltcl-debuginfo-17.11-150600.13.32.1 * postgresql17-server-devel-debuginfo-17.11-150600.13.32.1 * postgresql17-contrib-17.11-150600.13.32.1 * postgresql17-plperl-17.11-150600.13.32.1 * postgresql17-debuginfo-17.11-150600.13.32.1 * postgresql17-plpython-17.11-150600.13.32.1 * postgresql17-server-devel-17.11-150600.13.32.1 * postgresql17-debugsource-17.11-150600.13.32.1 * postgresql17-plperl-debuginfo-17.11-150600.13.32.1 * postgresql17-devel-17.11-150600.13.32.1 * Server Applications Module 15-SP7 (noarch) * postgresql17-docs-17.11-150600.13.32.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * postgresql17-contrib-17.11-150600.13.32.1 * postgresql17-server-devel-debuginfo-17.11-150600.13.32.1 * postgresql17-plperl-17.11-150600.13.32.1 * postgresql17-debugsource-17.11-150600.13.32.1 * postgresql17-17.11-150600.13.32.1 * postgresql17-llvmjit-debuginfo-17.11-150600.13.32.1 * postgresql17-llvmjit-17.11-150600.13.32.1 * postgresql17-devel-17.11-150600.13.32.1 * postgresql17-plpython-debuginfo-17.11-150600.13.32.1 * postgresql17-pltcl-debuginfo-17.11-150600.13.32.1 * postgresql17-test-17.11-150600.13.32.1 * postgresql17-plpython-17.11-150600.13.32.1 * postgresql17-plperl-debuginfo-17.11-150600.13.32.1 * postgresql17-contrib-debuginfo-17.11-150600.13.32.1 * postgresql17-devel-debuginfo-17.11-150600.13.32.1 * postgresql17-debuginfo-17.11-150600.13.32.1 * postgresql17-server-17.11-150600.13.32.1 * postgresql17-pltcl-17.11-150600.13.32.1 * postgresql17-server-debuginfo-17.11-150600.13.32.1 * postgresql17-server-devel-17.11-150600.13.32.1 * postgresql17-llvmjit-devel-17.11-150600.13.32.1 * openSUSE Leap 15.6 (noarch) * postgresql17-docs-17.11-150600.13.32.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * postgresql17-test-17.11-150600.13.32.1 * postgresql17-debuginfo-17.11-150600.13.32.1 * postgresql17-llvmjit-devel-17.11-150600.13.32.1 * postgresql17-debugsource-17.11-150600.13.32.1 * postgresql17-llvmjit-debuginfo-17.11-150600.13.32.1 * postgresql17-llvmjit-17.11-150600.13.32.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * postgresql17-contrib-debuginfo-17.11-150600.13.32.1 * postgresql17-devel-debuginfo-17.11-150600.13.32.1 * postgresql17-server-17.11-150600.13.32.1 * postgresql17-pltcl-17.11-150600.13.32.1 * postgresql17-plpython-debuginfo-17.11-150600.13.32.1 * postgresql17-server-debuginfo-17.11-150600.13.32.1 * postgresql17-pltcl-debuginfo-17.11-150600.13.32.1 * postgresql17-server-devel-debuginfo-17.11-150600.13.32.1 * postgresql17-contrib-17.11-150600.13.32.1 * postgresql17-plperl-17.11-150600.13.32.1 * postgresql17-debuginfo-17.11-150600.13.32.1 * postgresql17-plpython-17.11-150600.13.32.1 * postgresql17-server-devel-17.11-150600.13.32.1 * postgresql17-17.11-150600.13.32.1 * postgresql17-plperl-debuginfo-17.11-150600.13.32.1 * postgresql17-debugsource-17.11-150600.13.32.1 * postgresql17-devel-17.11-150600.13.32.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * postgresql17-docs-17.11-150600.13.32.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * postgresql17-contrib-debuginfo-17.11-150600.13.32.1 * postgresql17-devel-debuginfo-17.11-150600.13.32.1 * postgresql17-server-17.11-150600.13.32.1 * postgresql17-pltcl-17.11-150600.13.32.1 * postgresql17-server-debuginfo-17.11-150600.13.32.1 * postgresql17-plpython-debuginfo-17.11-150600.13.32.1 * postgresql17-pltcl-debuginfo-17.11-150600.13.32.1 * postgresql17-contrib-17.11-150600.13.32.1 * postgresql17-server-devel-debuginfo-17.11-150600.13.32.1 * postgresql17-plperl-17.11-150600.13.32.1 * postgresql17-debuginfo-17.11-150600.13.32.1 * postgresql17-plpython-17.11-150600.13.32.1 * postgresql17-server-devel-17.11-150600.13.32.1 * postgresql17-17.11-150600.13.32.1 * postgresql17-debugsource-17.11-150600.13.32.1 * postgresql17-plperl-debuginfo-17.11-150600.13.32.1 * postgresql17-devel-17.11-150600.13.32.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * postgresql17-docs-17.11-150600.13.32.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * postgresql17-debuginfo-17.11-150600.13.32.1 * postgresql17-17.11-150600.13.32.1 * postgresql17-debugsource-17.11-150600.13.32.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14672.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-14681.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html * https://bugzilla.suse.com/show_bug.cgi?id=1275001 * https://bugzilla.suse.com/show_bug.cgi?id=1275002 * https://bugzilla.suse.com/show_bug.cgi?id=1275042 * https://bugzilla.suse.com/show_bug.cgi?id=1275043 * https://bugzilla.suse.com/show_bug.cgi?id=1275044 * https://bugzilla.suse.com/show_bug.cgi?id=1275046 * https://bugzilla.suse.com/show_bug.cgi?id=1275047 * https://bugzilla.suse.com/show_bug.cgi?id=1275048 * https://bugzilla.suse.com/show_bug.cgi?id=1275049 * https://bugzilla.suse.com/show_bug.cgi?id=1275050 * https://bugzilla.suse.com/show_bug.cgi?id=1275051 * https://bugzilla.suse.com/show_bug.cgi?id=1275053 * https://bugzilla.suse.com/show_bug.cgi?id=1275054 * https://bugzilla.suse.com/show_bug.cgi?id=1275055 * https://bugzilla.suse.com/show_bug.cgi?id=1275056 * https://bugzilla.suse.com/show_bug.cgi?id=1275057 * https://bugzilla.suse.com/show_bug.cgi?id=1275058 * https://bugzilla.suse.com/show_bug.cgi?id=1275059 * https://bugzilla.suse.com/show_bug.cgi?id=1275062 * https://bugzilla.suse.com/show_bug.cgi?id=1275063 * https://bugzilla.suse.com/show_bug.cgi?id=1275064 * https://bugzilla.suse.com/show_bug.cgi?id=1275065 * https://bugzilla.suse.com/show_bug.cgi?id=1275066 * https://bugzilla.suse.com/show_bug.cgi?id=1275067 * https://bugzilla.suse.com/show_bug.cgi?id=1275068 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:48:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:48:36 -0000 Subject: SUSE-SU-2026:4015-1: important: Security update for postgresql18 Message-ID: <178878531654.9930.12226477107438285508@6bd16ccd9111> # Security update for postgresql18 Announcement ID: SUSE-SU-2026:4015-1 Release Date: 2026-09-07T07:37:29Z Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275052 * bsc#1275053 * bsc#1275054 * bsc#1275055 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275060 * bsc#1275061 * bsc#1275062 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14672 * CVE-2026-14673 * CVE-2026-14676 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-14681 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16238 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14662 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14664 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14666 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14668 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14669 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14672 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14672 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14673 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14673 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14676 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14676 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14678 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14679 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14680 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14681 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14681 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-15741 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15741 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15742 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16238 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16238 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16241 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18024 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18408 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19385 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6464 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6469 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6470 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6471 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 28 vulnerabilities can now be installed. ## Description: This update for postgresql18 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). * CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). * CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). * CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). * CVE-2026-14676: `pg_stat_statements` heap buffer overflow executes arbitrary code (bsc#1275060). * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). * CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). * CVE-2026-16238: type confusion in `pg_restore_attribute_stats()` executes arbitrary code (bsc#1275052). * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql18: * Update to version 18.6: * https://www.postgresql.org/docs/18/release-18-6.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4015=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4015=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4015=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4015=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4015=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4015=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4015=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4015=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libpq5-debuginfo-18.6-150200.5.17.1 * libecpg6-18.6-150200.5.17.1 * postgresql18-debugsource-18.6-150200.5.17.1 * postgresql18-debuginfo-18.6-150200.5.17.1 * libpq5-18.6-150200.5.17.1 * libecpg6-debuginfo-18.6-150200.5.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libpq5-32bit-debuginfo-18.6-150200.5.17.1 * libpq5-32bit-18.6-150200.5.17.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libpq5-debuginfo-18.6-150200.5.17.1 * libecpg6-18.6-150200.5.17.1 * postgresql18-debugsource-18.6-150200.5.17.1 * postgresql18-debuginfo-18.6-150200.5.17.1 * libpq5-18.6-150200.5.17.1 * libecpg6-debuginfo-18.6-150200.5.17.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libpq5-32bit-debuginfo-18.6-150200.5.17.1 * libpq5-32bit-18.6-150200.5.17.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libecpg6-debuginfo-18.6-150200.5.17.1 * libecpg6-18.6-150200.5.17.1 * postgresql18-debugsource-18.6-150200.5.17.1 * postgresql18-debuginfo-18.6-150200.5.17.1 * libpq5-18.6-150200.5.17.1 * libpq5-debuginfo-18.6-150200.5.17.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libpq5-32bit-debuginfo-18.6-150200.5.17.1 * libpq5-32bit-18.6-150200.5.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libpq5-32bit-debuginfo-18.6-150200.5.17.1 * libpq5-32bit-18.6-150200.5.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libecpg6-debuginfo-18.6-150200.5.17.1 * libecpg6-18.6-150200.5.17.1 * postgresql18-debugsource-18.6-150200.5.17.1 * postgresql18-debuginfo-18.6-150200.5.17.1 * libpq5-18.6-150200.5.17.1 * libpq5-debuginfo-18.6-150200.5.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libecpg6-debuginfo-18.6-150200.5.17.1 * libecpg6-18.6-150200.5.17.1 * postgresql18-debugsource-18.6-150200.5.17.1 * postgresql18-debuginfo-18.6-150200.5.17.1 * libpq5-18.6-150200.5.17.1 * libpq5-debuginfo-18.6-150200.5.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libpq5-32bit-debuginfo-18.6-150200.5.17.1 * libpq5-32bit-18.6-150200.5.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libpq5-debuginfo-18.6-150200.5.17.1 * libecpg6-18.6-150200.5.17.1 * postgresql18-debugsource-18.6-150200.5.17.1 * postgresql18-debuginfo-18.6-150200.5.17.1 * libpq5-18.6-150200.5.17.1 * libecpg6-debuginfo-18.6-150200.5.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libpq5-32bit-debuginfo-18.6-150200.5.17.1 * libpq5-32bit-18.6-150200.5.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libecpg6-debuginfo-18.6-150200.5.17.1 * libecpg6-18.6-150200.5.17.1 * postgresql18-debugsource-18.6-150200.5.17.1 * postgresql18-debuginfo-18.6-150200.5.17.1 * libpq5-18.6-150200.5.17.1 * libpq5-debuginfo-18.6-150200.5.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libpq5-32bit-debuginfo-18.6-150200.5.17.1 * libpq5-32bit-18.6-150200.5.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libpq5-debuginfo-18.6-150200.5.17.1 * libecpg6-18.6-150200.5.17.1 * postgresql18-debugsource-18.6-150200.5.17.1 * postgresql18-debuginfo-18.6-150200.5.17.1 * libpq5-18.6-150200.5.17.1 * libecpg6-debuginfo-18.6-150200.5.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libpq5-32bit-debuginfo-18.6-150200.5.17.1 * libpq5-32bit-18.6-150200.5.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14672.html * https://www.suse.com/security/cve/CVE-2026-14673.html * https://www.suse.com/security/cve/CVE-2026-14676.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-14681.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16238.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html * https://bugzilla.suse.com/show_bug.cgi?id=1275001 * https://bugzilla.suse.com/show_bug.cgi?id=1275002 * https://bugzilla.suse.com/show_bug.cgi?id=1275042 * https://bugzilla.suse.com/show_bug.cgi?id=1275043 * https://bugzilla.suse.com/show_bug.cgi?id=1275044 * https://bugzilla.suse.com/show_bug.cgi?id=1275046 * https://bugzilla.suse.com/show_bug.cgi?id=1275047 * https://bugzilla.suse.com/show_bug.cgi?id=1275048 * https://bugzilla.suse.com/show_bug.cgi?id=1275049 * https://bugzilla.suse.com/show_bug.cgi?id=1275050 * https://bugzilla.suse.com/show_bug.cgi?id=1275051 * https://bugzilla.suse.com/show_bug.cgi?id=1275052 * https://bugzilla.suse.com/show_bug.cgi?id=1275053 * https://bugzilla.suse.com/show_bug.cgi?id=1275054 * https://bugzilla.suse.com/show_bug.cgi?id=1275055 * https://bugzilla.suse.com/show_bug.cgi?id=1275056 * https://bugzilla.suse.com/show_bug.cgi?id=1275057 * https://bugzilla.suse.com/show_bug.cgi?id=1275058 * https://bugzilla.suse.com/show_bug.cgi?id=1275059 * https://bugzilla.suse.com/show_bug.cgi?id=1275060 * https://bugzilla.suse.com/show_bug.cgi?id=1275061 * https://bugzilla.suse.com/show_bug.cgi?id=1275062 * https://bugzilla.suse.com/show_bug.cgi?id=1275063 * https://bugzilla.suse.com/show_bug.cgi?id=1275064 * https://bugzilla.suse.com/show_bug.cgi?id=1275065 * https://bugzilla.suse.com/show_bug.cgi?id=1275066 * https://bugzilla.suse.com/show_bug.cgi?id=1275067 * https://bugzilla.suse.com/show_bug.cgi?id=1275068 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:49:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:49:50 -0000 Subject: SUSE-SU-2026:4014-1: important: Security update for postgresql18 Message-ID: <178878539081.9930.2733116422399787583@6bd16ccd9111> # Security update for postgresql18 Announcement ID: SUSE-SU-2026:4014-1 Release Date: 2026-09-07T07:36:31Z Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275052 * bsc#1275053 * bsc#1275054 * bsc#1275055 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275060 * bsc#1275061 * bsc#1275062 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14672 * CVE-2026-14673 * CVE-2026-14676 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-14681 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16238 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14662 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14664 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14666 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14668 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14669 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14672 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14672 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14673 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14673 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14676 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14676 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14678 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14679 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14680 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14681 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14681 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-15741 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15741 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15742 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16238 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16238 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16241 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18024 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18408 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19385 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6464 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6469 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6470 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6471 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 28 vulnerabilities can now be installed. ## Description: This update for postgresql18 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). * CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). * CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). * CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). * CVE-2026-14676: `pg_stat_statements` heap buffer overflow executes arbitrary code (bsc#1275060). * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). * CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). * CVE-2026-16238: type confusion in `pg_restore_attribute_stats()` executes arbitrary code (bsc#1275052). * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql18: * Update to version 18.6: * https://www.postgresql.org/docs/18/release-18-6.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4014=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4014=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-4014=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4014=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4014=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4014=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * postgresql18-server-devel-debuginfo-18.6-150600.13.16.1 * postgresql18-18.6-150600.13.16.1 * postgresql18-devel-18.6-150600.13.16.1 * postgresql18-llvmjit-18.6-150600.13.16.1 * postgresql18-pltcl-debuginfo-18.6-150600.13.16.1 * postgresql18-devel-debuginfo-18.6-150600.13.16.1 * postgresql18-devel-mini-debuginfo-18.6-150600.13.16.1 * postgresql18-contrib-18.6-150600.13.16.1 * postgresql18-devel-mini-18.6-150600.13.16.1 * postgresql18-debuginfo-18.6-150600.13.16.1 * postgresql18-debugsource-18.6-150600.13.16.1 * libecpg6-18.6-150600.13.16.1 * libecpg6-debuginfo-18.6-150600.13.16.1 * postgresql18-plpython-debuginfo-18.6-150600.13.16.1 * postgresql18-server-debuginfo-18.6-150600.13.16.1 * postgresql18-llvmjit-debuginfo-18.6-150600.13.16.1 * postgresql18-pltcl-18.6-150600.13.16.1 * libpq5-debuginfo-18.6-150600.13.16.1 * postgresql18-contrib-debuginfo-18.6-150600.13.16.1 * postgresql18-test-18.6-150600.13.16.1 * libpq5-18.6-150600.13.16.1 * postgresql18-plperl-debuginfo-18.6-150600.13.16.1 * postgresql18-server-devel-18.6-150600.13.16.1 * postgresql18-mini-debugsource-18.6-150600.13.16.1 * postgresql18-plpython-18.6-150600.13.16.1 * postgresql18-plperl-18.6-150600.13.16.1 * postgresql18-server-18.6-150600.13.16.1 * postgresql18-llvmjit-devel-18.6-150600.13.16.1 * openSUSE Leap 15.6 (noarch) * postgresql18-docs-18.6-150600.13.16.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libpq5-64bit-18.6-150600.13.16.1 * libecpg6-64bit-18.6-150600.13.16.1 * libpq5-64bit-debuginfo-18.6-150600.13.16.1 * libecpg6-64bit-debuginfo-18.6-150600.13.16.1 * openSUSE Leap 15.6 (x86_64) * libpq5-32bit-18.6-150600.13.16.1 * libpq5-32bit-debuginfo-18.6-150600.13.16.1 * libecpg6-32bit-debuginfo-18.6-150600.13.16.1 * libecpg6-32bit-18.6-150600.13.16.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libpq5-debuginfo-18.6-150600.13.16.1 * postgresql18-debugsource-18.6-150600.13.16.1 * postgresql18-18.6-150600.13.16.1 * libpq5-18.6-150600.13.16.1 * postgresql18-debuginfo-18.6-150600.13.16.1 * Basesystem Module 15-SP7 (x86_64) * libpq5-32bit-18.6-150600.13.16.1 * libpq5-32bit-debuginfo-18.6-150600.13.16.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * postgresql18-18.6-150600.13.16.1 * postgresql18-devel-18.6-150600.13.16.1 * postgresql18-devel-debuginfo-18.6-150600.13.16.1 * postgresql18-pltcl-debuginfo-18.6-150600.13.16.1 * postgresql18-contrib-18.6-150600.13.16.1 * postgresql18-debuginfo-18.6-150600.13.16.1 * postgresql18-debugsource-18.6-150600.13.16.1 * libecpg6-18.6-150600.13.16.1 * libecpg6-debuginfo-18.6-150600.13.16.1 * postgresql18-plpython-debuginfo-18.6-150600.13.16.1 * postgresql18-server-debuginfo-18.6-150600.13.16.1 * libpq5-debuginfo-18.6-150600.13.16.1 * postgresql18-pltcl-18.6-150600.13.16.1 * postgresql18-plperl-debuginfo-18.6-150600.13.16.1 * postgresql18-contrib-debuginfo-18.6-150600.13.16.1 * libpq5-18.6-150600.13.16.1 * postgresql18-server-devel-18.6-150600.13.16.1 * postgresql18-plpython-18.6-150600.13.16.1 * postgresql18-plperl-18.6-150600.13.16.1 * postgresql18-server-18.6-150600.13.16.1 * postgresql18-server-devel-debuginfo-18.6-150600.13.16.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * postgresql18-docs-18.6-150600.13.16.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libpq5-32bit-18.6-150600.13.16.1 * libpq5-32bit-debuginfo-18.6-150600.13.16.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * postgresql18-llvmjit-devel-18.6-150600.13.16.1 * postgresql18-llvmjit-18.6-150600.13.16.1 * postgresql18-llvmjit-debuginfo-18.6-150600.13.16.1 * postgresql18-test-18.6-150600.13.16.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * postgresql18-pltcl-18.6-150600.13.16.1 * postgresql18-debugsource-18.6-150600.13.16.1 * postgresql18-server-devel-debuginfo-18.6-150600.13.16.1 * libecpg6-18.6-150600.13.16.1 * libecpg6-debuginfo-18.6-150600.13.16.1 * postgresql18-plpython-debuginfo-18.6-150600.13.16.1 * postgresql18-plperl-debuginfo-18.6-150600.13.16.1 * postgresql18-contrib-debuginfo-18.6-150600.13.16.1 * postgresql18-server-debuginfo-18.6-150600.13.16.1 * postgresql18-debuginfo-18.6-150600.13.16.1 * postgresql18-devel-18.6-150600.13.16.1 * postgresql18-server-devel-18.6-150600.13.16.1 * postgresql18-plpython-18.6-150600.13.16.1 * postgresql18-devel-debuginfo-18.6-150600.13.16.1 * postgresql18-plperl-18.6-150600.13.16.1 * postgresql18-server-18.6-150600.13.16.1 * postgresql18-pltcl-debuginfo-18.6-150600.13.16.1 * postgresql18-contrib-18.6-150600.13.16.1 * Server Applications Module 15-SP7 (noarch) * postgresql18-docs-18.6-150600.13.16.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * postgresql18-18.6-150600.13.16.1 * postgresql18-devel-18.6-150600.13.16.1 * postgresql18-pltcl-debuginfo-18.6-150600.13.16.1 * postgresql18-devel-debuginfo-18.6-150600.13.16.1 * postgresql18-contrib-18.6-150600.13.16.1 * postgresql18-debuginfo-18.6-150600.13.16.1 * postgresql18-debugsource-18.6-150600.13.16.1 * libecpg6-18.6-150600.13.16.1 * libecpg6-debuginfo-18.6-150600.13.16.1 * postgresql18-plpython-debuginfo-18.6-150600.13.16.1 * postgresql18-server-debuginfo-18.6-150600.13.16.1 * libpq5-debuginfo-18.6-150600.13.16.1 * postgresql18-pltcl-18.6-150600.13.16.1 * postgresql18-contrib-debuginfo-18.6-150600.13.16.1 * libpq5-18.6-150600.13.16.1 * postgresql18-plperl-debuginfo-18.6-150600.13.16.1 * postgresql18-server-devel-18.6-150600.13.16.1 * postgresql18-plpython-18.6-150600.13.16.1 * postgresql18-plperl-18.6-150600.13.16.1 * postgresql18-server-18.6-150600.13.16.1 * postgresql18-server-devel-debuginfo-18.6-150600.13.16.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libpq5-32bit-18.6-150600.13.16.1 * libpq5-32bit-debuginfo-18.6-150600.13.16.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * postgresql18-docs-18.6-150600.13.16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14672.html * https://www.suse.com/security/cve/CVE-2026-14673.html * https://www.suse.com/security/cve/CVE-2026-14676.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-14681.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16238.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html * https://bugzilla.suse.com/show_bug.cgi?id=1275001 * https://bugzilla.suse.com/show_bug.cgi?id=1275002 * https://bugzilla.suse.com/show_bug.cgi?id=1275042 * https://bugzilla.suse.com/show_bug.cgi?id=1275043 * https://bugzilla.suse.com/show_bug.cgi?id=1275044 * https://bugzilla.suse.com/show_bug.cgi?id=1275046 * https://bugzilla.suse.com/show_bug.cgi?id=1275047 * https://bugzilla.suse.com/show_bug.cgi?id=1275048 * https://bugzilla.suse.com/show_bug.cgi?id=1275049 * https://bugzilla.suse.com/show_bug.cgi?id=1275050 * https://bugzilla.suse.com/show_bug.cgi?id=1275051 * https://bugzilla.suse.com/show_bug.cgi?id=1275052 * https://bugzilla.suse.com/show_bug.cgi?id=1275053 * https://bugzilla.suse.com/show_bug.cgi?id=1275054 * https://bugzilla.suse.com/show_bug.cgi?id=1275055 * https://bugzilla.suse.com/show_bug.cgi?id=1275056 * https://bugzilla.suse.com/show_bug.cgi?id=1275057 * https://bugzilla.suse.com/show_bug.cgi?id=1275058 * https://bugzilla.suse.com/show_bug.cgi?id=1275059 * https://bugzilla.suse.com/show_bug.cgi?id=1275060 * https://bugzilla.suse.com/show_bug.cgi?id=1275061 * https://bugzilla.suse.com/show_bug.cgi?id=1275062 * https://bugzilla.suse.com/show_bug.cgi?id=1275063 * https://bugzilla.suse.com/show_bug.cgi?id=1275064 * https://bugzilla.suse.com/show_bug.cgi?id=1275065 * https://bugzilla.suse.com/show_bug.cgi?id=1275066 * https://bugzilla.suse.com/show_bug.cgi?id=1275067 * https://bugzilla.suse.com/show_bug.cgi?id=1275068 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:51:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:51:19 -0000 Subject: SUSE-SU-2026:4013-1: important: Security update for postgresql17 Message-ID: <178878547950.9930.10594124365299632975@6bd16ccd9111> # Security update for postgresql17 Announcement ID: SUSE-SU-2026:4013-1 Release Date: 2026-09-07T07:35:51Z Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275053 * bsc#1275054 * bsc#1275055 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275062 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14672 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-14681 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14662 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14664 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14666 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14668 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14669 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14672 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14672 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14678 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14679 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14680 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14681 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14681 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-15741 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15741 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15742 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16241 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18024 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18408 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19385 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6464 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6469 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6470 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6471 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for postgresql17 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). * CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). * CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). * CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql17: * Update to version 17.11: * https://www.postgresql.org/docs/17/release-17-11.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4013=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4013=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4013=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4013=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4013=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4013=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4013=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4013=1 ## Package List: * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * postgresql17-server-devel-17.11-150200.5.33.1 * postgresql17-server-debuginfo-17.11-150200.5.33.1 * postgresql17-plpython-debuginfo-17.11-150200.5.33.1 * postgresql17-plperl-debuginfo-17.11-150200.5.33.1 * postgresql17-pltcl-debuginfo-17.11-150200.5.33.1 * postgresql17-debugsource-17.11-150200.5.33.1 * postgresql17-pltcl-17.11-150200.5.33.1 * postgresql17-server-devel-debuginfo-17.11-150200.5.33.1 * postgresql17-debuginfo-17.11-150200.5.33.1 * postgresql17-plpython-17.11-150200.5.33.1 * postgresql17-server-17.11-150200.5.33.1 * postgresql17-plperl-17.11-150200.5.33.1 * postgresql17-devel-17.11-150200.5.33.1 * postgresql17-contrib-17.11-150200.5.33.1 * postgresql17-17.11-150200.5.33.1 * postgresql17-contrib-debuginfo-17.11-150200.5.33.1 * postgresql17-devel-debuginfo-17.11-150200.5.33.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * postgresql17-docs-17.11-150200.5.33.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * postgresql17-server-devel-17.11-150200.5.33.1 * postgresql17-plpython-debuginfo-17.11-150200.5.33.1 * postgresql17-llvmjit-17.11-150200.5.33.1 * postgresql17-pltcl-debuginfo-17.11-150200.5.33.1 * postgresql17-debugsource-17.11-150200.5.33.1 * postgresql17-server-17.11-150200.5.33.1 * postgresql17-plpython-17.11-150200.5.33.1 * postgresql17-pltcl-17.11-150200.5.33.1 * postgresql17-devel-debuginfo-17.11-150200.5.33.1 * postgresql17-plperl-17.11-150200.5.33.1 * postgresql17-server-debuginfo-17.11-150200.5.33.1 * postgresql17-plperl-debuginfo-17.11-150200.5.33.1 * postgresql17-debuginfo-17.11-150200.5.33.1 * postgresql17-contrib-17.11-150200.5.33.1 * postgresql17-llvmjit-devel-17.11-150200.5.33.1 * postgresql17-devel-17.11-150200.5.33.1 * postgresql17-17.11-150200.5.33.1 * postgresql17-contrib-debuginfo-17.11-150200.5.33.1 * postgresql17-server-devel-debuginfo-17.11-150200.5.33.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * postgresql17-docs-17.11-150200.5.33.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * postgresql17-debugsource-17.11-150200.5.33.1 * postgresql17-debuginfo-17.11-150200.5.33.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * postgresql17-debugsource-17.11-150200.5.33.1 * postgresql17-debuginfo-17.11-150200.5.33.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * postgresql17-server-devel-17.11-150200.5.33.1 * postgresql17-server-debuginfo-17.11-150200.5.33.1 * postgresql17-plpython-debuginfo-17.11-150200.5.33.1 * postgresql17-plperl-debuginfo-17.11-150200.5.33.1 * postgresql17-pltcl-debuginfo-17.11-150200.5.33.1 * postgresql17-debugsource-17.11-150200.5.33.1 * postgresql17-pltcl-17.11-150200.5.33.1 * postgresql17-debuginfo-17.11-150200.5.33.1 * postgresql17-devel-17.11-150200.5.33.1 * postgresql17-devel-debuginfo-17.11-150200.5.33.1 * postgresql17-server-17.11-150200.5.33.1 * postgresql17-plpython-17.11-150200.5.33.1 * postgresql17-contrib-17.11-150200.5.33.1 * postgresql17-17.11-150200.5.33.1 * postgresql17-plperl-17.11-150200.5.33.1 * postgresql17-contrib-debuginfo-17.11-150200.5.33.1 * postgresql17-server-devel-debuginfo-17.11-150200.5.33.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * postgresql17-docs-17.11-150200.5.33.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * postgresql17-server-devel-17.11-150200.5.33.1 * postgresql17-plpython-debuginfo-17.11-150200.5.33.1 * postgresql17-llvmjit-17.11-150200.5.33.1 * postgresql17-pltcl-debuginfo-17.11-150200.5.33.1 * postgresql17-debugsource-17.11-150200.5.33.1 * postgresql17-server-17.11-150200.5.33.1 * postgresql17-plpython-17.11-150200.5.33.1 * postgresql17-pltcl-17.11-150200.5.33.1 * postgresql17-devel-debuginfo-17.11-150200.5.33.1 * postgresql17-plperl-17.11-150200.5.33.1 * postgresql17-server-debuginfo-17.11-150200.5.33.1 * postgresql17-plperl-debuginfo-17.11-150200.5.33.1 * postgresql17-debuginfo-17.11-150200.5.33.1 * postgresql17-contrib-17.11-150200.5.33.1 * postgresql17-llvmjit-devel-17.11-150200.5.33.1 * postgresql17-devel-17.11-150200.5.33.1 * postgresql17-17.11-150200.5.33.1 * postgresql17-contrib-debuginfo-17.11-150200.5.33.1 * postgresql17-server-devel-debuginfo-17.11-150200.5.33.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * postgresql17-docs-17.11-150200.5.33.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * postgresql17-debugsource-17.11-150200.5.33.1 * postgresql17-debuginfo-17.11-150200.5.33.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * postgresql17-debugsource-17.11-150200.5.33.1 * postgresql17-debuginfo-17.11-150200.5.33.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14672.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-14681.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html * https://bugzilla.suse.com/show_bug.cgi?id=1275001 * https://bugzilla.suse.com/show_bug.cgi?id=1275002 * https://bugzilla.suse.com/show_bug.cgi?id=1275042 * https://bugzilla.suse.com/show_bug.cgi?id=1275043 * https://bugzilla.suse.com/show_bug.cgi?id=1275044 * https://bugzilla.suse.com/show_bug.cgi?id=1275046 * https://bugzilla.suse.com/show_bug.cgi?id=1275047 * https://bugzilla.suse.com/show_bug.cgi?id=1275048 * https://bugzilla.suse.com/show_bug.cgi?id=1275049 * https://bugzilla.suse.com/show_bug.cgi?id=1275050 * https://bugzilla.suse.com/show_bug.cgi?id=1275051 * https://bugzilla.suse.com/show_bug.cgi?id=1275053 * https://bugzilla.suse.com/show_bug.cgi?id=1275054 * https://bugzilla.suse.com/show_bug.cgi?id=1275055 * https://bugzilla.suse.com/show_bug.cgi?id=1275056 * https://bugzilla.suse.com/show_bug.cgi?id=1275057 * https://bugzilla.suse.com/show_bug.cgi?id=1275058 * https://bugzilla.suse.com/show_bug.cgi?id=1275059 * https://bugzilla.suse.com/show_bug.cgi?id=1275062 * https://bugzilla.suse.com/show_bug.cgi?id=1275063 * https://bugzilla.suse.com/show_bug.cgi?id=1275064 * https://bugzilla.suse.com/show_bug.cgi?id=1275065 * https://bugzilla.suse.com/show_bug.cgi?id=1275066 * https://bugzilla.suse.com/show_bug.cgi?id=1275067 * https://bugzilla.suse.com/show_bug.cgi?id=1275068 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:52:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:52:01 -0000 Subject: SUSE-SU-2026:4012-1: moderate: Security update for cpio Message-ID: <178878552181.9930.12814247875013795413@6bd16ccd9111> # Security update for cpio Announcement ID: SUSE-SU-2026:4012-1 Release Date: 2026-09-07T07:34:55Z Rating: moderate References: * bsc#1274856 * bsc#1274857 * bsc#1274858 Cross-References: * CVE-2026-66484 * CVE-2026-66485 * CVE-2026-66486 CVSS scores: * CVE-2026-66484 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-66484 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66485 ( SUSE ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-66485 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66486 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-66486 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for cpio fixes the following issues: * CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). * CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). * CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4012=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4012=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4012=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4012=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4012=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4012=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4012=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cpio-mt-2.13-150400.3.10.1 * cpio-2.13-150400.3.10.1 * cpio-debuginfo-2.13-150400.3.10.1 * cpio-debugsource-2.13-150400.3.10.1 * cpio-mt-debuginfo-2.13-150400.3.10.1 * Basesystem Module 15-SP7 (noarch) * cpio-lang-2.13-150400.3.10.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * cpio-debugsource-2.13-150400.3.10.1 * cpio-2.13-150400.3.10.1 * cpio-debuginfo-2.13-150400.3.10.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * cpio-debugsource-2.13-150400.3.10.1 * cpio-2.13-150400.3.10.1 * cpio-debuginfo-2.13-150400.3.10.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * cpio-mt-2.13-150400.3.10.1 * cpio-2.13-150400.3.10.1 * cpio-debuginfo-2.13-150400.3.10.1 * cpio-debugsource-2.13-150400.3.10.1 * cpio-mt-debuginfo-2.13-150400.3.10.1 * openSUSE Leap 15.4 (noarch) * cpio-lang-2.13-150400.3.10.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * cpio-debugsource-2.13-150400.3.10.1 * cpio-2.13-150400.3.10.1 * cpio-debuginfo-2.13-150400.3.10.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * cpio-debugsource-2.13-150400.3.10.1 * cpio-2.13-150400.3.10.1 * cpio-debuginfo-2.13-150400.3.10.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * cpio-debugsource-2.13-150400.3.10.1 * cpio-2.13-150400.3.10.1 * cpio-debuginfo-2.13-150400.3.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-66484.html * https://www.suse.com/security/cve/CVE-2026-66485.html * https://www.suse.com/security/cve/CVE-2026-66486.html * https://bugzilla.suse.com/show_bug.cgi?id=1274856 * https://bugzilla.suse.com/show_bug.cgi?id=1274857 * https://bugzilla.suse.com/show_bug.cgi?id=1274858 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:52:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:52:57 -0000 Subject: SUSE-SU-2026:4011-1: moderate: Security update for libsoup Message-ID: <178878557752.9930.2136962547684421775@6bd16ccd9111> # Security update for libsoup Announcement ID: SUSE-SU-2026:4011-1 Release Date: 2026-09-07T07:34:18Z Rating: moderate References: * bsc#1272196 Cross-References: * CVE-2026-12548 CVSS scores: * CVE-2026-12548 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12548 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12548 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for libsoup fixes the following issue: * CVE-2026-12548: out-of-bounds read in multipart body parser due to an integer truncation (bsc#1272196). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4011=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libsoup-debugsource-3.0.4-150400.3.46.1 * typelib-1_0-Soup-3_0-3.0.4-150400.3.46.1 * libsoup-devel-3.0.4-150400.3.46.1 * libsoup-3_0-0-3.0.4-150400.3.46.1 * libsoup-3_0-0-debuginfo-3.0.4-150400.3.46.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libsoup-devel-64bit-3.0.4-150400.3.46.1 * libsoup-3_0-0-64bit-debuginfo-3.0.4-150400.3.46.1 * libsoup-3_0-0-64bit-3.0.4-150400.3.46.1 * openSUSE Leap 15.4 (x86_64) * libsoup-3_0-0-32bit-debuginfo-3.0.4-150400.3.46.1 * libsoup-3_0-0-32bit-3.0.4-150400.3.46.1 * libsoup-devel-32bit-3.0.4-150400.3.46.1 * openSUSE Leap 15.4 (noarch) * libsoup-lang-3.0.4-150400.3.46.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12548.html * https://bugzilla.suse.com/show_bug.cgi?id=1272196 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:53:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:53:58 -0000 Subject: SUSE-SU-2026:4010-1: important: Security update for libvirt Message-ID: <178878563853.9930.208357583599152220@6bd16ccd9111> # Security update for libvirt Announcement ID: SUSE-SU-2026:4010-1 Release Date: 2026-09-07T07:34:04Z Rating: important References: * bsc#1274576 * bsc#1274946 * bsc#1275264 * bsc#1275265 * bsc#1275863 Cross-References: * CVE-2026-18917 * CVE-2026-61477 * CVE-2026-63622 * CVE-2026-63623 * CVE-2026-77159 CVSS scores: * CVE-2026-18917 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-18917 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-61477 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-61477 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61477 ( NVD ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-63622 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63622 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63622 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63623 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-63623 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-63623 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-77159 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-77159 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves five vulnerabilities can now be installed. ## Description: This update for libvirt fixes the following issues: * CVE-2026-18917: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow (bsc#1275863). * CVE-2026-61477: newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection (bsc#1274576). * CVE-2026-63622: `swtpm` privilege escalation via symlink following (bsc#1275264). * CVE-2026-63623: information disclosure via world-readable storage volume images during clone/convert (bsc#1275265). * CVE-2026-77159: root `chown()` on `swtpm` logfile follows symlinks (bsc#1274946). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4010=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4010=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4010=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libvirt-daemon-log-10.0.0-150600.8.18.1 * libvirt-daemon-driver-network-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-core-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-core-10.0.0-150600.8.18.1 * libvirt-daemon-plugin-sanlock-10.0.0-150600.8.18.1 * libvirt-daemon-config-nwfilter-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-iscsi-10.0.0-150600.8.18.1 * libvirt-daemon-proxy-debuginfo-10.0.0-150600.8.18.1 * libvirt-libs-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-network-debuginfo-10.0.0-150600.8.18.1 * libvirt-libs-10.0.0-150600.8.18.1 * libvirt-daemon-plugin-lockd-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-logical-10.0.0-150600.8.18.1 * libvirt-daemon-log-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-nwfilter-debuginfo-10.0.0-150600.8.18.1 * wireshark-plugin-libvirt-10.0.0-150600.8.18.1 * libvirt-daemon-qemu-10.0.0-150600.8.18.1 * libvirt-daemon-driver-lxc-10.0.0-150600.8.18.1 * libvirt-daemon-hooks-10.0.0-150600.8.18.1 * libvirt-daemon-driver-lxc-debuginfo-10.0.0-150600.8.18.1 * libvirt-nss-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-secret-debuginfo-10.0.0-150600.8.18.1 * libvirt-client-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-iscsi-direct-10.0.0-150600.8.18.1 * libvirt-daemon-driver-nodedev-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-gluster-debuginfo-10.0.0-150600.8.18.1 * libvirt-debugsource-10.0.0-150600.8.18.1 * libvirt-daemon-config-network-10.0.0-150600.8.18.1 * libvirt-daemon-proxy-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-logical-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-interface-debuginfo-10.0.0-150600.8.18.1 * libvirt-10.0.0-150600.8.18.1 * libvirt-daemon-common-10.0.0-150600.8.18.1 * libvirt-daemon-driver-nodedev-debuginfo-10.0.0-150600.8.18.1 * libvirt-client-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-disk-10.0.0-150600.8.18.1 * libvirt-daemon-driver-interface-10.0.0-150600.8.18.1 * libvirt-daemon-driver-qemu-10.0.0-150600.8.18.1 * libvirt-devel-10.0.0-150600.8.18.1 * libvirt-daemon-driver-secret-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-mpath-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-lock-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-common-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-scsi-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-scsi-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-qemu-debuginfo-10.0.0-150600.8.18.1 * wireshark-plugin-libvirt-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-plugin-sanlock-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-nwfilter-10.0.0-150600.8.18.1 * libvirt-daemon-lock-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-10.0.0-150600.8.18.1 * libvirt-daemon-lxc-10.0.0-150600.8.18.1 * libvirt-nss-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-mpath-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-gluster-10.0.0-150600.8.18.1 * libvirt-daemon-plugin-lockd-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-disk-debuginfo-10.0.0-150600.8.18.1 * libvirt-client-qemu-10.0.0-150600.8.18.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libvirt-devel-64bit-10.0.0-150600.8.18.1 * libvirt-client-64bit-debuginfo-10.0.0-150600.8.18.1 * openSUSE Leap 15.6 (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-rbd-10.0.0-150600.8.18.1 * openSUSE Leap 15.6 (x86_64) * libvirt-devel-32bit-10.0.0-150600.8.18.1 * libvirt-daemon-driver-libxl-10.0.0-150600.8.18.1 * libvirt-client-32bit-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-xen-10.0.0-150600.8.18.1 * libvirt-daemon-driver-libxl-debuginfo-10.0.0-150600.8.18.1 * openSUSE Leap 15.6 (noarch) * libvirt-doc-10.0.0-150600.8.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libvirt-daemon-log-10.0.0-150600.8.18.1 * libvirt-daemon-driver-network-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-core-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-core-10.0.0-150600.8.18.1 * libvirt-daemon-plugin-sanlock-10.0.0-150600.8.18.1 * libvirt-daemon-config-nwfilter-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-iscsi-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-disk-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-proxy-debuginfo-10.0.0-150600.8.18.1 * libvirt-libs-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-network-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-plugin-lockd-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-log-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-logical-10.0.0-150600.8.18.1 * libvirt-daemon-driver-nwfilter-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-qemu-10.0.0-150600.8.18.1 * libvirt-nss-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-hooks-10.0.0-150600.8.18.1 * libvirt-daemon-driver-secret-debuginfo-10.0.0-150600.8.18.1 * libvirt-client-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-nodedev-10.0.0-150600.8.18.1 * libvirt-daemon-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-iscsi-direct-10.0.0-150600.8.18.1 * libvirt-debugsource-10.0.0-150600.8.18.1 * libvirt-daemon-config-network-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-logical-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-proxy-10.0.0-150600.8.18.1 * libvirt-10.0.0-150600.8.18.1 * libvirt-daemon-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-common-10.0.0-150600.8.18.1 * libvirt-daemon-driver-nodedev-debuginfo-10.0.0-150600.8.18.1 * libvirt-client-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-disk-10.0.0-150600.8.18.1 * libvirt-daemon-driver-interface-10.0.0-150600.8.18.1 * libvirt-daemon-driver-secret-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-mpath-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-qemu-10.0.0-150600.8.18.1 * libvirt-daemon-lock-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-common-debuginfo-10.0.0-150600.8.18.1 * libvirt-devel-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-scsi-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-scsi-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-qemu-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-plugin-sanlock-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-nwfilter-10.0.0-150600.8.18.1 * libvirt-daemon-lock-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-10.0.0-150600.8.18.1 * libvirt-nss-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-mpath-10.0.0-150600.8.18.1 * libvirt-daemon-driver-interface-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-plugin-lockd-10.0.0-150600.8.18.1 * libvirt-libs-10.0.0-150600.8.18.1 * libvirt-client-qemu-10.0.0-150600.8.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libvirt-daemon-xen-10.0.0-150600.8.18.1 * libvirt-daemon-driver-libxl-10.0.0-150600.8.18.1 * libvirt-daemon-driver-libxl-debuginfo-10.0.0-150600.8.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * libvirt-doc-10.0.0-150600.8.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-rbd-10.0.0-150600.8.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libvirt-daemon-log-10.0.0-150600.8.18.1 * libvirt-daemon-driver-network-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-core-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-plugin-sanlock-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-core-10.0.0-150600.8.18.1 * libvirt-daemon-config-nwfilter-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-iscsi-10.0.0-150600.8.18.1 * libvirt-daemon-proxy-debuginfo-10.0.0-150600.8.18.1 * libvirt-libs-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-network-debuginfo-10.0.0-150600.8.18.1 * libvirt-libs-10.0.0-150600.8.18.1 * libvirt-daemon-plugin-lockd-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-log-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-logical-10.0.0-150600.8.18.1 * libvirt-daemon-driver-nwfilter-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-qemu-10.0.0-150600.8.18.1 * libvirt-daemon-hooks-10.0.0-150600.8.18.1 * libvirt-nss-debuginfo-10.0.0-150600.8.18.1 * libvirt-client-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-secret-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-10.0.0-150600.8.18.1 * libvirt-daemon-driver-nodedev-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-iscsi-direct-10.0.0-150600.8.18.1 * libvirt-debugsource-10.0.0-150600.8.18.1 * libvirt-daemon-config-network-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-logical-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-proxy-10.0.0-150600.8.18.1 * libvirt-10.0.0-150600.8.18.1 * libvirt-daemon-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-common-10.0.0-150600.8.18.1 * libvirt-daemon-driver-nodedev-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-disk-10.0.0-150600.8.18.1 * libvirt-client-10.0.0-150600.8.18.1 * libvirt-daemon-driver-interface-10.0.0-150600.8.18.1 * libvirt-daemon-driver-qemu-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-mpath-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-secret-10.0.0-150600.8.18.1 * libvirt-devel-10.0.0-150600.8.18.1 * libvirt-daemon-common-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-lock-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-scsi-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-scsi-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-qemu-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-plugin-sanlock-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-nwfilter-10.0.0-150600.8.18.1 * libvirt-daemon-lock-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-10.0.0-150600.8.18.1 * libvirt-nss-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-mpath-10.0.0-150600.8.18.1 * libvirt-daemon-driver-interface-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-plugin-lockd-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-disk-debuginfo-10.0.0-150600.8.18.1 * libvirt-client-qemu-10.0.0-150600.8.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libvirt-daemon-driver-storage-rbd-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-libxl-10.0.0-150600.8.18.1 * libvirt-daemon-xen-10.0.0-150600.8.18.1 * libvirt-daemon-driver-libxl-debuginfo-10.0.0-150600.8.18.1 * libvirt-daemon-driver-storage-rbd-10.0.0-150600.8.18.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * libvirt-doc-10.0.0-150600.8.18.1 ## References: * https://www.suse.com/security/cve/CVE-2026-18917.html * https://www.suse.com/security/cve/CVE-2026-61477.html * https://www.suse.com/security/cve/CVE-2026-63622.html * https://www.suse.com/security/cve/CVE-2026-63623.html * https://www.suse.com/security/cve/CVE-2026-77159.html * https://bugzilla.suse.com/show_bug.cgi?id=1274576 * https://bugzilla.suse.com/show_bug.cgi?id=1274946 * https://bugzilla.suse.com/show_bug.cgi?id=1275264 * https://bugzilla.suse.com/show_bug.cgi?id=1275265 * https://bugzilla.suse.com/show_bug.cgi?id=1275863 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:54:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:54:59 -0000 Subject: SUSE-SU-2026:4009-1: important: Security update for libvirt Message-ID: <178878569997.9930.17314248055182840535@6bd16ccd9111> # Security update for libvirt Announcement ID: SUSE-SU-2026:4009-1 Release Date: 2026-09-07T07:33:48Z Rating: important References: * bsc#1274576 * bsc#1274946 * bsc#1275264 * bsc#1275265 * bsc#1275863 Cross-References: * CVE-2026-18917 * CVE-2026-61477 * CVE-2026-63622 * CVE-2026-63623 * CVE-2026-77159 CVSS scores: * CVE-2026-18917 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-18917 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-61477 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-61477 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61477 ( NVD ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-63622 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63622 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63622 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63623 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-63623 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-63623 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-77159 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-77159 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves five vulnerabilities can now be installed. ## Description: This update for libvirt fixes the following issues: * CVE-2026-18917: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow (bsc#1275863). * CVE-2026-61477: newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection (bsc#1274576). * CVE-2026-63622: `swtpm` privilege escalation via symlink following (bsc#1275264). * CVE-2026-63623: information disclosure via world-readable storage volume images during clone/convert (bsc#1275265). * CVE-2026-77159: root `chown()` on `swtpm` logfile follows symlinks (bsc#1274946). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4009=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4009=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-4009=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4009=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4009=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4009=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libvirt-daemon-driver-storage-iscsi-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-hooks-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-core-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-mpath-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nodedev-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nwfilter-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-mpath-9.0.0-150500.6.29.1 * libvirt-client-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-scsi-debuginfo-9.0.0-150500.6.29.1 * libvirt-debugsource-9.0.0-150500.6.29.1 * libvirt-daemon-driver-qemu-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-disk-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-9.0.0-150500.6.29.1 * libvirt-lock-sanlock-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-disk-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-core-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-secret-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-direct-9.0.0-150500.6.29.1 * libvirt-daemon-config-network-9.0.0-150500.6.29.1 * libvirt-daemon-driver-secret-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-9.0.0-150500.6.29.1 * libvirt-daemon-driver-interface-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-interface-9.0.0-150500.6.29.1 * libvirt-client-qemu-9.0.0-150500.6.29.1 * libvirt-daemon-config-nwfilter-9.0.0-150500.6.29.1 * libvirt-nss-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-qemu-9.0.0-150500.6.29.1 * libvirt-devel-9.0.0-150500.6.29.1 * libvirt-client-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nwfilter-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-qemu-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-scsi-9.0.0-150500.6.29.1 * libvirt-daemon-driver-network-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-logical-debuginfo-9.0.0-150500.6.29.1 * libvirt-nss-9.0.0-150500.6.29.1 * libvirt-lock-sanlock-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-logical-9.0.0-150500.6.29.1 * libvirt-daemon-driver-network-9.0.0-150500.6.29.1 * libvirt-libs-9.0.0-150500.6.29.1 * libvirt-9.0.0-150500.6.29.1 * libvirt-libs-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nodedev-9.0.0-150500.6.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * libvirt-doc-9.0.0-150500.6.29.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libvirt-daemon-xen-9.0.0-150500.6.29.1 * libvirt-daemon-driver-libxl-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-libxl-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-rbd-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-rbd-9.0.0-150500.6.29.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libvirt-daemon-driver-storage-iscsi-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-hooks-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-core-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-mpath-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nodedev-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nwfilter-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-mpath-9.0.0-150500.6.29.1 * libvirt-client-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-scsi-debuginfo-9.0.0-150500.6.29.1 * libvirt-debugsource-9.0.0-150500.6.29.1 * libvirt-daemon-driver-qemu-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-disk-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-debuginfo-9.0.0-150500.6.29.1 * libvirt-lock-sanlock-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-disk-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-direct-9.0.0-150500.6.29.1 * libvirt-daemon-driver-secret-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-core-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-config-network-9.0.0-150500.6.29.1 * libvirt-daemon-driver-secret-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-9.0.0-150500.6.29.1 * libvirt-daemon-driver-interface-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-interface-9.0.0-150500.6.29.1 * libvirt-client-qemu-9.0.0-150500.6.29.1 * libvirt-daemon-config-nwfilter-9.0.0-150500.6.29.1 * libvirt-nss-debuginfo-9.0.0-150500.6.29.1 * libvirt-devel-9.0.0-150500.6.29.1 * libvirt-daemon-qemu-9.0.0-150500.6.29.1 * libvirt-client-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nwfilter-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-qemu-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-scsi-9.0.0-150500.6.29.1 * libvirt-daemon-driver-network-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-logical-debuginfo-9.0.0-150500.6.29.1 * libvirt-nss-9.0.0-150500.6.29.1 * libvirt-lock-sanlock-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-logical-9.0.0-150500.6.29.1 * libvirt-daemon-driver-network-9.0.0-150500.6.29.1 * libvirt-libs-9.0.0-150500.6.29.1 * libvirt-9.0.0-150500.6.29.1 * libvirt-libs-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nodedev-9.0.0-150500.6.29.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * libvirt-doc-9.0.0-150500.6.29.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-rbd-debuginfo-9.0.0-150500.6.29.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libvirt-daemon-xen-9.0.0-150500.6.29.1 * libvirt-daemon-driver-libxl-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-libxl-9.0.0-150500.6.29.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * libvirt-daemon-driver-storage-iscsi-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-hooks-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-core-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-mpath-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nodedev-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nwfilter-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-mpath-9.0.0-150500.6.29.1 * libvirt-client-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-scsi-debuginfo-9.0.0-150500.6.29.1 * libvirt-debugsource-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-gluster-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-qemu-9.0.0-150500.6.29.1 * wireshark-plugin-libvirt-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-disk-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-debuginfo-9.0.0-150500.6.29.1 * libvirt-lock-sanlock-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-disk-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-core-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-direct-9.0.0-150500.6.29.1 * libvirt-daemon-driver-secret-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-config-network-9.0.0-150500.6.29.1 * libvirt-daemon-driver-secret-9.0.0-150500.6.29.1 * wireshark-plugin-libvirt-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-9.0.0-150500.6.29.1 * libvirt-daemon-driver-interface-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-interface-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-gluster-9.0.0-150500.6.29.1 * libvirt-client-qemu-9.0.0-150500.6.29.1 * libvirt-daemon-config-nwfilter-9.0.0-150500.6.29.1 * libvirt-nss-debuginfo-9.0.0-150500.6.29.1 * libvirt-devel-9.0.0-150500.6.29.1 * libvirt-daemon-qemu-9.0.0-150500.6.29.1 * libvirt-client-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nwfilter-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-qemu-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-scsi-9.0.0-150500.6.29.1 * libvirt-daemon-driver-network-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-lxc-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-logical-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-lxc-9.0.0-150500.6.29.1 * libvirt-nss-9.0.0-150500.6.29.1 * libvirt-lock-sanlock-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-logical-9.0.0-150500.6.29.1 * libvirt-daemon-driver-network-9.0.0-150500.6.29.1 * libvirt-libs-9.0.0-150500.6.29.1 * libvirt-9.0.0-150500.6.29.1 * libvirt-libs-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-lxc-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nodedev-9.0.0-150500.6.29.1 * openSUSE Leap 15.5 (x86_64) * libvirt-daemon-driver-libxl-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-xen-9.0.0-150500.6.29.1 * libvirt-daemon-driver-libxl-9.0.0-150500.6.29.1 * libvirt-client-32bit-debuginfo-9.0.0-150500.6.29.1 * libvirt-devel-32bit-9.0.0-150500.6.29.1 * openSUSE Leap 15.5 (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-rbd-debuginfo-9.0.0-150500.6.29.1 * openSUSE Leap 15.5 (noarch) * libvirt-doc-9.0.0-150500.6.29.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libvirt-client-64bit-debuginfo-9.0.0-150500.6.29.1 * libvirt-devel-64bit-9.0.0-150500.6.29.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libvirt-daemon-driver-storage-iscsi-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-hooks-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-core-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-mpath-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nodedev-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nwfilter-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-mpath-9.0.0-150500.6.29.1 * libvirt-client-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-scsi-debuginfo-9.0.0-150500.6.29.1 * libvirt-debugsource-9.0.0-150500.6.29.1 * libvirt-daemon-driver-qemu-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-rbd-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-disk-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-9.0.0-150500.6.29.1 * libvirt-lock-sanlock-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-disk-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-direct-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-core-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-secret-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-rbd-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-9.0.0-150500.6.29.1 * libvirt-daemon-config-network-9.0.0-150500.6.29.1 * libvirt-daemon-driver-secret-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-9.0.0-150500.6.29.1 * libvirt-daemon-driver-interface-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-interface-9.0.0-150500.6.29.1 * libvirt-client-qemu-9.0.0-150500.6.29.1 * libvirt-daemon-config-nwfilter-9.0.0-150500.6.29.1 * libvirt-nss-debuginfo-9.0.0-150500.6.29.1 * libvirt-devel-9.0.0-150500.6.29.1 * libvirt-daemon-qemu-9.0.0-150500.6.29.1 * libvirt-client-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nwfilter-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-qemu-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-scsi-9.0.0-150500.6.29.1 * libvirt-daemon-driver-network-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-logical-debuginfo-9.0.0-150500.6.29.1 * libvirt-nss-9.0.0-150500.6.29.1 * libvirt-lock-sanlock-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-logical-9.0.0-150500.6.29.1 * libvirt-daemon-driver-network-9.0.0-150500.6.29.1 * libvirt-libs-9.0.0-150500.6.29.1 * libvirt-9.0.0-150500.6.29.1 * libvirt-libs-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nodedev-9.0.0-150500.6.29.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libvirt-daemon-xen-9.0.0-150500.6.29.1 * libvirt-daemon-driver-libxl-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-libxl-9.0.0-150500.6.29.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * libvirt-doc-9.0.0-150500.6.29.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libvirt-daemon-driver-storage-iscsi-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-hooks-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-core-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-mpath-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nodedev-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nwfilter-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-mpath-9.0.0-150500.6.29.1 * libvirt-client-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-scsi-debuginfo-9.0.0-150500.6.29.1 * libvirt-debugsource-9.0.0-150500.6.29.1 * libvirt-daemon-driver-qemu-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-rbd-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-disk-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-9.0.0-150500.6.29.1 * libvirt-lock-sanlock-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-rbd-9.0.0-150500.6.29.1 * libvirt-daemon-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-direct-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-core-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-secret-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-disk-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-config-network-9.0.0-150500.6.29.1 * libvirt-daemon-driver-secret-9.0.0-150500.6.29.1 * libvirt-daemon-driver-interface-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-9.0.0-150500.6.29.1 * libvirt-daemon-driver-interface-9.0.0-150500.6.29.1 * libvirt-client-qemu-9.0.0-150500.6.29.1 * libvirt-daemon-config-nwfilter-9.0.0-150500.6.29.1 * libvirt-nss-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-qemu-9.0.0-150500.6.29.1 * libvirt-devel-9.0.0-150500.6.29.1 * libvirt-client-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nwfilter-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-qemu-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-scsi-9.0.0-150500.6.29.1 * libvirt-daemon-driver-network-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-logical-debuginfo-9.0.0-150500.6.29.1 * libvirt-nss-9.0.0-150500.6.29.1 * libvirt-lock-sanlock-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-logical-9.0.0-150500.6.29.1 * libvirt-daemon-driver-network-9.0.0-150500.6.29.1 * libvirt-libs-9.0.0-150500.6.29.1 * libvirt-9.0.0-150500.6.29.1 * libvirt-libs-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nodedev-9.0.0-150500.6.29.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * libvirt-doc-9.0.0-150500.6.29.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libvirt-daemon-driver-libxl-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-libxl-9.0.0-150500.6.29.1 * libvirt-daemon-xen-9.0.0-150500.6.29.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libvirt-daemon-driver-storage-iscsi-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-core-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-mpath-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nodedev-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nwfilter-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-mpath-9.0.0-150500.6.29.1 * libvirt-client-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-scsi-debuginfo-9.0.0-150500.6.29.1 * libvirt-debugsource-9.0.0-150500.6.29.1 * libvirt-daemon-driver-qemu-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-disk-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-disk-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-iscsi-direct-9.0.0-150500.6.29.1 * libvirt-daemon-driver-secret-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-core-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-secret-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-9.0.0-150500.6.29.1 * libvirt-daemon-driver-interface-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-interface-9.0.0-150500.6.29.1 * libvirt-daemon-qemu-9.0.0-150500.6.29.1 * libvirt-client-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nwfilter-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-qemu-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-scsi-9.0.0-150500.6.29.1 * libvirt-daemon-driver-network-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-logical-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-logical-9.0.0-150500.6.29.1 * libvirt-daemon-driver-network-9.0.0-150500.6.29.1 * libvirt-libs-9.0.0-150500.6.29.1 * libvirt-libs-debuginfo-9.0.0-150500.6.29.1 * libvirt-daemon-driver-nodedev-9.0.0-150500.6.29.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-9.0.0-150500.6.29.1 * libvirt-daemon-driver-storage-rbd-debuginfo-9.0.0-150500.6.29.1 ## References: * https://www.suse.com/security/cve/CVE-2026-18917.html * https://www.suse.com/security/cve/CVE-2026-61477.html * https://www.suse.com/security/cve/CVE-2026-63622.html * https://www.suse.com/security/cve/CVE-2026-63623.html * https://www.suse.com/security/cve/CVE-2026-77159.html * https://bugzilla.suse.com/show_bug.cgi?id=1274576 * https://bugzilla.suse.com/show_bug.cgi?id=1274946 * https://bugzilla.suse.com/show_bug.cgi?id=1275264 * https://bugzilla.suse.com/show_bug.cgi?id=1275265 * https://bugzilla.suse.com/show_bug.cgi?id=1275863 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:55:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:55:55 -0000 Subject: SUSE-SU-2026:4008-1: moderate: Security update for file-roller Message-ID: <178878575587.9930.16945555504433626959@6bd16ccd9111> # Security update for file-roller Announcement ID: SUSE-SU-2026:4008-1 Release Date: 2026-09-07T07:33:07Z Rating: moderate References: * bsc#1276442 Cross-References: * CVE-2026-78322 CVSS scores: * CVE-2026-78322 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-78322 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for file-roller fixes the following issue: * CVE-2026-78322: stack buffer overflow in parse_progress_line for 7z and RAR handlers (bsc#1276442). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4008=1 ## Package List: * openSUSE Leap 15.4 (noarch) * file-roller-lang-3.40.0-150400.5.3.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * nautilus-file-roller-3.40.0-150400.5.3.1 * file-roller-debugsource-3.40.0-150400.5.3.1 * nautilus-file-roller-debuginfo-3.40.0-150400.5.3.1 * file-roller-debuginfo-3.40.0-150400.5.3.1 * file-roller-3.40.0-150400.5.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-78322.html * https://bugzilla.suse.com/show_bug.cgi?id=1276442 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:56:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:56:51 -0000 Subject: SUSE-SU-2026:4007-1: moderate: Security update for file-roller Message-ID: <178878581164.9930.11102483193737736807@6bd16ccd9111> # Security update for file-roller Announcement ID: SUSE-SU-2026:4007-1 Release Date: 2026-09-07T07:32:50Z Rating: moderate References: * bsc#1276442 Cross-References: * CVE-2026-78322 CVSS scores: * CVE-2026-78322 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-78322 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for file-roller fixes the following issue: * CVE-2026-78322: stack buffer overflow in parse_progress_line for 7z and RAR handlers (bsc#1276442). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4007=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4007=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * file-roller-debugsource-43.1-150600.3.3.1 * nautilus-file-roller-43.1-150600.3.3.1 * nautilus-file-roller-debuginfo-43.1-150600.3.3.1 * file-roller-debuginfo-43.1-150600.3.3.1 * file-roller-43.1-150600.3.3.1 * openSUSE Leap 15.6 (noarch) * file-roller-lang-43.1-150600.3.3.1 * Desktop Applications Module 15-SP7 (noarch) * file-roller-lang-43.1-150600.3.3.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * file-roller-43.1-150600.3.3.1 * file-roller-debuginfo-43.1-150600.3.3.1 * file-roller-debugsource-43.1-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-78322.html * https://bugzilla.suse.com/show_bug.cgi?id=1276442 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:57:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:57:53 -0000 Subject: SUSE-SU-2026:4006-1: moderate: Security update for java-21-openjdk Message-ID: <178878587342.9930.1513116084795731032@6bd16ccd9111> # Security update for java-21-openjdk Announcement ID: SUSE-SU-2026:4006-1 Release Date: 2026-09-07T07:32:31Z Rating: moderate References: * bsc#1221224 * bsc#1275035 * bsc#1275764 * bsc#1275777 * bsc#1275778 Cross-References: * CVE-2026-60589 * CVE-2026-61308 * CVE-2026-70907 CVSS scores: * CVE-2026-60589 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-60589 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61308 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-61308 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-70907 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-70907 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities and has two security fixes can now be installed. ## Description: This update for java-21-openjdk fixes the following issues: Security issues fixed: * CVE-2026-60589: OpenJDK: Improve Resource Resolving (bsc#1275777). * CVE-2026-61308: OpenJDK: Enhance HTTP Connections (bsc#1275778). * CVE-2026-70907: OpenJDK: Enhance TLS server (bsc#1275764). Non security issue fixed: * java-21-openjdk classlist depends on the CPU count of the build machine (bsc#1221224). Changes for java-21-openjdk: * Update to jdk-21.0.12.1+1 (August 2026 CSPU) * backport upcoming upgrade of timezone data (bsc#1275035) * Explicitly use G1 if the JVM supports it. GC ergonomics pick SerialGC on single-CPU machines. SerialGC does not support dumping of the shared heap, thus the classlist is different on a single-CPU builder. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4006=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4006=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4006=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4006=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * java-21-openjdk-devel-21.0.12.1-150600.3.32.1 * java-21-openjdk-devel-debuginfo-21.0.12.1-150600.3.32.1 * java-21-openjdk-demo-21.0.12.1-150600.3.32.1 * java-21-openjdk-21.0.12.1-150600.3.32.1 * java-21-openjdk-debuginfo-21.0.12.1-150600.3.32.1 * java-21-openjdk-headless-debuginfo-21.0.12.1-150600.3.32.1 * java-21-openjdk-debugsource-21.0.12.1-150600.3.32.1 * java-21-openjdk-headless-21.0.12.1-150600.3.32.1 * openSUSE Leap 15.6 (noarch) * java-21-openjdk-javadoc-21.0.12.1-150600.3.32.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * java-21-openjdk-src-21.0.12.1-150600.3.32.1 * java-21-openjdk-devel-21.0.12.1-150600.3.32.1 * java-21-openjdk-devel-debuginfo-21.0.12.1-150600.3.32.1 * java-21-openjdk-demo-21.0.12.1-150600.3.32.1 * java-21-openjdk-21.0.12.1-150600.3.32.1 * java-21-openjdk-debuginfo-21.0.12.1-150600.3.32.1 * java-21-openjdk-jmods-21.0.12.1-150600.3.32.1 * java-21-openjdk-headless-debuginfo-21.0.12.1-150600.3.32.1 * java-21-openjdk-debugsource-21.0.12.1-150600.3.32.1 * java-21-openjdk-headless-21.0.12.1-150600.3.32.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * java-21-openjdk-devel-21.0.12.1-150600.3.32.1 * java-21-openjdk-devel-debuginfo-21.0.12.1-150600.3.32.1 * java-21-openjdk-demo-21.0.12.1-150600.3.32.1 * java-21-openjdk-21.0.12.1-150600.3.32.1 * java-21-openjdk-debuginfo-21.0.12.1-150600.3.32.1 * java-21-openjdk-headless-debuginfo-21.0.12.1-150600.3.32.1 * java-21-openjdk-debugsource-21.0.12.1-150600.3.32.1 * java-21-openjdk-headless-21.0.12.1-150600.3.32.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-21-openjdk-devel-21.0.12.1-150600.3.32.1 * java-21-openjdk-devel-debuginfo-21.0.12.1-150600.3.32.1 * java-21-openjdk-demo-21.0.12.1-150600.3.32.1 * java-21-openjdk-21.0.12.1-150600.3.32.1 * java-21-openjdk-debuginfo-21.0.12.1-150600.3.32.1 * java-21-openjdk-headless-debuginfo-21.0.12.1-150600.3.32.1 * java-21-openjdk-debugsource-21.0.12.1-150600.3.32.1 * java-21-openjdk-headless-21.0.12.1-150600.3.32.1 ## References: * https://www.suse.com/security/cve/CVE-2026-60589.html * https://www.suse.com/security/cve/CVE-2026-61308.html * https://www.suse.com/security/cve/CVE-2026-70907.html * https://bugzilla.suse.com/show_bug.cgi?id=1221224 * https://bugzilla.suse.com/show_bug.cgi?id=1275035 * https://bugzilla.suse.com/show_bug.cgi?id=1275764 * https://bugzilla.suse.com/show_bug.cgi?id=1275777 * https://bugzilla.suse.com/show_bug.cgi?id=1275778 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:58:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:58:51 -0000 Subject: SUSE-SU-2026:4005-1: important: Security update for openexr Message-ID: <178878593172.9930.7087552189853868967@6bd16ccd9111> # Security update for openexr Announcement ID: SUSE-SU-2026:4005-1 Release Date: 2026-09-07T07:31:53Z Rating: important References: * bsc#1276848 * bsc#1276850 * bsc#1276859 Cross-References: * CVE-2026-59186 * CVE-2026-61555 * CVE-2026-68515 CVSS scores: * CVE-2026-59186 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-59186 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-61555 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-61555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-68515 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-68515 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for openexr fixes the following issues: * CVE-2026-59186: On ILP32, the Array2D tile-conversion buffer size calculation overflows, allocates a much smaller heap buffer, and tile decode writes past that allocation (bsc#1276850). * CVE-2026-61555: crashing occurs when Imf::GetChannelsInMultiPartFile() processes a crafted EXR with an empty multiView header attribute and Imf::viewFromChannelName() indexes the empty vector for a dotless channel name (bsc#1276859). * CVE-2026-68515: The utility allocates sampled channel storage using a truncated union_width / xSampling, then reads the sampled input through a Slice based on the misaligned union window, producing a heap out-of-bounds write (bsc#1276848). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4005=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4005=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * openexr-debuginfo-2.1.0-6.51.1 * libIlmImf-Imf_2_1-21-debuginfo-2.1.0-6.51.1 * libIlmImf-Imf_2_1-21-2.1.0-6.51.1 * openexr-debugsource-2.1.0-6.51.1 * openexr-devel-2.1.0-6.51.1 * openexr-2.1.0-6.51.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * openexr-debuginfo-2.1.0-6.51.1 * libIlmImf-Imf_2_1-21-debuginfo-2.1.0-6.51.1 * libIlmImf-Imf_2_1-21-2.1.0-6.51.1 * openexr-debugsource-2.1.0-6.51.1 * openexr-devel-2.1.0-6.51.1 * openexr-2.1.0-6.51.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59186.html * https://www.suse.com/security/cve/CVE-2026-61555.html * https://www.suse.com/security/cve/CVE-2026-68515.html * https://bugzilla.suse.com/show_bug.cgi?id=1276848 * https://bugzilla.suse.com/show_bug.cgi?id=1276850 * https://bugzilla.suse.com/show_bug.cgi?id=1276859 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 12:59:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 12:59:36 -0000 Subject: SUSE-SU-2026:4004-1: important: Security update for libvirt Message-ID: <178878597613.9930.18398601768926385462@6bd16ccd9111> # Security update for libvirt Announcement ID: SUSE-SU-2026:4004-1 Release Date: 2026-09-07T07:30:44Z Rating: important References: * bsc#1274576 * bsc#1274946 * bsc#1275264 * bsc#1275265 * bsc#1275863 Cross-References: * CVE-2026-18917 * CVE-2026-61477 * CVE-2026-63622 * CVE-2026-63623 * CVE-2026-77159 CVSS scores: * CVE-2026-18917 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-18917 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-61477 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-61477 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61477 ( NVD ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-63622 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63622 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63622 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63623 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-63623 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-63623 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-77159 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-77159 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves five vulnerabilities can now be installed. ## Description: This update for libvirt fixes the following issues: * CVE-2026-18917: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow (bsc#1275863). * CVE-2026-61477: newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection (bsc#1274576). * CVE-2026-63622: `swtpm` privilege escalation via symlink following (bsc#1275264). * CVE-2026-63623: information disclosure via world-readable storage volume images during clone/convert (bsc#1275265). * CVE-2026-77159: root `chown()` on `swtpm` logfile follows symlinks (bsc#1274946). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4004=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4004=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4004=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4004=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4004=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4004=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4004=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4004=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4004=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-8.0.0-150400.7.17.1 * libvirt-lock-sanlock-8.0.0-150400.7.17.1 * libvirt-devel-8.0.0-150400.7.17.1 * libvirt-daemon-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-hooks-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-8.0.0-150400.7.17.1 * libvirt-nss-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-rbd-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-debuginfo-8.0.0-150400.7.17.1 * libvirt-8.0.0-150400.7.17.1 * libvirt-libs-debuginfo-8.0.0-150400.7.17.1 * libvirt-libs-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-8.0.0-150400.7.17.1 * libvirt-client-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-direct-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-8.0.0-150400.7.17.1 * libvirt-debugsource-8.0.0-150400.7.17.1 * libvirt-daemon-config-network-8.0.0-150400.7.17.1 * libvirt-daemon-config-nwfilter-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-debuginfo-8.0.0-150400.7.17.1 * libvirt-lock-sanlock-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-rbd-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-8.0.0-150400.7.17.1 * libvirt-daemon-qemu-8.0.0-150400.7.17.1 * libvirt-client-8.0.0-150400.7.17.1 * libvirt-nss-8.0.0-150400.7.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libvirt-daemon-driver-libxl-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-xen-8.0.0-150400.7.17.1 * libvirt-daemon-driver-libxl-8.0.0-150400.7.17.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * libvirt-doc-8.0.0-150400.7.17.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-8.0.0-150400.7.17.1 * libvirt-client-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-debuginfo-8.0.0-150400.7.17.1 * libvirt-libs-debuginfo-8.0.0-150400.7.17.1 * libvirt-libs-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-client-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-direct-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-8.0.0-150400.7.17.1 * libvirt-debugsource-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-8.0.0-150400.7.17.1 * libvirt-daemon-qemu-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-debuginfo-8.0.0-150400.7.17.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-rbd-debuginfo-8.0.0-150400.7.17.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-8.0.0-150400.7.17.1 * libvirt-client-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-debuginfo-8.0.0-150400.7.17.1 * libvirt-libs-debuginfo-8.0.0-150400.7.17.1 * libvirt-libs-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-client-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-direct-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-8.0.0-150400.7.17.1 * libvirt-debugsource-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-8.0.0-150400.7.17.1 * libvirt-daemon-qemu-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-debuginfo-8.0.0-150400.7.17.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-rbd-debuginfo-8.0.0-150400.7.17.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-8.0.0-150400.7.17.1 * libvirt-daemon-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-debuginfo-8.0.0-150400.7.17.1 * libvirt-libs-debuginfo-8.0.0-150400.7.17.1 * libvirt-libs-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-debuginfo-8.0.0-150400.7.17.1 * libvirt-client-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-direct-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-8.0.0-150400.7.17.1 * libvirt-debugsource-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-8.0.0-150400.7.17.1 * libvirt-daemon-qemu-8.0.0-150400.7.17.1 * libvirt-client-8.0.0-150400.7.17.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-rbd-debuginfo-8.0.0-150400.7.17.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-8.0.0-150400.7.17.1 * libvirt-daemon-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-debuginfo-8.0.0-150400.7.17.1 * libvirt-libs-debuginfo-8.0.0-150400.7.17.1 * libvirt-libs-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-debuginfo-8.0.0-150400.7.17.1 * libvirt-client-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-direct-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-8.0.0-150400.7.17.1 * libvirt-debugsource-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-8.0.0-150400.7.17.1 * libvirt-daemon-qemu-8.0.0-150400.7.17.1 * libvirt-client-8.0.0-150400.7.17.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-rbd-debuginfo-8.0.0-150400.7.17.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-8.0.0-150400.7.17.1 * libvirt-daemon-driver-lxc-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-lxc-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-8.0.0-150400.7.17.1 * libvirt-lock-sanlock-8.0.0-150400.7.17.1 * libvirt-devel-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-8.0.0-150400.7.17.1 * libvirt-daemon-hooks-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-8.0.0-150400.7.17.1 * libvirt-nss-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-gluster-8.0.0-150400.7.17.1 * libvirt-client-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-gluster-debuginfo-8.0.0-150400.7.17.1 * libvirt-8.0.0-150400.7.17.1 * libvirt-libs-debuginfo-8.0.0-150400.7.17.1 * libvirt-libs-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-debuginfo-8.0.0-150400.7.17.1 * wireshark-plugin-libvirt-8.0.0-150400.7.17.1 * wireshark-plugin-libvirt-debuginfo-8.0.0-150400.7.17.1 * libvirt-client-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-direct-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-8.0.0-150400.7.17.1 * libvirt-debugsource-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-8.0.0-150400.7.17.1 * libvirt-daemon-config-network-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-config-nwfilter-8.0.0-150400.7.17.1 * libvirt-lock-sanlock-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-8.0.0-150400.7.17.1 * libvirt-daemon-qemu-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-lxc-8.0.0-150400.7.17.1 * libvirt-nss-8.0.0-150400.7.17.1 * openSUSE Leap 15.4 (x86_64) * libvirt-client-32bit-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-libxl-debuginfo-8.0.0-150400.7.17.1 * libvirt-devel-32bit-8.0.0-150400.7.17.1 * libvirt-daemon-xen-8.0.0-150400.7.17.1 * libvirt-daemon-driver-libxl-8.0.0-150400.7.17.1 * openSUSE Leap 15.4 (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-rbd-debuginfo-8.0.0-150400.7.17.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libvirt-devel-64bit-8.0.0-150400.7.17.1 * libvirt-client-64bit-debuginfo-8.0.0-150400.7.17.1 * openSUSE Leap 15.4 (noarch) * libvirt-doc-8.0.0-150400.7.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-8.0.0-150400.7.17.1 * libvirt-lock-sanlock-8.0.0-150400.7.17.1 * libvirt-devel-8.0.0-150400.7.17.1 * libvirt-daemon-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-hooks-8.0.0-150400.7.17.1 * libvirt-nss-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-debuginfo-8.0.0-150400.7.17.1 * libvirt-8.0.0-150400.7.17.1 * libvirt-libs-debuginfo-8.0.0-150400.7.17.1 * libvirt-libs-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-client-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-direct-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-8.0.0-150400.7.17.1 * libvirt-debugsource-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-8.0.0-150400.7.17.1 * libvirt-daemon-config-nwfilter-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-config-network-8.0.0-150400.7.17.1 * libvirt-lock-sanlock-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-8.0.0-150400.7.17.1 * libvirt-daemon-qemu-8.0.0-150400.7.17.1 * libvirt-client-8.0.0-150400.7.17.1 * libvirt-nss-8.0.0-150400.7.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libvirt-daemon-driver-storage-rbd-8.0.0-150400.7.17.1 * libvirt-daemon-driver-libxl-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-xen-8.0.0-150400.7.17.1 * libvirt-daemon-driver-libxl-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-rbd-debuginfo-8.0.0-150400.7.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * libvirt-doc-8.0.0-150400.7.17.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-8.0.0-150400.7.17.1 * libvirt-lock-sanlock-8.0.0-150400.7.17.1 * libvirt-devel-8.0.0-150400.7.17.1 * libvirt-daemon-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-hooks-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-8.0.0-150400.7.17.1 * libvirt-nss-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-debuginfo-8.0.0-150400.7.17.1 * libvirt-8.0.0-150400.7.17.1 * libvirt-libs-debuginfo-8.0.0-150400.7.17.1 * libvirt-libs-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-debuginfo-8.0.0-150400.7.17.1 * libvirt-client-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-direct-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-8.0.0-150400.7.17.1 * libvirt-debugsource-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-8.0.0-150400.7.17.1 * libvirt-daemon-config-nwfilter-8.0.0-150400.7.17.1 * libvirt-daemon-config-network-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-debuginfo-8.0.0-150400.7.17.1 * libvirt-lock-sanlock-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-8.0.0-150400.7.17.1 * libvirt-daemon-qemu-8.0.0-150400.7.17.1 * libvirt-client-8.0.0-150400.7.17.1 * libvirt-nss-8.0.0-150400.7.17.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-rbd-debuginfo-8.0.0-150400.7.17.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libvirt-daemon-driver-libxl-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-xen-8.0.0-150400.7.17.1 * libvirt-daemon-driver-libxl-8.0.0-150400.7.17.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * libvirt-doc-8.0.0-150400.7.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-logical-8.0.0-150400.7.17.1 * libvirt-lock-sanlock-8.0.0-150400.7.17.1 * libvirt-devel-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-8.0.0-150400.7.17.1 * libvirt-daemon-hooks-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-rbd-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-8.0.0-150400.7.17.1 * libvirt-nss-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-qemu-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-8.0.0-150400.7.17.1 * libvirt-client-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-debuginfo-8.0.0-150400.7.17.1 * libvirt-8.0.0-150400.7.17.1 * libvirt-libs-debuginfo-8.0.0-150400.7.17.1 * libvirt-libs-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-network-8.0.0-150400.7.17.1 * libvirt-client-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-iscsi-direct-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-mpath-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-scsi-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-8.0.0-150400.7.17.1 * libvirt-debugsource-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-core-8.0.0-150400.7.17.1 * libvirt-daemon-config-nwfilter-8.0.0-150400.7.17.1 * libvirt-daemon-driver-secret-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-config-network-8.0.0-150400.7.17.1 * libvirt-lock-sanlock-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-disk-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-8.0.0-150400.7.17.1 * libvirt-daemon-driver-interface-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-storage-rbd-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nodedev-8.0.0-150400.7.17.1 * libvirt-daemon-qemu-8.0.0-150400.7.17.1 * libvirt-daemon-driver-nwfilter-debuginfo-8.0.0-150400.7.17.1 * libvirt-nss-8.0.0-150400.7.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libvirt-daemon-driver-libxl-debuginfo-8.0.0-150400.7.17.1 * libvirt-daemon-xen-8.0.0-150400.7.17.1 * libvirt-daemon-driver-libxl-8.0.0-150400.7.17.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * libvirt-doc-8.0.0-150400.7.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-18917.html * https://www.suse.com/security/cve/CVE-2026-61477.html * https://www.suse.com/security/cve/CVE-2026-63622.html * https://www.suse.com/security/cve/CVE-2026-63623.html * https://www.suse.com/security/cve/CVE-2026-77159.html * https://bugzilla.suse.com/show_bug.cgi?id=1274576 * https://bugzilla.suse.com/show_bug.cgi?id=1274946 * https://bugzilla.suse.com/show_bug.cgi?id=1275264 * https://bugzilla.suse.com/show_bug.cgi?id=1275265 * https://bugzilla.suse.com/show_bug.cgi?id=1275863 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 13:00:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 13:00:42 -0000 Subject: SUSE-SU-2026:4003-1: important: Security update for openexr Message-ID: <178878604205.9930.13843662688066297119@6bd16ccd9111> # Security update for openexr Announcement ID: SUSE-SU-2026:4003-1 Release Date: 2026-09-07T07:29:51Z Rating: important References: * bsc#1276848 * bsc#1276849 * bsc#1276850 * bsc#1276853 * bsc#1276855 * bsc#1276859 * bsc#1276862 Cross-References: * CVE-2026-59184 * CVE-2026-59186 * CVE-2026-59189 * CVE-2026-59981 * CVE-2026-59982 * CVE-2026-61555 * CVE-2026-68515 CVSS scores: * CVE-2026-59184 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-59184 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-59186 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-59186 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-59189 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-59189 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-59981 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-59981 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-59982 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-59982 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-61555 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-61555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-68515 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-68515 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves seven vulnerabilities can now be installed. ## Description: This update for openexr fixes the following issues: * CVE-2026-59184: invalid heap pointer, causing out-of-bounds or use-after- free writes (bsc#1276849). * CVE-2026-59186: On ILP32, the Array2D tile-conversion buffer size calculation overflows, allocates a much smaller heap buffer, and tile decode writes past that allocation (bsc#1276850). * CVE-2026-59189: API can return an out-of-bounds pointer when a deep image has a non-zero dataWindow origin, resulting in a heap out-of-bounds read and crash, with potential information disclosure under a controlled heap layout (bsc#1276855). * CVE-2026-59981: an attacker-controlled deep EXR file can access sample counts through row() performs an out-of-bounds read, which can crash the process or, under a controlled heap layout, return adjacent heap memory as sample-count values (bsc#1276862). * CVE-2026-59982: an out-of-bounds pointer from TypedDeepImageChannel::row() when a crafted deep EXR has a nonzero dataWindow origin (bsc#1276853). * CVE-2026-61555: crashing occurs when Imf::GetChannelsInMultiPartFile() processes a crafted EXR with an empty multiView header attribute and Imf::viewFromChannelName() indexes the empty vector for a dotless channel name (bsc#1276859). * CVE-2026-68515: The utility allocates sampled channel storage using a truncated union_width / xSampling, then reads the sampled input through a Slice based on the misaligned union window, producing a heap out-of-bounds write (bsc#1276848). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4003=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4003=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4003=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4003=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4003=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4003=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4003=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4003=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4003=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4003=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4003=1 ## Package List: * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * openexr-debuginfo-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-debuginfo-2.2.1-150000.3.55.1 * openexr-devel-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-debuginfo-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-2.2.1-150000.3.55.1 * openexr-debugsource-2.2.1-150000.3.55.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * openexr-debuginfo-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-debuginfo-2.2.1-150000.3.55.1 * openexr-devel-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-debuginfo-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-2.2.1-150000.3.55.1 * openexr-debugsource-2.2.1-150000.3.55.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * openexr-debuginfo-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-debuginfo-2.2.1-150000.3.55.1 * openexr-devel-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-debuginfo-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-2.2.1-150000.3.55.1 * openexr-debugsource-2.2.1-150000.3.55.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * openexr-debuginfo-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-debuginfo-2.2.1-150000.3.55.1 * openexr-devel-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-debuginfo-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-2.2.1-150000.3.55.1 * openexr-debugsource-2.2.1-150000.3.55.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * openexr-debuginfo-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-debuginfo-2.2.1-150000.3.55.1 * openexr-devel-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-debuginfo-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-2.2.1-150000.3.55.1 * openexr-debugsource-2.2.1-150000.3.55.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * openexr-debuginfo-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-debuginfo-2.2.1-150000.3.55.1 * openexr-devel-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-debuginfo-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-2.2.1-150000.3.55.1 * openexr-debugsource-2.2.1-150000.3.55.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * openexr-debuginfo-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-debuginfo-2.2.1-150000.3.55.1 * openexr-devel-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-debuginfo-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-2.2.1-150000.3.55.1 * openexr-debugsource-2.2.1-150000.3.55.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * openexr-debuginfo-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-debuginfo-2.2.1-150000.3.55.1 * openexr-devel-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-debuginfo-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-2.2.1-150000.3.55.1 * openexr-debugsource-2.2.1-150000.3.55.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * openexr-debuginfo-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-debuginfo-2.2.1-150000.3.55.1 * openexr-devel-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-debuginfo-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-2.2.1-150000.3.55.1 * openexr-debugsource-2.2.1-150000.3.55.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * openexr-debuginfo-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-debuginfo-2.2.1-150000.3.55.1 * openexr-devel-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-debuginfo-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-2.2.1-150000.3.55.1 * openexr-debugsource-2.2.1-150000.3.55.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * openexr-debuginfo-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-debuginfo-2.2.1-150000.3.55.1 * openexr-devel-2.2.1-150000.3.55.1 * libIlmImfUtil-2_2-23-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-debuginfo-2.2.1-150000.3.55.1 * libIlmImf-2_2-23-2.2.1-150000.3.55.1 * openexr-debugsource-2.2.1-150000.3.55.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59184.html * https://www.suse.com/security/cve/CVE-2026-59186.html * https://www.suse.com/security/cve/CVE-2026-59189.html * https://www.suse.com/security/cve/CVE-2026-59981.html * https://www.suse.com/security/cve/CVE-2026-59982.html * https://www.suse.com/security/cve/CVE-2026-61555.html * https://www.suse.com/security/cve/CVE-2026-68515.html * https://bugzilla.suse.com/show_bug.cgi?id=1276848 * https://bugzilla.suse.com/show_bug.cgi?id=1276849 * https://bugzilla.suse.com/show_bug.cgi?id=1276850 * https://bugzilla.suse.com/show_bug.cgi?id=1276853 * https://bugzilla.suse.com/show_bug.cgi?id=1276855 * https://bugzilla.suse.com/show_bug.cgi?id=1276859 * https://bugzilla.suse.com/show_bug.cgi?id=1276862 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 13:01:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 13:01:25 -0000 Subject: SUSE-SU-2026:4002-1: moderate: Security update for java-17-openjdk Message-ID: <178878608519.9930.16119517256695120793@6bd16ccd9111> # Security update for java-17-openjdk Announcement ID: SUSE-SU-2026:4002-1 Release Date: 2026-09-07T07:28:19Z Rating: moderate References: * bsc#1275035 * bsc#1275764 * bsc#1275777 * bsc#1275778 Cross-References: * CVE-2026-60589 * CVE-2026-61308 * CVE-2026-70907 CVSS scores: * CVE-2026-60589 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-60589 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61308 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-61308 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-70907 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-70907 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Legacy Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities and has one security fix can now be installed. ## Description: This update for java-17-openjdk fixes the following issues: Upgrade to upstream tag jdk-17.0.20.1+1 (August 2026 CSPU). * CVE-2026-60589: unauthenticated attacker with network access via multiple protocols can gain unauthorized read access to a subset of accessible data (bsc#1275777). * CVE-2026-61308: unauthenticated attacker with network access via HTTP can gain unauthorized access to critical data (bsc#1275778). * CVE-2026-70907: unauthenticated attacker with network access via TLS can cause a partial denial of service (bsc#1275764). Changes for java-17-openjdk: * Upgrade to upstream tag jdk-17.0.20.1+1 (August 2026 CSPU): * JDK-8389947: [17u] Remove designator `DEFAULT_PROMOTED_VERSION_PRE=ea` for release 17.0.20.1. * JDK-8333743: Change `.jcheck/conf` branches property to match valid branches * JDK-8388790: Bump update version for OpenJDK: jdk-17.0.20.1 * Backport upcoming upgrade of timezone data (bsc#1275035) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4002=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4002=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4002=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4002=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4002=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4002=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-4002=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4002=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4002=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4002=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4002=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4002=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * java-17-openjdk-debugsource-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-17.0.20.1-150400.3.72.1 * java-17-openjdk-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-demo-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-jmods-17.0.20.1-150400.3.72.1 * java-17-openjdk-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-src-17.0.20.1-150400.3.72.1 * openSUSE Leap 15.4 (noarch) * java-17-openjdk-javadoc-17.0.20.1-150400.3.72.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * java-17-openjdk-debugsource-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-17.0.20.1-150400.3.72.1 * java-17-openjdk-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-demo-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-debuginfo-17.0.20.1-150400.3.72.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * java-17-openjdk-debugsource-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-17.0.20.1-150400.3.72.1 * java-17-openjdk-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-demo-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-debuginfo-17.0.20.1-150400.3.72.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * java-17-openjdk-debugsource-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-17.0.20.1-150400.3.72.1 * java-17-openjdk-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-demo-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-debuginfo-17.0.20.1-150400.3.72.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-17-openjdk-debugsource-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-17.0.20.1-150400.3.72.1 * java-17-openjdk-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-demo-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-debuginfo-17.0.20.1-150400.3.72.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-17-openjdk-debugsource-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-17.0.20.1-150400.3.72.1 * java-17-openjdk-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-demo-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-debuginfo-17.0.20.1-150400.3.72.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * java-17-openjdk-debugsource-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-17.0.20.1-150400.3.72.1 * java-17-openjdk-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-demo-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-debuginfo-17.0.20.1-150400.3.72.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * java-17-openjdk-debugsource-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-17.0.20.1-150400.3.72.1 * java-17-openjdk-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-demo-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-debuginfo-17.0.20.1-150400.3.72.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * java-17-openjdk-debugsource-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-17.0.20.1-150400.3.72.1 * java-17-openjdk-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-demo-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-debuginfo-17.0.20.1-150400.3.72.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-17-openjdk-debugsource-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-17.0.20.1-150400.3.72.1 * java-17-openjdk-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-demo-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-debuginfo-17.0.20.1-150400.3.72.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-17-openjdk-debugsource-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-17.0.20.1-150400.3.72.1 * java-17-openjdk-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-demo-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-debuginfo-17.0.20.1-150400.3.72.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * java-17-openjdk-debugsource-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-17.0.20.1-150400.3.72.1 * java-17-openjdk-17.0.20.1-150400.3.72.1 * java-17-openjdk-devel-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-demo-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-17.0.20.1-150400.3.72.1 * java-17-openjdk-headless-debuginfo-17.0.20.1-150400.3.72.1 * java-17-openjdk-debuginfo-17.0.20.1-150400.3.72.1 ## References: * https://www.suse.com/security/cve/CVE-2026-60589.html * https://www.suse.com/security/cve/CVE-2026-61308.html * https://www.suse.com/security/cve/CVE-2026-70907.html * https://bugzilla.suse.com/show_bug.cgi?id=1275035 * https://bugzilla.suse.com/show_bug.cgi?id=1275764 * https://bugzilla.suse.com/show_bug.cgi?id=1275777 * https://bugzilla.suse.com/show_bug.cgi?id=1275778 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 13:02:21 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 13:02:21 -0000 Subject: SUSE-SU-2026:4001-1: important: Security update for webkit2gtk3 Message-ID: <178878614128.9930.8853792159936736059@6bd16ccd9111> # Security update for webkit2gtk3 Announcement ID: SUSE-SU-2026:4001-1 Release Date: 2026-09-07T07:26:27Z Rating: important References: * bsc#1275791 Cross-References: * CVE-2026-28984 * CVE-2026-43804 * CVE-2026-64713 * CVE-2026-64719 * CVE-2026-64728 * CVE-2026-64730 * CVE-2026-64757 * CVE-2026-64783 * CVE-2026-64787 CVSS scores: * CVE-2026-28984 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-28984 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-28984 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-43804 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43804 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43804 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-64713 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64713 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-64713 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-64719 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64719 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-64719 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-64728 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-64728 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-64728 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-64730 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-64730 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-64730 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-64757 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64757 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-64757 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64783 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64783 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-64783 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64787 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64787 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-64787 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves nine vulnerabilities can now be installed. ## Description: This update for webkit2gtk3 fixes the following issues: * CVE-2026-28984,CVE-2026-43804,CVE-2026-64713,CVE-2026-64719,CVE-2026-64728, CVE-2026-64730,CVE-2026-64757,CVE-2026-64783,CVE-2026-64787: WebKitGTK and WPE WebKit Security Advisory WSA-2026-0005 (bsc#1275791). Changes for webkit2gtk3: * Update to version 2.52.6 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4001=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4001=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4001=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4001=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4001=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4001=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4001=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4001=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4001=1 ## Package List: * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * WebKitGTK-6.0-lang-2.52.6-150400.4.149.2 * WebKitGTK-4.1-lang-2.52.6-150400.4.149.2 * WebKitGTK-4.0-lang-2.52.6-150400.4.149.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * webkit2gtk-4_1-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_1-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-devel-2.52.6-150400.4.149.2 * webkit2gtk3-debugsource-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_0-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-debugsource-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-devel-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_0-2.52.6-150400.4.149.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_0-2.52.6-150400.4.149.2 * webkit2gtk4-debugsource-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-2.52.6-150400.4.149.2 * webkitgtk-6_0-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_1-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_1-2.52.6-150400.4.149.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * webkit2gtk-4_1-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_1-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-devel-2.52.6-150400.4.149.2 * webkit2gtk3-debugsource-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_0-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-debugsource-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-devel-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_0-2.52.6-150400.4.149.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_0-2.52.6-150400.4.149.2 * webkit2gtk4-debugsource-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-2.52.6-150400.4.149.2 * webkitgtk-6_0-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_1-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_1-2.52.6-150400.4.149.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * WebKitGTK-4.1-lang-2.52.6-150400.4.149.2 * WebKitGTK-6.0-lang-2.52.6-150400.4.149.2 * WebKitGTK-4.0-lang-2.52.6-150400.4.149.2 * openSUSE Leap 15.4 (noarch) * WebKitGTK-6.0-lang-2.52.6-150400.4.149.2 * WebKitGTK-4.1-lang-2.52.6-150400.4.149.2 * WebKitGTK-4.0-lang-2.52.6-150400.4.149.2 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * webkit2gtk-4_1-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-minibrowser-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-2.52.6-150400.4.149.2 * webkit-jsc-4.1-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_1-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-devel-2.52.6-150400.4.149.2 * webkit2gtk3-debugsource-2.52.6-150400.4.149.2 * webkit2gtk4-minibrowser-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-minibrowser-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_0-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-debugsource-2.52.6-150400.4.149.2 * typelib-1_0-WebKit-6_0-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk4-devel-2.52.6-150400.4.149.2 * webkit2gtk4-minibrowser-2.52.6-150400.4.149.2 * webkit2gtk3-devel-2.52.6-150400.4.149.2 * typelib-1_0-WebKitWebProcessExtension-6_0-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-2.52.6-150400.4.149.2 * webkitgtk-6_0-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * webkit-jsc-4.1-debuginfo-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-2.52.6-150400.4.149.2 * webkit-jsc-4-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_1-2.52.6-150400.4.149.2 * webkit-jsc-6.0-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-6_0-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_0-2.52.6-150400.4.149.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * webkit-jsc-4-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_0-2.52.6-150400.4.149.2 * webkit2gtk4-debugsource-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-minibrowser-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-2.52.6-150400.4.149.2 * webkitgtk-6_0-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-minibrowser-debuginfo-2.52.6-150400.4.149.2 * webkit-jsc-6.0-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_1-2.52.6-150400.4.149.2 * openSUSE Leap 15.4 (x86_64) * libjavascriptcoregtk-4_0-18-32bit-debuginfo-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-32bit-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-32bit-debuginfo-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-32bit-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-32bit-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-32bit-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-32bit-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-32bit-debuginfo-2.52.6-150400.4.149.2 * openSUSE Leap 15.4 (aarch64_ilp32) * libjavascriptcoregtk-4_1-0-64bit-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-64bit-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-64bit-debuginfo-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-64bit-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-64bit-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-64bit-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-64bit-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-64bit-debuginfo-2.52.6-150400.4.149.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * webkit2gtk-4_1-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_1-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-devel-2.52.6-150400.4.149.2 * webkit2gtk3-debugsource-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_0-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-debugsource-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-devel-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_0-2.52.6-150400.4.149.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_0-2.52.6-150400.4.149.2 * webkit2gtk4-debugsource-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-2.52.6-150400.4.149.2 * webkitgtk-6_0-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_1-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_1-2.52.6-150400.4.149.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * WebKitGTK-6.0-lang-2.52.6-150400.4.149.2 * WebKitGTK-4.1-lang-2.52.6-150400.4.149.2 * WebKitGTK-4.0-lang-2.52.6-150400.4.149.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * webkit2gtk-4_1-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_1-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-devel-2.52.6-150400.4.149.2 * webkit2gtk3-debugsource-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_0-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-debugsource-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-devel-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_0-2.52.6-150400.4.149.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_0-2.52.6-150400.4.149.2 * webkit2gtk4-debugsource-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-2.52.6-150400.4.149.2 * webkitgtk-6_0-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_1-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_1-2.52.6-150400.4.149.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * WebKitGTK-6.0-lang-2.52.6-150400.4.149.2 * WebKitGTK-4.1-lang-2.52.6-150400.4.149.2 * WebKitGTK-4.0-lang-2.52.6-150400.4.149.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * webkit2gtk-4_1-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_1-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-devel-2.52.6-150400.4.149.2 * webkit2gtk3-debugsource-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_0-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-debugsource-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-devel-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_0-2.52.6-150400.4.149.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_0-2.52.6-150400.4.149.2 * webkit2gtk4-debugsource-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-2.52.6-150400.4.149.2 * webkitgtk-6_0-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_1-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_1-2.52.6-150400.4.149.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * WebKitGTK-6.0-lang-2.52.6-150400.4.149.2 * WebKitGTK-4.1-lang-2.52.6-150400.4.149.2 * WebKitGTK-4.0-lang-2.52.6-150400.4.149.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * WebKitGTK-6.0-lang-2.52.6-150400.4.149.2 * WebKitGTK-4.1-lang-2.52.6-150400.4.149.2 * WebKitGTK-4.0-lang-2.52.6-150400.4.149.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * webkit2gtk-4_1-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_1-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-devel-2.52.6-150400.4.149.2 * webkit2gtk3-debugsource-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_0-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-debugsource-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-devel-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_0-2.52.6-150400.4.149.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_0-2.52.6-150400.4.149.2 * webkit2gtk4-debugsource-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-2.52.6-150400.4.149.2 * webkitgtk-6_0-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_1-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_1-2.52.6-150400.4.149.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * webkit2gtk-4_1-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_1-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-devel-2.52.6-150400.4.149.2 * webkit2gtk3-debugsource-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_0-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-debugsource-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-devel-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_0-2.52.6-150400.4.149.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_0-2.52.6-150400.4.149.2 * webkit2gtk4-debugsource-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-2.52.6-150400.4.149.2 * webkitgtk-6_0-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_1-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_1-2.52.6-150400.4.149.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * WebKitGTK-6.0-lang-2.52.6-150400.4.149.2 * WebKitGTK-4.1-lang-2.52.6-150400.4.149.2 * WebKitGTK-4.0-lang-2.52.6-150400.4.149.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * webkit2gtk-4_1-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk-4_0-injected-bundles-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_1-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-devel-2.52.6-150400.4.149.2 * webkit2gtk3-debugsource-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_0-2.52.6-150400.4.149.2 * webkit2gtk3-soup2-debugsource-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_1-0-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-debuginfo-2.52.6-150400.4.149.2 * webkit2gtk3-devel-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-debuginfo-2.52.6-150400.4.149.2 * libwebkit2gtk-4_0-37-2.52.6-150400.4.149.2 * libwebkitgtk-6_0-4-2.52.6-150400.4.149.2 * typelib-1_0-JavaScriptCore-4_0-2.52.6-150400.4.149.2 * webkit2gtk-4_1-injected-bundles-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_0-2.52.6-150400.4.149.2 * webkit2gtk4-debugsource-2.52.6-150400.4.149.2 * libjavascriptcoregtk-4_0-18-2.52.6-150400.4.149.2 * libwebkit2gtk-4_1-0-2.52.6-150400.4.149.2 * webkitgtk-6_0-injected-bundles-2.52.6-150400.4.149.2 * libjavascriptcoregtk-6_0-1-debuginfo-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2WebExtension-4_1-2.52.6-150400.4.149.2 * typelib-1_0-WebKit2-4_1-2.52.6-150400.4.149.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * WebKitGTK-6.0-lang-2.52.6-150400.4.149.2 * WebKitGTK-4.1-lang-2.52.6-150400.4.149.2 * WebKitGTK-4.0-lang-2.52.6-150400.4.149.2 ## References: * https://www.suse.com/security/cve/CVE-2026-28984.html * https://www.suse.com/security/cve/CVE-2026-43804.html * https://www.suse.com/security/cve/CVE-2026-64713.html * https://www.suse.com/security/cve/CVE-2026-64719.html * https://www.suse.com/security/cve/CVE-2026-64728.html * https://www.suse.com/security/cve/CVE-2026-64730.html * https://www.suse.com/security/cve/CVE-2026-64757.html * https://www.suse.com/security/cve/CVE-2026-64783.html * https://www.suse.com/security/cve/CVE-2026-64787.html * https://bugzilla.suse.com/show_bug.cgi?id=1275791 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 13:03:17 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 13:03:17 -0000 Subject: SUSE-SU-2026:4000-1: moderate: Security update for libidn Message-ID: <178878619757.9930.8732925654879337139@6bd16ccd9111> # Security update for libidn Announcement ID: SUSE-SU-2026:4000-1 Release Date: 2026-09-07T07:25:02Z Rating: moderate References: * bsc#1268965 Cross-References: * CVE-2026-57053 CVSS scores: * CVE-2026-57053 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-57053 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-57053 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-57053 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for libidn fixes the following issue: * CVE-2026-57053: out-of-bounds read in `ToUnicode` APIs (bsc#1268965). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4000=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libidn11-1.34-150000.3.5.1 * libidn-tools-debuginfo-1.34-150000.3.5.1 * libidn-devel-1.34-150000.3.5.1 * libidn11-debuginfo-1.34-150000.3.5.1 * libidn-debugsource-1.34-150000.3.5.1 * libidn-tools-1.34-150000.3.5.1 * Basesystem Module 15-SP7 (x86_64) * libidn11-32bit-debuginfo-1.34-150000.3.5.1 * libidn11-32bit-1.34-150000.3.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-57053.html * https://bugzilla.suse.com/show_bug.cgi?id=1268965 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 13:04:02 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 13:04:02 -0000 Subject: SUSE-SU-2026:3999-1: important: Security update for java-25-openjdk Message-ID: <178878624286.9930.7774518966361460258@6bd16ccd9111> # Security update for java-25-openjdk Announcement ID: SUSE-SU-2026:3999-1 Release Date: 2026-09-07T07:24:42Z Rating: important References: * bsc#1275035 * bsc#1275763 * bsc#1275764 * bsc#1275777 * bsc#1275778 Cross-References: * CVE-2026-60589 * CVE-2026-61308 * CVE-2026-70906 * CVE-2026-70907 CVSS scores: * CVE-2026-60589 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-60589 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61308 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-61308 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-70906 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-70906 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-70907 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-70907 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities and has one security fix can now be installed. ## Description: This update for java-25-openjdk fixes the following issues: * CVE-2026-60589: OpenJDK: Improve Resource Resolving (bsc#1275777). * CVE-2026-61308: OpenJDK: Enhance HTTP Connections (bsc#1275778). * CVE-2026-70906: OpenJDK: Improve font loading (bsc#1275763). * CVE-2026-70907: OpenJDK: Enhance TLS server (bsc#1275764). Changes for java-25-openjdk: * Update to jdk-25.0.4.1+1 (August 2026 CSPU) * backport upcoming upgrade of timezone data (bsc#1275035) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-3999=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-25-openjdk-25.0.4.1-150700.15.16.1 * java-25-openjdk-devel-25.0.4.1-150700.15.16.1 * java-25-openjdk-headless-debuginfo-25.0.4.1-150700.15.16.1 * java-25-openjdk-debuginfo-25.0.4.1-150700.15.16.1 * java-25-openjdk-demo-25.0.4.1-150700.15.16.1 * java-25-openjdk-devel-debuginfo-25.0.4.1-150700.15.16.1 * java-25-openjdk-headless-25.0.4.1-150700.15.16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-60589.html * https://www.suse.com/security/cve/CVE-2026-61308.html * https://www.suse.com/security/cve/CVE-2026-70906.html * https://www.suse.com/security/cve/CVE-2026-70907.html * https://bugzilla.suse.com/show_bug.cgi?id=1275035 * https://bugzilla.suse.com/show_bug.cgi?id=1275763 * https://bugzilla.suse.com/show_bug.cgi?id=1275764 * https://bugzilla.suse.com/show_bug.cgi?id=1275777 * https://bugzilla.suse.com/show_bug.cgi?id=1275778 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 13:04:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 13:04:44 -0000 Subject: SUSE-SU-2026:3998-1: moderate: Security update for java-1_8_0-openjdk Message-ID: <178878628487.9930.15628789306011387662@6bd16ccd9111> # Security update for java-1_8_0-openjdk Announcement ID: SUSE-SU-2026:3998-1 Release Date: 2026-09-07T07:24:15Z Rating: moderate References: * bsc#1275764 * bsc#1275777 * bsc#1275778 Cross-References: * CVE-2026-60589 * CVE-2026-61308 * CVE-2026-70907 CVSS scores: * CVE-2026-60589 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-60589 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61308 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-61308 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-70907 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-70907 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Legacy Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for java-1_8_0-openjdk fixes the following issues: Update to version jdk8u504 (icedtea 3.40.1). * CVE-2026-60589: unauthenticated attacker with network access via multiple protocols can gain unauthorized read access to sensitive data (bsc#1275777). * CVE-2026-61308: unauthenticated attacker with network access via HTTP can gain unauthorized access to critical data (bsc#1275778). * CVE-2026-70907: unauthenticated attacker with network access via TLS can gain the ability to cause a partial denial of service (bsc#1275764). Changes for java-1_8_0-openjdk: * Version jdk8u504 (icedtea 3.40.1): * Import of OpenJDK 8 u504 build 01 * JDK-8382471: Improve Resource Resolving * JDK-8384708: Enhance HTTP Connections * JDK-8385390: Update FreeType to 2.14.3 * JDK-8386205: Enhance TLS server * JDK-8388811: [8u] VS2010 build broken by JDK-8374058 * JDK-8389477: Bump update version for OpenJDK: 8u504 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-3998=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-3998=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-3998=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-3998=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-3998=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-3998=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3998=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3998=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-3998=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * java-1_8_0-openjdk-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-demo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debugsource-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-demo-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-1.8.0.504-150000.3.126.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-1_8_0-openjdk-demo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debugsource-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-demo-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-1.8.0.504-150000.3.126.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * java-1_8_0-openjdk-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-demo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debugsource-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-demo-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-1.8.0.504-150000.3.126.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * java-1_8_0-openjdk-demo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debugsource-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-demo-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-1.8.0.504-150000.3.126.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-1_8_0-openjdk-demo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debugsource-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-demo-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-1.8.0.504-150000.3.126.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * java-1_8_0-openjdk-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-demo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debugsource-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-demo-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-1.8.0.504-150000.3.126.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-1_8_0-openjdk-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-demo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debugsource-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-demo-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-1.8.0.504-150000.3.126.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-1_8_0-openjdk-demo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debugsource-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-demo-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-1.8.0.504-150000.3.126.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * java-1_8_0-openjdk-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-demo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-debugsource-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-demo-debuginfo-1.8.0.504-150000.3.126.1 * java-1_8_0-openjdk-devel-1.8.0.504-150000.3.126.1 ## References: * https://www.suse.com/security/cve/CVE-2026-60589.html * https://www.suse.com/security/cve/CVE-2026-61308.html * https://www.suse.com/security/cve/CVE-2026-70907.html * https://bugzilla.suse.com/show_bug.cgi?id=1275764 * https://bugzilla.suse.com/show_bug.cgi?id=1275777 * https://bugzilla.suse.com/show_bug.cgi?id=1275778 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 13:05:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 13:05:25 -0000 Subject: SUSE-SU-2026:3997-1: important: Security update for dracut Message-ID: <178878632556.9930.7913696891086717909@6bd16ccd9111> # Security update for dracut Announcement ID: SUSE-SU-2026:3997-1 Release Date: 2026-09-07T07:23:02Z Rating: important References: * bsc#1268322 * bsc#1273580 Cross-References: * CVE-2026-16445 * CVE-2026-6893 CVSS scores: * CVE-2026-16445 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16445 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise High Availability Extension 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves two vulnerabilities can now be installed. ## Description: This update for dracut fixes the following issues: Update to version 059+suse.730.g73d3411aa. * CVE-2026-6893: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` (bsc#1268322). * CVE-2026-16445: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` during system boot (bsc#1273580). Changes for dracut: * Update to version 059+suse.730.g73d3411aa: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3997=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3997=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3997=1 * SUSE Linux Enterprise High Availability Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-3997=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * dracut-tools-059+suse.571.g3d42218af-150600.3.35.1 * dracut-ima-059+suse.571.g3d42218af-150600.3.35.1 * dracut-debuginfo-059+suse.571.g3d42218af-150600.3.35.1 * dracut-mkinitrd-deprecated-059+suse.571.g3d42218af-150600.3.35.1 * dracut-debugsource-059+suse.571.g3d42218af-150600.3.35.1 * dracut-059+suse.571.g3d42218af-150600.3.35.1 * dracut-fips-059+suse.571.g3d42218af-150600.3.35.1 * dracut-extra-059+suse.571.g3d42218af-150600.3.35.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * dracut-ima-059+suse.571.g3d42218af-150600.3.35.1 * dracut-debuginfo-059+suse.571.g3d42218af-150600.3.35.1 * dracut-debugsource-059+suse.571.g3d42218af-150600.3.35.1 * dracut-059+suse.571.g3d42218af-150600.3.35.1 * dracut-fips-059+suse.571.g3d42218af-150600.3.35.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * dracut-ima-059+suse.571.g3d42218af-150600.3.35.1 * dracut-debuginfo-059+suse.571.g3d42218af-150600.3.35.1 * dracut-debugsource-059+suse.571.g3d42218af-150600.3.35.1 * dracut-059+suse.571.g3d42218af-150600.3.35.1 * dracut-fips-059+suse.571.g3d42218af-150600.3.35.1 * SUSE Linux Enterprise High Availability Extension 15 SP6 (ppc64le x86_64) * dracut-mkinitrd-deprecated-059+suse.571.g3d42218af-150600.3.35.1 * dracut-debuginfo-059+suse.571.g3d42218af-150600.3.35.1 * dracut-debugsource-059+suse.571.g3d42218af-150600.3.35.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16445.html * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 * https://bugzilla.suse.com/show_bug.cgi?id=1273580 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 13:06:21 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 13:06:21 -0000 Subject: SUSE-SU-2026:3996-1: important: Security update for gegl Message-ID: <178878638141.9930.4255551439310601035@6bd16ccd9111> # Security update for gegl Announcement ID: SUSE-SU-2026:3996-1 Release Date: 2026-09-07T07:22:38Z Rating: important References: * bsc#1276229 Cross-References: * CVE-2026-18300 CVSS scores: * CVE-2026-18300 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-18300 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18300 ( NVD ): 7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for gegl fixes the following issue: * CVE-2026-18300: integer overflow in HDR file parsing can allow undersized buffer allocations (bsc#1276229). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-3996=1 ## Package List: * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * gegl-0_3-0.3.34-150000.3.12.1 * gegl-0_3-debuginfo-0.3.34-150000.3.12.1 * libgegl-0_3-0-debuginfo-0.3.34-150000.3.12.1 * gegl-debugsource-0.3.34-150000.3.12.1 * libgegl-0_3-0-0.3.34-150000.3.12.1 * gegl-debuginfo-0.3.34-150000.3.12.1 * typelib-1_0-Gegl-0_3-0.3.34-150000.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-18300.html * https://bugzilla.suse.com/show_bug.cgi?id=1276229 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 13:07:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 13:07:07 -0000 Subject: SUSE-SU-2026:3995-1: important: Security update for wireshark Message-ID: <178878642725.9930.4349494415101911828@6bd16ccd9111> # Security update for wireshark Announcement ID: SUSE-SU-2026:3995-1 Release Date: 2026-09-07T07:22:22Z Rating: important References: * bsc#1271133 * bsc#1271134 * bsc#1271137 * bsc#1271139 * bsc#1271142 * bsc#1271144 Cross-References: * CVE-2026-15163 * CVE-2026-15164 * CVE-2026-15167 * CVE-2026-15169 * CVE-2026-15172 * CVE-2026-15174 CVSS scores: * CVE-2026-15163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15163 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15164 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15167 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15167 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15169 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15169 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15169 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15174 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15174 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for wireshark fixes the following issues: * CVE-2026-15163: Denial of Service via multiple protocol dissector infinite loops (bsc#1271133). * CVE-2026-15164: Denial of Service vulnerability in ciscodump (bsc#1271134). * CVE-2026-15167: Denial of Service via DBS Etherwatch file parser crash (bsc#1271137). * CVE-2026-15169: Denial of Service via UMTS FP protocol dissector crash (bsc#1271139). * CVE-2026-15172: Denial of service via FMP/NOTIFY protocol dissector crash (bsc#1271142). * CVE-2026-15174: Denial of Service via Catapult DCT2000 protocol dissector crash (bsc#1271144). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3995=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3995=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * wireshark-gtk-debuginfo-2.4.16-48.72.1 * libwsutil8-debuginfo-2.4.16-48.72.1 * libwsutil8-2.4.16-48.72.1 * libwireshark9-2.4.16-48.72.1 * wireshark-devel-2.4.16-48.72.1 * wireshark-gtk-2.4.16-48.72.1 * libwireshark9-debuginfo-2.4.16-48.72.1 * libwscodecs1-2.4.16-48.72.1 * wireshark-debugsource-2.4.16-48.72.1 * libwscodecs1-debuginfo-2.4.16-48.72.1 * libwiretap7-2.4.16-48.72.1 * libwiretap7-debuginfo-2.4.16-48.72.1 * wireshark-debuginfo-2.4.16-48.72.1 * wireshark-2.4.16-48.72.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * wireshark-gtk-debuginfo-2.4.16-48.72.1 * libwsutil8-debuginfo-2.4.16-48.72.1 * libwsutil8-2.4.16-48.72.1 * libwireshark9-2.4.16-48.72.1 * wireshark-devel-2.4.16-48.72.1 * wireshark-gtk-2.4.16-48.72.1 * libwireshark9-debuginfo-2.4.16-48.72.1 * libwscodecs1-2.4.16-48.72.1 * wireshark-debugsource-2.4.16-48.72.1 * libwiretap7-2.4.16-48.72.1 * libwiretap7-debuginfo-2.4.16-48.72.1 * libwscodecs1-debuginfo-2.4.16-48.72.1 * wireshark-debuginfo-2.4.16-48.72.1 * wireshark-2.4.16-48.72.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15163.html * https://www.suse.com/security/cve/CVE-2026-15164.html * https://www.suse.com/security/cve/CVE-2026-15167.html * https://www.suse.com/security/cve/CVE-2026-15169.html * https://www.suse.com/security/cve/CVE-2026-15172.html * https://www.suse.com/security/cve/CVE-2026-15174.html * https://bugzilla.suse.com/show_bug.cgi?id=1271133 * https://bugzilla.suse.com/show_bug.cgi?id=1271134 * https://bugzilla.suse.com/show_bug.cgi?id=1271137 * https://bugzilla.suse.com/show_bug.cgi?id=1271139 * https://bugzilla.suse.com/show_bug.cgi?id=1271142 * https://bugzilla.suse.com/show_bug.cgi?id=1271144 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 13:07:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 13:07:58 -0000 Subject: SUSE-SU-2026:3994-1: important: Security update for wireshark Message-ID: <178878647898.9930.12765852742211871226@6bd16ccd9111> # Security update for wireshark Announcement ID: SUSE-SU-2026:3994-1 Release Date: 2026-09-07T07:22:07Z Rating: important References: * bsc#1271133 * bsc#1271134 * bsc#1271136 * bsc#1271137 * bsc#1271138 * bsc#1271139 * bsc#1271140 * bsc#1271141 * bsc#1271142 * bsc#1271144 Cross-References: * CVE-2026-15163 * CVE-2026-15164 * CVE-2026-15166 * CVE-2026-15167 * CVE-2026-15168 * CVE-2026-15169 * CVE-2026-15170 * CVE-2026-15171 * CVE-2026-15172 * CVE-2026-15174 CVSS scores: * CVE-2026-15163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15163 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15164 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15166 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15166 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15166 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15167 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15167 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15168 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-15168 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-15168 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-15169 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15169 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15169 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15170 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15170 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15171 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15171 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15174 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15174 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for wireshark fixes the following issues: * CVE-2026-15163: Denial of Service via multiple protocol dissector infinite loops (bsc#1271133). * CVE-2026-15164: Denial of Service vulnerability in ciscodump (bsc#1271134). * CVE-2026-15166: Denial of Service via IEEE 802.11 protocol dissector crash (bsc#1271136). * CVE-2026-15167: Denial of Service via DBS Etherwatch file parser crash (bsc#1271137). * CVE-2026-15168: BLF file parser allows possible information disclosure (bsc#1271138). * CVE-2026-15169: Denial of Service via UMTS FP protocol dissector crash (bsc#1271139). * CVE-2026-15170: Denial of service via Z39.50 protocol dissector crash (bsc#1271140). * CVE-2026-15171: Denial of service via SSH protocol dissector crash (bsc#1271141). * CVE-2026-15172: Denial of service via FMP/NOTIFY protocol dissector crash (bsc#1271142). * CVE-2026-15174: Denial of Service via Catapult DCT2000 protocol dissector crash (bsc#1271144). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3994=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3994=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3994=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * wireshark-4.2.14-150600.18.44.1 * wireshark-ui-qt-debuginfo-4.2.14-150600.18.44.1 * libwireshark17-4.2.14-150600.18.44.1 * libwiretap14-debuginfo-4.2.14-150600.18.44.1 * wireshark-debuginfo-4.2.14-150600.18.44.1 * wireshark-debugsource-4.2.14-150600.18.44.1 * libwsutil15-debuginfo-4.2.14-150600.18.44.1 * libwiretap14-4.2.14-150600.18.44.1 * wireshark-devel-4.2.14-150600.18.44.1 * libwsutil15-4.2.14-150600.18.44.1 * libwireshark17-debuginfo-4.2.14-150600.18.44.1 * wireshark-ui-qt-4.2.14-150600.18.44.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * wireshark-4.2.14-150600.18.44.1 * wireshark-ui-qt-debuginfo-4.2.14-150600.18.44.1 * libwireshark17-4.2.14-150600.18.44.1 * libwiretap14-debuginfo-4.2.14-150600.18.44.1 * wireshark-debuginfo-4.2.14-150600.18.44.1 * libwsutil15-debuginfo-4.2.14-150600.18.44.1 * wireshark-debugsource-4.2.14-150600.18.44.1 * libwiretap14-4.2.14-150600.18.44.1 * wireshark-devel-4.2.14-150600.18.44.1 * libwsutil15-4.2.14-150600.18.44.1 * libwireshark17-debuginfo-4.2.14-150600.18.44.1 * wireshark-ui-qt-4.2.14-150600.18.44.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * wireshark-4.2.14-150600.18.44.1 * wireshark-ui-qt-debuginfo-4.2.14-150600.18.44.1 * libwireshark17-4.2.14-150600.18.44.1 * libwireshark17-debuginfo-4.2.14-150600.18.44.1 * wireshark-debuginfo-4.2.14-150600.18.44.1 * wireshark-debugsource-4.2.14-150600.18.44.1 * libwsutil15-debuginfo-4.2.14-150600.18.44.1 * libwiretap14-4.2.14-150600.18.44.1 * wireshark-devel-4.2.14-150600.18.44.1 * libwsutil15-4.2.14-150600.18.44.1 * libwiretap14-debuginfo-4.2.14-150600.18.44.1 * wireshark-ui-qt-4.2.14-150600.18.44.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15163.html * https://www.suse.com/security/cve/CVE-2026-15164.html * https://www.suse.com/security/cve/CVE-2026-15166.html * https://www.suse.com/security/cve/CVE-2026-15167.html * https://www.suse.com/security/cve/CVE-2026-15168.html * https://www.suse.com/security/cve/CVE-2026-15169.html * https://www.suse.com/security/cve/CVE-2026-15170.html * https://www.suse.com/security/cve/CVE-2026-15171.html * https://www.suse.com/security/cve/CVE-2026-15172.html * https://www.suse.com/security/cve/CVE-2026-15174.html * https://bugzilla.suse.com/show_bug.cgi?id=1271133 * https://bugzilla.suse.com/show_bug.cgi?id=1271134 * https://bugzilla.suse.com/show_bug.cgi?id=1271136 * https://bugzilla.suse.com/show_bug.cgi?id=1271137 * https://bugzilla.suse.com/show_bug.cgi?id=1271138 * https://bugzilla.suse.com/show_bug.cgi?id=1271139 * https://bugzilla.suse.com/show_bug.cgi?id=1271140 * https://bugzilla.suse.com/show_bug.cgi?id=1271141 * https://bugzilla.suse.com/show_bug.cgi?id=1271142 * https://bugzilla.suse.com/show_bug.cgi?id=1271144 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 13:08:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 13:08:57 -0000 Subject: SUSE-SU-2026:3993-1: important: Security update for emacs Message-ID: <178878653768.9930.15406139403469199278@6bd16ccd9111> # Security update for emacs Announcement ID: SUSE-SU-2026:3993-1 Release Date: 2026-09-07T07:21:50Z Rating: important References: * bsc#1275927 * bsc#1275941 * bsc#1276264 Cross-References: * CVE-2026-77219 * CVE-2026-79992 CVSS scores: * CVE-2026-77219 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-77219 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-77219 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-79992 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-79992 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for emacs fixes the following issues: * code execution upon opening arbitrary file (bsc#1275941). * CVE-2026-77219: memory leak via the PBM/PPM/PGM image loader (bsc#1276264). * CVE-2026-79992: zero-click local command execution via TRAMP (bsc#1275927). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-3993=1 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-3993=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * emacs-nox-debuginfo-24.3-25.26.1 * emacs-x11-debuginfo-24.3-25.26.1 * emacs-nox-24.3-25.26.1 * etags-24.3-25.26.1 * etags-debuginfo-24.3-25.26.1 * emacs-debugsource-24.3-25.26.1 * emacs-debuginfo-24.3-25.26.1 * emacs-24.3-25.26.1 * emacs-x11-24.3-25.26.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * emacs-el-24.3-25.26.1 * emacs-info-24.3-25.26.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * emacs-nox-debuginfo-24.3-25.26.1 * emacs-x11-debuginfo-24.3-25.26.1 * emacs-nox-24.3-25.26.1 * etags-24.3-25.26.1 * etags-debuginfo-24.3-25.26.1 * emacs-debugsource-24.3-25.26.1 * emacs-debuginfo-24.3-25.26.1 * emacs-24.3-25.26.1 * emacs-x11-24.3-25.26.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * emacs-el-24.3-25.26.1 * emacs-info-24.3-25.26.1 ## References: * https://www.suse.com/security/cve/CVE-2026-77219.html * https://www.suse.com/security/cve/CVE-2026-79992.html * https://bugzilla.suse.com/show_bug.cgi?id=1275927 * https://bugzilla.suse.com/show_bug.cgi?id=1275941 * https://bugzilla.suse.com/show_bug.cgi?id=1276264 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 13:09:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 13:09:40 -0000 Subject: SUSE-SU-2026:3992-1: important: Security update for aws-nitro-enclaves-cli Message-ID: <178878658040.9930.5303402338230693163@6bd16ccd9111> # Security update for aws-nitro-enclaves-cli Announcement ID: SUSE-SU-2026:3992-1 Release Date: 2026-09-07T07:21:33Z Rating: important References: * bsc#1257933 * bsc#1270202 * bsc#1274300 Cross-References: * CVE-2026-25541 * CVE-2026-25727 * CVE-2026-41676 CVSS scores: * CVE-2026-25541 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25541 ( NVD ): 5.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( NVD ): 6.8 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for aws-nitro-enclaves-cli fixes the following issues: * CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to undefined behavior and crashes (bsc#1274300). * CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257933). * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270202). Changes for aws-nitro-enclaves-cli: * Update to version 1.5.0 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-3992=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-3992=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3992=1 ## Package List: * Public Cloud Module 15-SP7 (aarch64 x86_64) * aws-nitro-enclaves-cli-debugsource-1.5.0~git0.2950b36-150600.10.15.1 * aws-nitro-enclaves-cli-1.5.0~git0.2950b36-150600.10.15.1 * system-group-ne-1.5.0~git0.2950b36-150600.10.15.1 * aws-nitro-enclaves-cli-debuginfo-1.5.0~git0.2950b36-150600.10.15.1 * aws-nitro-enclaves-binaryblobs-upstream-1.5.0~git0.2950b36-150600.10.15.1 * aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.5.0~git0.2950b36-150600.10.15.1 * Public Cloud Module 15-SP6 (aarch64 x86_64) * aws-nitro-enclaves-cli-debugsource-1.5.0~git0.2950b36-150600.10.15.1 * aws-nitro-enclaves-binaryblobs-upstream-1.5.0~git0.2950b36-150600.10.15.1 * system-group-ne-1.5.0~git0.2950b36-150600.10.15.1 * aws-nitro-enclaves-cli-1.5.0~git0.2950b36-150600.10.15.1 * aws-nitro-enclaves-cli-debuginfo-1.5.0~git0.2950b36-150600.10.15.1 * aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.5.0~git0.2950b36-150600.10.15.1 * openSUSE Leap 15.6 (aarch64 x86_64) * aws-nitro-enclaves-cli-debugsource-1.5.0~git0.2950b36-150600.10.15.1 * aws-nitro-enclaves-cli-1.5.0~git0.2950b36-150600.10.15.1 * system-group-ne-1.5.0~git0.2950b36-150600.10.15.1 * aws-nitro-enclaves-cli-debuginfo-1.5.0~git0.2950b36-150600.10.15.1 * aws-nitro-enclaves-binaryblobs-upstream-1.5.0~git0.2950b36-150600.10.15.1 * aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.5.0~git0.2950b36-150600.10.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25541.html * https://www.suse.com/security/cve/CVE-2026-25727.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1257933 * https://bugzilla.suse.com/show_bug.cgi?id=1270202 * https://bugzilla.suse.com/show_bug.cgi?id=1274300 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 13:10:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 13:10:36 -0000 Subject: SUSE-SU-2026:3991-1: important: Security update for redis7 Message-ID: <178878663602.9930.2064952779646820442@6bd16ccd9111> # Security update for redis7 Announcement ID: SUSE-SU-2026:3991-1 Release Date: 2026-09-07T07:21:20Z Rating: important References: * bsc#1277794 Cross-References: * CVE-2026-81934 CVSS scores: * CVE-2026-81934 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-81934 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-81934 ( NVD ): 7.5 CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-81934 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for redis7 fixes the following issue: * CVE-2026-81934: TLS pending-data handling can cause use-after-free (bsc#1277794). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3991=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3991=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3991=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * redis7-7.0.8-150600.8.31.1 * redis7-debuginfo-7.0.8-150600.8.31.1 * redis7-debugsource-7.0.8-150600.8.31.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * redis7-7.0.8-150600.8.31.1 * redis7-debuginfo-7.0.8-150600.8.31.1 * redis7-debugsource-7.0.8-150600.8.31.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * redis7-7.0.8-150600.8.31.1 * redis7-debuginfo-7.0.8-150600.8.31.1 * redis7-debugsource-7.0.8-150600.8.31.1 ## References: * https://www.suse.com/security/cve/CVE-2026-81934.html * https://bugzilla.suse.com/show_bug.cgi?id=1277794 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 13:11:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 13:11:31 -0000 Subject: SUSE-SU-2026:3990-1: important: Security update for redis Message-ID: <178878669174.9930.8357493707992035250@6bd16ccd9111> # Security update for redis Announcement ID: SUSE-SU-2026:3990-1 Release Date: 2026-09-07T07:20:38Z Rating: important References: * bsc#1277794 Cross-References: * CVE-2026-81934 CVSS scores: * CVE-2026-81934 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-81934 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-81934 ( NVD ): 7.5 CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-81934 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for redis fixes the following issue: * CVE-2026-81934: TLS pending-data handling can cause use-after-free (bsc#1277794). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3990=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-3990=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3990=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * redis-debuginfo-7.2.4-150600.3.30.1 * redis-debugsource-7.2.4-150600.3.30.1 * redis-7.2.4-150600.3.30.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * redis-debuginfo-7.2.4-150600.3.30.1 * redis-debugsource-7.2.4-150600.3.30.1 * redis-7.2.4-150600.3.30.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * redis-debuginfo-7.2.4-150600.3.30.1 * redis-debugsource-7.2.4-150600.3.30.1 * redis-7.2.4-150600.3.30.1 ## References: * https://www.suse.com/security/cve/CVE-2026-81934.html * https://bugzilla.suse.com/show_bug.cgi?id=1277794 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:30:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:30:37 -0000 Subject: SUSE-SU-2026:4056-1: low: Security update for lcms2 Message-ID: <178881303714.10646.247557074974911287@2eb657abeeed> # Security update for lcms2 Announcement ID: SUSE-SU-2026:4056-1 Release Date: 2026-09-07T15:49:07Z Rating: low References: * bsc#1264994 Cross-References: * CVE-2026-41254 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for lcms2 fixes the following issue: * CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4056=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4056=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4056=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4056=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4056=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4056=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * lcms2-debugsource-2.12-150400.3.3.1 * lcms2-debuginfo-2.12-150400.3.3.1 * liblcms2-devel-2.12-150400.3.3.1 * liblcms2-2-2.12-150400.3.3.1 * lcms2-2.12-150400.3.3.1 * liblcms2-2-debuginfo-2.12-150400.3.3.1 * openSUSE Leap 15.4 (x86_64) * liblcms2-devel-32bit-2.12-150400.3.3.1 * liblcms2-2-32bit-2.12-150400.3.3.1 * liblcms2-2-32bit-debuginfo-2.12-150400.3.3.1 * openSUSE Leap 15.4 (aarch64_ilp32) * liblcms2-2-64bit-2.12-150400.3.3.1 * liblcms2-devel-64bit-2.12-150400.3.3.1 * liblcms2-2-64bit-debuginfo-2.12-150400.3.3.1 * openSUSE Leap 15.4 (noarch) * liblcms2-doc-2.12-150400.3.3.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * lcms2-debugsource-2.12-150400.3.3.1 * liblcms2-2-debuginfo-2.12-150400.3.3.1 * liblcms2-2-2.12-150400.3.3.1 * lcms2-debuginfo-2.12-150400.3.3.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * lcms2-debugsource-2.12-150400.3.3.1 * liblcms2-2-debuginfo-2.12-150400.3.3.1 * liblcms2-2-2.12-150400.3.3.1 * lcms2-debuginfo-2.12-150400.3.3.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * lcms2-debugsource-2.12-150400.3.3.1 * liblcms2-2-debuginfo-2.12-150400.3.3.1 * liblcms2-2-2.12-150400.3.3.1 * lcms2-debuginfo-2.12-150400.3.3.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * lcms2-debugsource-2.12-150400.3.3.1 * liblcms2-2-debuginfo-2.12-150400.3.3.1 * liblcms2-2-2.12-150400.3.3.1 * lcms2-debuginfo-2.12-150400.3.3.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * lcms2-debugsource-2.12-150400.3.3.1 * liblcms2-2-debuginfo-2.12-150400.3.3.1 * liblcms2-2-2.12-150400.3.3.1 * lcms2-debuginfo-2.12-150400.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://bugzilla.suse.com/show_bug.cgi?id=1264994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:31:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:31:33 -0000 Subject: SUSE-SU-2026:4055-1: low: Security update for bzip2 Message-ID: <178881309334.10646.15748359226246229863@2eb657abeeed> # Security update for bzip2 Announcement ID: SUSE-SU-2026:4055-1 Release Date: 2026-09-07T15:48:38Z Rating: low References: * bsc#1266786 Cross-References: * CVE-2026-42250 CVSS scores: * CVE-2026-42250 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42250 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-42250 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for bzip2 fixes the following issue: * CVE-2026-42250: off-by-one error in the bzip2recover utility when processing a specially crafted file can lead to a crash (bsc#1266786). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4055=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4055=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4055=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4055=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4055=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4055=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4055=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * bzip2-debuginfo-1.0.8-150400.3.4.1 * libbz2-1-debuginfo-1.0.8-150400.3.4.1 * bzip2-debugsource-1.0.8-150400.3.4.1 * libbz2-1-1.0.8-150400.3.4.1 * libbz2-devel-1.0.8-150400.3.4.1 * bzip2-1.0.8-150400.3.4.1 * openSUSE Leap 15.4 (noarch) * bzip2-doc-1.0.8-150400.3.4.1 * openSUSE Leap 15.4 (x86_64) * libbz2-devel-32bit-1.0.8-150400.3.4.1 * libbz2-1-32bit-debuginfo-1.0.8-150400.3.4.1 * libbz2-1-32bit-1.0.8-150400.3.4.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libbz2-1-64bit-debuginfo-1.0.8-150400.3.4.1 * libbz2-devel-64bit-1.0.8-150400.3.4.1 * libbz2-1-64bit-1.0.8-150400.3.4.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * bzip2-debuginfo-1.0.8-150400.3.4.1 * libbz2-1-debuginfo-1.0.8-150400.3.4.1 * bzip2-debugsource-1.0.8-150400.3.4.1 * libbz2-1-1.0.8-150400.3.4.1 * bzip2-1.0.8-150400.3.4.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * bzip2-debuginfo-1.0.8-150400.3.4.1 * libbz2-1-debuginfo-1.0.8-150400.3.4.1 * bzip2-debugsource-1.0.8-150400.3.4.1 * libbz2-1-1.0.8-150400.3.4.1 * bzip2-1.0.8-150400.3.4.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * bzip2-debuginfo-1.0.8-150400.3.4.1 * libbz2-1-debuginfo-1.0.8-150400.3.4.1 * bzip2-debugsource-1.0.8-150400.3.4.1 * libbz2-1-1.0.8-150400.3.4.1 * bzip2-1.0.8-150400.3.4.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * bzip2-debuginfo-1.0.8-150400.3.4.1 * libbz2-1-debuginfo-1.0.8-150400.3.4.1 * bzip2-debugsource-1.0.8-150400.3.4.1 * libbz2-1-1.0.8-150400.3.4.1 * bzip2-1.0.8-150400.3.4.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * bzip2-debuginfo-1.0.8-150400.3.4.1 * libbz2-1-debuginfo-1.0.8-150400.3.4.1 * bzip2-debugsource-1.0.8-150400.3.4.1 * libbz2-1-1.0.8-150400.3.4.1 * bzip2-1.0.8-150400.3.4.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * bzip2-debuginfo-1.0.8-150400.3.4.1 * libbz2-1-debuginfo-1.0.8-150400.3.4.1 * bzip2-debugsource-1.0.8-150400.3.4.1 * libbz2-1-1.0.8-150400.3.4.1 * libbz2-devel-1.0.8-150400.3.4.1 * bzip2-1.0.8-150400.3.4.1 * Basesystem Module 15-SP7 (x86_64) * libbz2-1-32bit-debuginfo-1.0.8-150400.3.4.1 * libbz2-1-32bit-1.0.8-150400.3.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42250.html * https://bugzilla.suse.com/show_bug.cgi?id=1266786 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:32:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:32:35 -0000 Subject: SUSE-SU-2026:4054-1: moderate: Security update for java-1_8_0-openjdk Message-ID: <178881315526.10646.16355889960099715666@2eb657abeeed> # Security update for java-1_8_0-openjdk Announcement ID: SUSE-SU-2026:4054-1 Release Date: 2026-09-07T15:47:55Z Rating: moderate References: * bsc#1275764 * bsc#1275777 * bsc#1275778 Cross-References: * CVE-2026-60589 * CVE-2026-61308 * CVE-2026-70907 CVSS scores: * CVE-2026-60589 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-60589 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61308 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-61308 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-70907 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-70907 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for java-1_8_0-openjdk fixes the following issues: Update to version jdk8u504 (icedtea 3.40.1). * CVE-2026-60589: unauthenticated attacker with network access via multiple protocols can gain unauthorized read access to sensitive data (bsc#1275777). * CVE-2026-61308: unauthenticated attacker with network access via HTTP can gain unauthorized access to critical data (bsc#1275778). * CVE-2026-70907: unauthenticated attacker with network access via TLS can gain the ability to cause a partial denial of service (bsc#1275764). Changes for java-1_8_0-openjdk: * Version jdk8u504 (icedtea 3.40.1): * Import of OpenJDK 8 u504 build 01 * JDK-8382471: Improve Resource Resolving * JDK-8384708: Enhance HTTP Connections * JDK-8385390: Update FreeType to 2.14.3 * JDK-8386205: Enhance TLS server * JDK-8388811: [8u] VS2010 build broken by JDK-8374058 * JDK-8389477: Bump update version for OpenJDK: 8u504 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4054=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4054=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-1_8_0-openjdk-1.8.0.504-27.134.1 * java-1_8_0-openjdk-demo-1.8.0.504-27.134.1 * java-1_8_0-openjdk-headless-1.8.0.504-27.134.1 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.504-27.134.1 * java-1_8_0-openjdk-debugsource-1.8.0.504-27.134.1 * java-1_8_0-openjdk-demo-debuginfo-1.8.0.504-27.134.1 * java-1_8_0-openjdk-devel-1.8.0.504-27.134.1 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.504-27.134.1 * java-1_8_0-openjdk-debuginfo-1.8.0.504-27.134.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * java-1_8_0-openjdk-1.8.0.504-27.134.1 * java-1_8_0-openjdk-demo-1.8.0.504-27.134.1 * java-1_8_0-openjdk-headless-1.8.0.504-27.134.1 * java-1_8_0-openjdk-headless-debuginfo-1.8.0.504-27.134.1 * java-1_8_0-openjdk-debugsource-1.8.0.504-27.134.1 * java-1_8_0-openjdk-demo-debuginfo-1.8.0.504-27.134.1 * java-1_8_0-openjdk-devel-1.8.0.504-27.134.1 * java-1_8_0-openjdk-devel-debuginfo-1.8.0.504-27.134.1 * java-1_8_0-openjdk-debuginfo-1.8.0.504-27.134.1 ## References: * https://www.suse.com/security/cve/CVE-2026-60589.html * https://www.suse.com/security/cve/CVE-2026-61308.html * https://www.suse.com/security/cve/CVE-2026-70907.html * https://bugzilla.suse.com/show_bug.cgi?id=1275764 * https://bugzilla.suse.com/show_bug.cgi?id=1275777 * https://bugzilla.suse.com/show_bug.cgi?id=1275778 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:33:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:33:16 -0000 Subject: SUSE-SU-2026:4053-1: moderate: Security update for wget Message-ID: <178881319623.10646.10093779363710384380@2eb657abeeed> # Security update for wget Announcement ID: SUSE-SU-2026:4053-1 Release Date: 2026-09-07T15:47:31Z Rating: moderate References: * bsc#1276962 Cross-References: * CVE-2026-16599 CVSS scores: * CVE-2026-16599 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-16599 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-16599 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Micro 5.5 An update that solves one vulnerability can now be installed. ## Description: This update for wget fixes the following issue: * CVE-2026-16599: server-controlled unbounded MD5 loop in FTP OPIE (bsc#1276962). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4053=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * wget-debugsource-1.20.3-150000.3.40.1 * wget-debuginfo-1.20.3-150000.3.40.1 * wget-1.20.3-150000.3.40.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16599.html * https://bugzilla.suse.com/show_bug.cgi?id=1276962 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:34:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:34:03 -0000 Subject: SUSE-SU-2026:4051-1: moderate: Security update for multipath-tools Message-ID: <178881324321.10646.6026073918499571782@2eb657abeeed> # Security update for multipath-tools Announcement ID: SUSE-SU-2026:4051-1 Release Date: 2026-09-07T15:47:06Z Rating: moderate References: * bsc#1277199 * bsc#1277203 * bsc#1277205 * bsc#1277208 * bsc#1277209 * bsc#1277210 * bsc#1277212 Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that has seven security fixes can now be installed. ## Description: This update for multipath-tools fixes the following issues: * Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205). * Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210). * SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212). * Local Denial of Service via Blocking IPC Send Operations (bsc#1277199). * Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209). * DoS on multipathd socket by exhausting connections (bsc#1277203). * Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208). Changes for multipath-tools: * Update to version 0.9.0+187+suse.5bd6993. * Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4051=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4051=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4051=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4051=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4051=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libdmmp-devel-0.9.0+187+suse.5bd6993-150400.4.25.1 * libdmmp0_2_0-0.9.0+187+suse.5bd6993-150400.4.25.1 * kpartx-0.9.0+187+suse.5bd6993-150400.4.25.1 * libmpath0-0.9.0+187+suse.5bd6993-150400.4.25.1 * multipath-tools-0.9.0+187+suse.5bd6993-150400.4.25.1 * libmpath0-debuginfo-0.9.0+187+suse.5bd6993-150400.4.25.1 * multipath-tools-debugsource-0.9.0+187+suse.5bd6993-150400.4.25.1 * kpartx-debuginfo-0.9.0+187+suse.5bd6993-150400.4.25.1 * multipath-tools-devel-0.9.0+187+suse.5bd6993-150400.4.25.1 * libdmmp0_2_0-debuginfo-0.9.0+187+suse.5bd6993-150400.4.25.1 * multipath-tools-debuginfo-0.9.0+187+suse.5bd6993-150400.4.25.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libmpath0-0.9.0+187+suse.5bd6993-150400.4.25.1 * kpartx-0.9.0+187+suse.5bd6993-150400.4.25.1 * multipath-tools-0.9.0+187+suse.5bd6993-150400.4.25.1 * libmpath0-debuginfo-0.9.0+187+suse.5bd6993-150400.4.25.1 * multipath-tools-debugsource-0.9.0+187+suse.5bd6993-150400.4.25.1 * kpartx-debuginfo-0.9.0+187+suse.5bd6993-150400.4.25.1 * multipath-tools-debuginfo-0.9.0+187+suse.5bd6993-150400.4.25.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libmpath0-0.9.0+187+suse.5bd6993-150400.4.25.1 * kpartx-0.9.0+187+suse.5bd6993-150400.4.25.1 * multipath-tools-0.9.0+187+suse.5bd6993-150400.4.25.1 * libmpath0-debuginfo-0.9.0+187+suse.5bd6993-150400.4.25.1 * multipath-tools-debugsource-0.9.0+187+suse.5bd6993-150400.4.25.1 * kpartx-debuginfo-0.9.0+187+suse.5bd6993-150400.4.25.1 * multipath-tools-debuginfo-0.9.0+187+suse.5bd6993-150400.4.25.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libmpath0-0.9.0+187+suse.5bd6993-150400.4.25.1 * kpartx-0.9.0+187+suse.5bd6993-150400.4.25.1 * multipath-tools-0.9.0+187+suse.5bd6993-150400.4.25.1 * libmpath0-debuginfo-0.9.0+187+suse.5bd6993-150400.4.25.1 * multipath-tools-debugsource-0.9.0+187+suse.5bd6993-150400.4.25.1 * kpartx-debuginfo-0.9.0+187+suse.5bd6993-150400.4.25.1 * multipath-tools-debuginfo-0.9.0+187+suse.5bd6993-150400.4.25.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libmpath0-0.9.0+187+suse.5bd6993-150400.4.25.1 * kpartx-0.9.0+187+suse.5bd6993-150400.4.25.1 * multipath-tools-0.9.0+187+suse.5bd6993-150400.4.25.1 * libmpath0-debuginfo-0.9.0+187+suse.5bd6993-150400.4.25.1 * multipath-tools-debugsource-0.9.0+187+suse.5bd6993-150400.4.25.1 * kpartx-debuginfo-0.9.0+187+suse.5bd6993-150400.4.25.1 * multipath-tools-debuginfo-0.9.0+187+suse.5bd6993-150400.4.25.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1277199 * https://bugzilla.suse.com/show_bug.cgi?id=1277203 * https://bugzilla.suse.com/show_bug.cgi?id=1277205 * https://bugzilla.suse.com/show_bug.cgi?id=1277208 * https://bugzilla.suse.com/show_bug.cgi?id=1277209 * https://bugzilla.suse.com/show_bug.cgi?id=1277210 * https://bugzilla.suse.com/show_bug.cgi?id=1277212 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:34:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:34:59 -0000 Subject: SUSE-SU-2026:4050-1: moderate: Security update for libusb-1_0 Message-ID: <178881329909.10646.16113387127692385001@2eb657abeeed> # Security update for libusb-1_0 Announcement ID: SUSE-SU-2026:4050-1 Release Date: 2026-09-07T13:55:42Z Rating: moderate References: * bsc#1266664 Cross-References: * CVE-2026-23679 CVSS scores: * CVE-2026-23679 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23679 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23679 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23679 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23679 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for libusb-1_0 fixes the following issue: * CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4050=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4050=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4050=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4050=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4050=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4050=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4050=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4050=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libusb-1_0-devel-1.0.24-150400.3.6.1 * libusb-1_0-0-debuginfo-1.0.24-150400.3.6.1 * libusb-1_0-debugsource-1.0.24-150400.3.6.1 * libusb-1_0-0-1.0.24-150400.3.6.1 * openSUSE Leap 15.4 (x86_64) * libusb-1_0-0-32bit-1.0.24-150400.3.6.1 * libusb-1_0-devel-32bit-1.0.24-150400.3.6.1 * libusb-1_0-0-32bit-debuginfo-1.0.24-150400.3.6.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libusb-1_0-0-64bit-debuginfo-1.0.24-150400.3.6.1 * libusb-1_0-0-64bit-1.0.24-150400.3.6.1 * libusb-1_0-devel-64bit-1.0.24-150400.3.6.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libusb-1_0-0-debuginfo-1.0.24-150400.3.6.1 * libusb-1_0-debugsource-1.0.24-150400.3.6.1 * libusb-1_0-0-1.0.24-150400.3.6.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libusb-1_0-0-debuginfo-1.0.24-150400.3.6.1 * libusb-1_0-debugsource-1.0.24-150400.3.6.1 * libusb-1_0-0-1.0.24-150400.3.6.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libusb-1_0-0-debuginfo-1.0.24-150400.3.6.1 * libusb-1_0-debugsource-1.0.24-150400.3.6.1 * libusb-1_0-0-1.0.24-150400.3.6.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libusb-1_0-0-debuginfo-1.0.24-150400.3.6.1 * libusb-1_0-debugsource-1.0.24-150400.3.6.1 * libusb-1_0-0-1.0.24-150400.3.6.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libusb-1_0-0-debuginfo-1.0.24-150400.3.6.1 * libusb-1_0-debugsource-1.0.24-150400.3.6.1 * libusb-1_0-0-1.0.24-150400.3.6.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libusb-1_0-devel-1.0.24-150400.3.6.1 * libusb-1_0-0-debuginfo-1.0.24-150400.3.6.1 * libusb-1_0-debugsource-1.0.24-150400.3.6.1 * libusb-1_0-0-1.0.24-150400.3.6.1 * SUSE Package Hub 15 15-SP7 (x86_64) * libusb-1_0-0-32bit-1.0.24-150400.3.6.1 * libusb-1_0-0-32bit-debuginfo-1.0.24-150400.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23679.html * https://bugzilla.suse.com/show_bug.cgi?id=1266664 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:35:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:35:55 -0000 Subject: SUSE-SU-2026:4049-1: moderate: Security update for wget Message-ID: <178881335514.10646.11830528342464177510@2eb657abeeed> # Security update for wget Announcement ID: SUSE-SU-2026:4049-1 Release Date: 2026-09-07T13:54:47Z Rating: moderate References: * bsc#1276962 Cross-References: * CVE-2026-16599 CVSS scores: * CVE-2026-16599 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-16599 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-16599 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for wget fixes the following issue: * CVE-2026-16599: server-controlled unbounded MD5 loop in FTP OPIE (bsc#1276962). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4049=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * wget-debuginfo-1.24.5-150700.3.12.1 * wget-1.24.5-150700.3.12.1 * wget-debugsource-1.24.5-150700.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16599.html * https://bugzilla.suse.com/show_bug.cgi?id=1276962 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:36:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:36:36 -0000 Subject: SUSE-SU-2026:4048-1: low: Security update for curl Message-ID: <178881339673.10646.16114516336374644132@2eb657abeeed> # Security update for curl Announcement ID: SUSE-SU-2026:4048-1 Release Date: 2026-09-07T13:54:21Z Rating: low References: * bsc#1277476 * bsc#1277479 * bsc#1277480 Cross-References: * CVE-2026-13608 * CVE-2026-80229 * CVE-2026-80230 CVSS scores: * CVE-2026-13608 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-13608 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-80229 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-80229 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-80230 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-80230 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues: * CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). * CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). * CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4048=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libcurl4-debuginfo-8.14.1-150700.7.26.1 * curl-debuginfo-8.14.1-150700.7.26.1 * libcurl4-8.14.1-150700.7.26.1 * curl-8.14.1-150700.7.26.1 * curl-debugsource-8.14.1-150700.7.26.1 * libcurl-devel-8.14.1-150700.7.26.1 * Basesystem Module 15-SP7 (x86_64) * libcurl4-32bit-8.14.1-150700.7.26.1 * libcurl4-32bit-debuginfo-8.14.1-150700.7.26.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13608.html * https://www.suse.com/security/cve/CVE-2026-80229.html * https://www.suse.com/security/cve/CVE-2026-80230.html * https://bugzilla.suse.com/show_bug.cgi?id=1277476 * https://bugzilla.suse.com/show_bug.cgi?id=1277479 * https://bugzilla.suse.com/show_bug.cgi?id=1277480 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:37:23 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:37:23 -0000 Subject: SUSE-SU-2026:4047-1: moderate: Security update for curl Message-ID: <178881344314.10646.6820736248541588092@2eb657abeeed> # Security update for curl Announcement ID: SUSE-SU-2026:4047-1 Release Date: 2026-09-07T13:53:52Z Rating: moderate References: * bsc#1262633 * bsc#1263440 * bsc#1264971 * bsc#1268412 * bsc#1277476 * bsc#1277479 * bsc#1277480 Cross-References: * CVE-2026-13608 * CVE-2026-5773 * CVE-2026-7168 * CVE-2026-80229 * CVE-2026-80230 * CVE-2026-8926 CVSS scores: * CVE-2026-13608 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-13608 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-5773 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-5773 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-5773 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-5773 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-7168 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-7168 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-7168 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-7168 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-80229 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-80229 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-80230 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-80230 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-8926 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8926 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-8926 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves six vulnerabilities and has one security fix can now be installed. ## Description: This update for curl fixes the following issues: * CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). * CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). * CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). * CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). * CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). * CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). Changes for curl: * Call http_size() first to prioritize Transfer-Encoding: chunked over a zero Content-Length empty body check (bsc#1264971) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4047=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4047=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4047=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * curl-debuginfo-8.14.1-150600.4.51.1 * libcurl4-8.14.1-150600.4.51.1 * libcurl4-debuginfo-8.14.1-150600.4.51.1 * curl-debugsource-8.14.1-150600.4.51.1 * libcurl-devel-8.14.1-150600.4.51.1 * curl-8.14.1-150600.4.51.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150600.4.51.1 * libcurl4-32bit-8.14.1-150600.4.51.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libcurl-mini4-8.14.1-150600.4.51.1 * curl-debuginfo-8.14.1-150600.4.51.1 * libcurl4-8.14.1-150600.4.51.1 * libcurl-devel-8.14.1-150600.4.51.1 * libcurl4-debuginfo-8.14.1-150600.4.51.1 * curl-debugsource-8.14.1-150600.4.51.1 * libcurl-mini4-debuginfo-8.14.1-150600.4.51.1 * curl-mini-debugsource-8.14.1-150600.4.51.1 * curl-8.14.1-150600.4.51.1 * openSUSE Leap 15.6 (noarch) * curl-fish-completion-8.14.1-150600.4.51.1 * curl-zsh-completion-8.14.1-150600.4.51.1 * libcurl-devel-doc-8.14.1-150600.4.51.1 * openSUSE Leap 15.6 (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150600.4.51.1 * libcurl4-32bit-8.14.1-150600.4.51.1 * libcurl-devel-32bit-8.14.1-150600.4.51.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libcurl4-64bit-debuginfo-8.14.1-150600.4.51.1 * libcurl4-64bit-8.14.1-150600.4.51.1 * libcurl-devel-64bit-8.14.1-150600.4.51.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * curl-debuginfo-8.14.1-150600.4.51.1 * libcurl4-8.14.1-150600.4.51.1 * libcurl4-debuginfo-8.14.1-150600.4.51.1 * curl-debugsource-8.14.1-150600.4.51.1 * libcurl-devel-8.14.1-150600.4.51.1 * curl-8.14.1-150600.4.51.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libcurl4-32bit-debuginfo-8.14.1-150600.4.51.1 * libcurl4-32bit-8.14.1-150600.4.51.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13608.html * https://www.suse.com/security/cve/CVE-2026-5773.html * https://www.suse.com/security/cve/CVE-2026-7168.html * https://www.suse.com/security/cve/CVE-2026-80229.html * https://www.suse.com/security/cve/CVE-2026-80230.html * https://www.suse.com/security/cve/CVE-2026-8926.html * https://bugzilla.suse.com/show_bug.cgi?id=1262633 * https://bugzilla.suse.com/show_bug.cgi?id=1263440 * https://bugzilla.suse.com/show_bug.cgi?id=1264971 * https://bugzilla.suse.com/show_bug.cgi?id=1268412 * https://bugzilla.suse.com/show_bug.cgi?id=1277476 * https://bugzilla.suse.com/show_bug.cgi?id=1277479 * https://bugzilla.suse.com/show_bug.cgi?id=1277480 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:38:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:38:18 -0000 Subject: SUSE-SU-2026:4046-1: moderate: Security update for perl-URI Message-ID: <178881349855.10646.9631471664917825111@2eb657abeeed> # Security update for perl-URI Announcement ID: SUSE-SU-2026:4046-1 Release Date: 2026-09-07T13:53:23Z Rating: moderate References: * bsc#1277886 Cross-References: * CVE-2026-19953 CVSS scores: * CVE-2026-19953 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L * CVE-2026-19953 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-19953 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for perl-URI fixes the following issue: * CVE-2026-19953: non-NFC host names encoded to non-standard punycode labels due to missing normalization in `nameprep` (bsc#1277886). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4046=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * perl-URI-1.73-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-19953.html * https://bugzilla.suse.com/show_bug.cgi?id=1277886 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:38:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:38:58 -0000 Subject: SUSE-SU-2026:4045-1: moderate: Security update for amazon-cloudwatch-agent Message-ID: <178881353862.10646.2729059797631867011@2eb657abeeed> # Security update for amazon-cloudwatch-agent Announcement ID: SUSE-SU-2026:4045-1 Release Date: 2026-09-07T13:52:57Z Rating: moderate References: * bsc#1276739 * bsc#1277995 Cross-References: * CVE-2026-37236 * CVE-2026-41178 CVSS scores: * CVE-2026-37236 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-37236 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-37236 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for amazon-cloudwatch-agent fixes the following issues: * CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST request through the X-HTTP-Method- Override header and bypass established access control (bsc#1277995). * CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276739). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-4045=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4045=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-4045=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-4045=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-4045=1 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * amazon-cloudwatch-agent-1.300069.0-150400.9.10.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * amazon-cloudwatch-agent-1.300069.0-150400.9.10.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * amazon-cloudwatch-agent-1.300069.0-150400.9.10.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * amazon-cloudwatch-agent-1.300069.0-150400.9.10.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * amazon-cloudwatch-agent-1.300069.0-150400.9.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-37236.html * https://www.suse.com/security/cve/CVE-2026-41178.html * https://bugzilla.suse.com/show_bug.cgi?id=1276739 * https://bugzilla.suse.com/show_bug.cgi?id=1277995 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:39:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:39:54 -0000 Subject: SUSE-SU-2026:4044-1: important: Security update for GraphicsMagick Message-ID: <178881359413.10646.18054899307940771238@2eb657abeeed> # Security update for GraphicsMagick Announcement ID: SUSE-SU-2026:4044-1 Release Date: 2026-09-07T09:26:20Z Rating: important References: * bsc#1248078 Cross-References: * CVE-2025-55154 CVSS scores: * CVE-2025-55154 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-55154 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-55154 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2025-55154 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for GraphicsMagick fixes the following issue: * CVE-2025-55154: integer overflow when performing magnified size calculations in ReadOneMNGIMage can lead to out-of- bounds write (bsc#1248078). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4044=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4044=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * GraphicsMagick-debuginfo-1.3.42-150600.3.45.1 * GraphicsMagick-1.3.42-150600.3.45.1 * GraphicsMagick-devel-1.3.42-150600.3.45.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.45.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.45.1 * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.45.1 * libGraphicsMagick3-config-1.3.42-150600.3.45.1 * GraphicsMagick-debugsource-1.3.42-150600.3.45.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.45.1 * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.45.1 * perl-GraphicsMagick-1.3.42-150600.3.45.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.45.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.45.1 * libGraphicsMagick++-devel-1.3.42-150600.3.45.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * GraphicsMagick-debuginfo-1.3.42-150600.3.45.1 * GraphicsMagick-1.3.42-150600.3.45.1 * GraphicsMagick-devel-1.3.42-150600.3.45.1 * libGraphicsMagick++-Q16-12-debuginfo-1.3.42-150600.3.45.1 * libGraphicsMagick++-Q16-12-1.3.42-150600.3.45.1 * libGraphicsMagickWand-Q16-2-debuginfo-1.3.42-150600.3.45.1 * libGraphicsMagick3-config-1.3.42-150600.3.45.1 * GraphicsMagick-debugsource-1.3.42-150600.3.45.1 * libGraphicsMagickWand-Q16-2-1.3.42-150600.3.45.1 * perl-GraphicsMagick-debuginfo-1.3.42-150600.3.45.1 * perl-GraphicsMagick-1.3.42-150600.3.45.1 * libGraphicsMagick-Q16-3-1.3.42-150600.3.45.1 * libGraphicsMagick-Q16-3-debuginfo-1.3.42-150600.3.45.1 * libGraphicsMagick++-devel-1.3.42-150600.3.45.1 ## References: * https://www.suse.com/security/cve/CVE-2025-55154.html * https://bugzilla.suse.com/show_bug.cgi?id=1248078 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:40:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:40:52 -0000 Subject: SUSE-SU-2026:4043-1: important: Security update for openssl-1_1 Message-ID: <178881365244.10646.6940450911274769578@2eb657abeeed> # Security update for openssl-1_1 Announcement ID: SUSE-SU-2026:4043-1 Release Date: 2026-09-07T08:30:31Z Rating: important References: * bsc#1274774 * bsc#1274788 * bsc#1274795 Cross-References: * CVE-2026-54874 * CVE-2026-63072 CVSS scores: * CVE-2026-54874 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-54874 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for openssl-1_1 fixes the following issues: August 2026 release. * CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). * CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4043=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4043=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * openssl-1_1-debugsource-1.1.1d-2.139.1 * libopenssl1_1-1.1.1d-2.139.1 * libopenssl1_1-hmac-1.1.1d-2.139.1 * libopenssl1_1-debuginfo-1.1.1d-2.139.1 * libopenssl-1_1-devel-1.1.1d-2.139.1 * openssl-1_1-debuginfo-1.1.1d-2.139.1 * openssl-1_1-1.1.1d-2.139.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libopenssl1_1-hmac-32bit-1.1.1d-2.139.1 * libopenssl1_1-32bit-1.1.1d-2.139.1 * libopenssl1_1-debuginfo-32bit-1.1.1d-2.139.1 * libopenssl-1_1-devel-32bit-1.1.1d-2.139.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * openssl-1_1-debugsource-1.1.1d-2.139.1 * libopenssl1_1-1.1.1d-2.139.1 * libopenssl1_1-32bit-1.1.1d-2.139.1 * libopenssl1_1-hmac-32bit-1.1.1d-2.139.1 * libopenssl1_1-debuginfo-32bit-1.1.1d-2.139.1 * libopenssl1_1-hmac-1.1.1d-2.139.1 * libopenssl1_1-debuginfo-1.1.1d-2.139.1 * libopenssl-1_1-devel-32bit-1.1.1d-2.139.1 * libopenssl-1_1-devel-1.1.1d-2.139.1 * openssl-1_1-debuginfo-1.1.1d-2.139.1 * openssl-1_1-1.1.1d-2.139.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54874.html * https://www.suse.com/security/cve/CVE-2026-63072.html * https://bugzilla.suse.com/show_bug.cgi?id=1274774 * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1274795 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:41:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:41:35 -0000 Subject: SUSE-SU-2026:4042-1: important: Security update for openssl-1_1-livepatches Message-ID: <178881369521.10646.2346953304186180564@2eb657abeeed> # Security update for openssl-1_1-livepatches Announcement ID: SUSE-SU-2026:4042-1 Release Date: 2026-09-07T08:30:15Z Rating: important References: * bsc#1271712 * bsc#1271713 * bsc#1274788 * bsc#1275133 Cross-References: * CVE-2026-63072 CVSS scores: * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability and has three security fixes can now be installed. ## Description: This update for openssl-1_1-livepatches fixes the following issues: * CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1275133, bsc#1274788). * HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker- controlled memory allocations (bsc#1271712, bsc#1271713). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-4042=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-4042=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP5 (x86_64) * openssl-1_1-livepatches-debugsource-0.8-150500.6.17.1 * openssl-1_1-livepatches-0.8-150500.6.17.1 * openssl-1_1-livepatches-debuginfo-0.8-150500.6.17.1 * openSUSE Leap 15.5 (x86_64) * openssl-1_1-livepatches-debugsource-0.8-150500.6.17.1 * openssl-1_1-livepatches-0.8-150500.6.17.1 * openssl-1_1-livepatches-debuginfo-0.8-150500.6.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-63072.html * https://bugzilla.suse.com/show_bug.cgi?id=1271712 * https://bugzilla.suse.com/show_bug.cgi?id=1271713 * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1275133 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:42:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:42:33 -0000 Subject: SUSE-SU-2026:4041-1: important: Security update for openssl-1_1 Message-ID: <178881375318.10646.7573161692698662434@2eb657abeeed> # Security update for openssl-1_1 Announcement ID: SUSE-SU-2026:4041-1 Release Date: 2026-09-07T08:30:04Z Rating: important References: * bsc#1274774 * bsc#1274788 * bsc#1274795 Cross-References: * CVE-2026-54874 * CVE-2026-63072 CVSS scores: * CVE-2026-54874 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-54874 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * Legacy Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for openssl-1_1 fixes the following issues: August 2026 release. * CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). * CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4041=1 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-4041=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-4041=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * openssl-1_1-debugsource-1.1.1w-150700.11.30.1 * openssl-1_1-debuginfo-1.1.1w-150700.11.30.1 * libopenssl1_1-debuginfo-1.1.1w-150700.11.30.1 * libopenssl1_1-1.1.1w-150700.11.30.1 * Basesystem Module 15-SP7 (x86_64) * libopenssl1_1-32bit-debuginfo-1.1.1w-150700.11.30.1 * libopenssl1_1-32bit-1.1.1w-150700.11.30.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * openssl-1_1-debugsource-1.1.1w-150700.11.30.1 * openssl-1_1-debuginfo-1.1.1w-150700.11.30.1 * libopenssl-1_1-devel-1.1.1w-150700.11.30.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * openssl-1_1-debugsource-1.1.1w-150700.11.30.1 * openssl-1_1-debuginfo-1.1.1w-150700.11.30.1 * openssl-1_1-1.1.1w-150700.11.30.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54874.html * https://www.suse.com/security/cve/CVE-2026-63072.html * https://bugzilla.suse.com/show_bug.cgi?id=1274774 * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1274795 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:43:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:43:18 -0000 Subject: SUSE-SU-2026:4040-1: important: Security update for openssl-3-livepatches Message-ID: <178881379813.10646.3422800903959812145@2eb657abeeed> # Security update for openssl-3-livepatches Announcement ID: SUSE-SU-2026:4040-1 Release Date: 2026-09-07T08:29:31Z Rating: important References: * bsc#1274788 * bsc#1274790 * bsc#1274792 * bsc#1275133 * bsc#1275143 * bsc#1275145 Cross-References: * CVE-2026-14457 * CVE-2026-63072 * CVE-2026-63076 CVSS scores: * CVE-2026-14457 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-14457 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities and has three security fixes can now be installed. ## Description: This update for openssl-3-livepatches fixes the following issues: * CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1275145, bsc#1274792). * CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1275133, bsc#1274788). * CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1275143, bsc#1274790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-4040=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le x86_64) * openssl-3-livepatches-debuginfo-0.6-150700.16.12.1 * openssl-3-livepatches-debugsource-0.6-150700.16.12.1 * openssl-3-livepatches-0.6-150700.16.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14457.html * https://www.suse.com/security/cve/CVE-2026-63072.html * https://www.suse.com/security/cve/CVE-2026-63076.html * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1274790 * https://bugzilla.suse.com/show_bug.cgi?id=1274792 * https://bugzilla.suse.com/show_bug.cgi?id=1275133 * https://bugzilla.suse.com/show_bug.cgi?id=1275143 * https://bugzilla.suse.com/show_bug.cgi?id=1275145 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:44:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:44:10 -0000 Subject: SUSE-SU-2026:4039-1: important: Security update for openssl-3 Message-ID: <178881385082.10646.15296971615406614890@2eb657abeeed> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:4039-1 Release Date: 2026-09-07T08:29:22Z Rating: important References: * bsc#1266343 * bsc#1274774 * bsc#1274777 * bsc#1274788 * bsc#1274790 * bsc#1274791 * bsc#1274792 * bsc#1274795 * bsc#1274796 * bsc#1274797 * bsc#1274798 * bsc#1275837 Cross-References: * CVE-2026-14456 * CVE-2026-14457 * CVE-2026-18798 * CVE-2026-34181 * CVE-2026-54874 * CVE-2026-63072 * CVE-2026-63073 * CVE-2026-63074 * CVE-2026-63075 * CVE-2026-63076 * CVE-2026-75803 CVSS scores: * CVE-2026-14456 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-14456 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-14457 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-14457 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-18798 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-18798 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34181 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34181 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-34181 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54874 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-54874 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63073 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-63073 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63074 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63074 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63075 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63075 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-75803 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-75803 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 11 vulnerabilities and has one security fix can now be installed. ## Description: This update for openssl-3 fixes the following issues: August 2026 release. * CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). * CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). * CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). * CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). * CVE-2026-54874: excessive Memory Use Buffering DTLS Records for a Future Epoch (bsc#1274795). * CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). * CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). * CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). * CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). * CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). * CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4039=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libopenssl3-3.5.0-150700.5.50.1 * openssl-3-debuginfo-3.5.0-150700.5.50.1 * openssl-3-3.5.0-150700.5.50.1 * libopenssl-3-fips-provider-debuginfo-3.5.0-150700.5.50.1 * openssl-3-debugsource-3.5.0-150700.5.50.1 * libopenssl3-debuginfo-3.5.0-150700.5.50.1 * libopenssl-3-devel-3.5.0-150700.5.50.1 * libopenssl-3-fips-provider-3.5.0-150700.5.50.1 * Basesystem Module 15-SP7 (x86_64) * libopenssl-3-fips-provider-32bit-3.5.0-150700.5.50.1 * libopenssl3-32bit-3.5.0-150700.5.50.1 * libopenssl3-32bit-debuginfo-3.5.0-150700.5.50.1 * libopenssl-3-fips-provider-32bit-debuginfo-3.5.0-150700.5.50.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14456.html * https://www.suse.com/security/cve/CVE-2026-14457.html * https://www.suse.com/security/cve/CVE-2026-18798.html * https://www.suse.com/security/cve/CVE-2026-34181.html * https://www.suse.com/security/cve/CVE-2026-54874.html * https://www.suse.com/security/cve/CVE-2026-63072.html * https://www.suse.com/security/cve/CVE-2026-63073.html * https://www.suse.com/security/cve/CVE-2026-63074.html * https://www.suse.com/security/cve/CVE-2026-63075.html * https://www.suse.com/security/cve/CVE-2026-63076.html * https://www.suse.com/security/cve/CVE-2026-75803.html * https://bugzilla.suse.com/show_bug.cgi?id=1266343 * https://bugzilla.suse.com/show_bug.cgi?id=1274774 * https://bugzilla.suse.com/show_bug.cgi?id=1274777 * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1274790 * https://bugzilla.suse.com/show_bug.cgi?id=1274791 * https://bugzilla.suse.com/show_bug.cgi?id=1274792 * https://bugzilla.suse.com/show_bug.cgi?id=1274795 * https://bugzilla.suse.com/show_bug.cgi?id=1274796 * https://bugzilla.suse.com/show_bug.cgi?id=1274797 * https://bugzilla.suse.com/show_bug.cgi?id=1274798 * https://bugzilla.suse.com/show_bug.cgi?id=1275837 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:44:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:44:55 -0000 Subject: SUSE-SU-2026:4038-1: important: Security update for openssl-3-livepatches Message-ID: <178881389585.10646.17713314003744870189@2eb657abeeed> # Security update for openssl-3-livepatches Announcement ID: SUSE-SU-2026:4038-1 Release Date: 2026-09-07T08:29:03Z Rating: important References: * bsc#1274788 * bsc#1274790 * bsc#1274792 * bsc#1275133 * bsc#1275143 * bsc#1275145 Cross-References: * CVE-2026-14457 * CVE-2026-63072 * CVE-2026-63076 CVSS scores: * CVE-2026-14457 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-14457 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves three vulnerabilities and has three security fixes can now be installed. ## Description: This update for openssl-3-livepatches fixes the following issues: * CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1275145, bsc#1274792). * CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1275133, bsc#1274788). * CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1275143, bsc#1274790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-4038=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4038=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (x86_64) * openssl-3-livepatches-0.6-150600.13.19.1 * openssl-3-livepatches-debugsource-0.6-150600.13.19.1 * openssl-3-livepatches-debuginfo-0.6-150600.13.19.1 * openSUSE Leap 15.6 (x86_64) * openssl-3-livepatches-0.6-150600.13.19.1 * openssl-3-livepatches-debugsource-0.6-150600.13.19.1 * openssl-3-livepatches-debuginfo-0.6-150600.13.19.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14457.html * https://www.suse.com/security/cve/CVE-2026-63072.html * https://www.suse.com/security/cve/CVE-2026-63076.html * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1274790 * https://bugzilla.suse.com/show_bug.cgi?id=1274792 * https://bugzilla.suse.com/show_bug.cgi?id=1275133 * https://bugzilla.suse.com/show_bug.cgi?id=1275143 * https://bugzilla.suse.com/show_bug.cgi?id=1275145 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:45:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:45:53 -0000 Subject: SUSE-SU-2026:4037-1: important: Security update for openssl-1_1-livepatches Message-ID: <178881395323.10646.13482839956217238735@2eb657abeeed> # Security update for openssl-1_1-livepatches Announcement ID: SUSE-SU-2026:4037-1 Release Date: 2026-09-07T08:28:58Z Rating: important References: * bsc#1274788 * bsc#1275133 Cross-References: * CVE-2026-63072 CVSS scores: * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability and has one security fix can now be installed. ## Description: This update for openssl-1_1-livepatches fixes the following issue: * CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1275133, bsc#1274788). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-4037=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le x86_64) * openssl-1_1-livepatches-debuginfo-0.8-150700.13.12.1 * openssl-1_1-livepatches-debugsource-0.8-150700.13.12.1 * openssl-1_1-livepatches-0.8-150700.13.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-63072.html * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1275133 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 7 20:46:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 07 Sep 2026 20:46:36 -0000 Subject: SUSE-SU-2026:4036-1: important: Security update for openssl-1_1-livepatches Message-ID: <178881399624.10646.9053254128440356337@2eb657abeeed> # Security update for openssl-1_1-livepatches Announcement ID: SUSE-SU-2026:4036-1 Release Date: 2026-09-07T08:28:51Z Rating: important References: * bsc#1271712 * bsc#1271713 * bsc#1274788 * bsc#1275133 Cross-References: * CVE-2026-63072 CVSS scores: * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability and has three security fixes can now be installed. ## Description: This update for openssl-1_1-livepatches fixes the following issues: * CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1275133, bsc#1274788). * HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker- controlled memory allocations (bsc#1271712, bsc#1271713). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-4036=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4036=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (x86_64) * openssl-1_1-livepatches-0.8-150600.11.9.1 * openssl-1_1-livepatches-debugsource-0.8-150600.11.9.1 * openssl-1_1-livepatches-debuginfo-0.8-150600.11.9.1 * openSUSE Leap 15.6 (x86_64) * openssl-1_1-livepatches-0.8-150600.11.9.1 * openssl-1_1-livepatches-debugsource-0.8-150600.11.9.1 * openssl-1_1-livepatches-debuginfo-0.8-150600.11.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-63072.html * https://bugzilla.suse.com/show_bug.cgi?id=1271712 * https://bugzilla.suse.com/show_bug.cgi?id=1271713 * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1275133 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:30:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:30:36 -0000 Subject: SUSE-SU-2026:4081-1: moderate: Security update for libidn Message-ID: <178887063654.401.15872037530582314859@d0473b53b788> # Security update for libidn Announcement ID: SUSE-SU-2026:4081-1 Release Date: 2026-09-08T07:14:43Z Rating: moderate References: * bsc#1268965 Cross-References: * CVE-2026-57053 CVSS scores: * CVE-2026-57053 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-57053 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-57053 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-57053 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libidn fixes the following issue: * CVE-2026-57053: out-of-bounds read in ToUnicode APIs (bsc#1268965). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4081=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libidn11-32bit-1.28-5.9.1 * libidn-tools-1.28-5.9.1 * libidn11-1.28-5.9.1 * libidn-tools-debuginfo-1.28-5.9.1 * libidn11-debuginfo-32bit-1.28-5.9.1 * libidn-devel-1.28-5.9.1 * libidn11-debuginfo-1.28-5.9.1 * libidn-debugsource-1.28-5.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-57053.html * https://bugzilla.suse.com/show_bug.cgi?id=1268965 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:31:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:31:15 -0000 Subject: SUSE-SU-2026:4080-1: moderate: Security update for libusb-1_0 Message-ID: <178887067556.401.277416250470962356@d0473b53b788> # Security update for libusb-1_0 Announcement ID: SUSE-SU-2026:4080-1 Release Date: 2026-09-08T07:14:26Z Rating: moderate References: * bsc#1266664 Cross-References: * CVE-2026-23679 CVSS scores: * CVE-2026-23679 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23679 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23679 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23679 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23679 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libusb-1_0 fixes the following issue: * CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4080=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libusb-1_0-0-debuginfo-1.0.20-7.3.1 * libusb-1_0-0-debuginfo-32bit-1.0.20-7.3.1 * libusb-1_0-devel-1.0.20-7.3.1 * libusb-1_0-0-1.0.20-7.3.1 * libusb-1_0-0-32bit-1.0.20-7.3.1 * libusb-1_0-debugsource-1.0.20-7.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23679.html * https://bugzilla.suse.com/show_bug.cgi?id=1266664 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:31:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:31:55 -0000 Subject: SUSE-SU-2026:4079-1: important: Security update for dracut Message-ID: <178887071570.401.14565460307487349508@d0473b53b788> # Security update for dracut Announcement ID: SUSE-SU-2026:4079-1 Release Date: 2026-09-08T07:14:09Z Rating: important References: * bsc#1268322 * bsc#1273580 Cross-References: * CVE-2026-16445 * CVE-2026-6893 CVSS scores: * CVE-2026-16445 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16445 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for dracut fixes the following issues: * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). * CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580). Changes for dracut: * Update to version 055+suse.408.g34171a9: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4079=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4079=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4079=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-4079=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4079=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4079=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * dracut-debuginfo-055+suse.408.g34171a9-150500.3.47.1 * dracut-mkinitrd-deprecated-055+suse.408.g34171a9-150500.3.47.1 * dracut-fips-055+suse.408.g34171a9-150500.3.47.1 * dracut-debugsource-055+suse.408.g34171a9-150500.3.47.1 * dracut-055+suse.408.g34171a9-150500.3.47.1 * dracut-ima-055+suse.408.g34171a9-150500.3.47.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * dracut-debuginfo-055+suse.408.g34171a9-150500.3.47.1 * dracut-mkinitrd-deprecated-055+suse.408.g34171a9-150500.3.47.1 * dracut-fips-055+suse.408.g34171a9-150500.3.47.1 * dracut-debugsource-055+suse.408.g34171a9-150500.3.47.1 * dracut-055+suse.408.g34171a9-150500.3.47.1 * dracut-ima-055+suse.408.g34171a9-150500.3.47.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * dracut-debuginfo-055+suse.408.g34171a9-150500.3.47.1 * dracut-mkinitrd-deprecated-055+suse.408.g34171a9-150500.3.47.1 * dracut-fips-055+suse.408.g34171a9-150500.3.47.1 * dracut-debugsource-055+suse.408.g34171a9-150500.3.47.1 * dracut-055+suse.408.g34171a9-150500.3.47.1 * dracut-ima-055+suse.408.g34171a9-150500.3.47.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * dracut-tools-055+suse.408.g34171a9-150500.3.47.1 * dracut-debuginfo-055+suse.408.g34171a9-150500.3.47.1 * dracut-ima-055+suse.408.g34171a9-150500.3.47.1 * dracut-mkinitrd-deprecated-055+suse.408.g34171a9-150500.3.47.1 * dracut-extra-055+suse.408.g34171a9-150500.3.47.1 * dracut-debugsource-055+suse.408.g34171a9-150500.3.47.1 * dracut-055+suse.408.g34171a9-150500.3.47.1 * dracut-fips-055+suse.408.g34171a9-150500.3.47.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * dracut-fips-055+suse.408.g34171a9-150500.3.47.1 * dracut-debugsource-055+suse.408.g34171a9-150500.3.47.1 * dracut-055+suse.408.g34171a9-150500.3.47.1 * dracut-debuginfo-055+suse.408.g34171a9-150500.3.47.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * dracut-debuginfo-055+suse.408.g34171a9-150500.3.47.1 * dracut-mkinitrd-deprecated-055+suse.408.g34171a9-150500.3.47.1 * dracut-fips-055+suse.408.g34171a9-150500.3.47.1 * dracut-debugsource-055+suse.408.g34171a9-150500.3.47.1 * dracut-055+suse.408.g34171a9-150500.3.47.1 * dracut-ima-055+suse.408.g34171a9-150500.3.47.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16445.html * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 * https://bugzilla.suse.com/show_bug.cgi?id=1273580 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:32:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:32:58 -0000 Subject: SUSE-SU-2026:4078-1: important: Security update for dracut Message-ID: <178887077883.401.5940641295515986088@d0473b53b788> # Security update for dracut Announcement ID: SUSE-SU-2026:4078-1 Release Date: 2026-09-08T07:13:24Z Rating: important References: * bsc#1268322 * bsc#1273580 Cross-References: * CVE-2026-16445 * CVE-2026-6893 CVSS scores: * CVE-2026-16445 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16445 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves two vulnerabilities can now be installed. ## Description: This update for dracut fixes the following issues: * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). * CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580). Changes for dracut: * Update to version 055+suse.371.g92f67c2: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4078=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4078=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4078=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4078=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4078=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4078=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4078=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4078=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4078=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * dracut-fips-055+suse.371.g92f67c2-150400.3.55.1 * dracut-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debugsource-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debuginfo-055+suse.371.g92f67c2-150400.3.55.1 * dracut-ima-055+suse.371.g92f67c2-150400.3.55.1 * dracut-mkinitrd-deprecated-055+suse.371.g92f67c2-150400.3.55.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * dracut-fips-055+suse.371.g92f67c2-150400.3.55.1 * dracut-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debugsource-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debuginfo-055+suse.371.g92f67c2-150400.3.55.1 * dracut-ima-055+suse.371.g92f67c2-150400.3.55.1 * dracut-mkinitrd-deprecated-055+suse.371.g92f67c2-150400.3.55.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * dracut-fips-055+suse.371.g92f67c2-150400.3.55.1 * dracut-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debugsource-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debuginfo-055+suse.371.g92f67c2-150400.3.55.1 * dracut-ima-055+suse.371.g92f67c2-150400.3.55.1 * dracut-mkinitrd-deprecated-055+suse.371.g92f67c2-150400.3.55.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * dracut-fips-055+suse.371.g92f67c2-150400.3.55.1 * dracut-055+suse.371.g92f67c2-150400.3.55.1 * dracut-mkinitrd-deprecated-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debugsource-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debuginfo-055+suse.371.g92f67c2-150400.3.55.1 * dracut-tools-055+suse.371.g92f67c2-150400.3.55.1 * dracut-ima-055+suse.371.g92f67c2-150400.3.55.1 * dracut-extra-055+suse.371.g92f67c2-150400.3.55.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * dracut-fips-055+suse.371.g92f67c2-150400.3.55.1 * dracut-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debugsource-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debuginfo-055+suse.371.g92f67c2-150400.3.55.1 * dracut-mkinitrd-deprecated-055+suse.371.g92f67c2-150400.3.55.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * dracut-fips-055+suse.371.g92f67c2-150400.3.55.1 * dracut-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debugsource-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debuginfo-055+suse.371.g92f67c2-150400.3.55.1 * dracut-mkinitrd-deprecated-055+suse.371.g92f67c2-150400.3.55.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * dracut-fips-055+suse.371.g92f67c2-150400.3.55.1 * dracut-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debugsource-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debuginfo-055+suse.371.g92f67c2-150400.3.55.1 * dracut-mkinitrd-deprecated-055+suse.371.g92f67c2-150400.3.55.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * dracut-fips-055+suse.371.g92f67c2-150400.3.55.1 * dracut-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debugsource-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debuginfo-055+suse.371.g92f67c2-150400.3.55.1 * dracut-mkinitrd-deprecated-055+suse.371.g92f67c2-150400.3.55.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * dracut-fips-055+suse.371.g92f67c2-150400.3.55.1 * dracut-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debugsource-055+suse.371.g92f67c2-150400.3.55.1 * dracut-debuginfo-055+suse.371.g92f67c2-150400.3.55.1 * dracut-ima-055+suse.371.g92f67c2-150400.3.55.1 * dracut-mkinitrd-deprecated-055+suse.371.g92f67c2-150400.3.55.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16445.html * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 * https://bugzilla.suse.com/show_bug.cgi?id=1273580 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:34:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:34:11 -0000 Subject: SUSE-SU-2026:4077-1: important: Security update for wireshark Message-ID: <178887085189.401.16564855472622977670@d0473b53b788> # Security update for wireshark Announcement ID: SUSE-SU-2026:4077-1 Release Date: 2026-09-08T07:12:31Z Rating: important References: * bsc#1271133 * bsc#1271134 * bsc#1271136 * bsc#1271137 * bsc#1271138 * bsc#1271139 * bsc#1271140 * bsc#1271142 * bsc#1271144 Cross-References: * CVE-2026-15163 * CVE-2026-15164 * CVE-2026-15166 * CVE-2026-15167 * CVE-2026-15168 * CVE-2026-15169 * CVE-2026-15170 * CVE-2026-15172 * CVE-2026-15174 CVSS scores: * CVE-2026-15163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15163 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15164 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15166 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15166 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15166 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15167 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15167 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15167 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15168 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-15168 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-15168 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-15169 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15169 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15169 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15170 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15170 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15172 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15172 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15174 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-15174 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves nine vulnerabilities can now be installed. ## Description: This update for wireshark fixes the following issues: * CVE-2026-15163: Denial of Service via multiple protocol dissector infinite loops (bsc#1271133). * CVE-2026-15164: Denial of Service vulnerability in ciscodump (bsc#1271134). * CVE-2026-15166: Denial of Service via IEEE 802.11 protocol dissector crash (bsc#1271136). * CVE-2026-15167: Denial of Service via DBS Etherwatch file parser crash (bsc#1271137). * CVE-2026-15168: BLF file parser allows possible information disclosure (bsc#1271138). * CVE-2026-15169: Denial of Service via UMTS FP protocol dissector crash (bsc#1271139). * CVE-2026-15170: Denial of service via Z39.50 protocol dissector crash (bsc#1271140). * CVE-2026-15172: Denial of service via FMP/NOTIFY protocol dissector crash (bsc#1271142). * CVE-2026-15174: Denial of Service via Catapult DCT2000 protocol dissector crash (bsc#1271144). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4077=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4077=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4077=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4077=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4077=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4077=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4077=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4077=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libwsutil13-debuginfo-3.6.24-150000.3.136.1 * wireshark-debugsource-3.6.24-150000.3.136.1 * libwireshark15-debuginfo-3.6.24-150000.3.136.1 * wireshark-ui-qt-3.6.24-150000.3.136.1 * libwiretap12-3.6.24-150000.3.136.1 * wireshark-debuginfo-3.6.24-150000.3.136.1 * libwireshark15-3.6.24-150000.3.136.1 * libwsutil13-3.6.24-150000.3.136.1 * wireshark-3.6.24-150000.3.136.1 * wireshark-ui-qt-debuginfo-3.6.24-150000.3.136.1 * libwiretap12-debuginfo-3.6.24-150000.3.136.1 * wireshark-devel-3.6.24-150000.3.136.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libwsutil13-debuginfo-3.6.24-150000.3.136.1 * wireshark-debugsource-3.6.24-150000.3.136.1 * libwireshark15-debuginfo-3.6.24-150000.3.136.1 * wireshark-ui-qt-3.6.24-150000.3.136.1 * libwiretap12-3.6.24-150000.3.136.1 * wireshark-debuginfo-3.6.24-150000.3.136.1 * libwireshark15-3.6.24-150000.3.136.1 * libwsutil13-3.6.24-150000.3.136.1 * wireshark-3.6.24-150000.3.136.1 * wireshark-ui-qt-debuginfo-3.6.24-150000.3.136.1 * libwiretap12-debuginfo-3.6.24-150000.3.136.1 * wireshark-devel-3.6.24-150000.3.136.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libwsutil13-debuginfo-3.6.24-150000.3.136.1 * wireshark-debugsource-3.6.24-150000.3.136.1 * libwireshark15-debuginfo-3.6.24-150000.3.136.1 * wireshark-ui-qt-3.6.24-150000.3.136.1 * libwiretap12-3.6.24-150000.3.136.1 * wireshark-debuginfo-3.6.24-150000.3.136.1 * libwireshark15-3.6.24-150000.3.136.1 * libwsutil13-3.6.24-150000.3.136.1 * wireshark-3.6.24-150000.3.136.1 * wireshark-ui-qt-debuginfo-3.6.24-150000.3.136.1 * libwiretap12-debuginfo-3.6.24-150000.3.136.1 * wireshark-devel-3.6.24-150000.3.136.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libwsutil13-debuginfo-3.6.24-150000.3.136.1 * wireshark-debugsource-3.6.24-150000.3.136.1 * libwireshark15-debuginfo-3.6.24-150000.3.136.1 * wireshark-ui-qt-3.6.24-150000.3.136.1 * libwiretap12-3.6.24-150000.3.136.1 * wireshark-debuginfo-3.6.24-150000.3.136.1 * libwireshark15-3.6.24-150000.3.136.1 * libwsutil13-3.6.24-150000.3.136.1 * wireshark-3.6.24-150000.3.136.1 * wireshark-ui-qt-debuginfo-3.6.24-150000.3.136.1 * libwiretap12-debuginfo-3.6.24-150000.3.136.1 * wireshark-devel-3.6.24-150000.3.136.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libwsutil13-debuginfo-3.6.24-150000.3.136.1 * wireshark-debugsource-3.6.24-150000.3.136.1 * libwireshark15-debuginfo-3.6.24-150000.3.136.1 * wireshark-ui-qt-3.6.24-150000.3.136.1 * libwiretap12-3.6.24-150000.3.136.1 * wireshark-debuginfo-3.6.24-150000.3.136.1 * libwireshark15-3.6.24-150000.3.136.1 * libwsutil13-3.6.24-150000.3.136.1 * wireshark-3.6.24-150000.3.136.1 * wireshark-ui-qt-debuginfo-3.6.24-150000.3.136.1 * libwiretap12-debuginfo-3.6.24-150000.3.136.1 * wireshark-devel-3.6.24-150000.3.136.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libwsutil13-debuginfo-3.6.24-150000.3.136.1 * wireshark-debugsource-3.6.24-150000.3.136.1 * libwireshark15-debuginfo-3.6.24-150000.3.136.1 * wireshark-ui-qt-3.6.24-150000.3.136.1 * libwiretap12-3.6.24-150000.3.136.1 * wireshark-debuginfo-3.6.24-150000.3.136.1 * libwireshark15-3.6.24-150000.3.136.1 * libwsutil13-3.6.24-150000.3.136.1 * wireshark-3.6.24-150000.3.136.1 * wireshark-ui-qt-debuginfo-3.6.24-150000.3.136.1 * libwiretap12-debuginfo-3.6.24-150000.3.136.1 * wireshark-devel-3.6.24-150000.3.136.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libwsutil13-debuginfo-3.6.24-150000.3.136.1 * wireshark-debugsource-3.6.24-150000.3.136.1 * libwireshark15-debuginfo-3.6.24-150000.3.136.1 * wireshark-ui-qt-3.6.24-150000.3.136.1 * libwiretap12-3.6.24-150000.3.136.1 * wireshark-debuginfo-3.6.24-150000.3.136.1 * libwireshark15-3.6.24-150000.3.136.1 * libwsutil13-3.6.24-150000.3.136.1 * wireshark-3.6.24-150000.3.136.1 * wireshark-ui-qt-debuginfo-3.6.24-150000.3.136.1 * libwiretap12-debuginfo-3.6.24-150000.3.136.1 * wireshark-devel-3.6.24-150000.3.136.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libwsutil13-debuginfo-3.6.24-150000.3.136.1 * wireshark-debugsource-3.6.24-150000.3.136.1 * libwireshark15-debuginfo-3.6.24-150000.3.136.1 * wireshark-ui-qt-3.6.24-150000.3.136.1 * libwiretap12-3.6.24-150000.3.136.1 * wireshark-debuginfo-3.6.24-150000.3.136.1 * libwireshark15-3.6.24-150000.3.136.1 * libwsutil13-3.6.24-150000.3.136.1 * wireshark-3.6.24-150000.3.136.1 * wireshark-ui-qt-debuginfo-3.6.24-150000.3.136.1 * libwiretap12-debuginfo-3.6.24-150000.3.136.1 * wireshark-devel-3.6.24-150000.3.136.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15163.html * https://www.suse.com/security/cve/CVE-2026-15164.html * https://www.suse.com/security/cve/CVE-2026-15166.html * https://www.suse.com/security/cve/CVE-2026-15167.html * https://www.suse.com/security/cve/CVE-2026-15168.html * https://www.suse.com/security/cve/CVE-2026-15169.html * https://www.suse.com/security/cve/CVE-2026-15170.html * https://www.suse.com/security/cve/CVE-2026-15172.html * https://www.suse.com/security/cve/CVE-2026-15174.html * https://bugzilla.suse.com/show_bug.cgi?id=1271133 * https://bugzilla.suse.com/show_bug.cgi?id=1271134 * https://bugzilla.suse.com/show_bug.cgi?id=1271136 * https://bugzilla.suse.com/show_bug.cgi?id=1271137 * https://bugzilla.suse.com/show_bug.cgi?id=1271138 * https://bugzilla.suse.com/show_bug.cgi?id=1271139 * https://bugzilla.suse.com/show_bug.cgi?id=1271140 * https://bugzilla.suse.com/show_bug.cgi?id=1271142 * https://bugzilla.suse.com/show_bug.cgi?id=1271144 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:34:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:34:51 -0000 Subject: SUSE-SU-2026:4076-1: important: Security update for python-tornado6 Message-ID: <178887089122.401.11520778354483668455@d0473b53b788> # Security update for python-tornado6 Announcement ID: SUSE-SU-2026:4076-1 Release Date: 2026-09-08T07:11:28Z Rating: important References: * bsc#1277725 Cross-References: * CVE-2026-82397 CVSS scores: * CVE-2026-82397 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-82397 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-tornado6 fixes the following issue * CVE-2026-82397: an unauthenticated request body containing millions of separator-delimited fields can synchronously stall the single-threaded event loop and delay every connection (bsc#1277725). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4076=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4076=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4076=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4076=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4076=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4076=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4076=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4076=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4076=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-4076=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4076=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4076=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.24.1 * python311-tornado6-6.3.2-150400.9.24.1 * python-tornado6-debugsource-6.3.2-150400.9.24.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.24.1 * python311-tornado6-6.3.2-150400.9.24.1 * python-tornado6-debugsource-6.3.2-150400.9.24.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.24.1 * python311-tornado6-6.3.2-150400.9.24.1 * python-tornado6-debugsource-6.3.2-150400.9.24.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.24.1 * python311-tornado6-6.3.2-150400.9.24.1 * python-tornado6-debugsource-6.3.2-150400.9.24.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.24.1 * python311-tornado6-6.3.2-150400.9.24.1 * python-tornado6-debugsource-6.3.2-150400.9.24.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.24.1 * python311-tornado6-6.3.2-150400.9.24.1 * python-tornado6-debugsource-6.3.2-150400.9.24.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.24.1 * python311-tornado6-6.3.2-150400.9.24.1 * python-tornado6-debugsource-6.3.2-150400.9.24.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.24.1 * python311-tornado6-6.3.2-150400.9.24.1 * python-tornado6-debugsource-6.3.2-150400.9.24.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.24.1 * python311-tornado6-6.3.2-150400.9.24.1 * python-tornado6-debugsource-6.3.2-150400.9.24.1 * Python 3 Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.24.1 * python311-tornado6-6.3.2-150400.9.24.1 * python-tornado6-debugsource-6.3.2-150400.9.24.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.24.1 * python311-tornado6-6.3.2-150400.9.24.1 * python-tornado6-debugsource-6.3.2-150400.9.24.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.3.2-150400.9.24.1 * python311-tornado6-6.3.2-150400.9.24.1 * python-tornado6-debugsource-6.3.2-150400.9.24.1 ## References: * https://www.suse.com/security/cve/CVE-2026-82397.html * https://bugzilla.suse.com/show_bug.cgi?id=1277725 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:35:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:35:46 -0000 Subject: SUSE-SU-2026:4075-1: moderate: Security update for rpcbind Message-ID: <178887094690.401.8627104972393174512@d0473b53b788> # Security update for rpcbind Announcement ID: SUSE-SU-2026:4075-1 Release Date: 2026-09-08T07:10:13Z Rating: moderate References: * bsc#1272340 Cross-References: * CVE-2026-16461 CVSS scores: * CVE-2026-16461 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-16461 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for rpcbind fixes the following issue: * CVE-2026-16461: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting (bsc#1272340). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4075=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * rpcbind-debugsource-0.2.3-24.15.1 * rpcbind-0.2.3-24.15.1 * rpcbind-debuginfo-0.2.3-24.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16461.html * https://bugzilla.suse.com/show_bug.cgi?id=1272340 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:36:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:36:25 -0000 Subject: SUSE-SU-2026:4074-1: moderate: Security update for wget Message-ID: <178887098568.401.7689053440932336925@d0473b53b788> # Security update for wget Announcement ID: SUSE-SU-2026:4074-1 Release Date: 2026-09-08T07:10:00Z Rating: moderate References: * bsc#1276962 Cross-References: * CVE-2026-16599 CVSS scores: * CVE-2026-16599 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-16599 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-16599 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for wget fixes the following issue: * CVE-2026-16599: server-controlled unbounded MD5 loop in FTP OPIE (bsc#1276962). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4074=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * wget-1.14-21.31.1 * wget-debugsource-1.14-21.31.1 * wget-debuginfo-1.14-21.31.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16599.html * https://bugzilla.suse.com/show_bug.cgi?id=1276962 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:37:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:37:04 -0000 Subject: SUSE-SU-2026:4073-1: important: Security update for python-tornado Message-ID: <178887102464.401.14226376121246331321@d0473b53b788> # Security update for python-tornado Announcement ID: SUSE-SU-2026:4073-1 Release Date: 2026-09-08T07:09:47Z Rating: important References: * bsc#1277725 Cross-References: * CVE-2026-82397 CVSS scores: * CVE-2026-82397 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-82397 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-tornado fixes the following issue: * CVE-2026-82397: an unauthenticated request body containing millions of separator-delimited fields can synchronously stall the single-threaded event loop and delay every connection (bsc#1277725). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4073=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4073=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4073=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4073=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4073=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4073=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4073=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4073=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4073=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4073=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4073=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4073=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4073=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4073=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4073=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4073=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * python-tornado-debuginfo-4.5.3-150000.3.28.1 * python3-tornado-4.5.3-150000.3.28.1 * python-tornado-debugsource-4.5.3-150000.3.28.1 * python3-tornado-debuginfo-4.5.3-150000.3.28.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * python-tornado-debuginfo-4.5.3-150000.3.28.1 * python3-tornado-4.5.3-150000.3.28.1 * python-tornado-debugsource-4.5.3-150000.3.28.1 * python3-tornado-debuginfo-4.5.3-150000.3.28.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * python-tornado-debuginfo-4.5.3-150000.3.28.1 * python3-tornado-4.5.3-150000.3.28.1 * python-tornado-debugsource-4.5.3-150000.3.28.1 * python3-tornado-debuginfo-4.5.3-150000.3.28.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * python-tornado-debuginfo-4.5.3-150000.3.28.1 * python3-tornado-4.5.3-150000.3.28.1 * python-tornado-debugsource-4.5.3-150000.3.28.1 * python3-tornado-debuginfo-4.5.3-150000.3.28.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * python-tornado-debuginfo-4.5.3-150000.3.28.1 * python3-tornado-4.5.3-150000.3.28.1 * python-tornado-debugsource-4.5.3-150000.3.28.1 * python3-tornado-debuginfo-4.5.3-150000.3.28.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python-tornado-debuginfo-4.5.3-150000.3.28.1 * python3-tornado-4.5.3-150000.3.28.1 * python-tornado-debugsource-4.5.3-150000.3.28.1 * python3-tornado-debuginfo-4.5.3-150000.3.28.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * python-tornado-debuginfo-4.5.3-150000.3.28.1 * python3-tornado-4.5.3-150000.3.28.1 * python-tornado-debugsource-4.5.3-150000.3.28.1 * python3-tornado-debuginfo-4.5.3-150000.3.28.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * python-tornado-debuginfo-4.5.3-150000.3.28.1 * python3-tornado-4.5.3-150000.3.28.1 * python-tornado-debugsource-4.5.3-150000.3.28.1 * python3-tornado-debuginfo-4.5.3-150000.3.28.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * python-tornado-debuginfo-4.5.3-150000.3.28.1 * python3-tornado-4.5.3-150000.3.28.1 * python-tornado-debugsource-4.5.3-150000.3.28.1 * python3-tornado-debuginfo-4.5.3-150000.3.28.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * python-tornado-debuginfo-4.5.3-150000.3.28.1 * python3-tornado-4.5.3-150000.3.28.1 * python-tornado-debugsource-4.5.3-150000.3.28.1 * python3-tornado-debuginfo-4.5.3-150000.3.28.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * python-tornado-debuginfo-4.5.3-150000.3.28.1 * python3-tornado-4.5.3-150000.3.28.1 * python-tornado-debugsource-4.5.3-150000.3.28.1 * python3-tornado-debuginfo-4.5.3-150000.3.28.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * python-tornado-debuginfo-4.5.3-150000.3.28.1 * python3-tornado-4.5.3-150000.3.28.1 * python-tornado-debugsource-4.5.3-150000.3.28.1 * python3-tornado-debuginfo-4.5.3-150000.3.28.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * python-tornado-debuginfo-4.5.3-150000.3.28.1 * python3-tornado-4.5.3-150000.3.28.1 * python-tornado-debugsource-4.5.3-150000.3.28.1 * python3-tornado-debuginfo-4.5.3-150000.3.28.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python-tornado-debuginfo-4.5.3-150000.3.28.1 * python3-tornado-4.5.3-150000.3.28.1 * python-tornado-debugsource-4.5.3-150000.3.28.1 * python3-tornado-debuginfo-4.5.3-150000.3.28.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python-tornado-debuginfo-4.5.3-150000.3.28.1 * python3-tornado-4.5.3-150000.3.28.1 * python-tornado-debugsource-4.5.3-150000.3.28.1 * python3-tornado-debuginfo-4.5.3-150000.3.28.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * python-tornado-debuginfo-4.5.3-150000.3.28.1 * python3-tornado-4.5.3-150000.3.28.1 * python-tornado-debugsource-4.5.3-150000.3.28.1 * python3-tornado-debuginfo-4.5.3-150000.3.28.1 ## References: * https://www.suse.com/security/cve/CVE-2026-82397.html * https://bugzilla.suse.com/show_bug.cgi?id=1277725 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:38:20 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:38:20 -0000 Subject: SUSE-SU-2026:4072-1: important: Security update for python-GitPython Message-ID: <178887110059.401.7694319199351619395@d0473b53b788> # Security update for python-GitPython Announcement ID: SUSE-SU-2026:4072-1 Release Date: 2026-09-08T07:07:37Z Rating: important References: * bsc#1264604 * bsc#1264605 * bsc#1264606 * bsc#1264608 * bsc#1273357 * bsc#1273358 * bsc#1273359 * bsc#1273364 * bsc#1273414 * bsc#1273498 * bsc#1275745 * bsc#1275746 * bsc#1275747 * bsc#1275748 * bsc#1275749 * bsc#1275750 * bsc#1275751 * bsc#1275752 * bsc#1275753 * bsc#1275754 * bsc#1275755 * bsc#1275756 * bsc#1275757 * bsc#1276430 * bsc#1276431 * bsc#1276432 * bsc#1276433 * bsc#1276434 Cross-References: * CVE-2026-42215 * CVE-2026-42284 * CVE-2026-44243 * CVE-2026-44244 * CVE-2026-67322 * CVE-2026-67323 * CVE-2026-67325 * CVE-2026-67326 * CVE-2026-69097 * CVE-2026-73619 * CVE-2026-73620 * CVE-2026-73621 * CVE-2026-73622 * CVE-2026-73623 * CVE-2026-73624 * CVE-2026-73625 * CVE-2026-76217 * CVE-2026-76218 * CVE-2026-76219 * CVE-2026-76220 * CVE-2026-76221 * CVE-2026-76222 * CVE-2026-78675 * CVE-2026-78676 * CVE-2026-78677 * CVE-2026-78678 * CVE-2026-78679 CVSS scores: * CVE-2026-42215 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42215 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42284 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42284 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-42284 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-44243 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44243 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-44243 ( NVD ): 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-44244 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-44244 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-67322 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-67322 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-67322 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-67323 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-67323 ( NVD ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-67323 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-67325 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-67325 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-67325 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-67326 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-67326 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-67326 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-69097 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-69097 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-69097 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-73619 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-73619 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-73619 ( NVD ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73619 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-73620 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73620 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-73620 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73620 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-73621 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-73621 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-73621 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73621 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-73622 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-73622 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-73622 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73622 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-73623 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73623 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-73623 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73623 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-73623 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-73624 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73624 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-73624 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73624 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-73625 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73625 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-73625 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73625 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-76217 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-76217 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-76217 ( NVD ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-76217 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-76218 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-76218 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-76218 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-76218 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-76218 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-76219 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-76219 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-76219 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-76219 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-76220 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-76220 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-76220 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-76220 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-76221 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-76221 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-76221 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-76221 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-76222 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-76222 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L * CVE-2026-76222 ( NVD ): 8.4 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-76222 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L * CVE-2026-78675 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-78675 ( NVD ): 8.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-78675 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-78675 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-78676 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-78676 ( NVD ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-78676 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-78677 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78677 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-78677 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78678 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78678 ( NVD ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-78678 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78679 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78679 ( NVD ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-78679 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 27 vulnerabilities and has one security fix can now be installed. ## Description: This update for python-GitPython fixes the following issues: * CVE-2026-42215: command injection via Git options bypass (bsc#1264604). * CVE-2026-42284: unsafe option check validates multi_options before shlex.split transforms it (bsc#1264605). * CVE-2026-44243: path traversal in GitPython reference APIs allows arbitrary file write and delete outside the repository (bsc#1264606). * CVE-2026-44244: newline injection in config_writer().set_value() enables RCE via core.hooksPath (bsc#1264608). * CVE-2026-67322: vulnerable to environment-variable exfiltration in Repo.clone_from() (bsc#1273357). * CVE-2026-67323: fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote() (bsc#1273358). * CVE-2026-67325: contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature (bsc#1273359). * CVE-2026-67326: fails to validate newline characters in the section parameter of config_writer() (bsc#1273364). * CVE-2026-69097: fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives through malicious submodule names (bsc#1273414). * CVE-2026-73619: incomplete denylist in the `unsafe_git_archive_options` guard that omits `--add-file` and `--add- virtual-file` options can lead to arbitrary file reads (bsc#1275755). * CVE-2026-73620: failure to guard git option forwarding in `IndexFile.checkout()` and `TagReference.create()` can lead to arbitrary file reads and writes (bsc#1275756). * CVE-2026-73621: argument injection in the `Commit.count()` method allows for destruction/blanking of arbitrary files (bsc#1275757). * CVE-2026-73622: failure to disable environment variable expansion in `Remote.create()` and `Submodule.add()` URL handling allows for secret exfiltration via URLs containing variable references (bsc#1275751). * CVE-2026-73623: incomplete denylist in `unsafe_git_clone_options` that omits `--template` allows for arbitrary command execution (bsc#1275752). * CVE-2026-73624: `Diffable.diff` method fails to validate git options passed through `kwargs`, which can lead to arbitrary file writes (bsc#1275753). * CVE-2026-73625: `check_unsafe_options` guard bypass via smuggling of git options inside single-character `kwarg` values can lead to arbitrary code execution (bsc#1275754). * CVE-2026-76217: failure to validate options passed to `git rm` and `git checkout` commands in `IndexFile.remove()` and `Head.checkout()` can lead to arbitrary file reads (bsc#1275745). * CVE-2026-76218: unguarded git option forwarding in `Repo.init` allows for arbitrary command execution (bsc#1275746). * CVE-2026-76219: unguarded `git read-tree` option forwarding in `IndexFile.from_tree/reset/merge_tree` can lead to arbitrary file overwrites (bsc#1275747). * CVE-2026-76220: `check_unsafe_options` guard can be bypassed by combining a single-character `kwarg` with `split_single_char_options=False`, which can lead to arbitrary OS command injection (bsc#1275748). * CVE-2026-76221: `config-name` injection in the `option-name` validator can lead to remote code execution (bsc#1275749). * CVE-2026-76222: failure to validate submodule names from `.gitmodules` files allows creation of Git repositories at arbitrary filesystem paths outside the intended clone directory (bsc#1275750). * CVE-2026-78675: fails to disable merge_includes when parsing .gitmodules, allowing attackers to disclose local file content by including arbitrary file paths via [include] directives (bsc#1276434). * CVE-2026-78676: fails to safely re-serialize multi-line git-config values during write operations, corrupting dormant quoted values into injected directives (bsc#1276433). * CVE-2026-78677: allowing creation of arbitrary git directories outside the intended clone destination (bsc#1276432). * CVE-2026-78678: an incomplete denylist in the unsafe_git_revision_options guard that omits --contents and -S options, allowing attackers to read arbitrary files (bsc#1276431). * CVE-2026-78679: an arbitrary file read vulnerability in TagReference.create() (bsc#1276430). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4072=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4072=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4072=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4072=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4072=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4072=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4072=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4072=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4072=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-4072=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4072=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4072=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.8.1 * openSUSE Leap 15.4 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.8.1 * Python 3 Module 15-SP7 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.8.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.8.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42215.html * https://www.suse.com/security/cve/CVE-2026-42284.html * https://www.suse.com/security/cve/CVE-2026-44243.html * https://www.suse.com/security/cve/CVE-2026-44244.html * https://www.suse.com/security/cve/CVE-2026-67322.html * https://www.suse.com/security/cve/CVE-2026-67323.html * https://www.suse.com/security/cve/CVE-2026-67325.html * https://www.suse.com/security/cve/CVE-2026-67326.html * https://www.suse.com/security/cve/CVE-2026-69097.html * https://www.suse.com/security/cve/CVE-2026-73619.html * https://www.suse.com/security/cve/CVE-2026-73620.html * https://www.suse.com/security/cve/CVE-2026-73621.html * https://www.suse.com/security/cve/CVE-2026-73622.html * https://www.suse.com/security/cve/CVE-2026-73623.html * https://www.suse.com/security/cve/CVE-2026-73624.html * https://www.suse.com/security/cve/CVE-2026-73625.html * https://www.suse.com/security/cve/CVE-2026-76217.html * https://www.suse.com/security/cve/CVE-2026-76218.html * https://www.suse.com/security/cve/CVE-2026-76219.html * https://www.suse.com/security/cve/CVE-2026-76220.html * https://www.suse.com/security/cve/CVE-2026-76221.html * https://www.suse.com/security/cve/CVE-2026-76222.html * https://www.suse.com/security/cve/CVE-2026-78675.html * https://www.suse.com/security/cve/CVE-2026-78676.html * https://www.suse.com/security/cve/CVE-2026-78677.html * https://www.suse.com/security/cve/CVE-2026-78678.html * https://www.suse.com/security/cve/CVE-2026-78679.html * https://bugzilla.suse.com/show_bug.cgi?id=1264604 * https://bugzilla.suse.com/show_bug.cgi?id=1264605 * https://bugzilla.suse.com/show_bug.cgi?id=1264606 * https://bugzilla.suse.com/show_bug.cgi?id=1264608 * https://bugzilla.suse.com/show_bug.cgi?id=1273357 * https://bugzilla.suse.com/show_bug.cgi?id=1273358 * https://bugzilla.suse.com/show_bug.cgi?id=1273359 * https://bugzilla.suse.com/show_bug.cgi?id=1273364 * https://bugzilla.suse.com/show_bug.cgi?id=1273414 * https://bugzilla.suse.com/show_bug.cgi?id=1273498 * https://bugzilla.suse.com/show_bug.cgi?id=1275745 * https://bugzilla.suse.com/show_bug.cgi?id=1275746 * https://bugzilla.suse.com/show_bug.cgi?id=1275747 * https://bugzilla.suse.com/show_bug.cgi?id=1275748 * https://bugzilla.suse.com/show_bug.cgi?id=1275749 * https://bugzilla.suse.com/show_bug.cgi?id=1275750 * https://bugzilla.suse.com/show_bug.cgi?id=1275751 * https://bugzilla.suse.com/show_bug.cgi?id=1275752 * https://bugzilla.suse.com/show_bug.cgi?id=1275753 * https://bugzilla.suse.com/show_bug.cgi?id=1275754 * https://bugzilla.suse.com/show_bug.cgi?id=1275755 * https://bugzilla.suse.com/show_bug.cgi?id=1275756 * https://bugzilla.suse.com/show_bug.cgi?id=1275757 * https://bugzilla.suse.com/show_bug.cgi?id=1276430 * https://bugzilla.suse.com/show_bug.cgi?id=1276431 * https://bugzilla.suse.com/show_bug.cgi?id=1276432 * https://bugzilla.suse.com/show_bug.cgi?id=1276433 * https://bugzilla.suse.com/show_bug.cgi?id=1276434 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:39:20 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:39:20 -0000 Subject: SUSE-SU-2026:4071-1: low: Security update for curl Message-ID: <178887116003.401.3995445972400593706@d0473b53b788> # Security update for curl Announcement ID: SUSE-SU-2026:4071-1 Release Date: 2026-09-08T07:06:13Z Rating: low References: * bsc#1277476 * bsc#1277479 * bsc#1277480 Cross-References: * CVE-2026-13608 * CVE-2026-80229 * CVE-2026-80230 CVSS scores: * CVE-2026-13608 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-13608 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-80229 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-80229 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-80230 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-80230 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues: * CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). * CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). * CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4071=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libcurl4-8.0.1-11.129.1 * libcurl-devel-8.0.1-11.129.1 * libcurl4-debuginfo-8.0.1-11.129.1 * libcurl4-debuginfo-32bit-8.0.1-11.129.1 * curl-8.0.1-11.129.1 * libcurl4-32bit-8.0.1-11.129.1 * curl-debugsource-8.0.1-11.129.1 * curl-debuginfo-8.0.1-11.129.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13608.html * https://www.suse.com/security/cve/CVE-2026-80229.html * https://www.suse.com/security/cve/CVE-2026-80230.html * https://bugzilla.suse.com/show_bug.cgi?id=1277476 * https://bugzilla.suse.com/show_bug.cgi?id=1277479 * https://bugzilla.suse.com/show_bug.cgi?id=1277480 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:39:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:39:59 -0000 Subject: SUSE-SU-2026:4070-1: moderate: Security update for perl-URI Message-ID: <178887119954.401.6998161395525805498@d0473b53b788> # Security update for perl-URI Announcement ID: SUSE-SU-2026:4070-1 Release Date: 2026-09-08T07:06:01Z Rating: moderate References: * bsc#1277886 Cross-References: * CVE-2026-19953 CVSS scores: * CVE-2026-19953 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L * CVE-2026-19953 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-19953 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for perl-URI fixes the following issue: * CVE-2026-19953: non-NFC host names encoded to non-standard punycode labels due to missing normalization in `nameprep` (bsc#1277886). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4070=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * perl-URI-1.60-9.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-19953.html * https://bugzilla.suse.com/show_bug.cgi?id=1277886 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:40:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:40:40 -0000 Subject: SUSE-SU-2026:4069-1: important: Security update for redis7 Message-ID: <178887124005.401.963452810563537289@d0473b53b788> # Security update for redis7 Announcement ID: SUSE-SU-2026:4069-1 Release Date: 2026-09-08T07:05:44Z Rating: important References: * bsc#1277794 Cross-References: * CVE-2026-81934 CVSS scores: * CVE-2026-81934 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-81934 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-81934 ( NVD ): 7.5 CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-81934 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for redis7 fixes the following issue: * CVE-2026-81934: TLS pending-data handling can cause use-after-free (bsc#1277794). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4069=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4069=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4069=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-4069=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4069=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * redis7-7.0.8-150500.3.37.1 * redis7-debuginfo-7.0.8-150500.3.37.1 * redis7-debugsource-7.0.8-150500.3.37.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * redis7-7.0.8-150500.3.37.1 * redis7-debuginfo-7.0.8-150500.3.37.1 * redis7-debugsource-7.0.8-150500.3.37.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * redis7-7.0.8-150500.3.37.1 * redis7-debuginfo-7.0.8-150500.3.37.1 * redis7-debugsource-7.0.8-150500.3.37.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * redis7-7.0.8-150500.3.37.1 * redis7-debuginfo-7.0.8-150500.3.37.1 * redis7-debugsource-7.0.8-150500.3.37.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * redis7-7.0.8-150500.3.37.1 * redis7-debuginfo-7.0.8-150500.3.37.1 * redis7-debugsource-7.0.8-150500.3.37.1 ## References: * https://www.suse.com/security/cve/CVE-2026-81934.html * https://bugzilla.suse.com/show_bug.cgi?id=1277794 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:41:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:41:35 -0000 Subject: SUSE-SU-2026:4068-1: important: Security update for redis Message-ID: <178887129590.401.2906853686275695329@d0473b53b788> # Security update for redis Announcement ID: SUSE-SU-2026:4068-1 Release Date: 2026-09-08T07:05:14Z Rating: important References: * bsc#1277794 Cross-References: * CVE-2026-81934 CVSS scores: * CVE-2026-81934 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-81934 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-81934 ( NVD ): 7.5 CVSS:4.0/AV:A/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-81934 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for redis fixes the following issue: * CVE-2026-81934: TLS pending-data handling can cause use-after-free (bsc#1277794). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4068=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4068=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4068=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4068=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4068=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4068=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4068=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4068=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4068=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * redis-debuginfo-6.2.6-150400.3.52.1 * redis-6.2.6-150400.3.52.1 * redis-debugsource-6.2.6-150400.3.52.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * redis-debuginfo-6.2.6-150400.3.52.1 * redis-6.2.6-150400.3.52.1 * redis-debugsource-6.2.6-150400.3.52.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * redis-debuginfo-6.2.6-150400.3.52.1 * redis-6.2.6-150400.3.52.1 * redis-debugsource-6.2.6-150400.3.52.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * redis-debuginfo-6.2.6-150400.3.52.1 * redis-6.2.6-150400.3.52.1 * redis-debugsource-6.2.6-150400.3.52.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * redis-debuginfo-6.2.6-150400.3.52.1 * redis-6.2.6-150400.3.52.1 * redis-debugsource-6.2.6-150400.3.52.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * redis-debuginfo-6.2.6-150400.3.52.1 * redis-6.2.6-150400.3.52.1 * redis-debugsource-6.2.6-150400.3.52.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * redis-debuginfo-6.2.6-150400.3.52.1 * redis-6.2.6-150400.3.52.1 * redis-debugsource-6.2.6-150400.3.52.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * redis-debuginfo-6.2.6-150400.3.52.1 * redis-6.2.6-150400.3.52.1 * redis-debugsource-6.2.6-150400.3.52.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * redis-debuginfo-6.2.6-150400.3.52.1 * redis-6.2.6-150400.3.52.1 * redis-debugsource-6.2.6-150400.3.52.1 ## References: * https://www.suse.com/security/cve/CVE-2026-81934.html * https://bugzilla.suse.com/show_bug.cgi?id=1277794 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:42:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:42:32 -0000 Subject: SUSE-SU-2026:4067-1: important: Security update for NetworkManager Message-ID: <178887135225.401.14159934861383495013@d0473b53b788> # Security update for NetworkManager Announcement ID: SUSE-SU-2026:4067-1 Release Date: 2026-09-08T07:03:50Z Rating: important References: * bsc#1267696 * bsc#1276764 Cross-References: * CVE-2026-10805 * CVE-2026-19685 CVSS scores: * CVE-2026-10805 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-10805 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19685 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-19685 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-19685 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19685 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro for Rancher 5.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for NetworkManager fixes the following issues: * CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). * CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4067=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4067=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * NetworkManager-1.38.2-150400.3.8.1 * NetworkManager-bluetooth-debuginfo-1.38.2-150400.3.8.1 * NetworkManager-cloud-setup-1.38.2-150400.3.8.1 * NetworkManager-cloud-setup-debuginfo-1.38.2-150400.3.8.1 * NetworkManager-tui-debuginfo-1.38.2-150400.3.8.1 * NetworkManager-pppoe-debuginfo-1.38.2-150400.3.8.1 * libnm0-1.38.2-150400.3.8.1 * NetworkManager-bluetooth-1.38.2-150400.3.8.1 * libnm0-debuginfo-1.38.2-150400.3.8.1 * NetworkManager-wwan-debuginfo-1.38.2-150400.3.8.1 * typelib-1_0-NM-1_0-1.38.2-150400.3.8.1 * NetworkManager-wwan-1.38.2-150400.3.8.1 * NetworkManager-pppoe-1.38.2-150400.3.8.1 * NetworkManager-debuginfo-1.38.2-150400.3.8.1 * NetworkManager-tui-1.38.2-150400.3.8.1 * NetworkManager-debugsource-1.38.2-150400.3.8.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * NetworkManager-1.38.2-150400.3.8.1 * NetworkManager-bluetooth-debuginfo-1.38.2-150400.3.8.1 * NetworkManager-cloud-setup-1.38.2-150400.3.8.1 * NetworkManager-cloud-setup-debuginfo-1.38.2-150400.3.8.1 * NetworkManager-tui-debuginfo-1.38.2-150400.3.8.1 * NetworkManager-pppoe-debuginfo-1.38.2-150400.3.8.1 * libnm0-1.38.2-150400.3.8.1 * NetworkManager-bluetooth-1.38.2-150400.3.8.1 * libnm0-debuginfo-1.38.2-150400.3.8.1 * NetworkManager-wwan-debuginfo-1.38.2-150400.3.8.1 * typelib-1_0-NM-1_0-1.38.2-150400.3.8.1 * NetworkManager-wwan-1.38.2-150400.3.8.1 * NetworkManager-pppoe-1.38.2-150400.3.8.1 * NetworkManager-debuginfo-1.38.2-150400.3.8.1 * NetworkManager-tui-1.38.2-150400.3.8.1 * NetworkManager-debugsource-1.38.2-150400.3.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10805.html * https://www.suse.com/security/cve/CVE-2026-19685.html * https://bugzilla.suse.com/show_bug.cgi?id=1267696 * https://bugzilla.suse.com/show_bug.cgi?id=1276764 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:43:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:43:12 -0000 Subject: SUSE-SU-2026:4066-1: important: Security update for NetworkManager Message-ID: <178887139243.401.8265174459837874225@d0473b53b788> # Security update for NetworkManager Announcement ID: SUSE-SU-2026:4066-1 Release Date: 2026-09-08T07:03:23Z Rating: important References: * bsc#1267696 * bsc#1276764 Cross-References: * CVE-2026-10805 * CVE-2026-19685 CVSS scores: * CVE-2026-10805 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-10805 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19685 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-19685 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-19685 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19685 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves two vulnerabilities can now be installed. ## Description: This update for NetworkManager fixes the following issues: * CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). * CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4066=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4066=1 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * NetworkManager-tui-1.38.2-150400.3.9.1 * NetworkManager-tui-debuginfo-1.38.2-150400.3.9.1 * NetworkManager-pppoe-1.38.2-150400.3.9.1 * NetworkManager-bluetooth-debuginfo-1.38.2-150400.3.9.1 * libnm0-debuginfo-1.38.2-150400.3.9.1 * NetworkManager-bluetooth-1.38.2-150400.3.9.1 * NetworkManager-debuginfo-1.38.2-150400.3.9.1 * NetworkManager-wwan-debuginfo-1.38.2-150400.3.9.1 * NetworkManager-wwan-1.38.2-150400.3.9.1 * typelib-1_0-NM-1_0-1.38.2-150400.3.9.1 * NetworkManager-cloud-setup-1.38.2-150400.3.9.1 * NetworkManager-pppoe-debuginfo-1.38.2-150400.3.9.1 * NetworkManager-debugsource-1.38.2-150400.3.9.1 * NetworkManager-cloud-setup-debuginfo-1.38.2-150400.3.9.1 * libnm0-1.38.2-150400.3.9.1 * NetworkManager-1.38.2-150400.3.9.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * NetworkManager-tui-1.38.2-150400.3.9.1 * NetworkManager-tui-debuginfo-1.38.2-150400.3.9.1 * NetworkManager-pppoe-1.38.2-150400.3.9.1 * NetworkManager-bluetooth-debuginfo-1.38.2-150400.3.9.1 * libnm0-debuginfo-1.38.2-150400.3.9.1 * NetworkManager-bluetooth-1.38.2-150400.3.9.1 * NetworkManager-debuginfo-1.38.2-150400.3.9.1 * NetworkManager-wwan-debuginfo-1.38.2-150400.3.9.1 * NetworkManager-wwan-1.38.2-150400.3.9.1 * typelib-1_0-NM-1_0-1.38.2-150400.3.9.1 * NetworkManager-cloud-setup-1.38.2-150400.3.9.1 * NetworkManager-pppoe-debuginfo-1.38.2-150400.3.9.1 * NetworkManager-debugsource-1.38.2-150400.3.9.1 * NetworkManager-cloud-setup-debuginfo-1.38.2-150400.3.9.1 * libnm0-1.38.2-150400.3.9.1 * NetworkManager-1.38.2-150400.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10805.html * https://www.suse.com/security/cve/CVE-2026-19685.html * https://bugzilla.suse.com/show_bug.cgi?id=1267696 * https://bugzilla.suse.com/show_bug.cgi?id=1276764 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:43:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:43:51 -0000 Subject: SUSE-SU-2026:4065-1: moderate: Security update for perl-Net-DNS Message-ID: <178887143126.401.5890739360581053360@d0473b53b788> # Security update for perl-Net-DNS Announcement ID: SUSE-SU-2026:4065-1 Release Date: 2026-09-08T07:03:05Z Rating: moderate References: * bsc#1278084 Cross-References: * CVE-2026-81928 CVSS scores: * CVE-2026-81928 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-81928 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for perl-Net-DNS fixes the following issue: * CVE-2026-81928: memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record (bsc#1278084). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4065=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * perl-Net-DNS-debugsource-0.73-5.6.1 * perl-Net-DNS-debuginfo-0.73-5.6.1 * perl-Net-DNS-0.73-5.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-81928.html * https://bugzilla.suse.com/show_bug.cgi?id=1278084 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:44:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:44:43 -0000 Subject: SUSE-SU-2026:4064-1: moderate: Security update for multipath-tools Message-ID: <178887148375.401.14265933067665364986@d0473b53b788> # Security update for multipath-tools Announcement ID: SUSE-SU-2026:4064-1 Release Date: 2026-09-08T07:02:50Z Rating: moderate References: * bsc#1277199 * bsc#1277203 * bsc#1277205 * bsc#1277208 * bsc#1277209 * bsc#1277210 * bsc#1277212 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Micro 5.5 An update that has seven security fixes can now be installed. ## Description: This update for multipath-tools fixes the following issues: * Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205). * Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210). * SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212). * Local Denial of Service via Blocking IPC Send Operations (bsc#1277199). * Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209). * DoS on multipathd socket by exhausting connections (bsc#1277203). * Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208). Changes for multipath-tools: * Update to version 0.9.4+153+suse.eec9ef1. * Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-4064=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4064=1 ## Package List: * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * libmpath0-0.9.4+153+suse.eec9ef1-150500.3.15.1 * multipath-tools-debuginfo-0.9.4+153+suse.eec9ef1-150500.3.15.1 * multipath-tools-0.9.4+153+suse.eec9ef1-150500.3.15.1 * libdmmp0_2_0-0.9.4+153+suse.eec9ef1-150500.3.15.1 * kpartx-debuginfo-0.9.4+153+suse.eec9ef1-150500.3.15.1 * multipath-tools-devel-0.9.4+153+suse.eec9ef1-150500.3.15.1 * libmpath0-debuginfo-0.9.4+153+suse.eec9ef1-150500.3.15.1 * multipath-tools-debugsource-0.9.4+153+suse.eec9ef1-150500.3.15.1 * kpartx-0.9.4+153+suse.eec9ef1-150500.3.15.1 * libdmmp0_2_0-debuginfo-0.9.4+153+suse.eec9ef1-150500.3.15.1 * libdmmp-devel-0.9.4+153+suse.eec9ef1-150500.3.15.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libmpath0-0.9.4+153+suse.eec9ef1-150500.3.15.1 * multipath-tools-debuginfo-0.9.4+153+suse.eec9ef1-150500.3.15.1 * multipath-tools-0.9.4+153+suse.eec9ef1-150500.3.15.1 * kpartx-debuginfo-0.9.4+153+suse.eec9ef1-150500.3.15.1 * libmpath0-debuginfo-0.9.4+153+suse.eec9ef1-150500.3.15.1 * kpartx-0.9.4+153+suse.eec9ef1-150500.3.15.1 * multipath-tools-debugsource-0.9.4+153+suse.eec9ef1-150500.3.15.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1277199 * https://bugzilla.suse.com/show_bug.cgi?id=1277203 * https://bugzilla.suse.com/show_bug.cgi?id=1277205 * https://bugzilla.suse.com/show_bug.cgi?id=1277208 * https://bugzilla.suse.com/show_bug.cgi?id=1277209 * https://bugzilla.suse.com/show_bug.cgi?id=1277210 * https://bugzilla.suse.com/show_bug.cgi?id=1277212 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:45:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:45:43 -0000 Subject: SUSE-SU-2026:4063-1: important: Security update for NetworkManager Message-ID: <178887154314.401.851236501431361531@d0473b53b788> # Security update for NetworkManager Announcement ID: SUSE-SU-2026:4063-1 Release Date: 2026-09-08T07:02:27Z Rating: important References: * bsc#1224868 * bsc#1267696 * bsc#1276764 Cross-References: * CVE-2026-10805 * CVE-2026-19685 CVSS scores: * CVE-2026-10805 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-10805 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19685 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-19685 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-19685 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19685 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for NetworkManager fixes the following issues: * CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). * CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). Changes for NetworkManager: * Add config-server subpackage (bsc#1224868). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4063=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4063=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4063=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-4063=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4063=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4063=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * typelib-1_0-NM-1_0-1.38.6-150500.3.10.1 * NetworkManager-debuginfo-1.38.6-150500.3.10.1 * libnm0-1.38.6-150500.3.10.1 * NetworkManager-wwan-1.38.6-150500.3.10.1 * NetworkManager-1.38.6-150500.3.10.1 * NetworkManager-debugsource-1.38.6-150500.3.10.1 * libnm0-debuginfo-1.38.6-150500.3.10.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * typelib-1_0-NM-1_0-1.38.6-150500.3.10.1 * NetworkManager-debuginfo-1.38.6-150500.3.10.1 * libnm0-1.38.6-150500.3.10.1 * NetworkManager-wwan-1.38.6-150500.3.10.1 * NetworkManager-1.38.6-150500.3.10.1 * NetworkManager-debugsource-1.38.6-150500.3.10.1 * libnm0-debuginfo-1.38.6-150500.3.10.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * typelib-1_0-NM-1_0-1.38.6-150500.3.10.1 * NetworkManager-debuginfo-1.38.6-150500.3.10.1 * libnm0-1.38.6-150500.3.10.1 * NetworkManager-wwan-1.38.6-150500.3.10.1 * NetworkManager-1.38.6-150500.3.10.1 * NetworkManager-debugsource-1.38.6-150500.3.10.1 * libnm0-debuginfo-1.38.6-150500.3.10.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * NetworkManager-wwan-debuginfo-1.38.6-150500.3.10.1 * NetworkManager-bluetooth-1.38.6-150500.3.10.1 * NetworkManager-ovs-debuginfo-1.38.6-150500.3.10.1 * NetworkManager-pppoe-debuginfo-1.38.6-150500.3.10.1 * NetworkManager-devel-1.38.6-150500.3.10.1 * NetworkManager-cloud-setup-1.38.6-150500.3.10.1 * typelib-1_0-NM-1_0-1.38.6-150500.3.10.1 * libnm0-1.38.6-150500.3.10.1 * NetworkManager-wwan-1.38.6-150500.3.10.1 * NetworkManager-1.38.6-150500.3.10.1 * NetworkManager-tui-debuginfo-1.38.6-150500.3.10.1 * NetworkManager-tui-1.38.6-150500.3.10.1 * libnm0-debuginfo-1.38.6-150500.3.10.1 * NetworkManager-debuginfo-1.38.6-150500.3.10.1 * NetworkManager-cloud-setup-debuginfo-1.38.6-150500.3.10.1 * NetworkManager-ovs-1.38.6-150500.3.10.1 * NetworkManager-pppoe-1.38.6-150500.3.10.1 * NetworkManager-debugsource-1.38.6-150500.3.10.1 * NetworkManager-bluetooth-debuginfo-1.38.6-150500.3.10.1 * openSUSE Leap 15.5 (x86_64) * libnm0-32bit-1.38.6-150500.3.10.1 * libnm0-32bit-debuginfo-1.38.6-150500.3.10.1 * NetworkManager-devel-32bit-1.38.6-150500.3.10.1 * openSUSE Leap 15.5 (aarch64_ilp32) * libnm0-64bit-debuginfo-1.38.6-150500.3.10.1 * libnm0-64bit-1.38.6-150500.3.10.1 * NetworkManager-devel-64bit-1.38.6-150500.3.10.1 * openSUSE Leap 15.5 (noarch) * NetworkManager-config-server-1.38.6-150500.3.10.1 * NetworkManager-branding-upstream-1.38.6-150500.3.10.1 * NetworkManager-lang-1.38.6-150500.3.10.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * NetworkManager-cloud-setup-1.38.6-150500.3.10.1 * NetworkManager-pppoe-1.38.6-150500.3.10.1 * typelib-1_0-NM-1_0-1.38.6-150500.3.10.1 * NetworkManager-debuginfo-1.38.6-150500.3.10.1 * NetworkManager-wwan-debuginfo-1.38.6-150500.3.10.1 * libnm0-1.38.6-150500.3.10.1 * NetworkManager-bluetooth-1.38.6-150500.3.10.1 * NetworkManager-wwan-1.38.6-150500.3.10.1 * NetworkManager-1.38.6-150500.3.10.1 * NetworkManager-tui-debuginfo-1.38.6-150500.3.10.1 * NetworkManager-cloud-setup-debuginfo-1.38.6-150500.3.10.1 * NetworkManager-debugsource-1.38.6-150500.3.10.1 * NetworkManager-pppoe-debuginfo-1.38.6-150500.3.10.1 * NetworkManager-bluetooth-debuginfo-1.38.6-150500.3.10.1 * NetworkManager-tui-1.38.6-150500.3.10.1 * libnm0-debuginfo-1.38.6-150500.3.10.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * typelib-1_0-NM-1_0-1.38.6-150500.3.10.1 * NetworkManager-debuginfo-1.38.6-150500.3.10.1 * libnm0-1.38.6-150500.3.10.1 * NetworkManager-wwan-1.38.6-150500.3.10.1 * NetworkManager-1.38.6-150500.3.10.1 * NetworkManager-debugsource-1.38.6-150500.3.10.1 * libnm0-debuginfo-1.38.6-150500.3.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10805.html * https://www.suse.com/security/cve/CVE-2026-19685.html * https://bugzilla.suse.com/show_bug.cgi?id=1224868 * https://bugzilla.suse.com/show_bug.cgi?id=1267696 * https://bugzilla.suse.com/show_bug.cgi?id=1276764 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:46:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:46:43 -0000 Subject: SUSE-SU-2026:4062-1: important: Security update for terraform-provider-null Message-ID: <178887160313.401.13124261170046710312@d0473b53b788> # Security update for terraform-provider-null Announcement ID: SUSE-SU-2026:4062-1 Release Date: 2026-09-08T07:01:38Z Rating: important References: * bsc#1278267 * bsc#1278269 * bsc#1278272 Cross-References: * CVE-2026-84303 * CVE-2026-84304 CVSS scores: * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for terraform-provider-null fixes the following issues: * CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1278269). * CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1278272). * gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation (bsc#1278267). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-4062=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-4062=1 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * terraform-provider-null-3.0.0-150200.6.27.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * terraform-provider-null-3.0.0-150200.6.27.1 ## References: * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://bugzilla.suse.com/show_bug.cgi?id=1278267 * https://bugzilla.suse.com/show_bug.cgi?id=1278269 * https://bugzilla.suse.com/show_bug.cgi?id=1278272 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:47:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:47:25 -0000 Subject: SUSE-SU-2026:4061-1: moderate: Security update for python Message-ID: <178887164561.401.16486182364451761555@d0473b53b788> # Security update for python Announcement ID: SUSE-SU-2026:4061-1 Release Date: 2026-09-08T07:00:57Z Rating: moderate References: * bsc#1273091 * bsc#1276903 * bsc#1277271 Cross-References: * CVE-2026-13346 * CVE-2026-1703 * CVE-2026-3219 CVSS scores: * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for python fixes the following issues: Security issues fixed: * CVE-2026-13346: pip: arbitrary file installation via malicious package indexes (bsc#1273091). Non security issue fixed: * Update bundled pip wheels to pip-10.0.1-py2.py3-none-any.whl ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4061=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * python-tk-debuginfo-2.7.18-33.85.2 * python-base-debuginfo-32bit-2.7.18-33.85.2 * python-base-debuginfo-2.7.18-33.85.2 * python-base-debugsource-2.7.18-33.85.2 * python-debuginfo-32bit-2.7.18-33.85.2 * libpython2_7-1_0-32bit-2.7.18-33.85.2 * python-debuginfo-2.7.18-33.85.2 * python-gdbm-2.7.18-33.85.2 * python-curses-2.7.18-33.85.2 * libpython2_7-1_0-2.7.18-33.85.2 * python-gdbm-debuginfo-2.7.18-33.85.2 * python-xml-debuginfo-2.7.18-33.85.2 * python-tk-2.7.18-33.85.2 * libpython2_7-1_0-debuginfo-32bit-2.7.18-33.85.2 * python-devel-2.7.18-33.85.2 * libpython2_7-1_0-debuginfo-2.7.18-33.85.2 * python-debugsource-2.7.18-33.85.2 * python-curses-debuginfo-2.7.18-33.85.2 * python-base-32bit-2.7.18-33.85.2 * python-32bit-2.7.18-33.85.2 * python-2.7.18-33.85.2 * python-idle-2.7.18-33.85.2 * python-xml-2.7.18-33.85.2 * python-base-2.7.18-33.85.2 * python-demo-2.7.18-33.85.2 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * python-doc-pdf-2.7.18-33.85.2 * python-doc-2.7.18-33.85.2 ## References: * https://www.suse.com/security/cve/CVE-2026-13346.html * https://www.suse.com/security/cve/CVE-2026-1703.html * https://www.suse.com/security/cve/CVE-2026-3219.html * https://bugzilla.suse.com/show_bug.cgi?id=1273091 * https://bugzilla.suse.com/show_bug.cgi?id=1276903 * https://bugzilla.suse.com/show_bug.cgi?id=1277271 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:48:08 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:48:08 -0000 Subject: SUSE-SU-2026:4060-1: moderate: Security update for python3 Message-ID: <178887168815.401.16586518987423669829@d0473b53b788> # Security update for python3 Announcement ID: SUSE-SU-2026:4060-1 Release Date: 2026-09-08T07:00:40Z Rating: moderate References: * bsc#1273091 * bsc#1276903 * bsc#1277271 Cross-References: * CVE-2026-13346 * CVE-2026-1703 * CVE-2026-3219 CVSS scores: * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for python3 fixes the following issues: Security issues fixed: * CVE-2026-13346: arbitrary file installation via malicious package indexes (bsc#1273091). Non security issue fixed: * Update bundled pip wheels to pip-10.0.1-py2.py3-none-any.whl ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4060=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * python3-curses-3.4.10-25.194.2 * python3-curses-debuginfo-3.4.10-25.194.2 * python3-base-debugsource-3.4.10-25.194.2 * python3-debuginfo-3.4.10-25.194.2 * python3-devel-debuginfo-3.4.10-25.194.2 * python3-base-debuginfo-32bit-3.4.10-25.194.2 * python3-devel-3.4.10-25.194.2 * python3-base-debuginfo-3.4.10-25.194.2 * libpython3_4m1_0-3.4.10-25.194.2 * libpython3_4m1_0-32bit-3.4.10-25.194.2 * python3-tk-3.4.10-25.194.2 * python3-3.4.10-25.194.2 * python3-tk-debuginfo-3.4.10-25.194.2 * libpython3_4m1_0-debuginfo-3.4.10-25.194.2 * python3-base-3.4.10-25.194.2 * python3-debugsource-3.4.10-25.194.2 * libpython3_4m1_0-debuginfo-32bit-3.4.10-25.194.2 ## References: * https://www.suse.com/security/cve/CVE-2026-13346.html * https://www.suse.com/security/cve/CVE-2026-1703.html * https://www.suse.com/security/cve/CVE-2026-3219.html * https://bugzilla.suse.com/show_bug.cgi?id=1273091 * https://bugzilla.suse.com/show_bug.cgi?id=1276903 * https://bugzilla.suse.com/show_bug.cgi?id=1277271 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 12:48:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 12:48:47 -0000 Subject: SUSE-SU-2026:4059-1: important: Security update for php-composer2 Message-ID: <178887172769.401.11816296874655090639@d0473b53b788> # Security update for php-composer2 Announcement ID: SUSE-SU-2026:4059-1 Release Date: 2026-09-08T07:00:15Z Rating: important References: * bsc#1278257 Cross-References: * CVE-2026-84361 CVSS scores: * CVE-2026-84361 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84361 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for php-composer2 fixes the following issue: * CVE-2026-84361: Arbitrary code execution via malicious Perforce source URL (bsc#1278257). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4059=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4059=1 * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-4059=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4059=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * php-composer2-2.6.4-150600.3.18.1 * openSUSE Leap 15.6 (noarch) * php-composer2-2.6.4-150600.3.18.1 * Web and Scripting Module 15-SP7 (noarch) * php-composer2-2.6.4-150600.3.18.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * php-composer2-2.6.4-150600.3.18.1 ## References: * https://www.suse.com/security/cve/CVE-2026-84361.html * https://bugzilla.suse.com/show_bug.cgi?id=1278257 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 16:30:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 16:30:40 -0000 Subject: SUSE-SU-2026:4086-1: moderate: Security update for perl-Net-DNS Message-ID: <178888504036.822.1942921222884695219@aaf27ed6f0fb> # Security update for perl-Net-DNS Announcement ID: SUSE-SU-2026:4086-1 Release Date: 2026-09-08T10:22:58Z Rating: moderate References: * bsc#1278084 Cross-References: * CVE-2026-81928 CVSS scores: * CVE-2026-81928 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-81928 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for perl-Net-DNS fixes the following issue: * CVE-2026-81928: memory exhaustion via unbounded recursion in sig_data when re-encoding a message with a misplaced TSIG record (bsc#1278084). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4086=1 ## Package List: * Basesystem Module 15-SP7 (noarch) * perl-Net-DNS-1.14-150000.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-81928.html * https://bugzilla.suse.com/show_bug.cgi?id=1278084 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 16:32:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 16:32:00 -0000 Subject: SUSE-SU-2026:4083-1: important: Security update for emacs Message-ID: <178888512096.822.15953334868114024510@aaf27ed6f0fb> # Security update for emacs Announcement ID: SUSE-SU-2026:4083-1 Release Date: 2026-09-08T09:56:22Z Rating: important References: * bsc#1275927 * bsc#1275941 * bsc#1276264 Cross-References: * CVE-2026-77219 * CVE-2026-79992 CVSS scores: * CVE-2026-77219 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-77219 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-77219 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-79992 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-79992 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities and has one security fix can now be installed. ## Description: This update for emacs fixes the following issues: * Arbitrary code execution when opening a specially crafted file (bsc#1275941). * CVE-2026-77219: integer overflow in the PBM/PPM/PGM image loader leads to heap memory content leaks when a crafted image with large dimensions and an elevated max color index is processed (bsc#1276264). * CVE-2026-79992: improper argument sanitization in TRAMP leads to arbitrary code execution via crafted filenames (bsc#1275927). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4083=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4083=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4083=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4083=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4083=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4083=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4083=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4083=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4083=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4083=1 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4083=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4083=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4083=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * emacs-debugsource-27.2-150400.3.31.2 * etags-debuginfo-27.2-150400.3.31.2 * emacs-debuginfo-27.2-150400.3.31.2 * emacs-x11-27.2-150400.3.31.2 * emacs-nox-27.2-150400.3.31.2 * emacs-27.2-150400.3.31.2 * emacs-x11-debuginfo-27.2-150400.3.31.2 * etags-27.2-150400.3.31.2 * emacs-nox-debuginfo-27.2-150400.3.31.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * emacs-info-27.2-150400.3.31.2 * emacs-el-27.2-150400.3.31.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * emacs-debugsource-27.2-150400.3.31.2 * etags-debuginfo-27.2-150400.3.31.2 * emacs-debuginfo-27.2-150400.3.31.2 * emacs-x11-27.2-150400.3.31.2 * emacs-nox-27.2-150400.3.31.2 * emacs-27.2-150400.3.31.2 * emacs-x11-debuginfo-27.2-150400.3.31.2 * etags-27.2-150400.3.31.2 * emacs-nox-debuginfo-27.2-150400.3.31.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * emacs-info-27.2-150400.3.31.2 * emacs-el-27.2-150400.3.31.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * emacs-debugsource-27.2-150400.3.31.2 * etags-debuginfo-27.2-150400.3.31.2 * emacs-debuginfo-27.2-150400.3.31.2 * emacs-x11-27.2-150400.3.31.2 * emacs-nox-27.2-150400.3.31.2 * emacs-27.2-150400.3.31.2 * emacs-x11-debuginfo-27.2-150400.3.31.2 * etags-27.2-150400.3.31.2 * emacs-nox-debuginfo-27.2-150400.3.31.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * emacs-info-27.2-150400.3.31.2 * emacs-el-27.2-150400.3.31.2 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * emacs-debugsource-27.2-150400.3.31.2 * etags-debuginfo-27.2-150400.3.31.2 * emacs-debuginfo-27.2-150400.3.31.2 * emacs-x11-27.2-150400.3.31.2 * emacs-nox-27.2-150400.3.31.2 * emacs-27.2-150400.3.31.2 * emacs-x11-debuginfo-27.2-150400.3.31.2 * etags-27.2-150400.3.31.2 * emacs-nox-debuginfo-27.2-150400.3.31.2 * openSUSE Leap 15.4 (noarch) * emacs-info-27.2-150400.3.31.2 * emacs-el-27.2-150400.3.31.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * emacs-debugsource-27.2-150400.3.31.2 * etags-debuginfo-27.2-150400.3.31.2 * emacs-debuginfo-27.2-150400.3.31.2 * emacs-x11-27.2-150400.3.31.2 * emacs-nox-27.2-150400.3.31.2 * emacs-27.2-150400.3.31.2 * emacs-x11-debuginfo-27.2-150400.3.31.2 * etags-27.2-150400.3.31.2 * emacs-nox-debuginfo-27.2-150400.3.31.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * emacs-info-27.2-150400.3.31.2 * emacs-el-27.2-150400.3.31.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * emacs-debugsource-27.2-150400.3.31.2 * etags-debuginfo-27.2-150400.3.31.2 * emacs-debuginfo-27.2-150400.3.31.2 * emacs-x11-27.2-150400.3.31.2 * emacs-nox-27.2-150400.3.31.2 * emacs-27.2-150400.3.31.2 * emacs-x11-debuginfo-27.2-150400.3.31.2 * etags-27.2-150400.3.31.2 * emacs-nox-debuginfo-27.2-150400.3.31.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * emacs-info-27.2-150400.3.31.2 * emacs-el-27.2-150400.3.31.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * emacs-debugsource-27.2-150400.3.31.2 * etags-debuginfo-27.2-150400.3.31.2 * emacs-debuginfo-27.2-150400.3.31.2 * emacs-x11-27.2-150400.3.31.2 * emacs-nox-27.2-150400.3.31.2 * emacs-27.2-150400.3.31.2 * emacs-x11-debuginfo-27.2-150400.3.31.2 * etags-27.2-150400.3.31.2 * emacs-nox-debuginfo-27.2-150400.3.31.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * emacs-info-27.2-150400.3.31.2 * emacs-el-27.2-150400.3.31.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * emacs-debugsource-27.2-150400.3.31.2 * etags-debuginfo-27.2-150400.3.31.2 * emacs-debuginfo-27.2-150400.3.31.2 * emacs-x11-27.2-150400.3.31.2 * emacs-nox-27.2-150400.3.31.2 * emacs-27.2-150400.3.31.2 * emacs-x11-debuginfo-27.2-150400.3.31.2 * etags-27.2-150400.3.31.2 * emacs-nox-debuginfo-27.2-150400.3.31.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * emacs-info-27.2-150400.3.31.2 * emacs-el-27.2-150400.3.31.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * emacs-debugsource-27.2-150400.3.31.2 * etags-debuginfo-27.2-150400.3.31.2 * emacs-debuginfo-27.2-150400.3.31.2 * emacs-x11-27.2-150400.3.31.2 * emacs-nox-27.2-150400.3.31.2 * emacs-27.2-150400.3.31.2 * emacs-x11-debuginfo-27.2-150400.3.31.2 * etags-27.2-150400.3.31.2 * emacs-nox-debuginfo-27.2-150400.3.31.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * emacs-info-27.2-150400.3.31.2 * emacs-el-27.2-150400.3.31.2 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * emacs-debugsource-27.2-150400.3.31.2 * etags-debuginfo-27.2-150400.3.31.2 * emacs-debuginfo-27.2-150400.3.31.2 * emacs-nox-27.2-150400.3.31.2 * emacs-27.2-150400.3.31.2 * etags-27.2-150400.3.31.2 * emacs-nox-debuginfo-27.2-150400.3.31.2 * Basesystem Module 15-SP7 (noarch) * emacs-info-27.2-150400.3.31.2 * emacs-el-27.2-150400.3.31.2 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * emacs-x11-debuginfo-27.2-150400.3.31.2 * emacs-debugsource-27.2-150400.3.31.2 * emacs-x11-27.2-150400.3.31.2 * emacs-debuginfo-27.2-150400.3.31.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * emacs-debugsource-27.2-150400.3.31.2 * etags-debuginfo-27.2-150400.3.31.2 * emacs-debuginfo-27.2-150400.3.31.2 * emacs-x11-27.2-150400.3.31.2 * emacs-nox-27.2-150400.3.31.2 * emacs-27.2-150400.3.31.2 * emacs-x11-debuginfo-27.2-150400.3.31.2 * etags-27.2-150400.3.31.2 * emacs-nox-debuginfo-27.2-150400.3.31.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * emacs-info-27.2-150400.3.31.2 * emacs-el-27.2-150400.3.31.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * emacs-debugsource-27.2-150400.3.31.2 * etags-debuginfo-27.2-150400.3.31.2 * emacs-debuginfo-27.2-150400.3.31.2 * emacs-x11-27.2-150400.3.31.2 * emacs-nox-27.2-150400.3.31.2 * emacs-27.2-150400.3.31.2 * emacs-x11-debuginfo-27.2-150400.3.31.2 * etags-27.2-150400.3.31.2 * emacs-nox-debuginfo-27.2-150400.3.31.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * emacs-info-27.2-150400.3.31.2 * emacs-el-27.2-150400.3.31.2 ## References: * https://www.suse.com/security/cve/CVE-2026-77219.html * https://www.suse.com/security/cve/CVE-2026-79992.html * https://bugzilla.suse.com/show_bug.cgi?id=1275927 * https://bugzilla.suse.com/show_bug.cgi?id=1275941 * https://bugzilla.suse.com/show_bug.cgi?id=1276264 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 16:32:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 16:32:58 -0000 Subject: SUSE-SU-2026:4082-1: important: Security update for amazon-ssm-agent Message-ID: <178888517818.822.12568326906750224254@aaf27ed6f0fb> # Security update for amazon-ssm-agent Announcement ID: SUSE-SU-2026:4082-1 Release Date: 2026-09-08T08:53:49Z Rating: important References: * bsc#1276981 * bsc#1276994 Cross-References: * CVE-2026-71556 * CVE-2026-71557 CVSS scores: * CVE-2026-71556 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L * CVE-2026-71556 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L * CVE-2026-71557 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-71557 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for amazon-ssm-agent fixes the following issues: * CVE-2026-71556: github.com/go-git/go-git/v5: Arbitrary file read/write via symbolic link resolution (bsc#1276981). * CVE-2026-71557: github.com/go-git/go-git/v5: Malicious reference names may modify files outside the reference storage (bsc#1276994). Changes for amazon-ssm-agent: * Update to version 3.3.5226.0 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-4082=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-4082=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-4082=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-4082=1 ## Package List: * Public Cloud Module 15-SP4 (aarch64 x86_64) * amazon-ssm-agent-3.3.5226.0-150000.5.40.1 * Public Cloud Module 15-SP5 (aarch64 x86_64) * amazon-ssm-agent-3.3.5226.0-150000.5.40.1 * Public Cloud Module 15-SP6 (aarch64 x86_64) * amazon-ssm-agent-3.3.5226.0-150000.5.40.1 * Public Cloud Module 15-SP7 (aarch64 x86_64) * amazon-ssm-agent-3.3.5226.0-150000.5.40.1 ## References: * https://www.suse.com/security/cve/CVE-2026-71556.html * https://www.suse.com/security/cve/CVE-2026-71557.html * https://bugzilla.suse.com/show_bug.cgi?id=1276981 * https://bugzilla.suse.com/show_bug.cgi?id=1276994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 20:31:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 20:31:19 -0000 Subject: SUSE-SU-2026:4090-1: important: Security update for xen Message-ID: <178889947948.874.10870018321550172854@d0473b53b788> # Security update for xen Announcement ID: SUSE-SU-2026:4090-1 Release Date: 2026-09-08T12:26:57Z Rating: important References: * bsc#1027519 * bsc#1271528 * bsc#1271530 * bsc#1271531 * bsc#1271532 * bsc#1271533 * bsc#1271534 * bsc#1271535 * bsc#1271536 * bsc#1271537 * bsc#1271538 * bsc#1271539 * bsc#1271947 * bsc#1276838 * bsc#1276839 * bsc#1276841 * jsc#PED-8907 Cross-References: * CVE-2026-42493 * CVE-2026-42494 * CVE-2026-42495 * CVE-2026-62423 * CVE-2026-62424 * CVE-2026-62425 * CVE-2026-62426 * CVE-2026-62427 * CVE-2026-62428 * CVE-2026-62429 * CVE-2026-62430 * CVE-2026-62431 * CVE-2026-62432 * CVE-2026-62433 * CVE-2026-62434 * CVE-2026-62437 * CVE-2026-79602 * CVE-2026-79603 CVSS scores: * CVE-2026-42493 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-42493 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-42493 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42494 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-42494 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-42494 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-42495 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-42495 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-42495 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62423 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62423 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62423 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62424 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62424 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62424 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62425 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62425 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62425 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-62426 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-62426 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-62426 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-62427 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-62427 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-62427 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-62428 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-62428 ( SUSE ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62428 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-62429 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-62429 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H * CVE-2026-62429 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-62430 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-62430 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-62430 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-62431 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-62431 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-62431 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-62432 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-62432 ( SUSE ): 8.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:H * CVE-2026-62432 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-62433 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-62433 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-62433 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-62434 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-62434 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:H * CVE-2026-62434 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-62437 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-79602 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-79603 ( SUSE ): 5.2 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N * CVE-2026-79603 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 18 vulnerabilities and contains one feature can now be installed. ## Description: This update for xen fixes the following issues: Update to version 4.20.3 (jsc#PED-8907). Security issues fixed: * CVE-2026-42493: x86 shadow paging is deprecated (bsc#1271528). * CVE-2026-42494,CVE-2026-42495,CVE-2026-62423,CVE-2026-62424,CVE-2026-62425: buffer overruns in libfsimage iso9660 handling (bsc#1271530). * CVE-2026-62426,CVE-2026-62427: sysctl and platform-op locks open to abuse (bsc#1271531). * CVE-2026-62428: grant-table: type confusion in grant-copy (bsc#1271532). * CVE-2026-62429: vNUMA domain cleanup may race other operations (bsc#1271534). * CVE-2026-62430: x86: Out-of-bounds read in vRTC emulation (bsc#1271535). * CVE-2026-62431: Viridian STIMER division by zero (bsc#1271536). * CVE-2026-62432: evtchn: Race between FIFO expand and reset (bsc#1271537). * CVE-2026-62433: correct buffer checks for DM_OP hypercalls (bsc#1271538). * CVE-2026-62434: PoD: Don't try to reclaim special pages (bsc#1271539). * CVE-2026-62437: x86: DMs may cause mem leak by IRQ binding (bsc#1276838). * CVE-2026-79602: x86: improper handling of HVM emulation return codes (bsc#1276839). * CVE-2026-79603: unconditionally do TLB flushing ahead of page scrubbing (bsc#1276841). * pygrub is only supported in de-privileged mode (bsc#1271947). Non security issue fixed: * Xen: Missing upstream bug fixes (bsc#1027519). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4090=1 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-4090=1 ## Package List: * Basesystem Module 15-SP7 (x86_64) * xen-debugsource-4.20.4_04-150700.3.46.1 * xen-tools-domU-4.20.4_04-150700.3.46.1 * xen-libs-debuginfo-4.20.4_04-150700.3.46.1 * xen-tools-domU-debuginfo-4.20.4_04-150700.3.46.1 * xen-libs-4.20.4_04-150700.3.46.1 * Server Applications Module 15-SP7 (x86_64) * xen-debugsource-4.20.4_04-150700.3.46.1 * xen-tools-debuginfo-4.20.4_04-150700.3.46.1 * xen-devel-4.20.4_04-150700.3.46.1 * xen-4.20.4_04-150700.3.46.1 * xen-tools-4.20.4_04-150700.3.46.1 * Server Applications Module 15-SP7 (noarch) * xen-tools-xendomains-wait-disk-4.20.4_04-150700.3.46.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42493.html * https://www.suse.com/security/cve/CVE-2026-42494.html * https://www.suse.com/security/cve/CVE-2026-42495.html * https://www.suse.com/security/cve/CVE-2026-62423.html * https://www.suse.com/security/cve/CVE-2026-62424.html * https://www.suse.com/security/cve/CVE-2026-62425.html * https://www.suse.com/security/cve/CVE-2026-62426.html * https://www.suse.com/security/cve/CVE-2026-62427.html * https://www.suse.com/security/cve/CVE-2026-62428.html * https://www.suse.com/security/cve/CVE-2026-62429.html * https://www.suse.com/security/cve/CVE-2026-62430.html * https://www.suse.com/security/cve/CVE-2026-62431.html * https://www.suse.com/security/cve/CVE-2026-62432.html * https://www.suse.com/security/cve/CVE-2026-62433.html * https://www.suse.com/security/cve/CVE-2026-62434.html * https://www.suse.com/security/cve/CVE-2026-62437.html * https://www.suse.com/security/cve/CVE-2026-79602.html * https://www.suse.com/security/cve/CVE-2026-79603.html * https://bugzilla.suse.com/show_bug.cgi?id=1027519 * https://bugzilla.suse.com/show_bug.cgi?id=1271528 * https://bugzilla.suse.com/show_bug.cgi?id=1271530 * https://bugzilla.suse.com/show_bug.cgi?id=1271531 * https://bugzilla.suse.com/show_bug.cgi?id=1271532 * https://bugzilla.suse.com/show_bug.cgi?id=1271533 * https://bugzilla.suse.com/show_bug.cgi?id=1271534 * https://bugzilla.suse.com/show_bug.cgi?id=1271535 * https://bugzilla.suse.com/show_bug.cgi?id=1271536 * https://bugzilla.suse.com/show_bug.cgi?id=1271537 * https://bugzilla.suse.com/show_bug.cgi?id=1271538 * https://bugzilla.suse.com/show_bug.cgi?id=1271539 * https://bugzilla.suse.com/show_bug.cgi?id=1271947 * https://bugzilla.suse.com/show_bug.cgi?id=1276838 * https://bugzilla.suse.com/show_bug.cgi?id=1276839 * https://bugzilla.suse.com/show_bug.cgi?id=1276841 * https://jira.suse.com/browse/PED-8907 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 20:31:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 20:31:59 -0000 Subject: SUSE-SU-2026:4089-1: moderate: Security update for xen Message-ID: <178889951935.874.6266570681868677589@d0473b53b788> # Security update for xen Announcement ID: SUSE-SU-2026:4089-1 Release Date: 2026-09-08T12:26:42Z Rating: moderate References: * bsc#1276838 * bsc#1276839 Cross-References: * CVE-2026-62437 * CVE-2026-79602 CVSS scores: * CVE-2026-62437 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-79602 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2026-62437: x86: DMs may cause mem leak by IRQ binding (bsc#1276838). * CVE-2026-79602: x86: improper handling of HVM emulation return codes (bsc#1276839). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4089=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * xen-libs-4.12.4_74-3.151.1 * xen-tools-domU-debuginfo-4.12.4_74-3.151.1 * xen-libs-debuginfo-4.12.4_74-3.151.1 * xen-debugsource-4.12.4_74-3.151.1 * xen-4.12.4_74-3.151.1 * xen-tools-domU-4.12.4_74-3.151.1 * xen-doc-html-4.12.4_74-3.151.1 * xen-tools-4.12.4_74-3.151.1 * xen-libs-32bit-4.12.4_74-3.151.1 * xen-tools-debuginfo-4.12.4_74-3.151.1 * xen-devel-4.12.4_74-3.151.1 * xen-libs-debuginfo-32bit-4.12.4_74-3.151.1 ## References: * https://www.suse.com/security/cve/CVE-2026-62437.html * https://www.suse.com/security/cve/CVE-2026-79602.html * https://bugzilla.suse.com/show_bug.cgi?id=1276838 * https://bugzilla.suse.com/show_bug.cgi?id=1276839 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 20:32:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 20:32:40 -0000 Subject: SUSE-SU-2026:4088-1: moderate: Security update for xen Message-ID: <178889956019.874.6746980871004034101@d0473b53b788> # Security update for xen Announcement ID: SUSE-SU-2026:4088-1 Release Date: 2026-09-08T12:26:33Z Rating: moderate References: * bsc#1276838 * bsc#1276839 * bsc#1276841 Cross-References: * CVE-2026-62437 * CVE-2026-79602 * CVE-2026-79603 CVSS scores: * CVE-2026-62437 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-79602 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-79603 ( SUSE ): 5.2 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N * CVE-2026-79603 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves three vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2026-62437: x86: DMs may cause mem leak by IRQ binding (bsc#1276838). * CVE-2026-79602: x86: improper handling of HVM emulation return codes (bsc#1276839). * CVE-2026-79603: unconditionally do TLB flushing ahead of page scrubbing (bsc#1276841). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4088=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4088=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4088=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4088=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4088=1 ## Package List: * openSUSE Leap 15.4 (x86_64) * xen-libs-32bit-4.16.7_14-150400.4.92.1 * xen-tools-debuginfo-4.16.7_14-150400.4.92.1 * xen-tools-4.16.7_14-150400.4.92.1 * xen-libs-32bit-debuginfo-4.16.7_14-150400.4.92.1 * xen-4.16.7_14-150400.4.92.1 * xen-doc-html-4.16.7_14-150400.4.92.1 * openSUSE Leap 15.4 (i586 x86_64) * xen-debugsource-4.16.7_14-150400.4.92.1 * xen-tools-domU-4.16.7_14-150400.4.92.1 * xen-tools-domU-debuginfo-4.16.7_14-150400.4.92.1 * xen-libs-debuginfo-4.16.7_14-150400.4.92.1 * xen-devel-4.16.7_14-150400.4.92.1 * xen-libs-4.16.7_14-150400.4.92.1 * openSUSE Leap 15.4 (noarch) * xen-tools-xendomains-wait-disk-4.16.7_14-150400.4.92.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * xen-debugsource-4.16.7_14-150400.4.92.1 * xen-libs-debuginfo-4.16.7_14-150400.4.92.1 * xen-libs-4.16.7_14-150400.4.92.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * xen-debugsource-4.16.7_14-150400.4.92.1 * xen-libs-debuginfo-4.16.7_14-150400.4.92.1 * xen-libs-4.16.7_14-150400.4.92.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * xen-debugsource-4.16.7_14-150400.4.92.1 * xen-libs-debuginfo-4.16.7_14-150400.4.92.1 * xen-libs-4.16.7_14-150400.4.92.1 * SUSE Linux Enterprise Micro 5.4 (x86_64) * xen-debugsource-4.16.7_14-150400.4.92.1 * xen-libs-debuginfo-4.16.7_14-150400.4.92.1 * xen-libs-4.16.7_14-150400.4.92.1 ## References: * https://www.suse.com/security/cve/CVE-2026-62437.html * https://www.suse.com/security/cve/CVE-2026-79602.html * https://www.suse.com/security/cve/CVE-2026-79603.html * https://bugzilla.suse.com/show_bug.cgi?id=1276838 * https://bugzilla.suse.com/show_bug.cgi?id=1276839 * https://bugzilla.suse.com/show_bug.cgi?id=1276841 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 8 20:33:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 08 Sep 2026 20:33:38 -0000 Subject: SUSE-SU-2026:4087-1: moderate: Security update for xen Message-ID: <178889961851.874.637815293973971124@d0473b53b788> # Security update for xen Announcement ID: SUSE-SU-2026:4087-1 Release Date: 2026-09-08T12:26:17Z Rating: moderate References: * bsc#1276838 * bsc#1276839 * bsc#1276841 Cross-References: * CVE-2026-62437 * CVE-2026-79602 * CVE-2026-79603 CVSS scores: * CVE-2026-62437 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-79602 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-79603 ( SUSE ): 5.2 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N * CVE-2026-79603 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Micro 5.5 An update that solves three vulnerabilities can now be installed. ## Description: This update for xen fixes the following issues: * CVE-2026-62437: x86: DMs may cause mem leak by IRQ binding (bsc#1276838). * CVE-2026-79602: x86: improper handling of HVM emulation return codes (bsc#1276839). * CVE-2026-79603: unconditionally do TLB flushing ahead of page scrubbing (bsc#1276841). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-4087=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4087=1 ## Package List: * openSUSE Leap 15.5 (x86_64) * xen-tools-4.17.6_16-150500.3.79.1 * xen-doc-html-4.17.6_16-150500.3.79.1 * xen-libs-32bit-debuginfo-4.17.6_16-150500.3.79.1 * xen-4.17.6_16-150500.3.79.1 * xen-tools-debuginfo-4.17.6_16-150500.3.79.1 * xen-libs-32bit-4.17.6_16-150500.3.79.1 * openSUSE Leap 15.5 (i586 x86_64) * xen-tools-domU-4.17.6_16-150500.3.79.1 * xen-libs-debuginfo-4.17.6_16-150500.3.79.1 * xen-devel-4.17.6_16-150500.3.79.1 * xen-tools-domU-debuginfo-4.17.6_16-150500.3.79.1 * xen-libs-4.17.6_16-150500.3.79.1 * xen-debugsource-4.17.6_16-150500.3.79.1 * openSUSE Leap 15.5 (noarch) * xen-tools-xendomains-wait-disk-4.17.6_16-150500.3.79.1 * SUSE Linux Enterprise Micro 5.5 (x86_64) * xen-libs-4.17.6_16-150500.3.79.1 * xen-libs-debuginfo-4.17.6_16-150500.3.79.1 * xen-debugsource-4.17.6_16-150500.3.79.1 ## References: * https://www.suse.com/security/cve/CVE-2026-62437.html * https://www.suse.com/security/cve/CVE-2026-79602.html * https://www.suse.com/security/cve/CVE-2026-79603.html * https://bugzilla.suse.com/show_bug.cgi?id=1276838 * https://bugzilla.suse.com/show_bug.cgi?id=1276839 * https://bugzilla.suse.com/show_bug.cgi?id=1276841 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 08:30:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 08:30:52 -0000 Subject: SUSE-SU-2026:4093-1: moderate: Security update for multipath-tools Message-ID: <178894265265.1424.12381583825096600889@a0307d149aa3> # Security update for multipath-tools Announcement ID: SUSE-SU-2026:4093-1 Release Date: 2026-09-08T16:31:59Z Rating: moderate References: * bsc#1277199 * bsc#1277203 * bsc#1277205 * bsc#1277208 * bsc#1277209 * bsc#1277210 * bsc#1277212 Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that has seven security fixes can now be installed. ## Description: This update for multipath-tools fixes the following issues: * Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205). * Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210). * SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212). * Local Denial of Service via Blocking IPC Send Operations (bsc#1277199). * Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209). * DoS on multipathd socket by exhausting connections (bsc#1277203). * Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208). Changes for multipath-tools: * Update to version 0.7.9+256+suse.60d6bf4. * Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4093=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * multipath-tools-devel-0.7.9+256+suse.60d6bf4-3.23.1 * multipath-tools-debugsource-0.7.9+256+suse.60d6bf4-3.23.1 * multipath-tools-0.7.9+256+suse.60d6bf4-3.23.1 * multipath-tools-debuginfo-0.7.9+256+suse.60d6bf4-3.23.1 * kpartx-0.7.9+256+suse.60d6bf4-3.23.1 * kpartx-debuginfo-0.7.9+256+suse.60d6bf4-3.23.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1277199 * https://bugzilla.suse.com/show_bug.cgi?id=1277203 * https://bugzilla.suse.com/show_bug.cgi?id=1277205 * https://bugzilla.suse.com/show_bug.cgi?id=1277208 * https://bugzilla.suse.com/show_bug.cgi?id=1277209 * https://bugzilla.suse.com/show_bug.cgi?id=1277210 * https://bugzilla.suse.com/show_bug.cgi?id=1277212 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 08:31:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 08:31:44 -0000 Subject: SUSE-SU-2026:4092-1: critical: Security update for libzypp, zypper Message-ID: <178894270448.1424.1708513073392828438@a0307d149aa3> # Security update for libzypp, zypper Announcement ID: SUSE-SU-2026:4092-1 Release Date: 2026-09-08T16:31:50Z Rating: critical References: * bsc#1257249 * bsc#1261038 * bsc#1268321 * bsc#1271730 * bsc#1272534 * bsc#1273242 * bsc#1274091 * bsc#1274625 * bsc#1277790 Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that has nine security fixes can now be installed. ## Description: This update for libzypp, zypper fixes the following issues: Security issue fixed: * invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY- CACHE-01] (bsc#1274625). * hasCredentials() requires both username AND password to be non-empty (bsc#1273242). * GPG Key hints in repoindex.xml require at least a long id to allow auto- import (bsc#1271730). Non security issues fixed: * Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). * libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). * Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). * zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). * Zypper patch doesn't give enough details about conflicts (bsc#1277790). * dependency issue for package "python3-vsts-cd-manager" after starting the upgrade (bsc#1261038). Changes for libzypp: * Update to version 17.38.15: * Prevent libgpgme from launching gpg-agents; we don't need them. * defaultLoadSystem: Hand out the ZYpp::Ptr as return value. * Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) * zypp: Improve Testcase Loading for MCP Tools. * spec: Remove useless %bcond visibility_hidden (is always ON in cmake) * zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: * Update to version 1.14.101. ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4092=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * zypper-debugsource-1.14.101-150700.13.9.1 * libzypp-17.38.15-150700.6.16.1 * zypper-debuginfo-1.14.101-150700.13.9.1 * zypper-1.14.101-150700.13.9.1 * libzypp-debugsource-17.38.15-150700.6.16.1 * libzypp-debuginfo-17.38.15-150700.6.16.1 * libzypp-devel-17.38.15-150700.6.16.1 * Basesystem Module 15-SP7 (noarch) * zypper-needs-restarting-1.14.101-150700.13.9.1 * zypper-log-1.14.101-150700.13.9.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1257249 * https://bugzilla.suse.com/show_bug.cgi?id=1261038 * https://bugzilla.suse.com/show_bug.cgi?id=1268321 * https://bugzilla.suse.com/show_bug.cgi?id=1271730 * https://bugzilla.suse.com/show_bug.cgi?id=1272534 * https://bugzilla.suse.com/show_bug.cgi?id=1273242 * https://bugzilla.suse.com/show_bug.cgi?id=1274091 * https://bugzilla.suse.com/show_bug.cgi?id=1274625 * https://bugzilla.suse.com/show_bug.cgi?id=1277790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 12:44:17 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 12:44:17 -0000 Subject: SUSE-SU-2026:23491-1: important: Security update for the Linux Kernel Message-ID: <178895785748.1855.11709884860116397364@aaf27ed6f0fb> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:23491-1 Release Date: 2026-09-08T11:04:19Z Rating: important References: * bsc#1230238 * bsc#1235944 * bsc#1247455 * bsc#1250748 * bsc#1251966 * bsc#1252682 * bsc#1254306 * bsc#1255225 * bsc#1255250 * bsc#1256629 * bsc#1256708 * bsc#1257154 * bsc#1258430 * bsc#1258517 * bsc#1260522 * bsc#1261780 * bsc#1261788 * bsc#1262073 * bsc#1263004 * bsc#1263061 * bsc#1263133 * bsc#1264335 * bsc#1264446 * bsc#1264541 * bsc#1264584 * bsc#1264587 * bsc#1264619 * bsc#1264788 * bsc#1265068 * bsc#1265121 * bsc#1265449 * bsc#1265928 * bsc#1266402 * bsc#1266860 * bsc#1266874 * bsc#1266897 * bsc#1267023 * bsc#1267238 * bsc#1267501 * bsc#1267612 * bsc#1268276 * bsc#1268972 * bsc#1268979 * bsc#1268987 * bsc#1269004 * bsc#1269013 * bsc#1269108 * bsc#1269113 * bsc#1269114 * bsc#1269126 * bsc#1269167 * bsc#1269234 * bsc#1269238 * bsc#1269242 * bsc#1269256 * bsc#1269301 * bsc#1269306 * bsc#1269381 * bsc#1269388 * bsc#1269412 * bsc#1269530 * bsc#1269579 * bsc#1269590 * bsc#1269635 * bsc#1269655 * bsc#1269665 * bsc#1269686 * bsc#1269695 * bsc#1269713 * bsc#1269731 * bsc#1269774 * bsc#1269783 * bsc#1269792 * bsc#1269815 * bsc#1269965 * bsc#1269969 * bsc#1269981 * bsc#1269985 * bsc#1270090 * bsc#1270108 * bsc#1270111 * bsc#1270251 * bsc#1271256 * bsc#1271365 * bsc#1271366 * bsc#1271825 * bsc#1271830 * bsc#1272150 * bsc#1272175 * bsc#1272179 * bsc#1272182 * bsc#1272200 * bsc#1272210 * bsc#1272213 * bsc#1272230 * bsc#1272260 * bsc#1272261 * bsc#1272262 * bsc#1272297 * bsc#1272346 * bsc#1272381 * bsc#1272385 * bsc#1272390 * bsc#1272423 * bsc#1272429 * bsc#1272484 * bsc#1272486 * bsc#1272497 * bsc#1272516 * bsc#1272569 * bsc#1272571 * bsc#1272641 * bsc#1272643 * bsc#1272662 * bsc#1272673 * bsc#1272680 * bsc#1272682 * bsc#1272756 * bsc#1272786 * bsc#1272788 * bsc#1272798 * bsc#1272799 * bsc#1272868 * bsc#1272877 * bsc#1272891 * bsc#1272963 * bsc#1272983 * bsc#1273008 * bsc#1273019 * bsc#1273027 * bsc#1273028 * bsc#1273030 * bsc#1273038 * bsc#1273053 * bsc#1273054 * bsc#1273060 * bsc#1273105 * bsc#1273249 * bsc#1273250 * bsc#1273260 * bsc#1273273 * bsc#1273274 * bsc#1273276 * bsc#1273281 * bsc#1273284 * bsc#1273285 * bsc#1273289 * bsc#1273291 * bsc#1273294 * bsc#1273302 * bsc#1273303 * bsc#1273305 * bsc#1273310 * bsc#1273311 * bsc#1273316 * bsc#1273318 * bsc#1273319 * bsc#1273323 * bsc#1273325 * bsc#1273327 * bsc#1273334 * bsc#1273335 * bsc#1273336 * bsc#1273337 * bsc#1273338 * bsc#1273340 * bsc#1273341 * bsc#1273346 * bsc#1273422 * bsc#1273426 * bsc#1273443 * bsc#1273463 * bsc#1273468 * bsc#1273469 * bsc#1273471 * bsc#1273479 * bsc#1273480 * bsc#1273482 * bsc#1273484 * bsc#1273488 * bsc#1273490 * bsc#1273501 * bsc#1273503 * bsc#1273504 * bsc#1273506 * bsc#1273523 * bsc#1273525 * bsc#1273533 * bsc#1273536 * bsc#1273542 * bsc#1273555 * bsc#1273578 * bsc#1273579 * bsc#1273582 * bsc#1273596 * bsc#1273597 * bsc#1273598 * bsc#1273600 * bsc#1273601 * bsc#1273602 * bsc#1273603 * bsc#1273682 * bsc#1273734 * bsc#1273738 * bsc#1273739 * bsc#1273741 * bsc#1273742 * bsc#1273743 * bsc#1273745 * bsc#1273748 * bsc#1273749 * bsc#1273755 * bsc#1273762 * bsc#1273765 * bsc#1273766 * bsc#1273769 * bsc#1273774 * bsc#1273778 * bsc#1273780 * bsc#1273790 * bsc#1273796 * bsc#1273804 * bsc#1273810 * bsc#1273811 * bsc#1273813 * bsc#1273817 * bsc#1273822 * bsc#1273824 * bsc#1273831 * bsc#1273832 * bsc#1273834 * bsc#1273838 * bsc#1273844 * bsc#1273849 * bsc#1273860 * bsc#1273862 * bsc#1273867 * bsc#1273868 * bsc#1273869 * bsc#1273872 * bsc#1273876 * bsc#1273877 * bsc#1273880 * bsc#1273882 * bsc#1273890 * bsc#1273891 * bsc#1273892 * bsc#1273895 * bsc#1273896 * bsc#1273903 * bsc#1273905 * bsc#1273930 * bsc#1273933 * bsc#1273934 * bsc#1273935 * bsc#1273936 * bsc#1273939 * bsc#1273940 * bsc#1273941 * bsc#1273942 * bsc#1273944 * bsc#1273945 * bsc#1273946 * bsc#1273956 * bsc#1273957 * bsc#1273958 * bsc#1273966 * bsc#1273967 * bsc#1273968 * bsc#1273972 * bsc#1273974 * bsc#1273975 * bsc#1273977 * bsc#1273982 * bsc#1273988 * bsc#1273990 * bsc#1273991 * bsc#1273995 * bsc#1274001 * bsc#1274003 * bsc#1274006 * bsc#1274011 * bsc#1274012 * bsc#1274014 * bsc#1274017 * bsc#1274019 * bsc#1274020 * bsc#1274026 * bsc#1274028 * bsc#1274030 * bsc#1274031 * bsc#1274035 * bsc#1274040 * bsc#1274041 * bsc#1274057 * bsc#1274058 * bsc#1274061 * bsc#1274063 * bsc#1274065 * bsc#1274067 * bsc#1274075 * bsc#1274076 * bsc#1274077 * bsc#1274078 * bsc#1274208 * bsc#1274226 * bsc#1274239 * bsc#1274243 * bsc#1274258 * bsc#1274265 * bsc#1274274 * bsc#1274277 * bsc#1274278 * bsc#1274281 * bsc#1274283 * bsc#1274286 * bsc#1274290 * bsc#1274294 * bsc#1274296 * bsc#1274297 * bsc#1274298 * bsc#1274314 * bsc#1274321 * bsc#1274491 * bsc#1274497 * bsc#1274539 * bsc#1274541 * bsc#1274543 * bsc#1274545 * bsc#1274547 * bsc#1274550 * bsc#1274573 * bsc#1274578 * bsc#1274580 * bsc#1274581 * bsc#1274620 * bsc#1274622 * bsc#1274624 * bsc#1274629 * bsc#1274632 * bsc#1274636 * bsc#1274639 * bsc#1274640 * bsc#1274642 * bsc#1274644 * bsc#1274645 * bsc#1274646 * bsc#1274649 * bsc#1274650 * bsc#1274651 * bsc#1274656 * bsc#1274659 * bsc#1274662 * bsc#1274663 * bsc#1274665 * bsc#1274667 * bsc#1274670 * bsc#1274675 * bsc#1274677 * bsc#1274678 * bsc#1274679 * bsc#1274681 * bsc#1274682 * bsc#1274690 * bsc#1274694 * bsc#1274696 * bsc#1274698 * bsc#1274699 * bsc#1274700 * bsc#1274702 * bsc#1274703 * bsc#1274705 * bsc#1274706 * bsc#1274709 * bsc#1274710 * bsc#1274713 * bsc#1274716 * bsc#1274721 * bsc#1274725 * bsc#1274737 * bsc#1274738 * bsc#1274749 * bsc#1274752 * bsc#1274753 * bsc#1274754 * bsc#1274755 * bsc#1274756 * bsc#1274764 * bsc#1274768 * bsc#1274770 * bsc#1274787 * bsc#1274800 * bsc#1274801 * bsc#1274802 * bsc#1274804 * bsc#1274805 * bsc#1274807 * bsc#1274808 * bsc#1274811 * bsc#1274813 * bsc#1274814 * bsc#1274831 * bsc#1274834 * bsc#1274847 * bsc#1274853 * bsc#1274868 * bsc#1274869 * bsc#1274872 * bsc#1274873 * bsc#1274874 * bsc#1274876 * bsc#1274879 * bsc#1274881 * bsc#1274883 * bsc#1274886 * bsc#1274888 * bsc#1274891 * bsc#1274892 * bsc#1274893 * bsc#1274894 * bsc#1274896 * bsc#1274897 * bsc#1274898 * bsc#1274899 * bsc#1274901 * bsc#1274902 * bsc#1274905 * bsc#1274907 * bsc#1274908 * bsc#1274913 * bsc#1274914 * bsc#1274920 * bsc#1274921 * bsc#1274924 * bsc#1274925 * bsc#1274929 * bsc#1274930 * bsc#1274933 * bsc#1274934 * bsc#1274935 * bsc#1274941 * bsc#1274945 * bsc#1274947 * bsc#1274951 * bsc#1274953 * bsc#1274958 * bsc#1274968 * bsc#1274981 * bsc#1275040 * bsc#1275069 * bsc#1275071 * bsc#1275073 * bsc#1275076 * bsc#1275080 * bsc#1275083 * bsc#1275088 * bsc#1275091 * bsc#1275125 * bsc#1275126 * bsc#1275131 * bsc#1275132 * bsc#1275150 * bsc#1275152 * bsc#1275154 * bsc#1275155 * bsc#1275157 * bsc#1275158 * bsc#1275161 * bsc#1275163 * bsc#1275164 * bsc#1275169 * bsc#1275173 * bsc#1275176 * bsc#1275185 * bsc#1275190 * bsc#1275236 * bsc#1275237 * bsc#1275239 * bsc#1275294 * bsc#1275301 * bsc#1275303 * bsc#1275304 * bsc#1275305 * bsc#1275306 * bsc#1275307 * bsc#1275470 * bsc#1275472 * bsc#1275474 * bsc#1275479 * bsc#1275483 * bsc#1275486 * bsc#1275487 * bsc#1275506 * bsc#1275509 * bsc#1275511 * bsc#1275517 * bsc#1275528 * bsc#1275535 * bsc#1275540 * bsc#1275553 * bsc#1275555 * bsc#1275561 * bsc#1275566 * bsc#1275569 * bsc#1275574 * bsc#1275578 * bsc#1275582 * bsc#1275583 * bsc#1275584 * bsc#1275591 * bsc#1275595 * bsc#1275633 * bsc#1275636 * bsc#1275650 * bsc#1275659 * bsc#1275665 * bsc#1275669 * bsc#1275687 * bsc#1275688 * bsc#1275695 * bsc#1275696 * bsc#1275704 * bsc#1275782 * bsc#1275784 * bsc#1275787 * bsc#1275788 * bsc#1275790 * bsc#1275797 * bsc#1275798 * bsc#1275805 * bsc#1275817 * bsc#1275818 * bsc#1275819 * bsc#1275820 * bsc#1275821 * bsc#1275827 * bsc#1275864 * bsc#1275867 * bsc#1275869 * bsc#1275870 * bsc#1275871 * bsc#1275872 * bsc#1275886 * bsc#1275905 * bsc#1275923 * bsc#1275925 * bsc#1275946 * bsc#1275950 * bsc#1275954 * bsc#1275970 * bsc#1275973 * bsc#1275975 * bsc#1275976 * bsc#1276029 * bsc#1276257 * bsc#1276263 * bsc#1276270 * bsc#1276273 * bsc#1276277 * bsc#1276335 * bsc#1276346 * bsc#1276350 * bsc#1276355 * bsc#1276446 * bsc#1276452 * bsc#1276500 * bsc#1276507 * bsc#1276542 * bsc#1276546 * bsc#1276551 * bsc#1276561 * bsc#1276569 * bsc#1276665 * bsc#1276864 * bsc#1276927 * bsc#1276931 * bsc#1276937 * bsc#1276941 * bsc#1276943 * bsc#1276961 * bsc#1277022 * bsc#1277034 * bsc#1277037 * bsc#1277047 * bsc#1277054 * bsc#1277057 * bsc#1277059 * bsc#1277064 * bsc#1277066 * bsc#1277069 * bsc#1277073 * bsc#1277077 * bsc#1277095 * bsc#1277155 * bsc#1277159 * bsc#1277160 * bsc#1277202 * bsc#1277204 * bsc#1277275 * bsc#1277285 * bsc#1277391 * bsc#1277408 * bsc#1277516 * bsc#1277523 * bsc#1277551 * bsc#1277625 * bsc#1277660 * bsc#1277678 * bsc#1277688 * bsc#1277775 * bsc#1277776 Cross-References: * CVE-2024-44981 * CVE-2024-57841 * CVE-2025-38469 * CVE-2025-39964 * CVE-2025-40022 * CVE-2025-68179 * CVE-2025-68214 * CVE-2025-71075 * CVE-2025-71104 * CVE-2026-23210 * CVE-2026-23230 * CVE-2026-23454 * CVE-2026-31392 * CVE-2026-31418 * CVE-2026-31531 * CVE-2026-31557 * CVE-2026-31663 * CVE-2026-43116 * CVE-2026-43125 * CVE-2026-43163 * CVE-2026-43271 * CVE-2026-43273 * CVE-2026-43278 * CVE-2026-43319 * CVE-2026-43363 * CVE-2026-43416 * CVE-2026-45897 * CVE-2026-45968 * CVE-2026-46070 * CVE-2026-46091 * CVE-2026-46107 * CVE-2026-46115 * CVE-2026-46195 * CVE-2026-52920 * CVE-2026-52925 * CVE-2026-52929 * CVE-2026-52935 * CVE-2026-52939 * CVE-2026-52946 * CVE-2026-52975 * CVE-2026-52977 * CVE-2026-52990 * CVE-2026-52994 * CVE-2026-53001 * CVE-2026-53033 * CVE-2026-53059 * CVE-2026-53076 * CVE-2026-53077 * CVE-2026-53089 * CVE-2026-53091 * CVE-2026-53094 * CVE-2026-53096 * CVE-2026-53110 * CVE-2026-53111 * CVE-2026-53126 * CVE-2026-53154 * CVE-2026-53163 * CVE-2026-53207 * CVE-2026-53219 * CVE-2026-53220 * CVE-2026-53223 * CVE-2026-53228 * CVE-2026-53238 * CVE-2026-53260 * CVE-2026-53264 * CVE-2026-53269 * CVE-2026-53273 * CVE-2026-53309 * CVE-2026-53330 * CVE-2026-53336 * CVE-2026-53337 * CVE-2026-53353 * CVE-2026-53365 * CVE-2026-53366 * CVE-2026-53381 * CVE-2026-53388 * CVE-2026-63801 * CVE-2026-63808 * CVE-2026-63810 * CVE-2026-63823 * CVE-2026-63827 * CVE-2026-63828 * CVE-2026-63860 * CVE-2026-63865 * CVE-2026-63868 * CVE-2026-63879 * CVE-2026-63881 * CVE-2026-63886 * CVE-2026-63887 * CVE-2026-63888 * CVE-2026-63889 * CVE-2026-63891 * CVE-2026-63898 * CVE-2026-63920 * CVE-2026-63925 * CVE-2026-63926 * CVE-2026-63928 * CVE-2026-63944 * CVE-2026-63969 * CVE-2026-63970 * CVE-2026-63972 * CVE-2026-63973 * CVE-2026-63980 * CVE-2026-63985 * CVE-2026-63990 * CVE-2026-63992 * CVE-2026-63999 * CVE-2026-64000 * CVE-2026-64001 * CVE-2026-64002 * CVE-2026-64004 * CVE-2026-64005 * CVE-2026-64006 * CVE-2026-64007 * CVE-2026-64010 * CVE-2026-64011 * CVE-2026-64014 * CVE-2026-64015 * CVE-2026-64018 * CVE-2026-64029 * CVE-2026-64034 * CVE-2026-64039 * CVE-2026-64047 * CVE-2026-64048 * CVE-2026-64051 * CVE-2026-64052 * CVE-2026-64073 * CVE-2026-64083 * CVE-2026-64084 * CVE-2026-64085 * CVE-2026-64086 * CVE-2026-64087 * CVE-2026-64088 * CVE-2026-64097 * CVE-2026-64098 * CVE-2026-64102 * CVE-2026-64109 * CVE-2026-64112 * CVE-2026-64113 * CVE-2026-64114 * CVE-2026-64115 * CVE-2026-64118 * CVE-2026-64121 * CVE-2026-64125 * CVE-2026-64126 * CVE-2026-64128 * CVE-2026-64131 * CVE-2026-64133 * CVE-2026-64135 * CVE-2026-64137 * CVE-2026-64148 * CVE-2026-64155 * CVE-2026-64164 * CVE-2026-64166 * CVE-2026-64168 * CVE-2026-64178 * CVE-2026-64185 * CVE-2026-64188 * CVE-2026-64190 * CVE-2026-64192 * CVE-2026-64214 * CVE-2026-64217 * CVE-2026-64218 * CVE-2026-64219 * CVE-2026-64222 * CVE-2026-64225 * CVE-2026-64237 * CVE-2026-64243 * CVE-2026-64245 * CVE-2026-64246 * CVE-2026-64247 * CVE-2026-64249 * CVE-2026-64257 * CVE-2026-64266 * CVE-2026-64268 * CVE-2026-64271 * CVE-2026-64273 * CVE-2026-64274 * CVE-2026-64275 * CVE-2026-64276 * CVE-2026-64277 * CVE-2026-64286 * CVE-2026-64287 * CVE-2026-64294 * CVE-2026-64296 * CVE-2026-64303 * CVE-2026-64304 * CVE-2026-64305 * CVE-2026-64306 * CVE-2026-64312 * CVE-2026-64313 * CVE-2026-64315 * CVE-2026-64316 * CVE-2026-64317 * CVE-2026-64322 * CVE-2026-64323 * CVE-2026-64329 * CVE-2026-64331 * CVE-2026-64332 * CVE-2026-64333 * CVE-2026-64334 * CVE-2026-64335 * CVE-2026-64337 * CVE-2026-64338 * CVE-2026-64340 * CVE-2026-64341 * CVE-2026-64342 * CVE-2026-64343 * CVE-2026-64344 * CVE-2026-64346 * CVE-2026-64348 * CVE-2026-64350 * CVE-2026-64351 * CVE-2026-64355 * CVE-2026-64358 * CVE-2026-64362 * CVE-2026-64365 * CVE-2026-64375 * CVE-2026-64376 * CVE-2026-64378 * CVE-2026-64381 * CVE-2026-64382 * CVE-2026-64383 * CVE-2026-64384 * CVE-2026-64385 * CVE-2026-64386 * CVE-2026-64387 * CVE-2026-64388 * CVE-2026-64401 * CVE-2026-64403 * CVE-2026-64406 * CVE-2026-64408 * CVE-2026-64409 * CVE-2026-64411 * CVE-2026-64412 * CVE-2026-64420 * CVE-2026-64421 * CVE-2026-64423 * CVE-2026-64427 * CVE-2026-64429 * CVE-2026-64433 * CVE-2026-64434 * CVE-2026-64436 * CVE-2026-64440 * CVE-2026-64442 * CVE-2026-64443 * CVE-2026-64444 * CVE-2026-64445 * CVE-2026-64448 * CVE-2026-64450 * CVE-2026-64454 * CVE-2026-64455 * CVE-2026-64463 * CVE-2026-64470 * CVE-2026-64471 * CVE-2026-64472 * CVE-2026-64478 * CVE-2026-64479 * CVE-2026-64480 * CVE-2026-64481 * CVE-2026-64482 * CVE-2026-64483 * CVE-2026-64484 * CVE-2026-64486 * CVE-2026-64487 * CVE-2026-64489 * CVE-2026-64494 * CVE-2026-64495 * CVE-2026-64496 * CVE-2026-64497 * CVE-2026-64500 * CVE-2026-64503 * CVE-2026-64504 * CVE-2026-64505 * CVE-2026-64511 * CVE-2026-64512 * CVE-2026-64513 * CVE-2026-64524 * CVE-2026-64527 * CVE-2026-64536 * CVE-2026-64537 * CVE-2026-64538 * CVE-2026-64539 * CVE-2026-64540 * CVE-2026-64541 * CVE-2026-64543 * CVE-2026-64544 * CVE-2026-64545 * CVE-2026-64546 * CVE-2026-64547 * CVE-2026-64548 * CVE-2026-64549 * CVE-2026-64551 * CVE-2026-64552 * CVE-2026-64553 * CVE-2026-64554 * CVE-2026-64562 * CVE-2026-64563 * CVE-2026-64565 * CVE-2026-64567 * CVE-2026-64571 * CVE-2026-64572 * CVE-2026-64573 * CVE-2026-64574 * CVE-2026-64576 * CVE-2026-64577 * CVE-2026-64581 * CVE-2026-64582 * CVE-2026-64583 * CVE-2026-64584 * CVE-2026-64585 * CVE-2026-64593 * CVE-2026-64597 * CVE-2026-64598 * CVE-2026-64599 * CVE-2026-64602 * CVE-2026-64604 * CVE-2026-68081 * CVE-2026-68082 * CVE-2026-68085 * CVE-2026-68086 * CVE-2026-68088 * CVE-2026-68091 * CVE-2026-68093 * CVE-2026-68102 * CVE-2026-68104 * CVE-2026-68106 * CVE-2026-68107 * CVE-2026-68108 * CVE-2026-68110 * CVE-2026-68111 * CVE-2026-68112 * CVE-2026-68115 * CVE-2026-68116 * CVE-2026-68117 * CVE-2026-68121 * CVE-2026-68123 * CVE-2026-68125 * CVE-2026-68126 * CVE-2026-68127 * CVE-2026-68129 * CVE-2026-68132 * CVE-2026-68133 * CVE-2026-68136 * CVE-2026-68137 * CVE-2026-68138 * CVE-2026-68139 * CVE-2026-68142 * CVE-2026-68143 * CVE-2026-68145 * CVE-2026-68149 * CVE-2026-68153 * CVE-2026-68154 * CVE-2026-68155 * CVE-2026-68156 * CVE-2026-68157 * CVE-2026-68158 * CVE-2026-68159 * CVE-2026-68160 * CVE-2026-68161 * CVE-2026-68162 * CVE-2026-68166 * CVE-2026-68180 * CVE-2026-68181 * CVE-2026-68182 * CVE-2026-68184 * CVE-2026-68188 * CVE-2026-68189 * CVE-2026-68192 * CVE-2026-68193 * CVE-2026-68194 * CVE-2026-68195 * CVE-2026-68196 * CVE-2026-68197 * CVE-2026-68199 * CVE-2026-68202 * CVE-2026-68204 * CVE-2026-68205 * CVE-2026-68206 * CVE-2026-68207 * CVE-2026-68209 * CVE-2026-68210 * CVE-2026-68212 * CVE-2026-68213 * CVE-2026-68214 * CVE-2026-68215 * CVE-2026-68216 * CVE-2026-68217 * CVE-2026-68218 * CVE-2026-68219 * CVE-2026-68220 * CVE-2026-68222 * CVE-2026-68223 * CVE-2026-68226 * CVE-2026-68227 * CVE-2026-68229 * CVE-2026-68231 * CVE-2026-68234 * CVE-2026-68236 * CVE-2026-68238 * CVE-2026-68243 * CVE-2026-68244 * CVE-2026-68246 * CVE-2026-68247 * CVE-2026-68248 * CVE-2026-68249 * CVE-2026-68250 * CVE-2026-68251 * CVE-2026-68254 * CVE-2026-68255 * CVE-2026-68256 * CVE-2026-68259 * CVE-2026-68269 * CVE-2026-68271 * CVE-2026-68272 * CVE-2026-68277 * CVE-2026-68278 * CVE-2026-68279 * CVE-2026-68280 * CVE-2026-68284 * CVE-2026-68286 * CVE-2026-68288 * CVE-2026-68289 * CVE-2026-68293 * CVE-2026-68297 * CVE-2026-68299 * CVE-2026-68300 * CVE-2026-68303 * CVE-2026-68304 * CVE-2026-68306 * CVE-2026-68308 * CVE-2026-68309 * CVE-2026-68310 * CVE-2026-68312 * CVE-2026-68313 * CVE-2026-68315 * CVE-2026-68320 * CVE-2026-68322 * CVE-2026-68324 * CVE-2026-68325 * CVE-2026-68326 * CVE-2026-68327 * CVE-2026-68328 * CVE-2026-68329 * CVE-2026-68331 * CVE-2026-68333 * CVE-2026-68335 * CVE-2026-68336 * CVE-2026-68339 * CVE-2026-68340 * CVE-2026-68343 * CVE-2026-68346 * CVE-2026-68348 * CVE-2026-68349 * CVE-2026-68350 * CVE-2026-68351 * CVE-2026-68352 * CVE-2026-68353 * CVE-2026-68354 * CVE-2026-68355 * CVE-2026-68357 * CVE-2026-68359 * CVE-2026-68360 * CVE-2026-68361 * CVE-2026-68362 * CVE-2026-68363 * CVE-2026-68365 * CVE-2026-68366 * CVE-2026-68368 * CVE-2026-68369 * CVE-2026-68370 * CVE-2026-68372 * CVE-2026-68373 * CVE-2026-68377 * CVE-2026-68386 * CVE-2026-68391 * CVE-2026-68392 * CVE-2026-68397 * CVE-2026-68398 * CVE-2026-68399 * CVE-2026-68402 * CVE-2026-68403 * CVE-2026-68405 * CVE-2026-68406 * CVE-2026-68407 * CVE-2026-68408 * CVE-2026-68410 * CVE-2026-68413 * CVE-2026-68414 * CVE-2026-68417 * CVE-2026-68418 * CVE-2026-68419 * CVE-2026-68422 * CVE-2026-68425 * CVE-2026-68426 * CVE-2026-68427 * CVE-2026-68428 * CVE-2026-68429 * CVE-2026-68430 * CVE-2026-68432 * CVE-2026-68433 * CVE-2026-68434 * CVE-2026-68444 * CVE-2026-68445 * CVE-2026-68446 * CVE-2026-68450 * CVE-2026-68470 * CVE-2026-68480 * CVE-2026-72020 * CVE-2026-72035 * CVE-2026-72036 * CVE-2026-72069 * CVE-2026-72072 * CVE-2026-72083 * CVE-2026-72084 * CVE-2026-72123 * CVE-2026-72132 * CVE-2026-72221 * CVE-2026-72222 * CVE-2026-72251 * CVE-2026-72254 * CVE-2026-72262 * CVE-2026-72288 * CVE-2026-72289 * CVE-2026-72296 * CVE-2026-72307 * CVE-2026-72308 * CVE-2026-72317 * CVE-2026-72341 * CVE-2026-72342 * CVE-2026-72343 * CVE-2026-72389 * CVE-2026-72463 * CVE-2026-72464 * CVE-2026-72466 * CVE-2026-72467 * CVE-2026-72469 * CVE-2026-72473 * CVE-2026-72494 * CVE-2026-72495 * CVE-2026-72496 * CVE-2026-72499 * CVE-2026-72501 * CVE-2026-72502 * CVE-2026-74269 * CVE-2026-74296 * CVE-2026-74297 * CVE-2026-74318 * CVE-2026-74321 * CVE-2026-74334 * CVE-2026-74345 * CVE-2026-74394 * CVE-2026-74395 * CVE-2026-74454 * CVE-2026-74474 * CVE-2026-74481 * CVE-2026-74482 * CVE-2026-74488 * CVE-2026-74495 * CVE-2026-74496 * CVE-2026-74509 * CVE-2026-74510 * CVE-2026-74512 * CVE-2026-74516 * CVE-2026-74518 * CVE-2026-74527 * CVE-2026-74537 * CVE-2026-74548 * CVE-2026-74550 * CVE-2026-74556 * CVE-2026-74563 * CVE-2026-74566 * CVE-2026-74567 * CVE-2026-74571 * CVE-2026-74581 * CVE-2026-74582 * CVE-2026-74584 * CVE-2026-74610 * CVE-2026-74669 * CVE-2026-74692 * CVE-2026-74694 * CVE-2026-74695 * CVE-2026-74717 * CVE-2026-74722 * CVE-2026-80529 * CVE-2026-80534 * CVE-2026-80590 * CVE-2026-80654 CVSS scores: * CVE-2024-44981 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L * CVE-2024-44981 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2024-44981 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-57841 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-38469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39964 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-39964 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-39964 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-39964 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40022 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-40022 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-68179 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68179 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68214 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71104 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2025-71104 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-71104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23210 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23230 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23230 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23230 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-23230 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23454 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23454 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23454 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31392 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-31392 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-31392 ( NVD ): 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L * CVE-2026-31418 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31418 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31531 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31557 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31663 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31663 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43116 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43163 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43271 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43271 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43271 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43319 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43319 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45897 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45897 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45897 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46070 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46070 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46091 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46091 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46091 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46107 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46107 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46107 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46115 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46115 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46195 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46195 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52920 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-52920 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-52925 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52925 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52925 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52939 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52939 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52977 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52977 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52990 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53033 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53059 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53059 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53059 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53076 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53076 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53077 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53077 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53077 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53089 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53089 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53091 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53091 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53091 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-53091 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53094 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53094 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53096 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53096 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53110 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53111 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53111 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53111 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53207 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53228 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53228 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53238 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53238 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53269 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53269 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53269 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53309 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53309 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53309 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53330 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53330 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53336 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53336 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53353 ( SUSE ): 0.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53353 ( SUSE ): 0.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N * CVE-2026-53353 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53365 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53365 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53365 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53381 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63801 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63801 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63801 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63808 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63808 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-63808 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63810 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63810 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63823 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63823 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63823 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63827 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63828 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63828 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63828 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-63860 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63860 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63860 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63865 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63865 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63865 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-63868 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63868 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63879 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63879 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63879 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63881 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63886 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63886 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63886 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63887 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63887 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63887 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63888 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63888 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63888 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63889 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63889 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63889 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63891 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63891 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63898 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63898 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63920 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63920 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63920 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63925 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63925 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63925 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-63926 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63926 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63926 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63928 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63928 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63944 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63944 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63969 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63969 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63970 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63970 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63972 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63972 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63972 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63973 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63973 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63980 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63985 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63985 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63985 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63990 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63990 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63992 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63992 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63992 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63999 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63999 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64000 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64000 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64000 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64001 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64001 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64002 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64002 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64002 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64004 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64004 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64005 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64005 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64005 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64006 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-64006 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-64007 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64007 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64007 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64010 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64011 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64014 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64014 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64015 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64015 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64018 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-64018 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-64018 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64029 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64029 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64029 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64034 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64039 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64039 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64039 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64047 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64047 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64048 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64048 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64048 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64051 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64051 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64051 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64052 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64052 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64052 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64073 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64073 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64073 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64083 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64083 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64083 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64084 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64084 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64084 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64085 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64085 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64085 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64086 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64086 ( SUSE ): 5.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64086 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64087 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64087 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64087 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64088 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64088 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64088 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64097 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64097 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64097 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64098 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64102 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-64102 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-64102 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64113 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64113 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64114 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64115 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64118 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64118 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64118 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64121 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64121 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64121 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64125 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64126 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64126 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L * CVE-2026-64126 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-64128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64128 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64135 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64137 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64137 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64137 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64148 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64148 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64148 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64155 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64164 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64166 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64178 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64178 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64185 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64185 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64188 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64188 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64188 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64190 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64190 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64190 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64217 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64217 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64217 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64218 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64219 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64222 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64222 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64222 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64225 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64225 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64225 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64237 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64237 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64245 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64246 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64246 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64246 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64247 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64247 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-64249 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64249 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64257 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64257 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-64257 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64266 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64266 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64268 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64271 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64271 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64271 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64273 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64275 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64275 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64277 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64286 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64286 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64287 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64303 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64303 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64303 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64304 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64305 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64305 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64306 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64313 ( SUSE ): 7.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-64313 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64313 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64315 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64316 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64316 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64317 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64317 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64317 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64322 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64322 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64322 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64323 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64323 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64329 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64329 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64329 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64331 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64331 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64333 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64333 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64334 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64334 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64334 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64335 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64335 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64335 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64337 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64337 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64338 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64340 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64340 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64340 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64341 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64342 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64343 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64344 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64346 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64348 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64348 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64348 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64350 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64350 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64350 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64351 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64351 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64351 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64355 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64355 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64358 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64358 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64365 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64375 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64375 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64376 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64376 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64376 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64381 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64381 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64382 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64382 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64383 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64383 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64384 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64385 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64386 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64387 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64388 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64388 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-64388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64401 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64401 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64403 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64403 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64403 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64406 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64408 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64409 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64409 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64411 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64411 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64411 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64412 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64412 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64412 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64420 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64421 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64421 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64427 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64427 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64434 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64436 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64436 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64440 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64440 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64440 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64442 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64442 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64443 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64443 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64444 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64444 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64444 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64445 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64448 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64448 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64450 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64454 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64471 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64478 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64478 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64479 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64480 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64481 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64481 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64482 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64482 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64483 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64484 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64484 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64486 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64487 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64489 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64497 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64500 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64503 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64504 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64505 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64511 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64511 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64512 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64513 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64527 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64537 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64537 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64538 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64540 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64540 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64540 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64541 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64541 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64541 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64544 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64544 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64545 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64547 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64547 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64547 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64548 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64548 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64549 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64551 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64551 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64552 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64552 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64552 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64553 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64562 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64562 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64563 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64563 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64565 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64565 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64567 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64567 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64567 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64571 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64571 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64572 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64572 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64573 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64573 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64574 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64576 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64576 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64576 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64577 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64577 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64577 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64581 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64581 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64581 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64582 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64583 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64583 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64584 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64585 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64593 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64593 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64598 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64598 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64599 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64599 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64602 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64604 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68081 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68081 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68082 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68082 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68082 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68085 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68085 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68085 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68086 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-68086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-68088 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68088 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68091 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68091 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68091 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68093 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-68093 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68102 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68102 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68104 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68106 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68106 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68106 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68107 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68107 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68107 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68108 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68108 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68108 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68110 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68110 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68111 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68111 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68115 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68115 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68116 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68116 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-68116 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68117 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68117 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68121 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68121 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68123 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68123 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68123 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68125 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68125 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68125 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68126 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68126 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68127 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68127 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68127 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68129 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68129 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68129 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68132 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68132 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68133 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68133 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68136 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68136 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68137 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68139 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68139 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68142 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68142 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-68142 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68143 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68143 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68143 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68145 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68145 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68145 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68149 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68149 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68149 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-68153 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68153 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68153 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68154 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68154 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68154 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68155 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68155 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68155 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68156 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68156 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68156 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68157 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68157 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68157 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68158 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68158 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68158 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68159 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68159 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68159 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68160 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68160 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68160 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68161 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68161 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68161 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68162 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68166 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68166 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68180 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68182 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68184 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68184 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68188 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68192 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68192 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68197 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68202 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68204 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68207 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68210 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68210 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68212 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68217 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68218 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68218 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68219 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68219 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68220 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68220 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68222 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68223 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68223 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68226 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68226 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68227 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68227 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68229 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68229 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-68229 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68231 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68231 ( SUSE ): 2.1 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68234 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68236 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68236 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68236 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68238 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68238 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68243 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68244 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68246 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68246 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68247 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68247 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68248 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68249 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68250 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68250 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68251 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68251 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68256 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68259 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68259 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68269 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68271 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68272 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68278 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68278 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68279 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68279 ( SUSE ): 2.4 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68280 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68280 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68284 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68284 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68286 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68286 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68288 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68288 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68289 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68293 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68293 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68299 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68308 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68309 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68310 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68312 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68313 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-68322 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68324 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68325 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68327 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68327 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68328 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68333 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68343 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68349 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68350 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68351 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68353 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68353 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68354 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68355 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68357 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68359 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68360 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68361 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68365 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68365 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-68366 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68368 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68369 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68370 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68372 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68377 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68377 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68386 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68391 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68391 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68392 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68392 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68402 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68402 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68403 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68405 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68406 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68407 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68408 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68410 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68413 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68414 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68414 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68422 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68425 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68425 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68426 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68426 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68427 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68427 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68427 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68428 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68430 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68430 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68433 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-68434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68444 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68445 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68445 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68445 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68446 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68446 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68470 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68470 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68470 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68480 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-72020 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72020 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72020 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72035 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72036 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72069 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72083 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72084 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72123 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72132 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72132 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72221 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72221 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72221 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72222 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72251 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72251 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72251 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72254 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72262 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72262 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72288 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72289 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72289 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72289 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72296 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72296 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72296 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-72307 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72307 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72308 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72308 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72317 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72317 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72317 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72341 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72342 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72342 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72343 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72343 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72389 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72463 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72463 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72464 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72464 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72467 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72473 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-72473 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72494 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72495 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72496 ( NVD ): 9.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H * CVE-2026-72499 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72499 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72501 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74269 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74269 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74318 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74345 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74345 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74345 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74394 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74395 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74395 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74454 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74454 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-74454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74474 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74474 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74481 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74482 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74482 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74488 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74488 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74495 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74495 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74509 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74509 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74516 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-74516 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74518 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74518 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74527 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-74527 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74537 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74537 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74550 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74550 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74556 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-74556 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74563 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74566 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-74567 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74567 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74571 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74581 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74581 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74582 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74584 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-74584 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-74584 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-74610 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-74610 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74610 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74692 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74694 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74694 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74695 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74695 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74717 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74717 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74722 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80534 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80534 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80590 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-80654 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80654 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves 588 vulnerabilities and has 23 fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 RT kernel was updated to fix various security issues: The following security issues were fixed: * CVE-2024-57841: net: fix memory leak in tcp_conn_request() (bsc#1235944) * CVE-2025-68214: timers: Fix NULL function pointer race in timer_shutdown_sync() (bsc#1255225). * CVE-2025-71075: scsi: aic94xx: fix use-after-free in device removal path (bsc#1256629). * CVE-2026-31392: smb: client: fix krb5 mount with username option (bsc#1261788). * CVE-2026-31418: netfilter: ipset: drop logically empty buckets in mtype_del (bsc#1262073). * CVE-2026-31531: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() (bsc#1263004). * CVE-2026-31557: nvmet: move async event work off nvmet-wq (bsc#1263061). * CVE-2026-31663: xfrm: hold device only for the asynchronous decryption (bsc#1263133). * CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack (bsc#1264619). * CVE-2026-43125: dlm: validate length in dlm_search_rsb_tree (bsc#1264541). * CVE-2026-43163: md/bitmap: fix GPF in write_page caused by resize race (bsc#1264335). * CVE-2026-43271: md-cluster: fix NULL pointer dereference in process_metadata_update (bsc#1264587). * CVE-2026-43273: ceph: supply snapshot context in ceph_zero_partial_object() (bsc#1264446). * CVE-2026-43278: dm: clear cloned request bio pointer when last clone bio completes (bsc#1264584). * CVE-2026-43319: spi: spidev: fix lock inversion between spi_lock and buf_lock (bsc#1264788). * CVE-2026-43363: x86/apic: Disable x2apic on resume if the kernel expects so (bsc#1265068). * CVE-2026-43416: powerpc, perf: Check that current->mm is alive before getting user callchain (bsc#1265121). * CVE-2026-45897: bpf: Fix UAF in sock clone early bailouts (bsc#1266897). * CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). * CVE-2026-46070: md/raid5: validate payload size before accessing journal metadata (bsc#1267501). * CVE-2026-46091: media: rc: igorplugusb: heed coherency rules (bsc#1267238). * CVE-2026-46107: dm-thin: fix metadata refcount underflow (bsc#1267612). * CVE-2026-46115: block: add pgmap check to biovec_phys_mergeable (bsc#1266874). * CVE-2026-46195: smb: client: validate dacloffset before building DACL pointers (bsc#1266860). * CVE-2026-52920: netfilter: xt_policy: fix strict mode inbound policy matching (bsc#1269013). * CVE-2026-52925: vrf: Fix a potential NPD when removing a port from a VRF (bsc#1268987). * CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). * CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send (bsc#1268979). * CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion (bsc#1268972). * CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (bsc#1269113). * CVE-2026-52975: bonding: 802.3ad replace MAC_ADDRESS_EQUAL with __agg_has_partner (bsc#1269234). * CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). * CVE-2026-52990: fsnotify: fix inode reference leak in fsnotify_recalc_mask() (bsc#1269108). * CVE-2026-52994: vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting (bsc#1269126). * CVE-2026-53001: netfilter: xtables: restrict several matches to inet family (bsc#1269114). * CVE-2026-53033: bpf, sockmap: Take state lock for af_unix iter (bsc#1269388). * CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). * CVE-2026-53076: bpf: Fix OOB in pcpu_init_value (bsc#1269695). * CVE-2026-53077: net/rds: Restrict use of RDS/IB to the initial network namespace (bsc#1269412). * CVE-2026-53089: bpf: Fix use-after-free in offloaded map/prog info fill (bsc#1269783). * CVE-2026-53091: net: account for encap headers in qdisc pkt len (bsc#1269530). * CVE-2026-53094: bpf: Fix stale offload->prog pointer after constant blinding (bsc#1269965). * CVE-2026-53096: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (bsc#1269969). * CVE-2026-53110: selftests/bpf: Add ASSERT_OK_FD macro (bsc#1269985). * CVE-2026-53111: bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap (bsc#1269167). * CVE-2026-53126: blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() (bsc#1269635). * CVE-2026-53154: mm/hugetlb: restore reservation on error in hugetlb folio copy paths (bsc#1269665). * CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). * CVE-2026-53207: mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison (bsc#1269590). * CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers (bsc#1269686). * CVE-2026-53220: netfilter: revalidate bridge ports (bsc#1269381). * CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs (bsc#1269301). * CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads (bsc#1269256). * CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths (bsc#1269774). * CVE-2026-53260: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req() (bsc#1269731). * CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). * CVE-2026-53269: netfilter: synproxy: add mutex to guard hook reference counting (bsc#1269579). * CVE-2026-53273: tee: optee: prevent use-after-free when the client exits before the supplicant (bsc#1269713). * CVE-2026-53309: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (bsc#1269815). * CVE-2026-53330: drm/amd/display: Fix out-of-bounds read in (bsc#1270090). * CVE-2026-53336: nvmem: layouts: onie-tlv: fix hang on unknown types (bsc#1270108). * CVE-2026-53337: net: bonding: fix NULL pointer dereference in bond_do_ioctl() (bsc#1270251). * CVE-2026-53353: hsr: Remove WARN_ONCE() in hsr_addr_is_self() (bsc#1270111). * CVE-2026-53365: vsock/virtio: fix zerocopy completion for multi-skb sends (bsc#1271365). * CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). * CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). * CVE-2026-63808: exfat: fix potential use-after-free in exfat_find_dir_entry() (bsc#1272260). * CVE-2026-63810: block: Avoid mounting the bdev pseudo-filesystem in userspace (bsc#1272297). * CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). * CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179). * CVE-2026-63828: apparmor: mediate the implicit connect of TCP fast open sendmsg (bsc#1272175). * CVE-2026-63860: RDMA/core: Prefer NLA_NUL_STRING (bsc#1272429). * CVE-2026-63865: bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (bsc#1272486). * CVE-2026-63868: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (bsc#1272497). * CVE-2026-63879: drm/amdgpu: fix amdgpu_hmm_range_get_pages (bsc#1272569). * CVE-2026-63881: drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger (bsc#1272571). * CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). * CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). * CVE-2026-63889: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (bsc#1272423). * CVE-2026-63891: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (bsc#1272641). * CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). * CVE-2026-63925: macsec: fix replay protection at XPN lower-PN wrap (bsc#1273008). * CVE-2026-63926: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (bsc#1273019). * CVE-2026-63944: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (bsc#1272662). * CVE-2026-63969: ipv6: fix possible infinite loop in rt6_fill_node() (bsc#1272484). * CVE-2026-63970: vsock/virtio: bind uarg before filling zerocopy skb (bsc#1272673). * CVE-2026-63980: net/handshake: Use spin_lock_bh for hn_lock (bsc#1273028). * CVE-2026-63985: ethtool: eeprom: add more safeties to EEPROM Netlink fallback (bsc#1272963). * CVE-2026-63990: bonding: refuse to enslave CAN devices (bsc#1273027). * CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). * CVE-2026-63999: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure (bsc#1273038). * CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273030). * CVE-2026-64001: ALSA: pcm: oss: Fix setup list UAF on proc write error (bsc#1273734). * CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). * CVE-2026-64004: net/iucv: fix locking in .getsockopt (bsc#1273804). * CVE-2026-64005: net/smc: Do not re-initialize smc hashtables (bsc#1273831). * CVE-2026-64006: netfilter: nf_tables: fix dst corruption in same register operation (bsc#1273834). * CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). * CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882). * CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891). * CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762). * CVE-2026-64029: ALSA: seq: Serialize UMP output teardown with event_input (bsc#1273766). * CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). * CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). * CVE-2026-64052: block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() (bsc#1272983). * CVE-2026-64073: irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT (bsc#1273490). * CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488). * CVE-2026-64102: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (bsc#1272516). * CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748). * CVE-2026-64112: rbd: eliminate a race in lock_dwork draining on unmap (bsc#1273741). * CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning (bsc#1272262). * CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). * CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). * CVE-2026-64118: qed: fix double free in qed_cxt_tables_alloc() (bsc#1273749). * CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273743). * CVE-2026-64125: net: bcmgenet: keep RBUF EEE/PM disabled (bsc#1272346). * CVE-2026-64131: mm/memory: fix spurious warning when unmapping device- private/exclusive pages (bsc#1274063). * CVE-2026-64148: pds_core: check health in devcmd wait (bsc#1273956). * CVE-2026-64164: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (bsc#1273957). * CVE-2026-64185: sysfs: don't remove existing directory on update failure (bsc#1272200). * CVE-2026-64188: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (bsc#1272150). * CVE-2026-64190: net: team: fix NULL pointer dereference in team_xmit during mode change (bsc#1272210). * CVE-2026-64192: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (bsc#1272213). * CVE-2026-64214: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() (bsc#1272799). * CVE-2026-64217: netfs: Fix overrun check in netfs_extract_user_iter() (bsc#1272798). * CVE-2026-64222: octeontx2-pf: avoid double free of pool->stack on AQ init failure (bsc#1272788). * CVE-2026-64225: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (bsc#1272786). * CVE-2026-64245: fbdev: modedb: fix a possible UAF in fb_find_mode() (bsc#1273905). * CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). * CVE-2026-64286: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (bsc#1274058). * CVE-2026-64287: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (bsc#1273325). * CVE-2026-64294: mm: do file ownership checks with the proper mount idmap (bsc#1273525). * CVE-2026-64296: exfat: bound uniname advance in exfat_find_dir_entry() (bsc#1273975). * CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944). * CVE-2026-64312: crypto: pcrypt - restore callback for non-parallel fallback (bsc#1273968). * CVE-2026-64315: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1274028). * CVE-2026-64316: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1273598). * CVE-2026-64317: isofs: bound Rock Ridge symlink components to the SL record (bsc#1273936). * CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count (bsc#1273958). * CVE-2026-64323: udf: validate VAT header length against the VAT inode size (bsc#1273305). * CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). * CVE-2026-64375: proc: protect ptrace_may_access() with exec_update_lock (FD links) (bsc#1273868). * CVE-2026-64378: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() (bsc#1273603). * CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard() (bsc#1273860). * CVE-2026-64382: smb: client: fix double-free in SMB2_open() replay (bsc#1273291). * CVE-2026-64383: smb: client: fix double-free in SMB2_flush() replay (bsc#1273426). * CVE-2026-64384: smb: client: fix change notify replay double-free (bsc#1274541). * CVE-2026-64385: smb: client: fix double-free in SMB2_ioctl() replay (bsc#1274539). * CVE-2026-64386: smb: client: fix query_info() replay double-free (bsc#1274543). * CVE-2026-64387: smb: client: fix query directory replay double-free (bsc#1274545). * CVE-2026-64388: smb/client: fix chown/chgrp with SMB3 POSIX Extensions (bsc#1274061). * CVE-2026-64411: netfilter: ebtables: terminate table name before find_table_lock() (bsc#1274077). * CVE-2026-64412: netfilter: ebtables: module names must be null-terminated (bsc#1273780). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). * CVE-2026-64434: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (bsc#1273880). * CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states (bsc#1274277). * CVE-2026-64448: smb: client: restrict implied bcc[0] exemption to responses without data area (bsc#1273982). * CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). * CVE-2026-64463: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres (bsc#1273273). * CVE-2026-64472: vfio/mlx5: Fix racy bitfields and tighten struct layout (bsc#1274075). * CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547). * CVE-2026-64537: bridge: cfm: reject invalid CCM interval at configuration time (bsc#1273289). * CVE-2026-64538: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change() (bsc#1273335). * CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). * CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). * CVE-2026-64545: net, bpf: check master for NULL in xdp_master_redirect() (bsc#1273318). * CVE-2026-64548: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (bsc#1273337). * CVE-2026-64551: sctp: validate STALE_COOKIE cause length before reading staleness (bsc#1273813). * CVE-2026-64552: virtio-net: fix len check in receive_big() (bsc#1273323). * CVE-2026-64553: net: psample: fix info leak in PSAMPLE_ATTR_DATA (bsc#1273336). * CVE-2026-64554: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (bsc#1273340). * CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930). * CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). * CVE-2026-64567: btrfs: reject free space cache with more entries than pages (bsc#1274006). * CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). * CVE-2026-64576: nexthop: initialize extack in nh_res_bucket_migrate() (bsc#1274030). * CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031). * CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). * CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (bsc#1274040). * CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497). * CVE-2026-64597: smb: client: fix double-free in SMB2_close() replay (bsc#1274297). * CVE-2026-64598: smb/client: Fix error code in smb2_aead_req_alloc() (bsc#1274298). * CVE-2026-68081: KVM: nVMX: Add helper to put (unmap) vmcs12 pages (bsc#1274580). * CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers() (bsc#1274581). * CVE-2026-68086: mm/khugepaged: write all dirty file folios when collapsing (bsc#1274713). * CVE-2026-68116: vxlan: mdb: Fix source list corruption on a failed replace (bsc#1274876). * CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (bsc#1274881). * CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). * CVE-2026-68123: openvswitch: fix GSO userspace truncation underflow (bsc#1275169). * CVE-2026-68127: ila: reload IPv6 header after pskb_may_pull in checksum adjust (bsc#1275237). * CVE-2026-68129: gve: fix Rx queue stall on alloc failure (bsc#1275517). * CVE-2026-68132: super: fix emergency thaw deadlock on frozen block devices (bsc#1275553). * CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). * CVE-2026-68139: net/mlx5e: Use sender devcom for MPV master-up (bsc#1275578). * CVE-2026-68142: geneve: require CAP_NET_ADMIN in the device netns for changelink (bsc#1275582). * CVE-2026-68143: net: slip: serialize receive against buffer reallocation (bsc#1275583). * CVE-2026-68145: iomap: fix out-of-bounds bitmap_set() with zero-length range (bsc#1275584). * CVE-2026-68149: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (bsc#1275294). * CVE-2026-68153: libceph: remove debugfs files before client teardown (bsc#1275301). * CVE-2026-68154: libceph: reject zero bucket types in crush_decode (bsc#1275303). * CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). * CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after authorizer update (bsc#1275305). * CVE-2026-68157: libceph: guard missing CRUSH type name lookup (bsc#1275306). * CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). * CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). * CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472). * CVE-2026-68161: sctp: close UDP tunnel sockets during netns teardown (bsc#1274892). * CVE-2026-68166: userfaultfd: prevent registration of special VMAs (bsc#1274930). * CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). * CVE-2026-68205: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (bsc#1274934). * CVE-2026-68238: drm/amdgpu: Release VFCT ACPI table reference (bsc#1275704). * CVE-2026-68247: drm/i915/bios: range check LFP Data Block panel_type2 (bsc#1275817). * CVE-2026-68254: drm/i915/vrr: require valid min/max vfreq for VRR (bsc#1275150). * CVE-2026-68284: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (bsc#1275970). * CVE-2026-68286: drop_monitor: perform u64_stats updates under IRQ-disabled section (bsc#1275973). * CVE-2026-68288: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (bsc#1275975). * CVE-2026-68289: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (bsc#1275976). * CVE-2026-68293: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (bsc#1275091). * CVE-2026-68297: tipc: fix u16 MTU truncation in media and bearer MTU validation (bsc#1275040). * CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (bsc#1275088). * CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL (bsc#1275083). * CVE-2026-68312: cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths (bsc#1274663). * CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit (bsc#1274665). * CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq() (bsc#1274662). * CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (bsc#1274659). * CVE-2026-68322: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (bsc#1274656). * CVE-2026-68324: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (bsc#1274649). * CVE-2026-68325: iommu/amd: Bound the early ACPI HID map (bsc#1274651). * CVE-2026-68328: nfp: Check resource mutex allocation (bsc#1274646). * CVE-2026-68329: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (bsc#1274645). * CVE-2026-68331: dpaa2-eth: put MAC endpoint device on disconnect (bsc#1274642). * CVE-2026-68333: dpaa2-switch: put MAC endpoint device on disconnect (bsc#1274644). * CVE-2026-68335: rds: drop incoming messages that cross network namespace boundaries (bsc#1274640). * CVE-2026-68336: bonding: fix devconf_all NULL dereference when IPv6 is disabled (bsc#1274639). * CVE-2026-68343: smb: client: validate DFS referral PathConsumed (bsc#1274629). * CVE-2026-68377: net/sched: act_tunnel_key: Defer dst_release to RCU callback (bsc#1274831). * CVE-2026-68386: bpf, sockmap: Reject unhashed UDP sockets on sockmap update (bsc#1274814). * CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). * CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). * CVE-2026-68408: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (bsc#1274709). * CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). * CVE-2026-68418: RDMA/irdma: Prevent user-triggered null deref on QP create (bsc#1274690). * CVE-2026-68419: RDMA/irdma: Prevent rereg_mr for non-mem regions (bsc#1274698). * CVE-2026-68422: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (bsc#1274706). * CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1274700). * CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). * CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink (bsc#1274800). * CVE-2026-68433: libceph: bound get_version reply decode to front len (bsc#1274801). * CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert (bsc#1274834). * CVE-2026-68470: wifi: cfg80211/mac80211: correctly parse S1G beacon optional elements (bsc#1276500). * CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). * CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). * CVE-2026-72035: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1276961). * CVE-2026-72036: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1277034). * CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). * CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155). * CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). * CVE-2026-72084: scsi: target: Bound PR-OUT TransportID parsing to the received buffer (bsc#1275540). * CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523). * CVE-2026-72132: NFS: Charge unstable writes by request size, not folio size (bsc#1277551). * CVE-2026-72221: sunrpc: wait for in-flight TLS handshake callback when cancel loses race (bsc#1275665). * CVE-2026-72222: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback (bsc#1275669). * CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). * CVE-2026-72254: netfilter: nft_fib: reject fib expression on the netdev egress hook (bsc#1277204). * CVE-2026-72262: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (bsc#1277678). * CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). * CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). * CVE-2026-72296: net: ife: require ETH_HLEN to be pullable in ife_decode() (bsc#1275923). * CVE-2026-72307: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (bsc#1277160). * CVE-2026-72308: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (bsc#1277159). * CVE-2026-72317: SUNRPC: pin upper rpc_clnt across the TLS connect_worker (bsc#1275925). * CVE-2026-72341: net/mlx5e: Fix publication race for priv->channel_stats[] (bsc#1277660). * CVE-2026-72342: net/mlx5e: Fix HV VHCA stats agent registration race (bsc#1277775). * CVE-2026-72343: net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation (bsc#1277776). * CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). * CVE-2026-72463: xfrm: Fix dev use-after-free in xfrm async resumption (bsc#1268276 bsc#1277064). * CVE-2026-72464: xprtrdma: Remove temp allocation of rpcrdma_rep objects (bsc#1277069). * CVE-2026-72466: xprtrdma: Fix bcall rep leak and unbounded peek (bsc#1277057). * CVE-2026-72467: xprtrdma: Check frwr_wp_create() during connect (bsc#1277059). * CVE-2026-72469: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE (bsc#1277047). * CVE-2026-72473: xprtrdma: Avoid 250 ms delay on backlog wakeup (bsc#1277037). * CVE-2026-72494: RDMA/irdma: Replace waitqueue and flag with completion (bsc#1276941). * CVE-2026-72495: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages (bsc#1276937). * CVE-2026-72496: RDMA/bnxt_re: Proper rollback if the ioremap fails (bsc#1276943). * CVE-2026-72499: RDMA/bnxt_re: Free CQ toggle page after firmware teardown (bsc#1276551). * CVE-2026-72501: RDMA/bnxt_re: Initialize dpi variable to zero (bsc#1276546). * CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (bsc#1276542). * CVE-2026-74269: bnxt: fix head underflow on XDP head-grow (bsc#1276507). * CVE-2026-74296: RDMA/mlx5: Release the HW-provided UAR index rather than the SW one (bsc#1276452). * CVE-2026-74297: RDMA/mlx5: Fix undefined shift of user RQ WQE size (bsc#1276446). * CVE-2026-74318: btrfs: fix deadlock cloning inline extent when using flushoncommit (bsc#1276864). * CVE-2026-74321: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (bsc#1277202). * CVE-2026-74334: RDMA/nldev: Fix locking when accessing mr->pd (bsc#1277095). * CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). * CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). * CVE-2026-74395: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (bsc#1277077). * CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073). * CVE-2026-74474: vxlan: use pskb_network_may_pull() for transmit path header pulls (bsc#1276335). * CVE-2026-74481: mm/page_reporting: use system_freezable_wq to fix UAF during suspend (bsc#1276355). * CVE-2026-74482: mm/huge_memory: unlock i_mmap_rwsem before releasing after- split folios (bsc#1276346). * CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350). * CVE-2026-74495: igbvf: Fix leak in TX DMA error cleanup (bsc#1275864). * CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). * CVE-2026-74509: Bluetooth: hci_sync: Fix advertising data UAFs (bsc#1275946). * CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation (bsc#1275950). * CVE-2026-74512: audit: fix potential use-after-free in audit_del_rule() (bsc#1275954). * CVE-2026-74516: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (bsc#1275797). * CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). * CVE-2026-74527: octeontx2-af: Block VFs from clobbering special CGX PKIND state (bsc#1275805). * CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). * CVE-2026-74548: forcedeth: fix UAF of txrx_stats in nv_remove (bsc#1275695). * CVE-2026-74550: net: do not send ICMP/NDISC Redirects when peer allocation fails (bsc#1275688). * CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). * CVE-2026-74563: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() (bsc#1275574). * CVE-2026-74566: keys: make keyring key-chunk byte order agree with keyring_diff_objects() (bsc#1275566). * CVE-2026-74567: keys: fix out-of-bounds read in keyring_get_key_chunk() (bsc#1275569). * CVE-2026-74571: btrfs: skip global block reserve accounting for rescue mounts (bsc#1275561). * CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782). * CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). * CVE-2026-74584: RDMA/bnxt_re: zero shared page before exposing to userspace (bsc#1277066). * CVE-2026-74610: tls: don't leave a full plaintext sk_msg ring unpushed (bsc#1277054). * CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). * CVE-2026-74692: net/smc: fix TOCTOU race between smc_listen_out() and listener close (bsc#1276927). * CVE-2026-74694: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (bsc#1277625). * CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). * CVE-2026-74717: net/mlx5: fw_tracer, return NULL on create error (bsc#1276569). * CVE-2026-74722: btrfs: fix memory leak in btrfs_do_encoded_write() (bsc#1276561). * CVE-2026-80529: xfs: don't swallow dquot recovery verification errors (bsc#1277688). * CVE-2026-80534: xfs: fix ilock leak on error in xfs_dq_get_next_id (bsc#1277022). * CVE-2026-80590: inet: frags: strip GSO state from fragments before reassembly (bsc#1277275). * CVE-2026-80654: soc: xilinx: Shutdown and free rx mailbox channel (bsc#1277516). The following non security issues were fixed: * accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() (git-fixes). * accessibility: speakup: unregister tty ldisc on later init failures (git- fixes). * ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer (git-fixes). * ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root (git- fixes). * ACPI: pfr_update: fix stack buffer overflow in query_capability() (git- fixes). * ACPI: processor: idle: Expand _LPI package sanity checks (git-fixes). * ACPI: processor: validate MADT IOAPIC entry bounds (git-fixes). * ACPI: scan: fix bus ID cleanup on device_add() failures (git-fixes). * ACPI: video: Release PCI device reference after lookup (git-fixes). * add my missing Reviewed-by: tag. * ALSA: 6fire: bound the MIDI event length from the device (git-fixes). * ALSA: 6fire: Fix UAF at error handling during probe (stable-fixes). * ALSA: bcd2000: clear the URB pointers on disconnect (git-fixes). * ALSA: core: Fix use-after-free in snd_card_do_free() (git-fixes). * ALSA: dummy: Check card index validity at probe (stable-fixes). * ALSA: hda/ext: preserve PPLCCTL bits when clearing reset (git-fixes). * ALSA: hda: Fix connection list comparison in proc output (git-fixes). * ALSA: hpi: Check transport errors during HPI6000 adapter initialization (git-fixes). * ALSA: pcxhr: initialize mutexes before requesting threaded IRQ (git-fixes). * ALSA: seq: midi: Optimize event_input locking with RCU (git-fixes). * ALSA: seq: midi: Serialize input teardown with event_input (git-fixes). * ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion (git-fixes). * ALSA: usb-audio: Complete cleanup after system-resume errors (git-fixes). * ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (git-fixes). * ALSA: usb-audio: fix OOB write on Type II inbound URBs (git-fixes). * ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (git-fixes). * ALSA: usx2y: bound the hwdep mmap fault offset (git-fixes). * ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() (git- fixes). * apparmor: advertise the tcp fast open fix is applied (git-fixes). * ASoC: adau1761: sort the register default table (git-fixes). * ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC (git-fixes). * ASoC: apple: mca: increase SERDES reset delay (git-fixes). * ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (git-fixes). * ASoC: cs35l33: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l34: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l41: sort the register default table (git-fixes). * ASoC: cs35l45: sort the register default table (git-fixes). * ASoC: cs4265: sort the register default table (git-fixes). * ASoC: cx2072x: sort the register default table (git-fixes). * ASoC: dapm: Fix off-by-one check on the second enum channel (git-fixes). * ASoC: fix unmet dependencies on PPC_BESTCOMM and SND_SOC_AC97_BUS (git- fixes). * ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready (git- fixes). * ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure (git-fixes). * ASoC: fsl_audmix: rework runtime PM handling in probe (git-fixes). * ASoC: fsl_easrc: sort the register default table (git-fixes). * AsoC: intel: sst: fix PCI device reference leak on probe failure (git- fixes). * ASoC: max9860: sort the register default table (git-fixes). * ASoC: meson: Keep link pointers valid on realloc failure (git-fixes). * ASoC: ml26124: sort the register default table (git-fixes). * ASoC: pcm512x: sort the register default table (git-fixes). * ASoC: pxa: Use devm_clk_get_optional() for extclk clock (git-fixes). * ASoC: qcom: q6apm: keep the graph start count in sync with the DSP (git- fixes). * ASoC: rt274: sort the register default table (git-fixes). * ASoC: rt286: sort the register default table (git-fixes). * ASoC: rt298: sort the register default table (git-fixes). * ASoC: rt700-sdw: always drain jack work on remove (git-fixes). * ASoC: rt700: drop duplicate reg_default entry (git-fixes). * ASoC: rt700: sort the register default table (git-fixes). * ASoC: rt711-sdca: sort the register default tables (git-fixes). * ASoC: rt711: sort the register default table (git-fixes). * ASoC: rt712-sdca-dmic: sort the register default table (git-fixes). * ASoC: rt715-sdca: drop duplicate reg_default entries (git-fixes). * ASoC: rt715-sdca: sort the register default tables (git-fixes). * ASoC: rt715: sort the register default table (git-fixes). * ASoC: rt1316-sdw: sort the register default table (git-fixes). * ASoC: rt1318-sdw: sort the register default table (git-fixes). * ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get (git-fixes). * ASoC: sgtl5000: sort the register default table (git-fixes). * ASoC: SOF: pcm: Move period/buffer configuration print after platform open (stable-fixes). * ASoC: sof: pcm: use snd_pcm_direction_name() (stable-fixes). * ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() (git- fixes). * ASoC: SOF: validate topology volume range before allocation (git-fixes). * ASoC: sti-sas: sort the register default table (git-fixes). * ASoC: tas2552: sort the register default table (git-fixes). * ASoC: tas2764: sort the register default table (git-fixes). * ASoC: tas2780: sort the register default table (git-fixes). * ASoC: tegra210_i2s: sort the register default table (git-fixes). * ASoC: tegra210_mixer: sort the register default table (git-fixes). * ASoC: tegra: Fix the MIXER enable default value (git-fixes). * ASoC: tegra: Sort MBDRC register defaults (git-fixes). * ASoC: xilinx: formatter_pcm: fix stream_data leak on open error (git-fixes). * ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (git-fixes). * batman-adv: bla: fix freeing of claims on meshif deletion (git-fixes). * batman-adv: bla: prevent CRC corruptions after claim flush (git-fixes). * batman-adv: dat: avoid unaligned fault in IP extraction (git-fixes). * batman-adv: fix stale receive device on merged fragments (git-fixes). * Bluetooth: btintel: Fix diagnostics event detection (git-fixes). * Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path (git-fixes). * Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX (git- fixes). * Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event (git- fixes). * Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() (git- fixes). * Bluetooth: do not leak an hci_conn when a second LE connect is rejected (git-fixes). * Bluetooth: eir: Fix OOB read in eir_get_service_data() (git-fixes). * Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (git-fixes). * Bluetooth: hci_conn: re-enable advertising only for peripheral role (git- fixes). * Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection (git- fixes). * Bluetooth: hci_event: fix LE list UAF on reset (git-fixes). * Bluetooth: hci_event: validate LE Set CIG Parameters response (git-fixes). * Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths (git-fixes). * Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (stable-fixes). * Bluetooth: hci_uart: Fix false success return in hci_uart_setup() (git- fixes). * Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready (git-fixes). * Bluetooth: MGMT: free the mesh send cancel command when it is cancelled (git-fixes). * Bluetooth: MSFT: validate evt_prefix_len against the response length (git- fixes). * Bluetooth: RFCOMM: serialize security confirmation handling (git-fixes). * Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (git- fixes). * Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop (git-fixes). * Bluetooth: virtio_bt: avoid OOB read of build info string (git-fixes). * bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation (git-fixes). * bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET (git-fixes). * bus: ti-sysc: Fix /chosen node reference leak (git-fixes). * cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64) (git-fixes). * can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (stable-fixes). * crypto: aspeed - Propagate platform_get_irq() errors (git-fixes). * crypto: atmel-sha204a - fix heap info leak on I2C transfer failure (git- fixes). * crypto: atmel-tdes - use scatterlist length before DMA mapping (git-fixes). * crypto: ccm - Set rfc4309 maxauthsize from child (git-fixes). * crypto: ccp - Fix memory leak in SEV INIT_EX path (git-fixes). * crypto: ccp - Fix possible deadlock in SEV init failure path (git-fixes). * crypto: doc - Remove extra parenthesis (git-fixes). * crypto: hisilicon/sec2 - fix CCM algorithm long packet failure (git-fixes). * crypto: keembay - Initialize completion before requesting IRQ (git-fixes). * crypto: keembay - publish OF module alias for OCS AES/SM4 (git-fixes). * crypto: mxs-dcp - fix source scatterlist length access (git-fixes). * crypto: qat - cancel work on re-enable SR-IOV timeout (git-fixes). * crypto: qat - clear AES key schedule from stack (git-fixes). * crypto: qce - fix CCM AAD buffer underallocation (git-fixes). * crypto: qce - fix error path in devm_qce_register_algs (git-fixes). * crypto: rk3288 - fail ahash requests on HASH idle timeout (git-fixes). * crypto: sa2ul - stop probe if context pool creation fails (git-fixes). * crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping (git- fixes). * device property: fix infinite loop in fwnode_for_each_child_node() (git- fixes). * dmaengine: dw-edma: Clear stale requests on termination (git-fixes). * dmaengine: dw-edma: Complete descriptors before pausing (git-fixes). * dmaengine: dw-edma: Initialize IRQ data before requesting IRQs (git-fixes). * dmaengine: dw-edma: Serialize abort state updates (git-fixes). * dmaengine: dw-edma: Serialize channel state checks (git-fixes). * dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe (git-fixes). * dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure (git-fixes). * dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal (git-fixes). * dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers (git-fixes). * dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout (git-fixes). * driver core: soc: Unregister bus on early device registration failure (git- fixes). * drm/amd/display: avoid divide-by-zero in __is_lut_linear() (git-fixes). * drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read (git- fixes). * drm/amdgpu/gfx6: Fixup emit_cntxcntl() (git-fixes). * drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets (git-fixes). * drm/amdgpu/gfx6: Use PFP on the compute queues too (git-fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup (git- fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup (git- fixes). * drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check (git- fixes). * drm/amdgpu: cap GTT size to physical RAM on APUs (stable-fixes). * drm/amdgpu: check ASPM on the dGPU host link (git-fixes). * drm/amdgpu: disallow multiple FENCE chunks in one submit (git-fixes). * drm/amdgpu: fix aperture iounmap skipped on device removal (git-fixes). * drm/amdgpu: fix autosuspend cleanup during removal (git-fixes). * drm/amdgpu: Fix UVD decode image min size calculation (stable-fixes). * drm/amdgpu: Fix UVD dpb min size calculation for H264 (stable-fixes). * drm/amdgpu: Fix UVD min buffer sizes (stable-fixes). * drm/amdgpu: Fix VCE 3 ring align_mask (git-fixes). * drm/amdgpu: Implement insert_end for VCE 3 (git-fixes). * drm/amdgpu: Reject UVD message with dimensions above 4096 (stable-fixes). * drm/amdgpu: Reject UVD message with invalid number of h265 refs (stable- fixes). * drm/amdgpu: restore UMD profile pstate after runtime resume (stable-fixes). * drm/amdgpu: validate GEM_CREATE domain combinations (stable-fixes). * drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (stable-fixes). * drm/amdkfd: fix QID bit leak in pqm_create_queue() (stable-fixes). * drm/amdkfd: Handle invalid event type in CRIU event restore (stable-fixes). * drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure (git-fixes). * drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure (git-fixes). * drm/bridge: ps8640: propagate AUX transfer register errors (git-fixes). * drm/bridge: tc358767: clamp the reported AUX read size to the request (git- fixes). * drm/connector: Fix epoch_counter docs to reflect reality (git-fixes). * drm/hibmc: Fix list of formats on the primary plane (git-fixes). * drm/hibmc: Use drm_atomic_helper_check_plane_state() (git-fixes). * drm/i915/fbc: Extract intel_fbc_has_fences() (stable-fixes). * drm/lima: call drm_mm_init() with a valid allocation range (git-fixes). * drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: Drop dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value (git- fixes). * drm/panel-edp: fix i2c adapter leak on probe failure (git-fixes). * drm/panel: samsung-s6d16d0: Power off on prepare failure (git-fixes). * drm/radeon: fix autosuspend cleanup during teardown (git-fixes). * drm/radeon: restore hardware polling in fence_is_signaled to fix performance regression (git-fixes). * drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format (git-fixes). * drm/ssd130x: fix column and row end address in partial updates for ssd132x (git-fixes). * drm/sun4i: crtc: Propagate layer initialization error (git-fixes). * drm/sun4i: Drop node references while building component list (git-fixes). * drm/sun4i: dw-hdmi: Drop TCON TOP port reference (git-fixes). * drm/sun4i: fix refcount leak in sun4i_backend_init_sat() (git-fixes). * drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz (git-fixes). * drm/sun4i: tcon: Drop remote endpoint reference (git-fixes). * drm/sun4i: tcon: Drop TCON TOP device reference (git-fixes). * drm/sun4i: tcon: Set output mux for DSI and LVDS (git-fixes). * drm/sun4i: vi scaler: Fix coefficient selection (git-fixes). * drm/tegra: dsi: Re-add clear enable register if DSI was powered by bootloader (git-fixes). * drm/tve200: add OF module alias for autoloading (git-fixes). * drm: fix race between partial drm_dev_register() failure and ioctl (git- fixes). * drm: lcdif: Wait for vblank before disabling DMA (git-fixes). * drm: Remove unused header in drm_dumb_buffers.c (git-fixes). * ethtool: rss: fix hkey leak when indir_size is 0 (git-fixes). * fbdev: bitblit: bound-check glyph index in bit_cursor() (git-fixes). * fbdev: core: Fix pointer desynchronization in fb_io_read() (git-fixes). * fbdev: kyro: Validate overlay viewport coordinates (git-fixes). * fbdev: omapfb: panel-dsi-cm: initialize lock before registering display (git-fixes). * fbdev: ssd1307fb: defer I2C transfers from damage callbacks (git-fixes). * fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() (git-fixes). * fbdev: uvesafb: unregister connector callback on init failure (git-fixes). * firmware: arm_scmi: Avoid IDR updates while cleaning channels (git-fixes). * firmware: arm_scmi: Drop handle on protocol bind failures (git-fixes). * firmware: arm_scmi: Fix requested device removal race (git-fixes). * firmware: arm_scmi: Free transport channel on IDR failure (git-fixes). * firmware: arm_scmi: Protect device request lookup with RCU (git-fixes). * firmware: arm_scmi: Reject out of range DT protocol IDs (git-fixes). * firmware: arm_scmi: Unregister device notifier before IDR teardown (git- fixes). * firmware: arm_scmi: Use channel ID for transport teardown (git-fixes). * firmware_loader: do not queue completed sysfs fallback requests (git-fixes). * fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write (git- fixes). * fpga: dfl: fme: add error handling (git-fixes). * fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration (git- fixes). * gpu: host1x: Avoid stack over-read in debug output helpers (git-fixes). * gpu: host1x: Fix offset calculation in trace_write_gather (git-fixes). * HID: core: fix number/pointer type confusion on long items (git-fixes). * HID: core: fix OOB read of field->usage in hid_set_field() (git-fixes). * HID: hyperv: validate initial device info bounds (git-fixes). * HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure (git-fixes). * HID: lg4ff: validate report length before fixed offsets (git-fixes). * HID: logitech-dj: Fix maxfield check in DJ short report validation (git- fixes). * HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (git- fixes). * HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (stable-fixes). * HID: logitech-dj: Standardise hid_report_enum variable nomenclature (stable- fixes). * HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID (stable-fixes). * HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (git- fixes). * HID: mcp2221: validate report size in mcp2221_raw_event() (git-fixes). * HID: nintendo: Fix imu_timestamp_us double increment per report (git-fixes). * HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() (git- fixes). * HID: picolcd: clamp eeprom debugfs read to bytes actually received (git- fixes). * HID: roccat: bound device-supplied profile index (git-fixes). * HID: roccat: free buffered reports when destroying device (git-fixes). * HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature (git- fixes). * HID: sensor: custom: Fix field sysfs group cleanup on failure (git-fixes). * HID: sensor: custom: Fix use-after-free in enable_sensor (git-fixes). * HID: tmff: Use 64-bit arithmetic for force feedback scaling (git-fixes). * hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (git-fixes). * hwmon: (lm25066) Use i2c_get_match_data() (stable-fixes). * hwmon: (max6621) fix negative temperature offset and crit readings (git- fixes). * hwmon: (max6621) fix temperature clamp range (git-fixes). * hwmon: (nzxt-smart2) Check return value of init_device() in probe (git- fixes). * hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (git-fixes). * hwrng: ks-sa - Fix runtime PM cleanup on registration failure (git-fixes). * hwrng: omap - Fix probe error path cleanup (git-fixes). * hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() (git- fixes). * i2c: bcm-iproc: remove printout on handled timeouts (stable-fixes). * i2c: iproc: reset bus after timeout if START_BUSY is stuck (git-fixes). * i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure (git-fixes). * i2c: mux: Fix channel node leak on adapter add failure (git-fixes). * i2c: ocores: Disable clock on failed resume (git-fixes). * i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices (git-fixes). * i3c: master: Fix device_register() error path (git-fixes). * i3c: master: Fix info leak and UAF in device unregister path (git-fixes). * i3c: master: svc: bound IBI payload to the requested max_payload_len (git- fixes). * ibmvnic: Only record tx completed bytes once per handler (bsc#1274620). * iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE (git-fixes). * iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable (git-fixes). * iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF (git-fixes). * iio: chemical: sgp30: Handle IAQ thread creation failure (git-fixes). * iio: dac: m62332: Fix regulator reference count imbalance (git-fixes). * iio: gyro: mpu3050: fix sign of raw angular velocity readings (git-fixes). * iio: light: cm32181: return zero after writing calibscale (git-fixes). * iio: light: gp2ap002: Disable regulators on resume failure (git-fixes). * iio: light: gp2ap002: re-enable irq if runtime suspend fails (git-fixes). * iio: light: isl29028: return zero in write_raw() on success (git-fixes). * iio: light: tsl2583: return zero in write_raw() on success (git-fixes). * iio: light: tsl2772: fix ALS calibscale readback (git-fixes). * iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure (git-fixes). * iio: pressure: dps310: fix NULL pointer dereference on ACPI probe (git- fixes). * iio: pressure: mpl115: Fix runtime PM cleanup (git-fixes). * iio: srf04: fix pm_runtime handling on probe error path (git-fixes). * iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() (git-fixes). * Input: atkbd - skip deactivate for HONOR ZQC-P (git-fixes). * Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (stable-fixes). * Input: evdev - fix information leak in evdev_pass_values() (stable-fixes). * Input: evdev - sanitize event type index when fetching event masks (stable- fixes). * Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (git-fixes). * Input: focaltech - use signed coordinates to prevent underflow (git-fixes). * Input: hynitron_cstxxx - validate touch count and finger IDs (git-fixes). * Input: iforce - validate input packet lengths (stable-fixes). * Input: iqs5xx - validate firmware record destination span (git-fixes). * Input: mms114 - fix Y-resolution configuration (git-fixes). * Input: psxpad-spi - set driver data before use (git-fixes). * Input: sur40 - fix input device registration ordering (stable-fixes). * Input: sur40 - fix V4L error path cleanup (stable-fixes). * Input: synaptics-rmi4 - block s_input when F54 queue is busy (git-fixes). * Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (git-fixes). * Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (git- fixes). * Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (git- fixes). * Input: synaptics-rmi4 - zero report size on F54 work error (git-fixes). * Input: xpad - add support for ZENAIM LEVERLESS (stable-fixes). * interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (git-fixes). * ipmi: ipmb: validate write message length (git-fixes). * ipmi: si: Fix NULL pointer dereference after failed registration (git- fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (git-fixes). * leds: pca9532: Fix inverted GPIO output polarity (git-fixes). * leds: pca9532: Fix phantom device registration on missing hardware (git- fixes). * lib/string: fix memchr_inv() for large ranges (git-fixes). * lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() (git-fixes). * mailbox: qcom-ipcc: fix duplicate channel allocation across holes (git- fixes). * mailbox: rockchip: disable pclk on probe failure and unbind (git-fixes). * maple_tree: fix argument name in header (git-fixes). * md/raid1: create serial pool adding rdev to array with serialize_policy=1 (bsc#1272261). * media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref (git-fixes). * media: cec-pin: Fix event FIFO ordering (git-fixes). * media: cec: disable delayed work before freeing an interrupted transmit (git-fixes). * media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash (git-fixes). * media: cec: Serialize exclusive follower delivery (git-fixes). * media: cec: stm32: prevent out-of-bounds write on RX overflow (git-fixes). * media: cedrus: fix memory leak in cedrus_init_ctrls() (git-fixes). * media: cobalt: Avoid freeing ALSA private data twice (git-fixes). * media: cx231xx: reject geometry changes while the VBI queue is busy (git- fixes). * media: cx23885: cancel NetUP CI work before teardown (git-fixes). * media: em28xx: defer audio-only extension registration (git-fixes). * media: em28xx: fix use-after-free of dev_next->devlist on disconnect (git- fixes). * media: go7007: defer the ALSA v4l2 put until card release (git-fixes). * media: i2c: ov02a10: fix endpoint parsing use-after-free (git-fixes). * media: i2c: ov7740: fix use-after-destroy in remove (git-fixes). * media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define (git- fixes). * media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define (git-fixes). * media: mc-entity: Add missing kerneldoc (git-fixes). * media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common (git- fixes). * media: nxp: imx8-isi: Correct color map between V4L2 and ISI (git-fixes). * media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing (git-fixes). * media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks (git-fixes). * media: rc: sunxi-cir: Unregister rc device on probe failure (git-fixes). * media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure (git-fixes). * media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak (git-fixes). * media: s2255: bound JPEG frame size before copying into the buffer (git- fixes). * media: s2255: check firmware size before reading trailing marker (git- fixes). * media: saa7164: fix cleanup on resource allocation failure (git-fixes). * media: tda18250: fix possible integer overflow (git-fixes). * media: usbtv: keep device alive while ALSA card exists (git-fixes). * media: v4l2-ctrls: Allow unknown HDR10 white point and luminance (git- fixes). * media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link (git-fixes). * media: venus: fix payload size calculation in parse_raw_formats() (git- fixes). * media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() (git-fixes). * media: vicodec: fix out-of-bounds write in FWHT encoder (git-fixes). * media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure (git-fixes). * media: vimc: fix pixel format lookup in enum_framesizes (git-fixes). * media: zoran: Avoid freeing a registered video_device twice (git-fixes). * mei: pull kvfree out of spinlock (git-fixes). * mfd: iqs62x: Reject zero-length firmware records (git-fixes). * mfd: rave-sp: validate received frame payload lengths (git-fixes). * misc: bcm-vk: Use acquire/release for msgq_inited (git-fixes). * misc: fastrpc: fix channel ctx ref leak when session alloc fails (git- fixes). * misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (git-fixes). * misc: fastrpc: Remove buffer from list prior to unmap operation (git-fixes). * misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke (git- fixes). * misc: rtsx: add missing write register handling (git-fixes). * misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() (git- fixes). * mkspec-dtb: Move DTS prefix into package list. * mkspec-dtb: Move provides-obsoletes to package list. * mkspec-dtb: Put per-architecture package lists into a hash. * mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (git- fixes). * mmc: sdhci: unmap the bounce buffer before device release (git-fixes). * mmc: via-sdmmc: stop card-detect handling on probe failure (git-fixes). * mtd: afs: validate v2 image info bounds (git-fixes). * mtd: mtdoops: free page bitmap when the backing MTD is removed (git-fixes). * mtd: mtdswap: Avoid freeing registered blktrans device twice (git-fixes). * mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() (git-fixes). * mtd: rawnand: validate ONFI extended parameter page sections (git-fixes). * net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes). * net: mana: Add handler for sriov configure (bsc#1272756). * net: mana: Cap MSI-X vectors to the device MSI-X table size (git-fixes). * net: mana: Extend RX CQE coalescing up to 8 packets (git-fixes). * net: mana: Fall back to scattered pages for GDMA queues (git-fixes). * net: mana: force full-page RX buffers via ethtool private flag (bsc#1269792). * net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792). * net: mana: Route ring-buffer access through offset-based helpers (git- fixes). * net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). * net: thunderbolt: Count delivered packets in rx_packets and rx_bytes (git- fixes). * net: thunderbolt: Mark the connection down when bringing it up fails (git- fixes). * net: thunderbolt: Release the Rx HopID that was handed out on mismatch (git- fixes). * net: thunderbolt: Tear down DMA paths before stopping the rings (git-fixes). * net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (git-fixes). * net: usb: ipheth: fix carrier_work UAF on disconnect (git-fixes). * nfc: digital: clamp SENSF_RES length to the destination buffer (git-fixes). * nfc: digital: Do not dump a NULL response in command completion (git-fixes). * nfc: fdp: bound the device-reported read length and fix an skb leak (git- fixes). * nfc: llcp: avoid userspace overflow on invalid optlen (git-fixes). * nfc: llcp: bound SNL TLV parsing to the skb and add length checks (git- fixes). * nfc: llcp: bound the connect_sn TLV walk to the skb (git-fixes). * nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (git-fixes). * nfc: llcp: read llcp_sock->local under the socket lock in getsockopt (git- fixes). * nfc: llcp: reject PDUs shorter than the LLCP header (git-fixes). * nfc: microread: validate target discovery payload lengths (git-fixes). * nfc: nci: fix double completion race in nci_data_exchange_complete (git- fixes). * nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (git- fixes). * nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (git- fixes). * nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing (git- fixes). * nfc: nci: free destination parameters when closing a connection (git-fixes). * nfc: pn533: hold a reference to the request skb during send_frame (git- fixes). * nfc: pn533: purge fragmented skbs during cleanup (git-fixes). * nfc: st21nfca: validate ATR_REQ length against the received frame (git- fixes). * nouveau/gem: reserve the bo in the info ioctl around the vma lookup (git- fixes). * PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] (git-fixes). * PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk (git- fixes). * PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git- fixes). * PCI: j721e: Fix incorrect max_lanes for J7200 (git-fixes). * PCI: meson: Fix GPIO state while requesting PERST# (git-fixes). * phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs (git- fixes). * phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend (git-fixes). * phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table (git- fixes). * phy: sunplus: fix error handling in sp_uphy_init() (git-fixes). * pinctrl: bcm2835: Don't remove an unregistered GPIO chip (git-fixes). * pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip (git-fixes). * pinctrl: rockchip: Reset the pin count when recalculating SoC data (git- fixes). * platform/chrome: cros_ec_debugfs: Clean up console log on probe failure (git-fixes). * platform/chrome: cros_ec_debugfs: Unregister panic notifier (git-fixes). * platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count (git- fixes). * platform/chrome: sensorhub: Bound the EC-reported sensor number (git-fixes). * platform/chrome: sensorhub: Fix dropped timestamp events and log spam (git- fixes). * platform/chrome: sensorhub: Fix memory overread in ring handler (git-fixes). * platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL (git- fixes). * platform/surface: acpi-notify: Check ACPI companion before use (git-fixes). * platform/x86: dell-privacy: Fix race condition (git-fixes). * platform/x86: dell-wmi-base: Fix resource leak on module load failure (git- fixes). * platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (git-fixes). * platform/x86: dell-wmi-sysman: Fix instance ID bounds (git-fixes). * platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path (git-fixes). * platform/x86: ISST: Just allow 2 bits for SST feature enable (git-fixes). * platform/x86: ISST: Validate level in perf mask ioctls (git-fixes). * platform/x86: ISST: Validate logical CPU id and clos id (git-fixes). * platform/x86: ISST: Validate socket ID in clos_assoc ioctl (git-fixes). * PM: sleep: Fix off-by-one in wakelocks number limit check (git-fixes). * power: supply: bd99954: Drop bad register fields (git-fixes). * power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq27520g4: fix REG_TTES address (git-fixes). * power: supply: bq256xx: drain usb_work before freeing the charger (git- fixes). * power: supply: bq24257: fix use-after-free on remove (git-fixes). * power: supply: bq25890: Fix power_supply reference leak (git-fixes). * power: supply: cros_usbpd-charger: bound the EC-reported port count (git- fixes). * power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS (git- fixes). * power: supply: isp1704_charger: cancel work on remove (git-fixes). * power: supply: lp8727: fix use-after-free in lp8727_release_irq() (git- fixes). * power: supply: max17040: drop incorrect I2C functionality check (git-fixes). * power: supply: max17040: synchronize work cancellation on suspend (git- fixes). * power: supply: qcom_battmgr: terminate the strings from firmware (git- fixes). * power: supply: rt9455: quiesce delayed work before teardown (git-fixes). * power: supply: sbs-battery: Use a per-device serial number buffer (git- fixes). * power: supply: twl4030_charger: cancel workers via devm (git-fixes). * power: supply: ucs1002: fix use-after-free on remove (git-fixes). * powercap: intel_rapl_tpmi: Handle PMU registration failure during probe (git-fixes). * powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash (bsc#1271256). * powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). * powerpc/pseries: pci - logic bug (bsc#1274749 ltc#221282 bsc#1274755 ltc#221284 bsc#1274756 ltc#221283). * ppdev: prevent overflow when setting port timeout (git-fixes). * qede: fix out-of-bounds check for cqe->len_list (git-fixes). * rapidio: clear mport->net when rio_add_net() fails (git-fixes). * rapidio: mport_cdev: fix use-after-free in dma_req_free() (git-fixes). * RDMA/irdma: Remove redundant legacy_mode checks (git-fixes). * RDMA/mana_ib: drain QP references after partial table insertion (git-fixes). * RDMA/mana_ib: unify QP lookup table (git-fixes). * RDMA/mlx5: Fix integer overflow of user QP buffer size (git-fixes). * regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (git-fixes). * regulator: core: use system_freezable_wq for init complete work (git-fixes). * regulator: devres: add API for reference voltage supplies (stable-fixes). * regulator: devres: fix devm_regulator_get_enable_read_voltage() return (git- fixes). * regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata (git-fixes). * regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling (git-fixes). * remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev (git-fixes). * remoteproc: qcom_q6v5_adsp: Fix reference leak for device node (git-fixes). * remoteproc: scp: Fix device reference leak on failed lookup (git-fixes). * Revert "drm/amdgpu: fix aperture mapping leak" (git-fixes). * Revert "media: v4l2-dev: fix error handling in __video_register_device()" (git-fixes). * Revert "thermal/drivers/hwmon: Cleanup coding style a bit" (stable-fixes). * rpmsg: core: Fix incorrect return value documentation (git-fixes). * rpmsg: glink: smem: order FIFO read after availability check (git-fixes). * rtc: gamecube: check return value of devm_rtc_register_device() (git-fixes). * rtc: pcf8563: fix clock provider leak on unbind (git-fixes). * rtc: pcf85363: Add error checking to regmap calls in probe() (git-fixes). * rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers (git-fixes). * rtc: rzn1: Fix weekday underflow when alarm crosses month boundary (git- fixes). * rtc: zynqmp: Return optional clock lookup errors (git-fixes). * scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes). * sctp: avoid auth_enable sysctl UAF during netns teardown (git-fixes). * serial: 8250_dma: Clear stale RX state on shutdown (git-fixes). * serial: amba-pl011: unprepare console clock on unregister (git-fixes). * serial: core: clear freed pointers on uart_register_driver() failure (git- fixes). * serial: qcom-geni: fix TX DMA buffer flush (git-fixes). * serial: sc16is7xx: fix copy-paste errors in EFR_SWFLOWx_BIT constants (stable-fixes). * smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). * smb: client: reject overlapping data areas in SMB2 responses (git-fixes). * smb: client: require net admin for CIFS SWN netlink (bsc#1273966). * smb: client: resolve SWN tcon from live registrations (bsc#1273872). * soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() (git- fixes). * soc: qcom: rpmh-rsc: manage PM notifiers with devres (git-fixes). * soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() (git-fixes). * software node: Fix software_node_get_reference_args() with index -1 (git- fixes). * soundwire: qcom: Fix port exhaustion check in stream_alloc_ports (git- fixes). * speakup: keyhelp: guard letter_offsets possible out-of-range indexing (git- fixes). * spi: img-spfi: don't disable runtime PM on DMA deferred probe (git-fixes). * spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (stable-fixes). * spi: sprd-adi: Fix probe succeeding without registering the controller (git- fixes). * staging: fbtft: Use sysfs_emit_at() to print to sysfs file (git-fixes). * staging: media: tegra-video: vi: fix probe failure on skipped last port (git-fixes). * staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown (git- fixes). * staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() (git-fixes). * staging: rtl8723bs: fix missing shared-key auth challenge length check (git- fixes). * staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (git-fixes). * staging: rtl8723bs: fix OOB read in WMM_param_handler() (git-fixes). * staging: rtl8723bs: use kfree_sensitive() for key material (git-fixes). * staging: rtl8723bs: validate monitor transmit frame lengths (git-fixes). * staging: sm750fb: gate dualview dataflow using g_dualview (git-fixes). * thermal/drivers/imx: Disable clock on runtime resume failure (git-fixes). * thermal/drivers/qoriq: Disable clock on resume failure (git-fixes). * thermal: intel: int3400: clean up ODVP on probe failures (git-fixes). * thunderbolt: Bound the DROM dual link port number before indexing sw->ports (git-fixes). * thunderbolt: icm: Preserve USB4 proxy data-valid bit (git-fixes). * tlclk: if sscanf() fails, fall back to 0, not random value (git-fixes). * tpm: st33zp24: Return zero on status read failure (git-fixes). * tpm: st33zp24: Validate locality read result (git-fixes). * tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (git-fixes). * tty: clear cdev pointer after cdev_add() failure (git-fixes). * tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 (git-fixes). * tty: skip cdev_del() when no cdev is registered (git-fixes). * uio: Fix stale info pointer in failed registration path (git-fixes). * usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (git-fixes). * usb: atm: usbatm: fix invalid ci_range initialization (git-fixes). * USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (git-fixes). * usb: cdnsp: fix incorrect endian conversions for APB timeout register (git- fixes). * usb: dwc2: add missing @remotewakeup kernel-doc parameter (git-fixes). * usb: dwc2: gadget: Exit partial power down state when changing USB pull-up (git-fixes). * usb: gadget: configfs: fix out-of-bounds read of qw_sign (git-fixes). * usb: gadget: f_fs: Prevent deadlock during ep0 read loop (git-fixes). * usb: gadget: f_ncm: Use unsigned int for ndp_index (git-fixes). * usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() (git-fixes). * usb: gadget: f_uac1_legacy: remove broken string configfs attributes (git- fixes). * usb: gadget: pch_udc: remove excess kernel-doc member for registered (git- fixes). * usb: gadget: r8a66597: avoid double free of ep0_req in probe error path (git-fixes). * usb: gadget: snps_udc_plat: clean up PHY on probe deferral (git-fixes). * usb: gadget: u_audio: Fix use-after-free on sound card disconnect (git- fixes). * usb: gadget: uac: validate rate list length before storing (git-fixes). * usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() (git-fixes). * usb: mtu3: allow system suspend during active gadget connection (git-fixes). * usb: musb: omap2430: clean up probe error handling (stable-fixes). * USB: phy: fsl-usb: fix missing static keywords (git-fixes). * usb: renesas_usbhs: Fix power-off ordering on unbind (git-fixes). * USB: serial: digi_acceleport: fix port registration order (git-fixes). * USB: serial: ftdi_sio: add support for E+H FXA291 (stable-fixes). * USB: serial: option: add TDTECH MT5710-CN (stable-fixes). * USB: serial: option: fix slab OOB read in interrupt URB callback (git- fixes). * USB: serial: spcp8x5: drop broken carrier detect support (git-fixes). * USB: storage: add NO_ATA_1X quirk for Longmai USB Key (stable-fixes). * usb: typec: ucsi: unregister debugfs entries on teardown (git-fixes). * usb: usbfs: fix use-after-free of usb_device in usbdev_release() (git- fixes). * usb: xhci: Handle USB3 port events when there is one roothub (git-fixes). * vt: add permission check for KDSKBMETA ioctl (stable-fixes). * vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (stable- fixes). * w1: ds28e17: reject an oversize length on an I2C block read (git-fixes). * w1: ds2482: Fix signedness bug in ds2482_w1_triplet() (git-fixes). * wifi: ath6kl: avoid buffer overreads in WMI event handlers (git-fixes). * wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (git-fixes). * wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump (git-fixes). * wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() (git-fixes). * wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate (git- fixes). * wifi: ath11k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() (git-fixes). * wifi: ath12k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (git-fixes). * wifi: brcmfmac: fix P2P action frame handling without device vif (git- fixes). * wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs (git-fixes). * wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments (git-fixes). * wifi: iwlwifi: mei: pass correct argument to function (git-fixes). * wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser (git-fixes). * wifi: mac80211: send TWT teardown to peer after setup TX failure (git- fixes). * wifi: mac80211: skip default WMM setup for AP_VLAN links (git-fixes). * wifi: mac80211: skip unused probe response countdown offsets (git-fixes). * wifi: mt76: fix 4th chain ACK RSSI bitmask in sta_poll (git-fixes). * wifi: mt76: fix ER-SU 106-tone RU check in RX rate decode (git-fixes). * wifi: mt76: fix HE DCM max-RU capability encoding (git-fixes). * wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length (git- fixes). * wifi: mt76: mt792x: Fix memory leak in SDIO TX path (git-fixes). * wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (git- fixes). * wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss (git- fixes). * wifi: mt76: mt7915: fix double hif2 init on the non-WED path (git-fixes). * wifi: mt76: mt7915: fix ext PHY use-after-free on register error path (git- fixes). * wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 (git- fixes). * wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie (git-fixes). * wifi: mt76: mt7915: release hif2 reference on probe IRQ failure (git-fixes). * wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement (git- fixes). * wifi: mt76: mt7915: unwind state on add_interface failure (git-fixes). * wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields (git- fixes). * wifi: mt76: mt7915: write RX header translation bit to the correct register (git-fixes). * wifi: mt76: mt7921: validate CLC firmware records (git-fixes). * wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (git- fixes). * wifi: mt76: mt7925: fix msg len mismatch between driver and firmware (git- fixes). * wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config (git- fixes). * wifi: mt76: mt7996: don't report a zero TX bitrate (git-fixes). * wifi: mt76: mt7996: fix reg addr remap when addr is 0 (git-fixes). * wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV (git- fixes). * wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset (git-fixes). * wifi: mt76: mt7996: validate RX band_idx before dereferencing phys (git- fixes). * wifi: mt76: report data NSS for STBC frames in RX rate decode (git-fixes). * wifi: mwifiex: Detach sync cmd buffer on interrupted wait (git-fixes). * wifi: rtlwifi: pci: fix error path in rtl_pci_probe() (git-fixes). * wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (git-fixes). * wifi: rtw89: fix HE extended capability length check (git-fixes). * wifi: zd1211rw: reject secondary interfaces to prevent conflicts (git- fixes). * x86/bugs: Clarify that syscall hardening isn't a BHI mitigation (git-fixes). * xhci: dbgtty: Fix unregister on tty_alloc_driver() failure (git-fixes). * xhci: dbgtty: Fix unregister on tty_register_driver() failure (git-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-kernel-603=1 ## Package List: * SUSE Linux Micro Extras 6.0 (nosrc) * kernel-rt-6.4.0-52.1 * SUSE Linux Micro Extras 6.0 (x86_64) * kernel-rt-debugsource-6.4.0-52.1 * kernel-rt-devel-debuginfo-6.4.0-52.1 * kernel-rt-devel-6.4.0-52.1 ## References: * https://www.suse.com/security/cve/CVE-2024-44981.html * https://www.suse.com/security/cve/CVE-2024-57841.html * https://www.suse.com/security/cve/CVE-2025-38469.html * https://www.suse.com/security/cve/CVE-2025-39964.html * https://www.suse.com/security/cve/CVE-2025-40022.html * https://www.suse.com/security/cve/CVE-2025-68179.html * https://www.suse.com/security/cve/CVE-2025-68214.html * https://www.suse.com/security/cve/CVE-2025-71075.html * https://www.suse.com/security/cve/CVE-2025-71104.html * https://www.suse.com/security/cve/CVE-2026-23210.html * https://www.suse.com/security/cve/CVE-2026-23230.html * https://www.suse.com/security/cve/CVE-2026-23454.html * https://www.suse.com/security/cve/CVE-2026-31392.html * https://www.suse.com/security/cve/CVE-2026-31418.html * https://www.suse.com/security/cve/CVE-2026-31531.html * https://www.suse.com/security/cve/CVE-2026-31557.html * https://www.suse.com/security/cve/CVE-2026-31663.html * https://www.suse.com/security/cve/CVE-2026-43116.html * https://www.suse.com/security/cve/CVE-2026-43125.html * https://www.suse.com/security/cve/CVE-2026-43163.html * https://www.suse.com/security/cve/CVE-2026-43271.html * https://www.suse.com/security/cve/CVE-2026-43273.html * https://www.suse.com/security/cve/CVE-2026-43278.html * https://www.suse.com/security/cve/CVE-2026-43319.html * https://www.suse.com/security/cve/CVE-2026-43363.html * https://www.suse.com/security/cve/CVE-2026-43416.html * https://www.suse.com/security/cve/CVE-2026-45897.html * https://www.suse.com/security/cve/CVE-2026-45968.html * https://www.suse.com/security/cve/CVE-2026-46070.html * https://www.suse.com/security/cve/CVE-2026-46091.html * https://www.suse.com/security/cve/CVE-2026-46107.html * https://www.suse.com/security/cve/CVE-2026-46115.html * https://www.suse.com/security/cve/CVE-2026-46195.html * https://www.suse.com/security/cve/CVE-2026-52920.html * https://www.suse.com/security/cve/CVE-2026-52925.html * https://www.suse.com/security/cve/CVE-2026-52929.html * https://www.suse.com/security/cve/CVE-2026-52935.html * https://www.suse.com/security/cve/CVE-2026-52939.html * https://www.suse.com/security/cve/CVE-2026-52946.html * https://www.suse.com/security/cve/CVE-2026-52975.html * https://www.suse.com/security/cve/CVE-2026-52977.html * https://www.suse.com/security/cve/CVE-2026-52990.html * https://www.suse.com/security/cve/CVE-2026-52994.html * https://www.suse.com/security/cve/CVE-2026-53001.html * https://www.suse.com/security/cve/CVE-2026-53033.html * https://www.suse.com/security/cve/CVE-2026-53059.html * https://www.suse.com/security/cve/CVE-2026-53076.html * https://www.suse.com/security/cve/CVE-2026-53077.html * https://www.suse.com/security/cve/CVE-2026-53089.html * https://www.suse.com/security/cve/CVE-2026-53091.html * https://www.suse.com/security/cve/CVE-2026-53094.html * https://www.suse.com/security/cve/CVE-2026-53096.html * https://www.suse.com/security/cve/CVE-2026-53110.html * https://www.suse.com/security/cve/CVE-2026-53111.html * https://www.suse.com/security/cve/CVE-2026-53126.html * https://www.suse.com/security/cve/CVE-2026-53154.html * https://www.suse.com/security/cve/CVE-2026-53163.html * https://www.suse.com/security/cve/CVE-2026-53207.html * https://www.suse.com/security/cve/CVE-2026-53219.html * https://www.suse.com/security/cve/CVE-2026-53220.html * https://www.suse.com/security/cve/CVE-2026-53223.html * https://www.suse.com/security/cve/CVE-2026-53228.html * https://www.suse.com/security/cve/CVE-2026-53238.html * https://www.suse.com/security/cve/CVE-2026-53260.html * https://www.suse.com/security/cve/CVE-2026-53264.html * https://www.suse.com/security/cve/CVE-2026-53269.html * https://www.suse.com/security/cve/CVE-2026-53273.html * https://www.suse.com/security/cve/CVE-2026-53309.html * https://www.suse.com/security/cve/CVE-2026-53330.html * https://www.suse.com/security/cve/CVE-2026-53336.html * https://www.suse.com/security/cve/CVE-2026-53337.html * https://www.suse.com/security/cve/CVE-2026-53353.html * https://www.suse.com/security/cve/CVE-2026-53365.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://www.suse.com/security/cve/CVE-2026-53381.html * https://www.suse.com/security/cve/CVE-2026-53388.html * https://www.suse.com/security/cve/CVE-2026-63801.html * https://www.suse.com/security/cve/CVE-2026-63808.html * https://www.suse.com/security/cve/CVE-2026-63810.html * https://www.suse.com/security/cve/CVE-2026-63823.html * https://www.suse.com/security/cve/CVE-2026-63827.html * https://www.suse.com/security/cve/CVE-2026-63828.html * https://www.suse.com/security/cve/CVE-2026-63860.html * https://www.suse.com/security/cve/CVE-2026-63865.html * https://www.suse.com/security/cve/CVE-2026-63868.html * https://www.suse.com/security/cve/CVE-2026-63879.html * https://www.suse.com/security/cve/CVE-2026-63881.html * https://www.suse.com/security/cve/CVE-2026-63886.html * https://www.suse.com/security/cve/CVE-2026-63887.html * https://www.suse.com/security/cve/CVE-2026-63888.html * https://www.suse.com/security/cve/CVE-2026-63889.html * https://www.suse.com/security/cve/CVE-2026-63891.html * https://www.suse.com/security/cve/CVE-2026-63898.html * https://www.suse.com/security/cve/CVE-2026-63920.html * https://www.suse.com/security/cve/CVE-2026-63925.html * https://www.suse.com/security/cve/CVE-2026-63926.html * https://www.suse.com/security/cve/CVE-2026-63928.html * https://www.suse.com/security/cve/CVE-2026-63944.html * https://www.suse.com/security/cve/CVE-2026-63969.html * https://www.suse.com/security/cve/CVE-2026-63970.html * https://www.suse.com/security/cve/CVE-2026-63972.html * https://www.suse.com/security/cve/CVE-2026-63973.html * https://www.suse.com/security/cve/CVE-2026-63980.html * https://www.suse.com/security/cve/CVE-2026-63985.html * https://www.suse.com/security/cve/CVE-2026-63990.html * https://www.suse.com/security/cve/CVE-2026-63992.html * https://www.suse.com/security/cve/CVE-2026-63999.html * https://www.suse.com/security/cve/CVE-2026-64000.html * https://www.suse.com/security/cve/CVE-2026-64001.html * https://www.suse.com/security/cve/CVE-2026-64002.html * https://www.suse.com/security/cve/CVE-2026-64004.html * https://www.suse.com/security/cve/CVE-2026-64005.html * https://www.suse.com/security/cve/CVE-2026-64006.html * https://www.suse.com/security/cve/CVE-2026-64007.html * https://www.suse.com/security/cve/CVE-2026-64010.html * https://www.suse.com/security/cve/CVE-2026-64011.html * https://www.suse.com/security/cve/CVE-2026-64014.html * https://www.suse.com/security/cve/CVE-2026-64015.html * https://www.suse.com/security/cve/CVE-2026-64018.html * https://www.suse.com/security/cve/CVE-2026-64029.html * https://www.suse.com/security/cve/CVE-2026-64034.html * https://www.suse.com/security/cve/CVE-2026-64039.html * https://www.suse.com/security/cve/CVE-2026-64047.html * https://www.suse.com/security/cve/CVE-2026-64048.html * https://www.suse.com/security/cve/CVE-2026-64051.html * https://www.suse.com/security/cve/CVE-2026-64052.html * https://www.suse.com/security/cve/CVE-2026-64073.html * https://www.suse.com/security/cve/CVE-2026-64083.html * https://www.suse.com/security/cve/CVE-2026-64084.html * https://www.suse.com/security/cve/CVE-2026-64085.html * https://www.suse.com/security/cve/CVE-2026-64086.html * https://www.suse.com/security/cve/CVE-2026-64087.html * https://www.suse.com/security/cve/CVE-2026-64088.html * https://www.suse.com/security/cve/CVE-2026-64097.html * https://www.suse.com/security/cve/CVE-2026-64098.html * https://www.suse.com/security/cve/CVE-2026-64102.html * https://www.suse.com/security/cve/CVE-2026-64109.html * https://www.suse.com/security/cve/CVE-2026-64112.html * https://www.suse.com/security/cve/CVE-2026-64113.html * https://www.suse.com/security/cve/CVE-2026-64114.html * https://www.suse.com/security/cve/CVE-2026-64115.html * https://www.suse.com/security/cve/CVE-2026-64118.html * https://www.suse.com/security/cve/CVE-2026-64121.html * https://www.suse.com/security/cve/CVE-2026-64125.html * https://www.suse.com/security/cve/CVE-2026-64126.html * https://www.suse.com/security/cve/CVE-2026-64128.html * https://www.suse.com/security/cve/CVE-2026-64131.html * https://www.suse.com/security/cve/CVE-2026-64133.html * https://www.suse.com/security/cve/CVE-2026-64135.html * https://www.suse.com/security/cve/CVE-2026-64137.html * https://www.suse.com/security/cve/CVE-2026-64148.html * https://www.suse.com/security/cve/CVE-2026-64155.html * https://www.suse.com/security/cve/CVE-2026-64164.html * https://www.suse.com/security/cve/CVE-2026-64166.html * https://www.suse.com/security/cve/CVE-2026-64168.html * https://www.suse.com/security/cve/CVE-2026-64178.html * https://www.suse.com/security/cve/CVE-2026-64185.html * https://www.suse.com/security/cve/CVE-2026-64188.html * https://www.suse.com/security/cve/CVE-2026-64190.html * https://www.suse.com/security/cve/CVE-2026-64192.html * https://www.suse.com/security/cve/CVE-2026-64214.html * https://www.suse.com/security/cve/CVE-2026-64217.html * https://www.suse.com/security/cve/CVE-2026-64218.html * https://www.suse.com/security/cve/CVE-2026-64219.html * https://www.suse.com/security/cve/CVE-2026-64222.html * https://www.suse.com/security/cve/CVE-2026-64225.html * https://www.suse.com/security/cve/CVE-2026-64237.html * https://www.suse.com/security/cve/CVE-2026-64243.html * https://www.suse.com/security/cve/CVE-2026-64245.html * https://www.suse.com/security/cve/CVE-2026-64246.html * https://www.suse.com/security/cve/CVE-2026-64247.html * https://www.suse.com/security/cve/CVE-2026-64249.html * https://www.suse.com/security/cve/CVE-2026-64257.html * https://www.suse.com/security/cve/CVE-2026-64266.html * https://www.suse.com/security/cve/CVE-2026-64268.html * https://www.suse.com/security/cve/CVE-2026-64271.html * https://www.suse.com/security/cve/CVE-2026-64273.html * https://www.suse.com/security/cve/CVE-2026-64274.html * https://www.suse.com/security/cve/CVE-2026-64275.html * https://www.suse.com/security/cve/CVE-2026-64276.html * https://www.suse.com/security/cve/CVE-2026-64277.html * https://www.suse.com/security/cve/CVE-2026-64286.html * https://www.suse.com/security/cve/CVE-2026-64287.html * https://www.suse.com/security/cve/CVE-2026-64294.html * https://www.suse.com/security/cve/CVE-2026-64296.html * https://www.suse.com/security/cve/CVE-2026-64303.html * https://www.suse.com/security/cve/CVE-2026-64304.html * https://www.suse.com/security/cve/CVE-2026-64305.html * https://www.suse.com/security/cve/CVE-2026-64306.html * https://www.suse.com/security/cve/CVE-2026-64312.html * https://www.suse.com/security/cve/CVE-2026-64313.html * https://www.suse.com/security/cve/CVE-2026-64315.html * https://www.suse.com/security/cve/CVE-2026-64316.html * https://www.suse.com/security/cve/CVE-2026-64317.html * https://www.suse.com/security/cve/CVE-2026-64322.html * https://www.suse.com/security/cve/CVE-2026-64323.html * https://www.suse.com/security/cve/CVE-2026-64329.html * https://www.suse.com/security/cve/CVE-2026-64331.html * https://www.suse.com/security/cve/CVE-2026-64332.html * https://www.suse.com/security/cve/CVE-2026-64333.html * https://www.suse.com/security/cve/CVE-2026-64334.html * https://www.suse.com/security/cve/CVE-2026-64335.html * https://www.suse.com/security/cve/CVE-2026-64337.html * https://www.suse.com/security/cve/CVE-2026-64338.html * https://www.suse.com/security/cve/CVE-2026-64340.html * https://www.suse.com/security/cve/CVE-2026-64341.html * https://www.suse.com/security/cve/CVE-2026-64342.html * https://www.suse.com/security/cve/CVE-2026-64343.html * https://www.suse.com/security/cve/CVE-2026-64344.html * https://www.suse.com/security/cve/CVE-2026-64346.html * https://www.suse.com/security/cve/CVE-2026-64348.html * https://www.suse.com/security/cve/CVE-2026-64350.html * https://www.suse.com/security/cve/CVE-2026-64351.html * https://www.suse.com/security/cve/CVE-2026-64355.html * https://www.suse.com/security/cve/CVE-2026-64358.html * https://www.suse.com/security/cve/CVE-2026-64362.html * https://www.suse.com/security/cve/CVE-2026-64365.html * https://www.suse.com/security/cve/CVE-2026-64375.html * https://www.suse.com/security/cve/CVE-2026-64376.html * https://www.suse.com/security/cve/CVE-2026-64378.html * https://www.suse.com/security/cve/CVE-2026-64381.html * https://www.suse.com/security/cve/CVE-2026-64382.html * https://www.suse.com/security/cve/CVE-2026-64383.html * https://www.suse.com/security/cve/CVE-2026-64384.html * https://www.suse.com/security/cve/CVE-2026-64385.html * https://www.suse.com/security/cve/CVE-2026-64386.html * https://www.suse.com/security/cve/CVE-2026-64387.html * https://www.suse.com/security/cve/CVE-2026-64388.html * https://www.suse.com/security/cve/CVE-2026-64401.html * https://www.suse.com/security/cve/CVE-2026-64403.html * https://www.suse.com/security/cve/CVE-2026-64406.html * https://www.suse.com/security/cve/CVE-2026-64408.html * https://www.suse.com/security/cve/CVE-2026-64409.html * https://www.suse.com/security/cve/CVE-2026-64411.html * https://www.suse.com/security/cve/CVE-2026-64412.html * https://www.suse.com/security/cve/CVE-2026-64420.html * https://www.suse.com/security/cve/CVE-2026-64421.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64427.html * https://www.suse.com/security/cve/CVE-2026-64429.html * https://www.suse.com/security/cve/CVE-2026-64433.html * https://www.suse.com/security/cve/CVE-2026-64434.html * https://www.suse.com/security/cve/CVE-2026-64436.html * https://www.suse.com/security/cve/CVE-2026-64440.html * https://www.suse.com/security/cve/CVE-2026-64442.html * https://www.suse.com/security/cve/CVE-2026-64443.html * https://www.suse.com/security/cve/CVE-2026-64444.html * https://www.suse.com/security/cve/CVE-2026-64445.html * https://www.suse.com/security/cve/CVE-2026-64448.html * https://www.suse.com/security/cve/CVE-2026-64450.html * https://www.suse.com/security/cve/CVE-2026-64454.html * https://www.suse.com/security/cve/CVE-2026-64455.html * https://www.suse.com/security/cve/CVE-2026-64463.html * https://www.suse.com/security/cve/CVE-2026-64470.html * https://www.suse.com/security/cve/CVE-2026-64471.html * https://www.suse.com/security/cve/CVE-2026-64472.html * https://www.suse.com/security/cve/CVE-2026-64478.html * https://www.suse.com/security/cve/CVE-2026-64479.html * https://www.suse.com/security/cve/CVE-2026-64480.html * https://www.suse.com/security/cve/CVE-2026-64481.html * https://www.suse.com/security/cve/CVE-2026-64482.html * https://www.suse.com/security/cve/CVE-2026-64483.html * https://www.suse.com/security/cve/CVE-2026-64484.html * https://www.suse.com/security/cve/CVE-2026-64486.html * https://www.suse.com/security/cve/CVE-2026-64487.html * https://www.suse.com/security/cve/CVE-2026-64489.html * https://www.suse.com/security/cve/CVE-2026-64494.html * https://www.suse.com/security/cve/CVE-2026-64495.html * https://www.suse.com/security/cve/CVE-2026-64496.html * https://www.suse.com/security/cve/CVE-2026-64497.html * https://www.suse.com/security/cve/CVE-2026-64500.html * https://www.suse.com/security/cve/CVE-2026-64503.html * https://www.suse.com/security/cve/CVE-2026-64504.html * https://www.suse.com/security/cve/CVE-2026-64505.html * https://www.suse.com/security/cve/CVE-2026-64511.html * https://www.suse.com/security/cve/CVE-2026-64512.html * https://www.suse.com/security/cve/CVE-2026-64513.html * https://www.suse.com/security/cve/CVE-2026-64524.html * https://www.suse.com/security/cve/CVE-2026-64527.html * https://www.suse.com/security/cve/CVE-2026-64536.html * https://www.suse.com/security/cve/CVE-2026-64537.html * https://www.suse.com/security/cve/CVE-2026-64538.html * https://www.suse.com/security/cve/CVE-2026-64539.html * https://www.suse.com/security/cve/CVE-2026-64540.html * https://www.suse.com/security/cve/CVE-2026-64541.html * https://www.suse.com/security/cve/CVE-2026-64543.html * https://www.suse.com/security/cve/CVE-2026-64544.html * https://www.suse.com/security/cve/CVE-2026-64545.html * https://www.suse.com/security/cve/CVE-2026-64546.html * https://www.suse.com/security/cve/CVE-2026-64547.html * https://www.suse.com/security/cve/CVE-2026-64548.html * https://www.suse.com/security/cve/CVE-2026-64549.html * https://www.suse.com/security/cve/CVE-2026-64551.html * https://www.suse.com/security/cve/CVE-2026-64552.html * https://www.suse.com/security/cve/CVE-2026-64553.html * https://www.suse.com/security/cve/CVE-2026-64554.html * https://www.suse.com/security/cve/CVE-2026-64562.html * https://www.suse.com/security/cve/CVE-2026-64563.html * https://www.suse.com/security/cve/CVE-2026-64565.html * https://www.suse.com/security/cve/CVE-2026-64567.html * https://www.suse.com/security/cve/CVE-2026-64571.html * https://www.suse.com/security/cve/CVE-2026-64572.html * https://www.suse.com/security/cve/CVE-2026-64573.html * https://www.suse.com/security/cve/CVE-2026-64574.html * https://www.suse.com/security/cve/CVE-2026-64576.html * https://www.suse.com/security/cve/CVE-2026-64577.html * https://www.suse.com/security/cve/CVE-2026-64581.html * https://www.suse.com/security/cve/CVE-2026-64582.html * https://www.suse.com/security/cve/CVE-2026-64583.html * https://www.suse.com/security/cve/CVE-2026-64584.html * https://www.suse.com/security/cve/CVE-2026-64585.html * https://www.suse.com/security/cve/CVE-2026-64593.html * https://www.suse.com/security/cve/CVE-2026-64597.html * https://www.suse.com/security/cve/CVE-2026-64598.html * https://www.suse.com/security/cve/CVE-2026-64599.html * https://www.suse.com/security/cve/CVE-2026-64602.html * https://www.suse.com/security/cve/CVE-2026-64604.html * https://www.suse.com/security/cve/CVE-2026-68081.html * https://www.suse.com/security/cve/CVE-2026-68082.html * https://www.suse.com/security/cve/CVE-2026-68085.html * https://www.suse.com/security/cve/CVE-2026-68086.html * https://www.suse.com/security/cve/CVE-2026-68088.html * https://www.suse.com/security/cve/CVE-2026-68091.html * https://www.suse.com/security/cve/CVE-2026-68093.html * https://www.suse.com/security/cve/CVE-2026-68102.html * https://www.suse.com/security/cve/CVE-2026-68104.html * https://www.suse.com/security/cve/CVE-2026-68106.html * https://www.suse.com/security/cve/CVE-2026-68107.html * https://www.suse.com/security/cve/CVE-2026-68108.html * https://www.suse.com/security/cve/CVE-2026-68110.html * https://www.suse.com/security/cve/CVE-2026-68111.html * https://www.suse.com/security/cve/CVE-2026-68112.html * https://www.suse.com/security/cve/CVE-2026-68115.html * https://www.suse.com/security/cve/CVE-2026-68116.html * https://www.suse.com/security/cve/CVE-2026-68117.html * https://www.suse.com/security/cve/CVE-2026-68121.html * https://www.suse.com/security/cve/CVE-2026-68123.html * https://www.suse.com/security/cve/CVE-2026-68125.html * https://www.suse.com/security/cve/CVE-2026-68126.html * https://www.suse.com/security/cve/CVE-2026-68127.html * https://www.suse.com/security/cve/CVE-2026-68129.html * https://www.suse.com/security/cve/CVE-2026-68132.html * https://www.suse.com/security/cve/CVE-2026-68133.html * https://www.suse.com/security/cve/CVE-2026-68136.html * https://www.suse.com/security/cve/CVE-2026-68137.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://www.suse.com/security/cve/CVE-2026-68139.html * https://www.suse.com/security/cve/CVE-2026-68142.html * https://www.suse.com/security/cve/CVE-2026-68143.html * https://www.suse.com/security/cve/CVE-2026-68145.html * https://www.suse.com/security/cve/CVE-2026-68149.html * https://www.suse.com/security/cve/CVE-2026-68153.html * https://www.suse.com/security/cve/CVE-2026-68154.html * https://www.suse.com/security/cve/CVE-2026-68155.html * https://www.suse.com/security/cve/CVE-2026-68156.html * https://www.suse.com/security/cve/CVE-2026-68157.html * https://www.suse.com/security/cve/CVE-2026-68158.html * https://www.suse.com/security/cve/CVE-2026-68159.html * https://www.suse.com/security/cve/CVE-2026-68160.html * https://www.suse.com/security/cve/CVE-2026-68161.html * https://www.suse.com/security/cve/CVE-2026-68162.html * https://www.suse.com/security/cve/CVE-2026-68166.html * https://www.suse.com/security/cve/CVE-2026-68180.html * https://www.suse.com/security/cve/CVE-2026-68181.html * https://www.suse.com/security/cve/CVE-2026-68182.html * https://www.suse.com/security/cve/CVE-2026-68184.html * https://www.suse.com/security/cve/CVE-2026-68188.html * https://www.suse.com/security/cve/CVE-2026-68189.html * https://www.suse.com/security/cve/CVE-2026-68192.html * https://www.suse.com/security/cve/CVE-2026-68193.html * https://www.suse.com/security/cve/CVE-2026-68194.html * https://www.suse.com/security/cve/CVE-2026-68195.html * https://www.suse.com/security/cve/CVE-2026-68196.html * https://www.suse.com/security/cve/CVE-2026-68197.html * https://www.suse.com/security/cve/CVE-2026-68199.html * https://www.suse.com/security/cve/CVE-2026-68202.html * https://www.suse.com/security/cve/CVE-2026-68204.html * https://www.suse.com/security/cve/CVE-2026-68205.html * https://www.suse.com/security/cve/CVE-2026-68206.html * https://www.suse.com/security/cve/CVE-2026-68207.html * https://www.suse.com/security/cve/CVE-2026-68209.html * https://www.suse.com/security/cve/CVE-2026-68210.html * https://www.suse.com/security/cve/CVE-2026-68212.html * https://www.suse.com/security/cve/CVE-2026-68213.html * https://www.suse.com/security/cve/CVE-2026-68214.html * https://www.suse.com/security/cve/CVE-2026-68215.html * https://www.suse.com/security/cve/CVE-2026-68216.html * https://www.suse.com/security/cve/CVE-2026-68217.html * https://www.suse.com/security/cve/CVE-2026-68218.html * https://www.suse.com/security/cve/CVE-2026-68219.html * https://www.suse.com/security/cve/CVE-2026-68220.html * https://www.suse.com/security/cve/CVE-2026-68222.html * https://www.suse.com/security/cve/CVE-2026-68223.html * https://www.suse.com/security/cve/CVE-2026-68226.html * https://www.suse.com/security/cve/CVE-2026-68227.html * https://www.suse.com/security/cve/CVE-2026-68229.html * https://www.suse.com/security/cve/CVE-2026-68231.html * https://www.suse.com/security/cve/CVE-2026-68234.html * https://www.suse.com/security/cve/CVE-2026-68236.html * https://www.suse.com/security/cve/CVE-2026-68238.html * https://www.suse.com/security/cve/CVE-2026-68243.html * https://www.suse.com/security/cve/CVE-2026-68244.html * https://www.suse.com/security/cve/CVE-2026-68246.html * https://www.suse.com/security/cve/CVE-2026-68247.html * https://www.suse.com/security/cve/CVE-2026-68248.html * https://www.suse.com/security/cve/CVE-2026-68249.html * https://www.suse.com/security/cve/CVE-2026-68250.html * https://www.suse.com/security/cve/CVE-2026-68251.html * https://www.suse.com/security/cve/CVE-2026-68254.html * https://www.suse.com/security/cve/CVE-2026-68255.html * https://www.suse.com/security/cve/CVE-2026-68256.html * https://www.suse.com/security/cve/CVE-2026-68259.html * https://www.suse.com/security/cve/CVE-2026-68269.html * https://www.suse.com/security/cve/CVE-2026-68271.html * https://www.suse.com/security/cve/CVE-2026-68272.html * https://www.suse.com/security/cve/CVE-2026-68277.html * https://www.suse.com/security/cve/CVE-2026-68278.html * https://www.suse.com/security/cve/CVE-2026-68279.html * https://www.suse.com/security/cve/CVE-2026-68280.html * https://www.suse.com/security/cve/CVE-2026-68284.html * https://www.suse.com/security/cve/CVE-2026-68286.html * https://www.suse.com/security/cve/CVE-2026-68288.html * https://www.suse.com/security/cve/CVE-2026-68289.html * https://www.suse.com/security/cve/CVE-2026-68293.html * https://www.suse.com/security/cve/CVE-2026-68297.html * https://www.suse.com/security/cve/CVE-2026-68299.html * https://www.suse.com/security/cve/CVE-2026-68300.html * https://www.suse.com/security/cve/CVE-2026-68303.html * https://www.suse.com/security/cve/CVE-2026-68304.html * https://www.suse.com/security/cve/CVE-2026-68306.html * https://www.suse.com/security/cve/CVE-2026-68308.html * https://www.suse.com/security/cve/CVE-2026-68309.html * https://www.suse.com/security/cve/CVE-2026-68310.html * https://www.suse.com/security/cve/CVE-2026-68312.html * https://www.suse.com/security/cve/CVE-2026-68313.html * https://www.suse.com/security/cve/CVE-2026-68315.html * https://www.suse.com/security/cve/CVE-2026-68320.html * https://www.suse.com/security/cve/CVE-2026-68322.html * https://www.suse.com/security/cve/CVE-2026-68324.html * https://www.suse.com/security/cve/CVE-2026-68325.html * https://www.suse.com/security/cve/CVE-2026-68326.html * https://www.suse.com/security/cve/CVE-2026-68327.html * https://www.suse.com/security/cve/CVE-2026-68328.html * https://www.suse.com/security/cve/CVE-2026-68329.html * https://www.suse.com/security/cve/CVE-2026-68331.html * https://www.suse.com/security/cve/CVE-2026-68333.html * https://www.suse.com/security/cve/CVE-2026-68335.html * https://www.suse.com/security/cve/CVE-2026-68336.html * https://www.suse.com/security/cve/CVE-2026-68339.html * https://www.suse.com/security/cve/CVE-2026-68340.html * https://www.suse.com/security/cve/CVE-2026-68343.html * https://www.suse.com/security/cve/CVE-2026-68346.html * https://www.suse.com/security/cve/CVE-2026-68348.html * https://www.suse.com/security/cve/CVE-2026-68349.html * https://www.suse.com/security/cve/CVE-2026-68350.html * https://www.suse.com/security/cve/CVE-2026-68351.html * https://www.suse.com/security/cve/CVE-2026-68352.html * https://www.suse.com/security/cve/CVE-2026-68353.html * https://www.suse.com/security/cve/CVE-2026-68354.html * https://www.suse.com/security/cve/CVE-2026-68355.html * https://www.suse.com/security/cve/CVE-2026-68357.html * https://www.suse.com/security/cve/CVE-2026-68359.html * https://www.suse.com/security/cve/CVE-2026-68360.html * https://www.suse.com/security/cve/CVE-2026-68361.html * https://www.suse.com/security/cve/CVE-2026-68362.html * https://www.suse.com/security/cve/CVE-2026-68363.html * https://www.suse.com/security/cve/CVE-2026-68365.html * https://www.suse.com/security/cve/CVE-2026-68366.html * https://www.suse.com/security/cve/CVE-2026-68368.html * https://www.suse.com/security/cve/CVE-2026-68369.html * https://www.suse.com/security/cve/CVE-2026-68370.html * https://www.suse.com/security/cve/CVE-2026-68372.html * https://www.suse.com/security/cve/CVE-2026-68373.html * https://www.suse.com/security/cve/CVE-2026-68377.html * https://www.suse.com/security/cve/CVE-2026-68386.html * https://www.suse.com/security/cve/CVE-2026-68391.html * https://www.suse.com/security/cve/CVE-2026-68392.html * https://www.suse.com/security/cve/CVE-2026-68397.html * https://www.suse.com/security/cve/CVE-2026-68398.html * https://www.suse.com/security/cve/CVE-2026-68399.html * https://www.suse.com/security/cve/CVE-2026-68402.html * https://www.suse.com/security/cve/CVE-2026-68403.html * https://www.suse.com/security/cve/CVE-2026-68405.html * https://www.suse.com/security/cve/CVE-2026-68406.html * https://www.suse.com/security/cve/CVE-2026-68407.html * https://www.suse.com/security/cve/CVE-2026-68408.html * https://www.suse.com/security/cve/CVE-2026-68410.html * https://www.suse.com/security/cve/CVE-2026-68413.html * https://www.suse.com/security/cve/CVE-2026-68414.html * https://www.suse.com/security/cve/CVE-2026-68417.html * https://www.suse.com/security/cve/CVE-2026-68418.html * https://www.suse.com/security/cve/CVE-2026-68419.html * https://www.suse.com/security/cve/CVE-2026-68422.html * https://www.suse.com/security/cve/CVE-2026-68425.html * https://www.suse.com/security/cve/CVE-2026-68426.html * https://www.suse.com/security/cve/CVE-2026-68427.html * https://www.suse.com/security/cve/CVE-2026-68428.html * https://www.suse.com/security/cve/CVE-2026-68429.html * https://www.suse.com/security/cve/CVE-2026-68430.html * https://www.suse.com/security/cve/CVE-2026-68432.html * https://www.suse.com/security/cve/CVE-2026-68433.html * https://www.suse.com/security/cve/CVE-2026-68434.html * https://www.suse.com/security/cve/CVE-2026-68444.html * https://www.suse.com/security/cve/CVE-2026-68445.html * https://www.suse.com/security/cve/CVE-2026-68446.html * https://www.suse.com/security/cve/CVE-2026-68450.html * https://www.suse.com/security/cve/CVE-2026-68470.html * https://www.suse.com/security/cve/CVE-2026-68480.html * https://www.suse.com/security/cve/CVE-2026-72020.html * https://www.suse.com/security/cve/CVE-2026-72035.html * https://www.suse.com/security/cve/CVE-2026-72036.html * https://www.suse.com/security/cve/CVE-2026-72069.html * https://www.suse.com/security/cve/CVE-2026-72072.html * https://www.suse.com/security/cve/CVE-2026-72083.html * https://www.suse.com/security/cve/CVE-2026-72084.html * https://www.suse.com/security/cve/CVE-2026-72123.html * https://www.suse.com/security/cve/CVE-2026-72132.html * https://www.suse.com/security/cve/CVE-2026-72221.html * https://www.suse.com/security/cve/CVE-2026-72222.html * https://www.suse.com/security/cve/CVE-2026-72251.html * https://www.suse.com/security/cve/CVE-2026-72254.html * https://www.suse.com/security/cve/CVE-2026-72262.html * https://www.suse.com/security/cve/CVE-2026-72288.html * https://www.suse.com/security/cve/CVE-2026-72289.html * https://www.suse.com/security/cve/CVE-2026-72296.html * https://www.suse.com/security/cve/CVE-2026-72307.html * https://www.suse.com/security/cve/CVE-2026-72308.html * https://www.suse.com/security/cve/CVE-2026-72317.html * https://www.suse.com/security/cve/CVE-2026-72341.html * https://www.suse.com/security/cve/CVE-2026-72342.html * https://www.suse.com/security/cve/CVE-2026-72343.html * https://www.suse.com/security/cve/CVE-2026-72389.html * https://www.suse.com/security/cve/CVE-2026-72463.html * https://www.suse.com/security/cve/CVE-2026-72464.html * https://www.suse.com/security/cve/CVE-2026-72466.html * https://www.suse.com/security/cve/CVE-2026-72467.html * https://www.suse.com/security/cve/CVE-2026-72469.html * https://www.suse.com/security/cve/CVE-2026-72473.html * https://www.suse.com/security/cve/CVE-2026-72494.html * https://www.suse.com/security/cve/CVE-2026-72495.html * https://www.suse.com/security/cve/CVE-2026-72496.html * https://www.suse.com/security/cve/CVE-2026-72499.html * https://www.suse.com/security/cve/CVE-2026-72501.html * https://www.suse.com/security/cve/CVE-2026-72502.html * https://www.suse.com/security/cve/CVE-2026-74269.html * https://www.suse.com/security/cve/CVE-2026-74296.html * https://www.suse.com/security/cve/CVE-2026-74297.html * https://www.suse.com/security/cve/CVE-2026-74318.html * https://www.suse.com/security/cve/CVE-2026-74321.html * https://www.suse.com/security/cve/CVE-2026-74334.html * https://www.suse.com/security/cve/CVE-2026-74345.html * https://www.suse.com/security/cve/CVE-2026-74394.html * https://www.suse.com/security/cve/CVE-2026-74395.html * https://www.suse.com/security/cve/CVE-2026-74454.html * https://www.suse.com/security/cve/CVE-2026-74474.html * https://www.suse.com/security/cve/CVE-2026-74481.html * https://www.suse.com/security/cve/CVE-2026-74482.html * https://www.suse.com/security/cve/CVE-2026-74488.html * https://www.suse.com/security/cve/CVE-2026-74495.html * https://www.suse.com/security/cve/CVE-2026-74496.html * https://www.suse.com/security/cve/CVE-2026-74509.html * https://www.suse.com/security/cve/CVE-2026-74510.html * https://www.suse.com/security/cve/CVE-2026-74512.html * https://www.suse.com/security/cve/CVE-2026-74516.html * https://www.suse.com/security/cve/CVE-2026-74518.html * https://www.suse.com/security/cve/CVE-2026-74527.html * https://www.suse.com/security/cve/CVE-2026-74537.html * https://www.suse.com/security/cve/CVE-2026-74548.html * https://www.suse.com/security/cve/CVE-2026-74550.html * https://www.suse.com/security/cve/CVE-2026-74556.html * https://www.suse.com/security/cve/CVE-2026-74563.html * https://www.suse.com/security/cve/CVE-2026-74566.html * https://www.suse.com/security/cve/CVE-2026-74567.html * https://www.suse.com/security/cve/CVE-2026-74571.html * https://www.suse.com/security/cve/CVE-2026-74581.html * https://www.suse.com/security/cve/CVE-2026-74582.html * https://www.suse.com/security/cve/CVE-2026-74584.html * https://www.suse.com/security/cve/CVE-2026-74610.html * https://www.suse.com/security/cve/CVE-2026-74669.html * https://www.suse.com/security/cve/CVE-2026-74692.html * https://www.suse.com/security/cve/CVE-2026-74694.html * https://www.suse.com/security/cve/CVE-2026-74695.html * https://www.suse.com/security/cve/CVE-2026-74717.html * https://www.suse.com/security/cve/CVE-2026-74722.html * https://www.suse.com/security/cve/CVE-2026-80529.html * https://www.suse.com/security/cve/CVE-2026-80534.html * https://www.suse.com/security/cve/CVE-2026-80590.html * https://www.suse.com/security/cve/CVE-2026-80654.html * https://bugzilla.suse.com/show_bug.cgi?id=1230238 * https://bugzilla.suse.com/show_bug.cgi?id=1235944 * https://bugzilla.suse.com/show_bug.cgi?id=1247455 * https://bugzilla.suse.com/show_bug.cgi?id=1250748 * https://bugzilla.suse.com/show_bug.cgi?id=1251966 * https://bugzilla.suse.com/show_bug.cgi?id=1252682 * https://bugzilla.suse.com/show_bug.cgi?id=1254306 * https://bugzilla.suse.com/show_bug.cgi?id=1255225 * https://bugzilla.suse.com/show_bug.cgi?id=1255250 * https://bugzilla.suse.com/show_bug.cgi?id=1256629 * https://bugzilla.suse.com/show_bug.cgi?id=1256708 * https://bugzilla.suse.com/show_bug.cgi?id=1257154 * https://bugzilla.suse.com/show_bug.cgi?id=1258430 * https://bugzilla.suse.com/show_bug.cgi?id=1258517 * https://bugzilla.suse.com/show_bug.cgi?id=1260522 * https://bugzilla.suse.com/show_bug.cgi?id=1261780 * https://bugzilla.suse.com/show_bug.cgi?id=1261788 * https://bugzilla.suse.com/show_bug.cgi?id=1262073 * https://bugzilla.suse.com/show_bug.cgi?id=1263004 * https://bugzilla.suse.com/show_bug.cgi?id=1263061 * https://bugzilla.suse.com/show_bug.cgi?id=1263133 * https://bugzilla.suse.com/show_bug.cgi?id=1264335 * https://bugzilla.suse.com/show_bug.cgi?id=1264446 * https://bugzilla.suse.com/show_bug.cgi?id=1264541 * https://bugzilla.suse.com/show_bug.cgi?id=1264584 * https://bugzilla.suse.com/show_bug.cgi?id=1264587 * https://bugzilla.suse.com/show_bug.cgi?id=1264619 * https://bugzilla.suse.com/show_bug.cgi?id=1264788 * https://bugzilla.suse.com/show_bug.cgi?id=1265068 * https://bugzilla.suse.com/show_bug.cgi?id=1265121 * https://bugzilla.suse.com/show_bug.cgi?id=1265449 * https://bugzilla.suse.com/show_bug.cgi?id=1265928 * https://bugzilla.suse.com/show_bug.cgi?id=1266402 * https://bugzilla.suse.com/show_bug.cgi?id=1266860 * https://bugzilla.suse.com/show_bug.cgi?id=1266874 * https://bugzilla.suse.com/show_bug.cgi?id=1266897 * https://bugzilla.suse.com/show_bug.cgi?id=1267023 * https://bugzilla.suse.com/show_bug.cgi?id=1267238 * https://bugzilla.suse.com/show_bug.cgi?id=1267501 * https://bugzilla.suse.com/show_bug.cgi?id=1267612 * https://bugzilla.suse.com/show_bug.cgi?id=1268276 * https://bugzilla.suse.com/show_bug.cgi?id=1268972 * https://bugzilla.suse.com/show_bug.cgi?id=1268979 * https://bugzilla.suse.com/show_bug.cgi?id=1268987 * https://bugzilla.suse.com/show_bug.cgi?id=1269004 * https://bugzilla.suse.com/show_bug.cgi?id=1269013 * https://bugzilla.suse.com/show_bug.cgi?id=1269108 * https://bugzilla.suse.com/show_bug.cgi?id=1269113 * https://bugzilla.suse.com/show_bug.cgi?id=1269114 * https://bugzilla.suse.com/show_bug.cgi?id=1269126 * https://bugzilla.suse.com/show_bug.cgi?id=1269167 * https://bugzilla.suse.com/show_bug.cgi?id=1269234 * https://bugzilla.suse.com/show_bug.cgi?id=1269238 * https://bugzilla.suse.com/show_bug.cgi?id=1269242 * https://bugzilla.suse.com/show_bug.cgi?id=1269256 * https://bugzilla.suse.com/show_bug.cgi?id=1269301 * https://bugzilla.suse.com/show_bug.cgi?id=1269306 * https://bugzilla.suse.com/show_bug.cgi?id=1269381 * https://bugzilla.suse.com/show_bug.cgi?id=1269388 * https://bugzilla.suse.com/show_bug.cgi?id=1269412 * https://bugzilla.suse.com/show_bug.cgi?id=1269530 * https://bugzilla.suse.com/show_bug.cgi?id=1269579 * https://bugzilla.suse.com/show_bug.cgi?id=1269590 * https://bugzilla.suse.com/show_bug.cgi?id=1269635 * https://bugzilla.suse.com/show_bug.cgi?id=1269655 * https://bugzilla.suse.com/show_bug.cgi?id=1269665 * https://bugzilla.suse.com/show_bug.cgi?id=1269686 * https://bugzilla.suse.com/show_bug.cgi?id=1269695 * https://bugzilla.suse.com/show_bug.cgi?id=1269713 * https://bugzilla.suse.com/show_bug.cgi?id=1269731 * https://bugzilla.suse.com/show_bug.cgi?id=1269774 * https://bugzilla.suse.com/show_bug.cgi?id=1269783 * https://bugzilla.suse.com/show_bug.cgi?id=1269792 * https://bugzilla.suse.com/show_bug.cgi?id=1269815 * https://bugzilla.suse.com/show_bug.cgi?id=1269965 * https://bugzilla.suse.com/show_bug.cgi?id=1269969 * https://bugzilla.suse.com/show_bug.cgi?id=1269981 * https://bugzilla.suse.com/show_bug.cgi?id=1269985 * https://bugzilla.suse.com/show_bug.cgi?id=1270090 * https://bugzilla.suse.com/show_bug.cgi?id=1270108 * https://bugzilla.suse.com/show_bug.cgi?id=1270111 * https://bugzilla.suse.com/show_bug.cgi?id=1270251 * https://bugzilla.suse.com/show_bug.cgi?id=1271256 * https://bugzilla.suse.com/show_bug.cgi?id=1271365 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 * https://bugzilla.suse.com/show_bug.cgi?id=1271825 * https://bugzilla.suse.com/show_bug.cgi?id=1271830 * https://bugzilla.suse.com/show_bug.cgi?id=1272150 * https://bugzilla.suse.com/show_bug.cgi?id=1272175 * https://bugzilla.suse.com/show_bug.cgi?id=1272179 * https://bugzilla.suse.com/show_bug.cgi?id=1272182 * https://bugzilla.suse.com/show_bug.cgi?id=1272200 * https://bugzilla.suse.com/show_bug.cgi?id=1272210 * https://bugzilla.suse.com/show_bug.cgi?id=1272213 * https://bugzilla.suse.com/show_bug.cgi?id=1272230 * https://bugzilla.suse.com/show_bug.cgi?id=1272260 * https://bugzilla.suse.com/show_bug.cgi?id=1272261 * https://bugzilla.suse.com/show_bug.cgi?id=1272262 * https://bugzilla.suse.com/show_bug.cgi?id=1272297 * https://bugzilla.suse.com/show_bug.cgi?id=1272346 * https://bugzilla.suse.com/show_bug.cgi?id=1272381 * https://bugzilla.suse.com/show_bug.cgi?id=1272385 * https://bugzilla.suse.com/show_bug.cgi?id=1272390 * https://bugzilla.suse.com/show_bug.cgi?id=1272423 * https://bugzilla.suse.com/show_bug.cgi?id=1272429 * https://bugzilla.suse.com/show_bug.cgi?id=1272484 * https://bugzilla.suse.com/show_bug.cgi?id=1272486 * https://bugzilla.suse.com/show_bug.cgi?id=1272497 * https://bugzilla.suse.com/show_bug.cgi?id=1272516 * https://bugzilla.suse.com/show_bug.cgi?id=1272569 * https://bugzilla.suse.com/show_bug.cgi?id=1272571 * https://bugzilla.suse.com/show_bug.cgi?id=1272641 * https://bugzilla.suse.com/show_bug.cgi?id=1272643 * https://bugzilla.suse.com/show_bug.cgi?id=1272662 * https://bugzilla.suse.com/show_bug.cgi?id=1272673 * https://bugzilla.suse.com/show_bug.cgi?id=1272680 * https://bugzilla.suse.com/show_bug.cgi?id=1272682 * https://bugzilla.suse.com/show_bug.cgi?id=1272756 * https://bugzilla.suse.com/show_bug.cgi?id=1272786 * https://bugzilla.suse.com/show_bug.cgi?id=1272788 * https://bugzilla.suse.com/show_bug.cgi?id=1272798 * https://bugzilla.suse.com/show_bug.cgi?id=1272799 * https://bugzilla.suse.com/show_bug.cgi?id=1272868 * https://bugzilla.suse.com/show_bug.cgi?id=1272877 * https://bugzilla.suse.com/show_bug.cgi?id=1272891 * https://bugzilla.suse.com/show_bug.cgi?id=1272963 * https://bugzilla.suse.com/show_bug.cgi?id=1272983 * https://bugzilla.suse.com/show_bug.cgi?id=1273008 * https://bugzilla.suse.com/show_bug.cgi?id=1273019 * https://bugzilla.suse.com/show_bug.cgi?id=1273027 * https://bugzilla.suse.com/show_bug.cgi?id=1273028 * https://bugzilla.suse.com/show_bug.cgi?id=1273030 * https://bugzilla.suse.com/show_bug.cgi?id=1273038 * https://bugzilla.suse.com/show_bug.cgi?id=1273053 * https://bugzilla.suse.com/show_bug.cgi?id=1273054 * https://bugzilla.suse.com/show_bug.cgi?id=1273060 * https://bugzilla.suse.com/show_bug.cgi?id=1273105 * https://bugzilla.suse.com/show_bug.cgi?id=1273249 * https://bugzilla.suse.com/show_bug.cgi?id=1273250 * https://bugzilla.suse.com/show_bug.cgi?id=1273260 * https://bugzilla.suse.com/show_bug.cgi?id=1273273 * https://bugzilla.suse.com/show_bug.cgi?id=1273274 * https://bugzilla.suse.com/show_bug.cgi?id=1273276 * https://bugzilla.suse.com/show_bug.cgi?id=1273281 * https://bugzilla.suse.com/show_bug.cgi?id=1273284 * https://bugzilla.suse.com/show_bug.cgi?id=1273285 * https://bugzilla.suse.com/show_bug.cgi?id=1273289 * https://bugzilla.suse.com/show_bug.cgi?id=1273291 * https://bugzilla.suse.com/show_bug.cgi?id=1273294 * https://bugzilla.suse.com/show_bug.cgi?id=1273302 * https://bugzilla.suse.com/show_bug.cgi?id=1273303 * https://bugzilla.suse.com/show_bug.cgi?id=1273305 * https://bugzilla.suse.com/show_bug.cgi?id=1273310 * https://bugzilla.suse.com/show_bug.cgi?id=1273311 * https://bugzilla.suse.com/show_bug.cgi?id=1273316 * https://bugzilla.suse.com/show_bug.cgi?id=1273318 * https://bugzilla.suse.com/show_bug.cgi?id=1273319 * https://bugzilla.suse.com/show_bug.cgi?id=1273323 * https://bugzilla.suse.com/show_bug.cgi?id=1273325 * https://bugzilla.suse.com/show_bug.cgi?id=1273327 * https://bugzilla.suse.com/show_bug.cgi?id=1273334 * https://bugzilla.suse.com/show_bug.cgi?id=1273335 * https://bugzilla.suse.com/show_bug.cgi?id=1273336 * https://bugzilla.suse.com/show_bug.cgi?id=1273337 * https://bugzilla.suse.com/show_bug.cgi?id=1273338 * https://bugzilla.suse.com/show_bug.cgi?id=1273340 * https://bugzilla.suse.com/show_bug.cgi?id=1273341 * https://bugzilla.suse.com/show_bug.cgi?id=1273346 * https://bugzilla.suse.com/show_bug.cgi?id=1273422 * https://bugzilla.suse.com/show_bug.cgi?id=1273426 * https://bugzilla.suse.com/show_bug.cgi?id=1273443 * https://bugzilla.suse.com/show_bug.cgi?id=1273463 * https://bugzilla.suse.com/show_bug.cgi?id=1273468 * https://bugzilla.suse.com/show_bug.cgi?id=1273469 * https://bugzilla.suse.com/show_bug.cgi?id=1273471 * https://bugzilla.suse.com/show_bug.cgi?id=1273479 * https://bugzilla.suse.com/show_bug.cgi?id=1273480 * https://bugzilla.suse.com/show_bug.cgi?id=1273482 * https://bugzilla.suse.com/show_bug.cgi?id=1273484 * https://bugzilla.suse.com/show_bug.cgi?id=1273488 * https://bugzilla.suse.com/show_bug.cgi?id=1273490 * https://bugzilla.suse.com/show_bug.cgi?id=1273501 * https://bugzilla.suse.com/show_bug.cgi?id=1273503 * https://bugzilla.suse.com/show_bug.cgi?id=1273504 * https://bugzilla.suse.com/show_bug.cgi?id=1273506 * https://bugzilla.suse.com/show_bug.cgi?id=1273523 * https://bugzilla.suse.com/show_bug.cgi?id=1273525 * https://bugzilla.suse.com/show_bug.cgi?id=1273533 * https://bugzilla.suse.com/show_bug.cgi?id=1273536 * https://bugzilla.suse.com/show_bug.cgi?id=1273542 * https://bugzilla.suse.com/show_bug.cgi?id=1273555 * https://bugzilla.suse.com/show_bug.cgi?id=1273578 * https://bugzilla.suse.com/show_bug.cgi?id=1273579 * https://bugzilla.suse.com/show_bug.cgi?id=1273582 * https://bugzilla.suse.com/show_bug.cgi?id=1273596 * https://bugzilla.suse.com/show_bug.cgi?id=1273597 * https://bugzilla.suse.com/show_bug.cgi?id=1273598 * https://bugzilla.suse.com/show_bug.cgi?id=1273600 * https://bugzilla.suse.com/show_bug.cgi?id=1273601 * https://bugzilla.suse.com/show_bug.cgi?id=1273602 * https://bugzilla.suse.com/show_bug.cgi?id=1273603 * https://bugzilla.suse.com/show_bug.cgi?id=1273682 * https://bugzilla.suse.com/show_bug.cgi?id=1273734 * https://bugzilla.suse.com/show_bug.cgi?id=1273738 * https://bugzilla.suse.com/show_bug.cgi?id=1273739 * https://bugzilla.suse.com/show_bug.cgi?id=1273741 * https://bugzilla.suse.com/show_bug.cgi?id=1273742 * https://bugzilla.suse.com/show_bug.cgi?id=1273743 * https://bugzilla.suse.com/show_bug.cgi?id=1273745 * https://bugzilla.suse.com/show_bug.cgi?id=1273748 * https://bugzilla.suse.com/show_bug.cgi?id=1273749 * https://bugzilla.suse.com/show_bug.cgi?id=1273755 * https://bugzilla.suse.com/show_bug.cgi?id=1273762 * https://bugzilla.suse.com/show_bug.cgi?id=1273765 * https://bugzilla.suse.com/show_bug.cgi?id=1273766 * https://bugzilla.suse.com/show_bug.cgi?id=1273769 * https://bugzilla.suse.com/show_bug.cgi?id=1273774 * https://bugzilla.suse.com/show_bug.cgi?id=1273778 * https://bugzilla.suse.com/show_bug.cgi?id=1273780 * https://bugzilla.suse.com/show_bug.cgi?id=1273790 * https://bugzilla.suse.com/show_bug.cgi?id=1273796 * https://bugzilla.suse.com/show_bug.cgi?id=1273804 * https://bugzilla.suse.com/show_bug.cgi?id=1273810 * https://bugzilla.suse.com/show_bug.cgi?id=1273811 * https://bugzilla.suse.com/show_bug.cgi?id=1273813 * https://bugzilla.suse.com/show_bug.cgi?id=1273817 * https://bugzilla.suse.com/show_bug.cgi?id=1273822 * https://bugzilla.suse.com/show_bug.cgi?id=1273824 * https://bugzilla.suse.com/show_bug.cgi?id=1273831 * https://bugzilla.suse.com/show_bug.cgi?id=1273832 * https://bugzilla.suse.com/show_bug.cgi?id=1273834 * https://bugzilla.suse.com/show_bug.cgi?id=1273838 * https://bugzilla.suse.com/show_bug.cgi?id=1273844 * https://bugzilla.suse.com/show_bug.cgi?id=1273849 * https://bugzilla.suse.com/show_bug.cgi?id=1273860 * https://bugzilla.suse.com/show_bug.cgi?id=1273862 * https://bugzilla.suse.com/show_bug.cgi?id=1273867 * https://bugzilla.suse.com/show_bug.cgi?id=1273868 * https://bugzilla.suse.com/show_bug.cgi?id=1273869 * https://bugzilla.suse.com/show_bug.cgi?id=1273872 * https://bugzilla.suse.com/show_bug.cgi?id=1273876 * https://bugzilla.suse.com/show_bug.cgi?id=1273877 * https://bugzilla.suse.com/show_bug.cgi?id=1273880 * https://bugzilla.suse.com/show_bug.cgi?id=1273882 * https://bugzilla.suse.com/show_bug.cgi?id=1273890 * https://bugzilla.suse.com/show_bug.cgi?id=1273891 * https://bugzilla.suse.com/show_bug.cgi?id=1273892 * https://bugzilla.suse.com/show_bug.cgi?id=1273895 * https://bugzilla.suse.com/show_bug.cgi?id=1273896 * https://bugzilla.suse.com/show_bug.cgi?id=1273903 * https://bugzilla.suse.com/show_bug.cgi?id=1273905 * https://bugzilla.suse.com/show_bug.cgi?id=1273930 * https://bugzilla.suse.com/show_bug.cgi?id=1273933 * https://bugzilla.suse.com/show_bug.cgi?id=1273934 * https://bugzilla.suse.com/show_bug.cgi?id=1273935 * https://bugzilla.suse.com/show_bug.cgi?id=1273936 * https://bugzilla.suse.com/show_bug.cgi?id=1273939 * https://bugzilla.suse.com/show_bug.cgi?id=1273940 * https://bugzilla.suse.com/show_bug.cgi?id=1273941 * https://bugzilla.suse.com/show_bug.cgi?id=1273942 * https://bugzilla.suse.com/show_bug.cgi?id=1273944 * https://bugzilla.suse.com/show_bug.cgi?id=1273945 * https://bugzilla.suse.com/show_bug.cgi?id=1273946 * https://bugzilla.suse.com/show_bug.cgi?id=1273956 * https://bugzilla.suse.com/show_bug.cgi?id=1273957 * https://bugzilla.suse.com/show_bug.cgi?id=1273958 * https://bugzilla.suse.com/show_bug.cgi?id=1273966 * https://bugzilla.suse.com/show_bug.cgi?id=1273967 * https://bugzilla.suse.com/show_bug.cgi?id=1273968 * https://bugzilla.suse.com/show_bug.cgi?id=1273972 * https://bugzilla.suse.com/show_bug.cgi?id=1273974 * https://bugzilla.suse.com/show_bug.cgi?id=1273975 * https://bugzilla.suse.com/show_bug.cgi?id=1273977 * https://bugzilla.suse.com/show_bug.cgi?id=1273982 * https://bugzilla.suse.com/show_bug.cgi?id=1273988 * https://bugzilla.suse.com/show_bug.cgi?id=1273990 * https://bugzilla.suse.com/show_bug.cgi?id=1273991 * https://bugzilla.suse.com/show_bug.cgi?id=1273995 * https://bugzilla.suse.com/show_bug.cgi?id=1274001 * https://bugzilla.suse.com/show_bug.cgi?id=1274003 * https://bugzilla.suse.com/show_bug.cgi?id=1274006 * https://bugzilla.suse.com/show_bug.cgi?id=1274011 * https://bugzilla.suse.com/show_bug.cgi?id=1274012 * https://bugzilla.suse.com/show_bug.cgi?id=1274014 * https://bugzilla.suse.com/show_bug.cgi?id=1274017 * https://bugzilla.suse.com/show_bug.cgi?id=1274019 * https://bugzilla.suse.com/show_bug.cgi?id=1274020 * https://bugzilla.suse.com/show_bug.cgi?id=1274026 * https://bugzilla.suse.com/show_bug.cgi?id=1274028 * https://bugzilla.suse.com/show_bug.cgi?id=1274030 * https://bugzilla.suse.com/show_bug.cgi?id=1274031 * https://bugzilla.suse.com/show_bug.cgi?id=1274035 * https://bugzilla.suse.com/show_bug.cgi?id=1274040 * https://bugzilla.suse.com/show_bug.cgi?id=1274041 * https://bugzilla.suse.com/show_bug.cgi?id=1274057 * https://bugzilla.suse.com/show_bug.cgi?id=1274058 * https://bugzilla.suse.com/show_bug.cgi?id=1274061 * https://bugzilla.suse.com/show_bug.cgi?id=1274063 * https://bugzilla.suse.com/show_bug.cgi?id=1274065 * https://bugzilla.suse.com/show_bug.cgi?id=1274067 * https://bugzilla.suse.com/show_bug.cgi?id=1274075 * https://bugzilla.suse.com/show_bug.cgi?id=1274076 * https://bugzilla.suse.com/show_bug.cgi?id=1274077 * https://bugzilla.suse.com/show_bug.cgi?id=1274078 * https://bugzilla.suse.com/show_bug.cgi?id=1274208 * https://bugzilla.suse.com/show_bug.cgi?id=1274226 * https://bugzilla.suse.com/show_bug.cgi?id=1274239 * https://bugzilla.suse.com/show_bug.cgi?id=1274243 * https://bugzilla.suse.com/show_bug.cgi?id=1274258 * https://bugzilla.suse.com/show_bug.cgi?id=1274265 * https://bugzilla.suse.com/show_bug.cgi?id=1274274 * https://bugzilla.suse.com/show_bug.cgi?id=1274277 * https://bugzilla.suse.com/show_bug.cgi?id=1274278 * https://bugzilla.suse.com/show_bug.cgi?id=1274281 * https://bugzilla.suse.com/show_bug.cgi?id=1274283 * https://bugzilla.suse.com/show_bug.cgi?id=1274286 * https://bugzilla.suse.com/show_bug.cgi?id=1274290 * https://bugzilla.suse.com/show_bug.cgi?id=1274294 * https://bugzilla.suse.com/show_bug.cgi?id=1274296 * https://bugzilla.suse.com/show_bug.cgi?id=1274297 * https://bugzilla.suse.com/show_bug.cgi?id=1274298 * https://bugzilla.suse.com/show_bug.cgi?id=1274314 * https://bugzilla.suse.com/show_bug.cgi?id=1274321 * https://bugzilla.suse.com/show_bug.cgi?id=1274491 * https://bugzilla.suse.com/show_bug.cgi?id=1274497 * https://bugzilla.suse.com/show_bug.cgi?id=1274539 * https://bugzilla.suse.com/show_bug.cgi?id=1274541 * https://bugzilla.suse.com/show_bug.cgi?id=1274543 * https://bugzilla.suse.com/show_bug.cgi?id=1274545 * https://bugzilla.suse.com/show_bug.cgi?id=1274547 * https://bugzilla.suse.com/show_bug.cgi?id=1274550 * https://bugzilla.suse.com/show_bug.cgi?id=1274573 * https://bugzilla.suse.com/show_bug.cgi?id=1274578 * https://bugzilla.suse.com/show_bug.cgi?id=1274580 * https://bugzilla.suse.com/show_bug.cgi?id=1274581 * https://bugzilla.suse.com/show_bug.cgi?id=1274620 * https://bugzilla.suse.com/show_bug.cgi?id=1274622 * https://bugzilla.suse.com/show_bug.cgi?id=1274624 * https://bugzilla.suse.com/show_bug.cgi?id=1274629 * https://bugzilla.suse.com/show_bug.cgi?id=1274632 * https://bugzilla.suse.com/show_bug.cgi?id=1274636 * https://bugzilla.suse.com/show_bug.cgi?id=1274639 * https://bugzilla.suse.com/show_bug.cgi?id=1274640 * https://bugzilla.suse.com/show_bug.cgi?id=1274642 * https://bugzilla.suse.com/show_bug.cgi?id=1274644 * https://bugzilla.suse.com/show_bug.cgi?id=1274645 * https://bugzilla.suse.com/show_bug.cgi?id=1274646 * https://bugzilla.suse.com/show_bug.cgi?id=1274649 * https://bugzilla.suse.com/show_bug.cgi?id=1274650 * https://bugzilla.suse.com/show_bug.cgi?id=1274651 * https://bugzilla.suse.com/show_bug.cgi?id=1274656 * https://bugzilla.suse.com/show_bug.cgi?id=1274659 * https://bugzilla.suse.com/show_bug.cgi?id=1274662 * https://bugzilla.suse.com/show_bug.cgi?id=1274663 * https://bugzilla.suse.com/show_bug.cgi?id=1274665 * https://bugzilla.suse.com/show_bug.cgi?id=1274667 * https://bugzilla.suse.com/show_bug.cgi?id=1274670 * https://bugzilla.suse.com/show_bug.cgi?id=1274675 * https://bugzilla.suse.com/show_bug.cgi?id=1274677 * https://bugzilla.suse.com/show_bug.cgi?id=1274678 * https://bugzilla.suse.com/show_bug.cgi?id=1274679 * https://bugzilla.suse.com/show_bug.cgi?id=1274681 * https://bugzilla.suse.com/show_bug.cgi?id=1274682 * https://bugzilla.suse.com/show_bug.cgi?id=1274690 * https://bugzilla.suse.com/show_bug.cgi?id=1274694 * https://bugzilla.suse.com/show_bug.cgi?id=1274696 * https://bugzilla.suse.com/show_bug.cgi?id=1274698 * https://bugzilla.suse.com/show_bug.cgi?id=1274699 * https://bugzilla.suse.com/show_bug.cgi?id=1274700 * https://bugzilla.suse.com/show_bug.cgi?id=1274702 * https://bugzilla.suse.com/show_bug.cgi?id=1274703 * https://bugzilla.suse.com/show_bug.cgi?id=1274705 * https://bugzilla.suse.com/show_bug.cgi?id=1274706 * https://bugzilla.suse.com/show_bug.cgi?id=1274709 * https://bugzilla.suse.com/show_bug.cgi?id=1274710 * https://bugzilla.suse.com/show_bug.cgi?id=1274713 * https://bugzilla.suse.com/show_bug.cgi?id=1274716 * https://bugzilla.suse.com/show_bug.cgi?id=1274721 * https://bugzilla.suse.com/show_bug.cgi?id=1274725 * https://bugzilla.suse.com/show_bug.cgi?id=1274737 * https://bugzilla.suse.com/show_bug.cgi?id=1274738 * https://bugzilla.suse.com/show_bug.cgi?id=1274749 * https://bugzilla.suse.com/show_bug.cgi?id=1274752 * https://bugzilla.suse.com/show_bug.cgi?id=1274753 * https://bugzilla.suse.com/show_bug.cgi?id=1274754 * https://bugzilla.suse.com/show_bug.cgi?id=1274755 * https://bugzilla.suse.com/show_bug.cgi?id=1274756 * https://bugzilla.suse.com/show_bug.cgi?id=1274764 * https://bugzilla.suse.com/show_bug.cgi?id=1274768 * https://bugzilla.suse.com/show_bug.cgi?id=1274770 * https://bugzilla.suse.com/show_bug.cgi?id=1274787 * https://bugzilla.suse.com/show_bug.cgi?id=1274800 * https://bugzilla.suse.com/show_bug.cgi?id=1274801 * https://bugzilla.suse.com/show_bug.cgi?id=1274802 * https://bugzilla.suse.com/show_bug.cgi?id=1274804 * https://bugzilla.suse.com/show_bug.cgi?id=1274805 * https://bugzilla.suse.com/show_bug.cgi?id=1274807 * https://bugzilla.suse.com/show_bug.cgi?id=1274808 * https://bugzilla.suse.com/show_bug.cgi?id=1274811 * https://bugzilla.suse.com/show_bug.cgi?id=1274813 * https://bugzilla.suse.com/show_bug.cgi?id=1274814 * https://bugzilla.suse.com/show_bug.cgi?id=1274831 * https://bugzilla.suse.com/show_bug.cgi?id=1274834 * https://bugzilla.suse.com/show_bug.cgi?id=1274847 * https://bugzilla.suse.com/show_bug.cgi?id=1274853 * https://bugzilla.suse.com/show_bug.cgi?id=1274868 * https://bugzilla.suse.com/show_bug.cgi?id=1274869 * https://bugzilla.suse.com/show_bug.cgi?id=1274872 * https://bugzilla.suse.com/show_bug.cgi?id=1274873 * https://bugzilla.suse.com/show_bug.cgi?id=1274874 * https://bugzilla.suse.com/show_bug.cgi?id=1274876 * https://bugzilla.suse.com/show_bug.cgi?id=1274879 * https://bugzilla.suse.com/show_bug.cgi?id=1274881 * https://bugzilla.suse.com/show_bug.cgi?id=1274883 * https://bugzilla.suse.com/show_bug.cgi?id=1274886 * https://bugzilla.suse.com/show_bug.cgi?id=1274888 * https://bugzilla.suse.com/show_bug.cgi?id=1274891 * https://bugzilla.suse.com/show_bug.cgi?id=1274892 * https://bugzilla.suse.com/show_bug.cgi?id=1274893 * https://bugzilla.suse.com/show_bug.cgi?id=1274894 * https://bugzilla.suse.com/show_bug.cgi?id=1274896 * https://bugzilla.suse.com/show_bug.cgi?id=1274897 * https://bugzilla.suse.com/show_bug.cgi?id=1274898 * https://bugzilla.suse.com/show_bug.cgi?id=1274899 * https://bugzilla.suse.com/show_bug.cgi?id=1274901 * https://bugzilla.suse.com/show_bug.cgi?id=1274902 * https://bugzilla.suse.com/show_bug.cgi?id=1274905 * https://bugzilla.suse.com/show_bug.cgi?id=1274907 * https://bugzilla.suse.com/show_bug.cgi?id=1274908 * https://bugzilla.suse.com/show_bug.cgi?id=1274913 * https://bugzilla.suse.com/show_bug.cgi?id=1274914 * https://bugzilla.suse.com/show_bug.cgi?id=1274920 * https://bugzilla.suse.com/show_bug.cgi?id=1274921 * https://bugzilla.suse.com/show_bug.cgi?id=1274924 * https://bugzilla.suse.com/show_bug.cgi?id=1274925 * https://bugzilla.suse.com/show_bug.cgi?id=1274929 * https://bugzilla.suse.com/show_bug.cgi?id=1274930 * https://bugzilla.suse.com/show_bug.cgi?id=1274933 * https://bugzilla.suse.com/show_bug.cgi?id=1274934 * https://bugzilla.suse.com/show_bug.cgi?id=1274935 * https://bugzilla.suse.com/show_bug.cgi?id=1274941 * https://bugzilla.suse.com/show_bug.cgi?id=1274945 * https://bugzilla.suse.com/show_bug.cgi?id=1274947 * https://bugzilla.suse.com/show_bug.cgi?id=1274951 * https://bugzilla.suse.com/show_bug.cgi?id=1274953 * https://bugzilla.suse.com/show_bug.cgi?id=1274958 * https://bugzilla.suse.com/show_bug.cgi?id=1274968 * https://bugzilla.suse.com/show_bug.cgi?id=1274981 * https://bugzilla.suse.com/show_bug.cgi?id=1275040 * https://bugzilla.suse.com/show_bug.cgi?id=1275069 * https://bugzilla.suse.com/show_bug.cgi?id=1275071 * https://bugzilla.suse.com/show_bug.cgi?id=1275073 * https://bugzilla.suse.com/show_bug.cgi?id=1275076 * https://bugzilla.suse.com/show_bug.cgi?id=1275080 * https://bugzilla.suse.com/show_bug.cgi?id=1275083 * https://bugzilla.suse.com/show_bug.cgi?id=1275088 * https://bugzilla.suse.com/show_bug.cgi?id=1275091 * https://bugzilla.suse.com/show_bug.cgi?id=1275125 * https://bugzilla.suse.com/show_bug.cgi?id=1275126 * https://bugzilla.suse.com/show_bug.cgi?id=1275131 * https://bugzilla.suse.com/show_bug.cgi?id=1275132 * https://bugzilla.suse.com/show_bug.cgi?id=1275150 * https://bugzilla.suse.com/show_bug.cgi?id=1275152 * https://bugzilla.suse.com/show_bug.cgi?id=1275154 * https://bugzilla.suse.com/show_bug.cgi?id=1275155 * https://bugzilla.suse.com/show_bug.cgi?id=1275157 * https://bugzilla.suse.com/show_bug.cgi?id=1275158 * https://bugzilla.suse.com/show_bug.cgi?id=1275161 * https://bugzilla.suse.com/show_bug.cgi?id=1275163 * https://bugzilla.suse.com/show_bug.cgi?id=1275164 * https://bugzilla.suse.com/show_bug.cgi?id=1275169 * https://bugzilla.suse.com/show_bug.cgi?id=1275173 * https://bugzilla.suse.com/show_bug.cgi?id=1275176 * https://bugzilla.suse.com/show_bug.cgi?id=1275185 * https://bugzilla.suse.com/show_bug.cgi?id=1275190 * https://bugzilla.suse.com/show_bug.cgi?id=1275236 * https://bugzilla.suse.com/show_bug.cgi?id=1275237 * https://bugzilla.suse.com/show_bug.cgi?id=1275239 * https://bugzilla.suse.com/show_bug.cgi?id=1275294 * https://bugzilla.suse.com/show_bug.cgi?id=1275301 * https://bugzilla.suse.com/show_bug.cgi?id=1275303 * https://bugzilla.suse.com/show_bug.cgi?id=1275304 * https://bugzilla.suse.com/show_bug.cgi?id=1275305 * https://bugzilla.suse.com/show_bug.cgi?id=1275306 * https://bugzilla.suse.com/show_bug.cgi?id=1275307 * https://bugzilla.suse.com/show_bug.cgi?id=1275470 * https://bugzilla.suse.com/show_bug.cgi?id=1275472 * https://bugzilla.suse.com/show_bug.cgi?id=1275474 * https://bugzilla.suse.com/show_bug.cgi?id=1275479 * https://bugzilla.suse.com/show_bug.cgi?id=1275483 * https://bugzilla.suse.com/show_bug.cgi?id=1275486 * https://bugzilla.suse.com/show_bug.cgi?id=1275487 * https://bugzilla.suse.com/show_bug.cgi?id=1275506 * https://bugzilla.suse.com/show_bug.cgi?id=1275509 * https://bugzilla.suse.com/show_bug.cgi?id=1275511 * https://bugzilla.suse.com/show_bug.cgi?id=1275517 * https://bugzilla.suse.com/show_bug.cgi?id=1275528 * https://bugzilla.suse.com/show_bug.cgi?id=1275535 * https://bugzilla.suse.com/show_bug.cgi?id=1275540 * https://bugzilla.suse.com/show_bug.cgi?id=1275553 * https://bugzilla.suse.com/show_bug.cgi?id=1275555 * https://bugzilla.suse.com/show_bug.cgi?id=1275561 * https://bugzilla.suse.com/show_bug.cgi?id=1275566 * https://bugzilla.suse.com/show_bug.cgi?id=1275569 * https://bugzilla.suse.com/show_bug.cgi?id=1275574 * https://bugzilla.suse.com/show_bug.cgi?id=1275578 * https://bugzilla.suse.com/show_bug.cgi?id=1275582 * https://bugzilla.suse.com/show_bug.cgi?id=1275583 * https://bugzilla.suse.com/show_bug.cgi?id=1275584 * https://bugzilla.suse.com/show_bug.cgi?id=1275591 * https://bugzilla.suse.com/show_bug.cgi?id=1275595 * https://bugzilla.suse.com/show_bug.cgi?id=1275633 * https://bugzilla.suse.com/show_bug.cgi?id=1275636 * https://bugzilla.suse.com/show_bug.cgi?id=1275650 * https://bugzilla.suse.com/show_bug.cgi?id=1275659 * https://bugzilla.suse.com/show_bug.cgi?id=1275665 * https://bugzilla.suse.com/show_bug.cgi?id=1275669 * https://bugzilla.suse.com/show_bug.cgi?id=1275687 * https://bugzilla.suse.com/show_bug.cgi?id=1275688 * https://bugzilla.suse.com/show_bug.cgi?id=1275695 * https://bugzilla.suse.com/show_bug.cgi?id=1275696 * https://bugzilla.suse.com/show_bug.cgi?id=1275704 * https://bugzilla.suse.com/show_bug.cgi?id=1275782 * https://bugzilla.suse.com/show_bug.cgi?id=1275784 * https://bugzilla.suse.com/show_bug.cgi?id=1275787 * https://bugzilla.suse.com/show_bug.cgi?id=1275788 * https://bugzilla.suse.com/show_bug.cgi?id=1275790 * https://bugzilla.suse.com/show_bug.cgi?id=1275797 * https://bugzilla.suse.com/show_bug.cgi?id=1275798 * https://bugzilla.suse.com/show_bug.cgi?id=1275805 * https://bugzilla.suse.com/show_bug.cgi?id=1275817 * https://bugzilla.suse.com/show_bug.cgi?id=1275818 * https://bugzilla.suse.com/show_bug.cgi?id=1275819 * https://bugzilla.suse.com/show_bug.cgi?id=1275820 * https://bugzilla.suse.com/show_bug.cgi?id=1275821 * https://bugzilla.suse.com/show_bug.cgi?id=1275827 * https://bugzilla.suse.com/show_bug.cgi?id=1275864 * https://bugzilla.suse.com/show_bug.cgi?id=1275867 * https://bugzilla.suse.com/show_bug.cgi?id=1275869 * https://bugzilla.suse.com/show_bug.cgi?id=1275870 * https://bugzilla.suse.com/show_bug.cgi?id=1275871 * https://bugzilla.suse.com/show_bug.cgi?id=1275872 * https://bugzilla.suse.com/show_bug.cgi?id=1275886 * https://bugzilla.suse.com/show_bug.cgi?id=1275905 * https://bugzilla.suse.com/show_bug.cgi?id=1275923 * https://bugzilla.suse.com/show_bug.cgi?id=1275925 * https://bugzilla.suse.com/show_bug.cgi?id=1275946 * https://bugzilla.suse.com/show_bug.cgi?id=1275950 * https://bugzilla.suse.com/show_bug.cgi?id=1275954 * https://bugzilla.suse.com/show_bug.cgi?id=1275970 * https://bugzilla.suse.com/show_bug.cgi?id=1275973 * https://bugzilla.suse.com/show_bug.cgi?id=1275975 * https://bugzilla.suse.com/show_bug.cgi?id=1275976 * https://bugzilla.suse.com/show_bug.cgi?id=1276029 * https://bugzilla.suse.com/show_bug.cgi?id=1276257 * https://bugzilla.suse.com/show_bug.cgi?id=1276263 * https://bugzilla.suse.com/show_bug.cgi?id=1276270 * https://bugzilla.suse.com/show_bug.cgi?id=1276273 * https://bugzilla.suse.com/show_bug.cgi?id=1276277 * https://bugzilla.suse.com/show_bug.cgi?id=1276335 * https://bugzilla.suse.com/show_bug.cgi?id=1276346 * https://bugzilla.suse.com/show_bug.cgi?id=1276350 * https://bugzilla.suse.com/show_bug.cgi?id=1276355 * https://bugzilla.suse.com/show_bug.cgi?id=1276446 * https://bugzilla.suse.com/show_bug.cgi?id=1276452 * https://bugzilla.suse.com/show_bug.cgi?id=1276500 * https://bugzilla.suse.com/show_bug.cgi?id=1276507 * https://bugzilla.suse.com/show_bug.cgi?id=1276542 * https://bugzilla.suse.com/show_bug.cgi?id=1276546 * https://bugzilla.suse.com/show_bug.cgi?id=1276551 * https://bugzilla.suse.com/show_bug.cgi?id=1276561 * https://bugzilla.suse.com/show_bug.cgi?id=1276569 * https://bugzilla.suse.com/show_bug.cgi?id=1276665 * https://bugzilla.suse.com/show_bug.cgi?id=1276864 * https://bugzilla.suse.com/show_bug.cgi?id=1276927 * https://bugzilla.suse.com/show_bug.cgi?id=1276931 * https://bugzilla.suse.com/show_bug.cgi?id=1276937 * https://bugzilla.suse.com/show_bug.cgi?id=1276941 * https://bugzilla.suse.com/show_bug.cgi?id=1276943 * https://bugzilla.suse.com/show_bug.cgi?id=1276961 * https://bugzilla.suse.com/show_bug.cgi?id=1277022 * https://bugzilla.suse.com/show_bug.cgi?id=1277034 * https://bugzilla.suse.com/show_bug.cgi?id=1277037 * https://bugzilla.suse.com/show_bug.cgi?id=1277047 * https://bugzilla.suse.com/show_bug.cgi?id=1277054 * https://bugzilla.suse.com/show_bug.cgi?id=1277057 * https://bugzilla.suse.com/show_bug.cgi?id=1277059 * https://bugzilla.suse.com/show_bug.cgi?id=1277064 * https://bugzilla.suse.com/show_bug.cgi?id=1277066 * https://bugzilla.suse.com/show_bug.cgi?id=1277069 * https://bugzilla.suse.com/show_bug.cgi?id=1277073 * https://bugzilla.suse.com/show_bug.cgi?id=1277077 * https://bugzilla.suse.com/show_bug.cgi?id=1277095 * https://bugzilla.suse.com/show_bug.cgi?id=1277155 * https://bugzilla.suse.com/show_bug.cgi?id=1277159 * https://bugzilla.suse.com/show_bug.cgi?id=1277160 * https://bugzilla.suse.com/show_bug.cgi?id=1277202 * https://bugzilla.suse.com/show_bug.cgi?id=1277204 * https://bugzilla.suse.com/show_bug.cgi?id=1277275 * https://bugzilla.suse.com/show_bug.cgi?id=1277285 * https://bugzilla.suse.com/show_bug.cgi?id=1277391 * https://bugzilla.suse.com/show_bug.cgi?id=1277408 * https://bugzilla.suse.com/show_bug.cgi?id=1277516 * https://bugzilla.suse.com/show_bug.cgi?id=1277523 * https://bugzilla.suse.com/show_bug.cgi?id=1277551 * https://bugzilla.suse.com/show_bug.cgi?id=1277625 * https://bugzilla.suse.com/show_bug.cgi?id=1277660 * https://bugzilla.suse.com/show_bug.cgi?id=1277678 * https://bugzilla.suse.com/show_bug.cgi?id=1277688 * https://bugzilla.suse.com/show_bug.cgi?id=1277775 * https://bugzilla.suse.com/show_bug.cgi?id=1277776 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 12:58:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 12:58:45 -0000 Subject: SUSE-SU-2026:23490-1: important: Security update for the Linux Kernel Message-ID: <178895872545.1855.11022003187159198130@aaf27ed6f0fb> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:23490-1 Release Date: 2026-09-08T13:00:49Z Rating: important References: * bsc#1230238 * bsc#1235944 * bsc#1247455 * bsc#1250748 * bsc#1251966 * bsc#1252682 * bsc#1254306 * bsc#1255225 * bsc#1255250 * bsc#1256629 * bsc#1256708 * bsc#1257154 * bsc#1258430 * bsc#1258517 * bsc#1260522 * bsc#1261780 * bsc#1261788 * bsc#1262073 * bsc#1263004 * bsc#1263061 * bsc#1263133 * bsc#1264335 * bsc#1264446 * bsc#1264541 * bsc#1264584 * bsc#1264587 * bsc#1264619 * bsc#1264788 * bsc#1265068 * bsc#1265121 * bsc#1265449 * bsc#1265928 * bsc#1266402 * bsc#1266860 * bsc#1266874 * bsc#1266897 * bsc#1267023 * bsc#1267238 * bsc#1267501 * bsc#1267612 * bsc#1268276 * bsc#1268972 * bsc#1268979 * bsc#1268987 * bsc#1269004 * bsc#1269013 * bsc#1269108 * bsc#1269113 * bsc#1269114 * bsc#1269126 * bsc#1269167 * bsc#1269234 * bsc#1269238 * bsc#1269242 * bsc#1269256 * bsc#1269301 * bsc#1269306 * bsc#1269381 * bsc#1269388 * bsc#1269412 * bsc#1269530 * bsc#1269579 * bsc#1269590 * bsc#1269635 * bsc#1269655 * bsc#1269665 * bsc#1269686 * bsc#1269695 * bsc#1269713 * bsc#1269731 * bsc#1269774 * bsc#1269783 * bsc#1269792 * bsc#1269815 * bsc#1269965 * bsc#1269969 * bsc#1269981 * bsc#1269985 * bsc#1270090 * bsc#1270108 * bsc#1270111 * bsc#1270251 * bsc#1271256 * bsc#1271365 * bsc#1271366 * bsc#1271825 * bsc#1271830 * bsc#1272150 * bsc#1272175 * bsc#1272179 * bsc#1272182 * bsc#1272200 * bsc#1272210 * bsc#1272213 * bsc#1272230 * bsc#1272260 * bsc#1272261 * bsc#1272262 * bsc#1272297 * bsc#1272346 * bsc#1272381 * bsc#1272385 * bsc#1272390 * bsc#1272423 * bsc#1272429 * bsc#1272484 * bsc#1272486 * bsc#1272497 * bsc#1272516 * bsc#1272569 * bsc#1272571 * bsc#1272641 * bsc#1272643 * bsc#1272662 * bsc#1272673 * bsc#1272680 * bsc#1272682 * bsc#1272756 * bsc#1272786 * bsc#1272788 * bsc#1272798 * bsc#1272799 * bsc#1272868 * bsc#1272877 * bsc#1272891 * bsc#1272963 * bsc#1272983 * bsc#1273008 * bsc#1273019 * bsc#1273027 * bsc#1273028 * bsc#1273030 * bsc#1273038 * bsc#1273053 * bsc#1273054 * bsc#1273060 * bsc#1273105 * bsc#1273249 * bsc#1273250 * bsc#1273260 * bsc#1273273 * bsc#1273274 * bsc#1273276 * bsc#1273281 * bsc#1273284 * bsc#1273285 * bsc#1273289 * bsc#1273291 * bsc#1273294 * bsc#1273302 * bsc#1273303 * bsc#1273305 * bsc#1273310 * bsc#1273311 * bsc#1273316 * bsc#1273318 * bsc#1273319 * bsc#1273323 * bsc#1273325 * bsc#1273327 * bsc#1273334 * bsc#1273335 * bsc#1273336 * bsc#1273337 * bsc#1273338 * bsc#1273340 * bsc#1273341 * bsc#1273346 * bsc#1273422 * bsc#1273426 * bsc#1273443 * bsc#1273463 * bsc#1273468 * bsc#1273469 * bsc#1273471 * bsc#1273479 * bsc#1273480 * bsc#1273482 * bsc#1273484 * bsc#1273488 * bsc#1273490 * bsc#1273501 * bsc#1273503 * bsc#1273504 * bsc#1273506 * bsc#1273523 * bsc#1273525 * bsc#1273533 * bsc#1273536 * bsc#1273542 * bsc#1273555 * bsc#1273578 * bsc#1273579 * bsc#1273582 * bsc#1273596 * bsc#1273597 * bsc#1273598 * bsc#1273600 * bsc#1273601 * bsc#1273602 * bsc#1273603 * bsc#1273682 * bsc#1273734 * bsc#1273738 * bsc#1273739 * bsc#1273741 * bsc#1273742 * bsc#1273743 * bsc#1273745 * bsc#1273748 * bsc#1273749 * bsc#1273755 * bsc#1273762 * bsc#1273765 * bsc#1273766 * bsc#1273769 * bsc#1273774 * bsc#1273778 * bsc#1273780 * bsc#1273790 * bsc#1273796 * bsc#1273804 * bsc#1273810 * bsc#1273811 * bsc#1273813 * bsc#1273817 * bsc#1273822 * bsc#1273824 * bsc#1273831 * bsc#1273832 * bsc#1273834 * bsc#1273838 * bsc#1273844 * bsc#1273849 * bsc#1273860 * bsc#1273862 * bsc#1273867 * bsc#1273868 * bsc#1273869 * bsc#1273872 * bsc#1273876 * bsc#1273877 * bsc#1273880 * bsc#1273882 * bsc#1273890 * bsc#1273891 * bsc#1273892 * bsc#1273895 * bsc#1273896 * bsc#1273903 * bsc#1273905 * bsc#1273930 * bsc#1273933 * bsc#1273934 * bsc#1273935 * bsc#1273936 * bsc#1273939 * bsc#1273940 * bsc#1273941 * bsc#1273942 * bsc#1273944 * bsc#1273945 * bsc#1273946 * bsc#1273956 * bsc#1273957 * bsc#1273958 * bsc#1273966 * bsc#1273967 * bsc#1273968 * bsc#1273972 * bsc#1273974 * bsc#1273975 * bsc#1273977 * bsc#1273982 * bsc#1273988 * bsc#1273990 * bsc#1273991 * bsc#1273995 * bsc#1274001 * bsc#1274003 * bsc#1274006 * bsc#1274011 * bsc#1274012 * bsc#1274014 * bsc#1274017 * bsc#1274019 * bsc#1274020 * bsc#1274026 * bsc#1274028 * bsc#1274030 * bsc#1274031 * bsc#1274035 * bsc#1274040 * bsc#1274041 * bsc#1274057 * bsc#1274058 * bsc#1274061 * bsc#1274063 * bsc#1274065 * bsc#1274067 * bsc#1274075 * bsc#1274076 * bsc#1274077 * bsc#1274078 * bsc#1274208 * bsc#1274226 * bsc#1274239 * bsc#1274243 * bsc#1274258 * bsc#1274265 * bsc#1274274 * bsc#1274277 * bsc#1274278 * bsc#1274281 * bsc#1274283 * bsc#1274286 * bsc#1274290 * bsc#1274294 * bsc#1274296 * bsc#1274297 * bsc#1274298 * bsc#1274314 * bsc#1274321 * bsc#1274491 * bsc#1274497 * bsc#1274539 * bsc#1274541 * bsc#1274543 * bsc#1274545 * bsc#1274547 * bsc#1274550 * bsc#1274573 * bsc#1274578 * bsc#1274580 * bsc#1274581 * bsc#1274620 * bsc#1274622 * bsc#1274624 * bsc#1274629 * bsc#1274632 * bsc#1274636 * bsc#1274639 * bsc#1274640 * bsc#1274642 * bsc#1274644 * bsc#1274645 * bsc#1274646 * bsc#1274649 * bsc#1274650 * bsc#1274651 * bsc#1274656 * bsc#1274659 * bsc#1274662 * bsc#1274663 * bsc#1274665 * bsc#1274667 * bsc#1274670 * bsc#1274675 * bsc#1274677 * bsc#1274678 * bsc#1274679 * bsc#1274681 * bsc#1274682 * bsc#1274690 * bsc#1274694 * bsc#1274696 * bsc#1274698 * bsc#1274699 * bsc#1274700 * bsc#1274702 * bsc#1274703 * bsc#1274705 * bsc#1274706 * bsc#1274709 * bsc#1274710 * bsc#1274713 * bsc#1274716 * bsc#1274721 * bsc#1274725 * bsc#1274737 * bsc#1274738 * bsc#1274749 * bsc#1274752 * bsc#1274753 * bsc#1274754 * bsc#1274755 * bsc#1274756 * bsc#1274764 * bsc#1274768 * bsc#1274770 * bsc#1274787 * bsc#1274800 * bsc#1274801 * bsc#1274802 * bsc#1274804 * bsc#1274805 * bsc#1274807 * bsc#1274808 * bsc#1274811 * bsc#1274813 * bsc#1274814 * bsc#1274831 * bsc#1274834 * bsc#1274847 * bsc#1274853 * bsc#1274868 * bsc#1274869 * bsc#1274872 * bsc#1274873 * bsc#1274874 * bsc#1274876 * bsc#1274879 * bsc#1274881 * bsc#1274883 * bsc#1274886 * bsc#1274888 * bsc#1274891 * bsc#1274892 * bsc#1274893 * bsc#1274894 * bsc#1274896 * bsc#1274897 * bsc#1274898 * bsc#1274899 * bsc#1274901 * bsc#1274902 * bsc#1274905 * bsc#1274907 * bsc#1274908 * bsc#1274913 * bsc#1274914 * bsc#1274920 * bsc#1274921 * bsc#1274924 * bsc#1274925 * bsc#1274929 * bsc#1274930 * bsc#1274933 * bsc#1274934 * bsc#1274935 * bsc#1274941 * bsc#1274945 * bsc#1274947 * bsc#1274951 * bsc#1274953 * bsc#1274958 * bsc#1274968 * bsc#1274981 * bsc#1275040 * bsc#1275069 * bsc#1275071 * bsc#1275073 * bsc#1275076 * bsc#1275080 * bsc#1275083 * bsc#1275088 * bsc#1275091 * bsc#1275125 * bsc#1275126 * bsc#1275131 * bsc#1275132 * bsc#1275150 * bsc#1275152 * bsc#1275154 * bsc#1275155 * bsc#1275157 * bsc#1275158 * bsc#1275161 * bsc#1275163 * bsc#1275164 * bsc#1275169 * bsc#1275173 * bsc#1275176 * bsc#1275185 * bsc#1275190 * bsc#1275236 * bsc#1275237 * bsc#1275239 * bsc#1275294 * bsc#1275301 * bsc#1275303 * bsc#1275304 * bsc#1275305 * bsc#1275306 * bsc#1275307 * bsc#1275470 * bsc#1275472 * bsc#1275474 * bsc#1275479 * bsc#1275483 * bsc#1275486 * bsc#1275487 * bsc#1275506 * bsc#1275509 * bsc#1275511 * bsc#1275517 * bsc#1275528 * bsc#1275535 * bsc#1275540 * bsc#1275553 * bsc#1275555 * bsc#1275561 * bsc#1275566 * bsc#1275569 * bsc#1275574 * bsc#1275578 * bsc#1275582 * bsc#1275583 * bsc#1275584 * bsc#1275591 * bsc#1275595 * bsc#1275633 * bsc#1275636 * bsc#1275650 * bsc#1275659 * bsc#1275665 * bsc#1275669 * bsc#1275687 * bsc#1275688 * bsc#1275695 * bsc#1275696 * bsc#1275704 * bsc#1275782 * bsc#1275784 * bsc#1275787 * bsc#1275788 * bsc#1275790 * bsc#1275797 * bsc#1275798 * bsc#1275805 * bsc#1275817 * bsc#1275818 * bsc#1275819 * bsc#1275820 * bsc#1275821 * bsc#1275827 * bsc#1275864 * bsc#1275867 * bsc#1275869 * bsc#1275870 * bsc#1275871 * bsc#1275872 * bsc#1275886 * bsc#1275905 * bsc#1275923 * bsc#1275925 * bsc#1275946 * bsc#1275950 * bsc#1275954 * bsc#1275970 * bsc#1275973 * bsc#1275975 * bsc#1275976 * bsc#1276029 * bsc#1276257 * bsc#1276263 * bsc#1276270 * bsc#1276273 * bsc#1276277 * bsc#1276335 * bsc#1276346 * bsc#1276350 * bsc#1276355 * bsc#1276446 * bsc#1276452 * bsc#1276500 * bsc#1276507 * bsc#1276542 * bsc#1276546 * bsc#1276551 * bsc#1276561 * bsc#1276569 * bsc#1276665 * bsc#1276864 * bsc#1276927 * bsc#1276931 * bsc#1276937 * bsc#1276941 * bsc#1276943 * bsc#1276961 * bsc#1277022 * bsc#1277034 * bsc#1277037 * bsc#1277047 * bsc#1277054 * bsc#1277057 * bsc#1277059 * bsc#1277064 * bsc#1277066 * bsc#1277069 * bsc#1277073 * bsc#1277077 * bsc#1277095 * bsc#1277155 * bsc#1277159 * bsc#1277160 * bsc#1277202 * bsc#1277204 * bsc#1277275 * bsc#1277285 * bsc#1277391 * bsc#1277408 * bsc#1277516 * bsc#1277523 * bsc#1277551 * bsc#1277625 * bsc#1277660 * bsc#1277678 * bsc#1277688 * bsc#1277775 * bsc#1277776 Cross-References: * CVE-2024-44981 * CVE-2024-57841 * CVE-2025-38469 * CVE-2025-39964 * CVE-2025-40022 * CVE-2025-68179 * CVE-2025-68214 * CVE-2025-71075 * CVE-2025-71104 * CVE-2026-23210 * CVE-2026-23230 * CVE-2026-23454 * CVE-2026-31392 * CVE-2026-31418 * CVE-2026-31531 * CVE-2026-31557 * CVE-2026-31663 * CVE-2026-43116 * CVE-2026-43125 * CVE-2026-43163 * CVE-2026-43271 * CVE-2026-43273 * CVE-2026-43278 * CVE-2026-43319 * CVE-2026-43363 * CVE-2026-43416 * CVE-2026-45897 * CVE-2026-45968 * CVE-2026-46070 * CVE-2026-46091 * CVE-2026-46107 * CVE-2026-46115 * CVE-2026-46195 * CVE-2026-52920 * CVE-2026-52925 * CVE-2026-52929 * CVE-2026-52935 * CVE-2026-52939 * CVE-2026-52946 * CVE-2026-52975 * CVE-2026-52977 * CVE-2026-52990 * CVE-2026-52994 * CVE-2026-53001 * CVE-2026-53033 * CVE-2026-53059 * CVE-2026-53076 * CVE-2026-53077 * CVE-2026-53089 * CVE-2026-53091 * CVE-2026-53094 * CVE-2026-53096 * CVE-2026-53110 * CVE-2026-53111 * CVE-2026-53126 * CVE-2026-53154 * CVE-2026-53163 * CVE-2026-53207 * CVE-2026-53219 * CVE-2026-53220 * CVE-2026-53223 * CVE-2026-53228 * CVE-2026-53238 * CVE-2026-53260 * CVE-2026-53264 * CVE-2026-53269 * CVE-2026-53273 * CVE-2026-53309 * CVE-2026-53330 * CVE-2026-53336 * CVE-2026-53337 * CVE-2026-53353 * CVE-2026-53365 * CVE-2026-53366 * CVE-2026-53381 * CVE-2026-53388 * CVE-2026-63801 * CVE-2026-63808 * CVE-2026-63810 * CVE-2026-63823 * CVE-2026-63827 * CVE-2026-63828 * CVE-2026-63860 * CVE-2026-63865 * CVE-2026-63868 * CVE-2026-63879 * CVE-2026-63881 * CVE-2026-63886 * CVE-2026-63887 * CVE-2026-63888 * CVE-2026-63889 * CVE-2026-63891 * CVE-2026-63898 * CVE-2026-63920 * CVE-2026-63925 * CVE-2026-63926 * CVE-2026-63928 * CVE-2026-63944 * CVE-2026-63969 * CVE-2026-63970 * CVE-2026-63972 * CVE-2026-63973 * CVE-2026-63980 * CVE-2026-63985 * CVE-2026-63990 * CVE-2026-63992 * CVE-2026-63999 * CVE-2026-64000 * CVE-2026-64001 * CVE-2026-64002 * CVE-2026-64004 * CVE-2026-64005 * CVE-2026-64006 * CVE-2026-64007 * CVE-2026-64010 * CVE-2026-64011 * CVE-2026-64014 * CVE-2026-64015 * CVE-2026-64018 * CVE-2026-64029 * CVE-2026-64034 * CVE-2026-64039 * CVE-2026-64047 * CVE-2026-64048 * CVE-2026-64051 * CVE-2026-64052 * CVE-2026-64073 * CVE-2026-64083 * CVE-2026-64084 * CVE-2026-64085 * CVE-2026-64086 * CVE-2026-64087 * CVE-2026-64088 * CVE-2026-64097 * CVE-2026-64098 * CVE-2026-64102 * CVE-2026-64109 * CVE-2026-64112 * CVE-2026-64113 * CVE-2026-64114 * CVE-2026-64115 * CVE-2026-64118 * CVE-2026-64121 * CVE-2026-64125 * CVE-2026-64126 * CVE-2026-64128 * CVE-2026-64131 * CVE-2026-64133 * CVE-2026-64135 * CVE-2026-64137 * CVE-2026-64148 * CVE-2026-64155 * CVE-2026-64164 * CVE-2026-64166 * CVE-2026-64168 * CVE-2026-64178 * CVE-2026-64185 * CVE-2026-64188 * CVE-2026-64190 * CVE-2026-64192 * CVE-2026-64214 * CVE-2026-64217 * CVE-2026-64218 * CVE-2026-64219 * CVE-2026-64222 * CVE-2026-64225 * CVE-2026-64237 * CVE-2026-64243 * CVE-2026-64245 * CVE-2026-64246 * CVE-2026-64247 * CVE-2026-64249 * CVE-2026-64257 * CVE-2026-64266 * CVE-2026-64268 * CVE-2026-64271 * CVE-2026-64273 * CVE-2026-64274 * CVE-2026-64275 * CVE-2026-64276 * CVE-2026-64277 * CVE-2026-64286 * CVE-2026-64287 * CVE-2026-64294 * CVE-2026-64296 * CVE-2026-64303 * CVE-2026-64304 * CVE-2026-64305 * CVE-2026-64306 * CVE-2026-64312 * CVE-2026-64313 * CVE-2026-64315 * CVE-2026-64316 * CVE-2026-64317 * CVE-2026-64322 * CVE-2026-64323 * CVE-2026-64329 * CVE-2026-64331 * CVE-2026-64332 * CVE-2026-64333 * CVE-2026-64334 * CVE-2026-64335 * CVE-2026-64337 * CVE-2026-64338 * CVE-2026-64340 * CVE-2026-64341 * CVE-2026-64342 * CVE-2026-64343 * CVE-2026-64344 * CVE-2026-64346 * CVE-2026-64348 * CVE-2026-64350 * CVE-2026-64351 * CVE-2026-64355 * CVE-2026-64358 * CVE-2026-64362 * CVE-2026-64365 * CVE-2026-64375 * CVE-2026-64376 * CVE-2026-64378 * CVE-2026-64381 * CVE-2026-64382 * CVE-2026-64383 * CVE-2026-64384 * CVE-2026-64385 * CVE-2026-64386 * CVE-2026-64387 * CVE-2026-64388 * CVE-2026-64401 * CVE-2026-64403 * CVE-2026-64406 * CVE-2026-64408 * CVE-2026-64409 * CVE-2026-64411 * CVE-2026-64412 * CVE-2026-64420 * CVE-2026-64421 * CVE-2026-64423 * CVE-2026-64427 * CVE-2026-64429 * CVE-2026-64433 * CVE-2026-64434 * CVE-2026-64436 * CVE-2026-64440 * CVE-2026-64442 * CVE-2026-64443 * CVE-2026-64444 * CVE-2026-64445 * CVE-2026-64448 * CVE-2026-64450 * CVE-2026-64454 * CVE-2026-64455 * CVE-2026-64463 * CVE-2026-64470 * CVE-2026-64471 * CVE-2026-64472 * CVE-2026-64478 * CVE-2026-64479 * CVE-2026-64480 * CVE-2026-64481 * CVE-2026-64482 * CVE-2026-64483 * CVE-2026-64484 * CVE-2026-64486 * CVE-2026-64487 * CVE-2026-64489 * CVE-2026-64494 * CVE-2026-64495 * CVE-2026-64496 * CVE-2026-64497 * CVE-2026-64500 * CVE-2026-64503 * CVE-2026-64504 * CVE-2026-64505 * CVE-2026-64511 * CVE-2026-64512 * CVE-2026-64513 * CVE-2026-64524 * CVE-2026-64527 * CVE-2026-64536 * CVE-2026-64537 * CVE-2026-64538 * CVE-2026-64539 * CVE-2026-64540 * CVE-2026-64541 * CVE-2026-64543 * CVE-2026-64544 * CVE-2026-64545 * CVE-2026-64546 * CVE-2026-64547 * CVE-2026-64548 * CVE-2026-64549 * CVE-2026-64551 * CVE-2026-64552 * CVE-2026-64553 * CVE-2026-64554 * CVE-2026-64562 * CVE-2026-64563 * CVE-2026-64565 * CVE-2026-64567 * CVE-2026-64571 * CVE-2026-64572 * CVE-2026-64573 * CVE-2026-64574 * CVE-2026-64576 * CVE-2026-64577 * CVE-2026-64581 * CVE-2026-64582 * CVE-2026-64583 * CVE-2026-64584 * CVE-2026-64585 * CVE-2026-64593 * CVE-2026-64597 * CVE-2026-64598 * CVE-2026-64599 * CVE-2026-64602 * CVE-2026-64604 * CVE-2026-68081 * CVE-2026-68082 * CVE-2026-68085 * CVE-2026-68086 * CVE-2026-68088 * CVE-2026-68091 * CVE-2026-68093 * CVE-2026-68102 * CVE-2026-68104 * CVE-2026-68106 * CVE-2026-68107 * CVE-2026-68108 * CVE-2026-68110 * CVE-2026-68111 * CVE-2026-68112 * CVE-2026-68115 * CVE-2026-68116 * CVE-2026-68117 * CVE-2026-68121 * CVE-2026-68123 * CVE-2026-68125 * CVE-2026-68126 * CVE-2026-68127 * CVE-2026-68129 * CVE-2026-68132 * CVE-2026-68133 * CVE-2026-68136 * CVE-2026-68137 * CVE-2026-68138 * CVE-2026-68139 * CVE-2026-68142 * CVE-2026-68143 * CVE-2026-68145 * CVE-2026-68149 * CVE-2026-68153 * CVE-2026-68154 * CVE-2026-68155 * CVE-2026-68156 * CVE-2026-68157 * CVE-2026-68158 * CVE-2026-68159 * CVE-2026-68160 * CVE-2026-68161 * CVE-2026-68162 * CVE-2026-68166 * CVE-2026-68180 * CVE-2026-68181 * CVE-2026-68182 * CVE-2026-68184 * CVE-2026-68188 * CVE-2026-68189 * CVE-2026-68192 * CVE-2026-68193 * CVE-2026-68194 * CVE-2026-68195 * CVE-2026-68196 * CVE-2026-68197 * CVE-2026-68199 * CVE-2026-68202 * CVE-2026-68204 * CVE-2026-68205 * CVE-2026-68206 * CVE-2026-68207 * CVE-2026-68209 * CVE-2026-68210 * CVE-2026-68212 * CVE-2026-68213 * CVE-2026-68214 * CVE-2026-68215 * CVE-2026-68216 * CVE-2026-68217 * CVE-2026-68218 * CVE-2026-68219 * CVE-2026-68220 * CVE-2026-68222 * CVE-2026-68223 * CVE-2026-68226 * CVE-2026-68227 * CVE-2026-68229 * CVE-2026-68231 * CVE-2026-68234 * CVE-2026-68236 * CVE-2026-68238 * CVE-2026-68243 * CVE-2026-68244 * CVE-2026-68246 * CVE-2026-68247 * CVE-2026-68248 * CVE-2026-68249 * CVE-2026-68250 * CVE-2026-68251 * CVE-2026-68254 * CVE-2026-68255 * CVE-2026-68256 * CVE-2026-68259 * CVE-2026-68269 * CVE-2026-68271 * CVE-2026-68272 * CVE-2026-68277 * CVE-2026-68278 * CVE-2026-68279 * CVE-2026-68280 * CVE-2026-68284 * CVE-2026-68286 * CVE-2026-68288 * CVE-2026-68289 * CVE-2026-68293 * CVE-2026-68297 * CVE-2026-68299 * CVE-2026-68300 * CVE-2026-68303 * CVE-2026-68304 * CVE-2026-68306 * CVE-2026-68308 * CVE-2026-68309 * CVE-2026-68310 * CVE-2026-68312 * CVE-2026-68313 * CVE-2026-68315 * CVE-2026-68320 * CVE-2026-68322 * CVE-2026-68324 * CVE-2026-68325 * CVE-2026-68326 * CVE-2026-68327 * CVE-2026-68328 * CVE-2026-68329 * CVE-2026-68331 * CVE-2026-68333 * CVE-2026-68335 * CVE-2026-68336 * CVE-2026-68339 * CVE-2026-68340 * CVE-2026-68343 * CVE-2026-68346 * CVE-2026-68348 * CVE-2026-68349 * CVE-2026-68350 * CVE-2026-68351 * CVE-2026-68352 * CVE-2026-68353 * CVE-2026-68354 * CVE-2026-68355 * CVE-2026-68357 * CVE-2026-68359 * CVE-2026-68360 * CVE-2026-68361 * CVE-2026-68362 * CVE-2026-68363 * CVE-2026-68365 * CVE-2026-68366 * CVE-2026-68368 * CVE-2026-68369 * CVE-2026-68370 * CVE-2026-68372 * CVE-2026-68373 * CVE-2026-68377 * CVE-2026-68386 * CVE-2026-68391 * CVE-2026-68392 * CVE-2026-68397 * CVE-2026-68398 * CVE-2026-68399 * CVE-2026-68402 * CVE-2026-68403 * CVE-2026-68405 * CVE-2026-68406 * CVE-2026-68407 * CVE-2026-68408 * CVE-2026-68410 * CVE-2026-68413 * CVE-2026-68414 * CVE-2026-68417 * CVE-2026-68418 * CVE-2026-68419 * CVE-2026-68422 * CVE-2026-68425 * CVE-2026-68426 * CVE-2026-68427 * CVE-2026-68428 * CVE-2026-68429 * CVE-2026-68430 * CVE-2026-68432 * CVE-2026-68433 * CVE-2026-68434 * CVE-2026-68444 * CVE-2026-68445 * CVE-2026-68446 * CVE-2026-68450 * CVE-2026-68470 * CVE-2026-68480 * CVE-2026-72020 * CVE-2026-72035 * CVE-2026-72036 * CVE-2026-72069 * CVE-2026-72072 * CVE-2026-72083 * CVE-2026-72084 * CVE-2026-72123 * CVE-2026-72132 * CVE-2026-72221 * CVE-2026-72222 * CVE-2026-72251 * CVE-2026-72254 * CVE-2026-72262 * CVE-2026-72288 * CVE-2026-72289 * CVE-2026-72296 * CVE-2026-72307 * CVE-2026-72308 * CVE-2026-72317 * CVE-2026-72341 * CVE-2026-72342 * CVE-2026-72343 * CVE-2026-72389 * CVE-2026-72463 * CVE-2026-72464 * CVE-2026-72466 * CVE-2026-72467 * CVE-2026-72469 * CVE-2026-72473 * CVE-2026-72494 * CVE-2026-72495 * CVE-2026-72496 * CVE-2026-72499 * CVE-2026-72501 * CVE-2026-72502 * CVE-2026-74269 * CVE-2026-74296 * CVE-2026-74297 * CVE-2026-74318 * CVE-2026-74321 * CVE-2026-74334 * CVE-2026-74345 * CVE-2026-74394 * CVE-2026-74395 * CVE-2026-74454 * CVE-2026-74474 * CVE-2026-74481 * CVE-2026-74482 * CVE-2026-74488 * CVE-2026-74495 * CVE-2026-74496 * CVE-2026-74509 * CVE-2026-74510 * CVE-2026-74512 * CVE-2026-74516 * CVE-2026-74518 * CVE-2026-74527 * CVE-2026-74537 * CVE-2026-74548 * CVE-2026-74550 * CVE-2026-74556 * CVE-2026-74563 * CVE-2026-74566 * CVE-2026-74567 * CVE-2026-74571 * CVE-2026-74581 * CVE-2026-74582 * CVE-2026-74584 * CVE-2026-74610 * CVE-2026-74669 * CVE-2026-74692 * CVE-2026-74694 * CVE-2026-74695 * CVE-2026-74717 * CVE-2026-74722 * CVE-2026-80529 * CVE-2026-80534 * CVE-2026-80590 * CVE-2026-80654 CVSS scores: * CVE-2024-44981 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L * CVE-2024-44981 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2024-44981 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-57841 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-38469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39964 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-39964 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-39964 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-39964 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40022 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-40022 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-68179 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68179 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68214 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71104 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2025-71104 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-71104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23210 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23230 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23230 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23230 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-23230 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23454 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23454 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23454 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31392 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-31392 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-31392 ( NVD ): 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L * CVE-2026-31418 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31418 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31531 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31557 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31663 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31663 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43116 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43125 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43163 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43271 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43271 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43271 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43319 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43319 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45897 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45897 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45897 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46070 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46070 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46091 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46091 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46091 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46107 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46107 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46107 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46115 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46115 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46195 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46195 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52920 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-52920 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-52925 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52925 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52925 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52939 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52939 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52977 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52977 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52990 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53033 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53059 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53059 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53059 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53076 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53076 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53077 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53077 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53077 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53089 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53089 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53091 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53091 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53091 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53091 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-53094 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53094 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53096 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53096 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53110 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53111 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53111 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53111 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53207 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53228 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53228 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53238 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53238 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53269 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53269 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53269 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53309 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53309 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53309 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53330 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53330 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53336 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53336 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53353 ( SUSE ): 0.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53353 ( SUSE ): 0.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N * CVE-2026-53353 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53365 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53365 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53365 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53381 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63801 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63801 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63801 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63808 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63808 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-63808 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63810 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63810 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63823 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63823 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63823 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63827 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63828 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63828 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63828 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-63860 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63860 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63860 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63865 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63865 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63865 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-63868 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63868 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63879 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63879 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63879 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63881 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63886 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63886 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63886 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63887 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63887 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63887 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63888 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63888 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63888 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63889 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63889 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63889 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63891 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63891 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63898 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63898 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63920 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63920 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63920 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63925 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63925 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63925 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-63926 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63926 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63926 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63928 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63928 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63944 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63944 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63969 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63969 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63970 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63970 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63972 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63972 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63972 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63973 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63973 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63980 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63985 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63985 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63985 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63990 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63990 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63992 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63992 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63992 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63999 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63999 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64000 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64000 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64000 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64001 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64001 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64002 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64002 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64002 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64004 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64004 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64005 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64005 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64005 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64006 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-64006 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-64007 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64007 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64007 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64010 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64011 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64014 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64014 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64015 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64015 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64018 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-64018 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-64018 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64029 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64029 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64029 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64034 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64039 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64039 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64039 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64047 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64047 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64048 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64048 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64048 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64051 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64051 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64051 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64052 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64052 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64052 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64073 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64073 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64073 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64083 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64083 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64083 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64084 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64084 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64084 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64085 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64085 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64085 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64086 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64086 ( SUSE ): 5.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64086 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64087 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64087 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64087 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64088 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64088 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64088 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64097 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64097 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64097 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64098 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64102 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-64102 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-64102 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64113 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64113 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64114 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64115 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64118 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64118 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64118 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64121 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64121 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64121 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64125 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64126 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64126 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L * CVE-2026-64126 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-64128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64128 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64135 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64137 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64137 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64137 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64148 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64148 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64148 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64155 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64164 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64166 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64178 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64178 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64185 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64185 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64188 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64188 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64188 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64190 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64190 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64190 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64217 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64217 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64217 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64218 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64219 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64222 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64222 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64222 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64225 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64225 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64225 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64237 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64237 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64245 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64246 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64246 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64246 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64247 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64247 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-64249 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64249 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64257 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64257 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-64257 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64266 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64266 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64268 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64271 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64271 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64271 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64273 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64275 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64275 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64277 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64286 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64286 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64287 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64303 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64303 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64303 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64304 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64305 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64305 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64306 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64313 ( SUSE ): 7.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-64313 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64313 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64315 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64316 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64316 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64317 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64317 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64317 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64322 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64322 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64322 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64323 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64323 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64329 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64329 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64329 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64331 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64331 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64333 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64333 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64334 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64334 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64334 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64335 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64335 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64335 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64337 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64337 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64338 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64340 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64340 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64340 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64341 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64342 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64343 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64344 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64346 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64348 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64348 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64348 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64350 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64350 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64350 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64351 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64351 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64351 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64355 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64355 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64358 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64358 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64365 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64375 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64375 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64376 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64376 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64376 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64381 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64381 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64382 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64382 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64383 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64383 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64384 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64385 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64386 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64387 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64388 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64388 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-64388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64401 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64401 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64403 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64403 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64403 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64406 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64408 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64409 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64409 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64411 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64411 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64411 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64412 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64412 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64412 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64420 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64421 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64421 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64427 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64427 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64434 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64436 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64436 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64440 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64440 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64440 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64442 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64442 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64443 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64443 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64444 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64444 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64444 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64445 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64448 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64448 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64450 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64454 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64471 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64478 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64478 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64479 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64480 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64481 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64481 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64482 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64482 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64483 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64484 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64484 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64486 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64487 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64489 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64497 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64500 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64503 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64504 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64505 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64511 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64511 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64512 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64513 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64527 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64537 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64537 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64538 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64540 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64540 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64540 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64541 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64541 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64541 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64544 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64544 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64545 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64547 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64547 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64547 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64548 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64548 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64549 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64551 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64551 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64552 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64552 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64552 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64553 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64562 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64562 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64563 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64563 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64565 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64565 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64567 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64567 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64567 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64571 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64571 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64572 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64572 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64573 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64573 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64574 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64576 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64576 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64576 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64577 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64577 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64577 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64581 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64581 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64581 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64582 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64583 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64583 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64584 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64585 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64593 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64593 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64598 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64598 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64599 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64599 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64602 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64604 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68081 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68081 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68082 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68082 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68082 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68085 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68085 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68085 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68086 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-68086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-68088 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68088 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68091 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68091 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68091 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68093 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-68093 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68102 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68102 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68104 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68106 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68106 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68106 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68107 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68107 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68107 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68108 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68108 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68108 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68110 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68110 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68111 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68111 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68115 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68115 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68116 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68116 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-68116 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68117 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68117 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68121 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68121 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68123 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68123 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68123 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68125 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68125 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68125 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68126 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68126 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68127 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68127 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68127 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68129 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68129 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68129 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68132 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68132 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68133 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68133 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68136 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68136 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68137 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68139 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68139 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68142 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68142 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-68142 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68143 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68143 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68143 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68145 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68145 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68145 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68149 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68149 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68149 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-68153 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68153 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68153 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68154 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68154 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68154 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68155 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68155 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68155 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68156 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68156 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68156 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68157 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68157 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68157 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68158 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68158 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68158 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68159 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68159 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68159 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68160 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68160 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68160 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68161 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68161 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68161 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68162 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68166 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68166 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68180 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68182 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68184 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68184 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68188 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68192 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68192 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68197 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68202 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68204 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68207 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68210 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68210 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68212 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68217 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68218 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68218 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68219 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68219 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68220 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68220 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68222 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68223 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68223 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68226 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68226 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68227 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68227 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68229 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68229 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-68229 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68231 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68231 ( SUSE ): 2.1 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68234 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68236 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68236 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68236 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68238 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68238 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68243 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68244 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68246 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68246 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68247 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68247 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68248 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68249 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68250 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68250 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68251 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68251 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68256 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68259 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68259 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68269 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68271 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68272 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68278 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68278 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68279 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68279 ( SUSE ): 2.4 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68280 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68280 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68284 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68284 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68286 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68286 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68288 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68288 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68289 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68293 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68293 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68299 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68308 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68309 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68310 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68312 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68313 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-68322 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68324 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68325 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68327 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68327 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68328 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68333 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68343 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68349 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68350 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68351 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68353 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68353 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68354 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68355 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68357 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68359 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68360 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68361 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68365 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68365 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-68366 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68368 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68369 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68370 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68372 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68377 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68377 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68386 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68391 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68391 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68392 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68392 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68402 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68402 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68403 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68405 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68406 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68407 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68408 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68410 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68413 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68414 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68414 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68422 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68425 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68425 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68426 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68426 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68427 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68427 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68427 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68428 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68430 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68430 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68433 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-68434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68444 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68445 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68445 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68445 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68446 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68446 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68470 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68470 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68470 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68480 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-72020 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72020 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72020 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72035 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72036 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72069 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72083 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72084 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72123 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72132 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72132 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72221 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72221 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72221 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72222 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72251 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72251 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72251 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72254 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72262 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72262 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72288 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72289 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72289 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72289 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72296 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72296 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72296 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-72307 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72307 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72308 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72308 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72317 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72317 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72317 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72341 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72342 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72342 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72343 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72343 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72389 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72463 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72463 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72464 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72464 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72467 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72473 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-72473 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72494 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72495 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72496 ( NVD ): 9.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H * CVE-2026-72499 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72499 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72501 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74269 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74269 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74318 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74345 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74345 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74345 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74394 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74395 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74395 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74454 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74454 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-74454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74474 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74474 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74481 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74482 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74482 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74488 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74488 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74495 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74495 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74509 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74509 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74516 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-74516 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74518 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74518 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74527 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-74527 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74537 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74537 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74550 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74550 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74556 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-74556 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74563 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74566 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-74567 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74567 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74571 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74581 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74581 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74582 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74584 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-74584 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-74584 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-74610 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-74610 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74610 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74692 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74694 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74694 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74695 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74695 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74717 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74717 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74722 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80534 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80534 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80590 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-80654 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80654 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro Extras 6.0 An update that solves 588 vulnerabilities and has 23 fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 kernel was updated to fix various security issues: The following security issues were fixed: * CVE-2024-57841: net: fix memory leak in tcp_conn_request() (bsc#1269731). * CVE-2025-68214: timers: Fix NULL function pointer race in timer_shutdown_sync() (bsc#1255225). * CVE-2025-71075: scsi: aic94xx: fix use-after-free in device removal path (bsc#1256629). * CVE-2026-31392: smb: client: fix krb5 mount with username option (bsc#1261788). * CVE-2026-31418: netfilter: ipset: drop logically empty buckets in mtype_del (bsc#1262073). * CVE-2026-31531: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() (bsc#1263004). * CVE-2026-31557: nvmet: move async event work off nvmet-wq (bsc#1263061). * CVE-2026-31663: xfrm: hold device only for the asynchronous decryption (bsc#1263133). * CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack (bsc#1264619). * CVE-2026-43125: dlm: validate length in dlm_search_rsb_tree (bsc#1264541). * CVE-2026-43163: md/bitmap: fix GPF in write_page caused by resize race (bsc#1264335). * CVE-2026-43271: md-cluster: fix NULL pointer dereference in process_metadata_update (bsc#1264587). * CVE-2026-43273: ceph: supply snapshot context in ceph_zero_partial_object() (bsc#1264446). * CVE-2026-43278: dm: clear cloned request bio pointer when last clone bio completes (bsc#1264584). * CVE-2026-43319: spi: spidev: fix lock inversion between spi_lock and buf_lock (bsc#1264788). * CVE-2026-43363: x86/apic: Disable x2apic on resume if the kernel expects so (bsc#1265068). * CVE-2026-43416: powerpc, perf: Check that current->mm is alive before getting user callchain (bsc#1265121). * CVE-2026-45897: bpf: Fix UAF in sock clone early bailouts (bsc#1266897). * CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). * CVE-2026-46070: md/raid5: validate payload size before accessing journal metadata (bsc#1267501). * CVE-2026-46091: media: rc: igorplugusb: heed coherency rules (bsc#1267238). * CVE-2026-46107: dm-thin: fix metadata refcount underflow (bsc#1267612). * CVE-2026-46115: block: add pgmap check to biovec_phys_mergeable (bsc#1266874). * CVE-2026-46195: smb: client: validate dacloffset before building DACL pointers (bsc#1266860). * CVE-2026-52920: netfilter: xt_policy: fix strict mode inbound policy matching (bsc#1269013). * CVE-2026-52925: vrf: Fix a potential NPD when removing a port from a VRF (bsc#1268987). * CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). * CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send (bsc#1268979). * CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion (bsc#1268972). * CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (bsc#1269113). * CVE-2026-52975: bonding: 802.3ad replace MAC_ADDRESS_EQUAL with __agg_has_partner (bsc#1269234). * CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). * CVE-2026-52990: fsnotify: fix inode reference leak in fsnotify_recalc_mask() (bsc#1269108). * CVE-2026-52994: vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting (bsc#1269126). * CVE-2026-53001: netfilter: xtables: restrict several matches to inet family (bsc#1269114). * CVE-2026-53033: bpf, sockmap: Take state lock for af_unix iter (bsc#1269388). * CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). * CVE-2026-53076: bpf: Fix OOB in pcpu_init_value (bsc#1269695). * CVE-2026-53077: net/rds: Restrict use of RDS/IB to the initial network namespace (bsc#1269412). * CVE-2026-53089: bpf: Fix use-after-free in offloaded map/prog info fill (bsc#1269783). * CVE-2026-53091: net: account for encap headers in qdisc pkt len (bsc#1269530). * CVE-2026-53094: bpf: Fix stale offload->prog pointer after constant blinding (bsc#1269965). * CVE-2026-53096: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (bsc#1269969). * CVE-2026-53110: selftests/bpf: Add ASSERT_OK_FD macro (bsc#1269985). * CVE-2026-53111: bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap (bsc#1269167). * CVE-2026-53126: blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() (bsc#1269635). * CVE-2026-53154: mm/hugetlb: restore reservation on error in hugetlb folio copy paths (bsc#1269665). * CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). * CVE-2026-53207: mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison (bsc#1269590). * CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers (bsc#1269686). * CVE-2026-53220: netfilter: revalidate bridge ports (bsc#1269381). * CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs (bsc#1269301). * CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads (bsc#1269256). * CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths (bsc#1269774). * CVE-2026-53260: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req() (bsc#1269731) * CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). * CVE-2026-53269: netfilter: synproxy: add mutex to guard hook reference counting (bsc#1269579). * CVE-2026-53273: tee: optee: prevent use-after-free when the client exits before the supplicant (bsc#1269713). * CVE-2026-53309: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (bsc#1269815). * CVE-2026-53330: drm/amd/display: Fix out-of-bounds read in (bsc#1270090). * CVE-2026-53336: nvmem: layouts: onie-tlv: fix hang on unknown types (bsc#1270108). * CVE-2026-53337: net: bonding: fix NULL pointer dereference in bond_do_ioctl() (bsc#1270251). * CVE-2026-53353: hsr: Remove WARN_ONCE() in hsr_addr_is_self() (bsc#1270111). * CVE-2026-53365: vsock/virtio: fix zerocopy completion for multi-skb sends (bsc#1271365). * CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). * CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). * CVE-2026-63808: exfat: fix potential use-after-free in exfat_find_dir_entry() (bsc#1272260). * CVE-2026-63810: block: Avoid mounting the bdev pseudo-filesystem in userspace (bsc#1272297). * CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). * CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179). * CVE-2026-63828: apparmor: mediate the implicit connect of TCP fast open sendmsg (bsc#1272175). * CVE-2026-63860: RDMA/core: Prefer NLA_NUL_STRING (bsc#1272429). * CVE-2026-63865: bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (bsc#1272486). * CVE-2026-63868: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (bsc#1272497). * CVE-2026-63879: drm/amdgpu: fix amdgpu_hmm_range_get_pages (bsc#1272569). * CVE-2026-63881: drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger (bsc#1272571). * CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). * CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). * CVE-2026-63889: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (bsc#1272423). * CVE-2026-63891: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (bsc#1272641). * CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). * CVE-2026-63925: macsec: fix replay protection at XPN lower-PN wrap (bsc#1273008). * CVE-2026-63926: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (bsc#1273019). * CVE-2026-63944: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (bsc#1272662). * CVE-2026-63969: ipv6: fix possible infinite loop in rt6_fill_node() (bsc#1272484). * CVE-2026-63970: vsock/virtio: bind uarg before filling zerocopy skb (bsc#1272673). * CVE-2026-63980: net/handshake: Use spin_lock_bh for hn_lock (bsc#1273028). * CVE-2026-63985: ethtool: eeprom: add more safeties to EEPROM Netlink fallback (bsc#1272963). * CVE-2026-63990: bonding: refuse to enslave CAN devices (bsc#1273027). * CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). * CVE-2026-63999: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure (bsc#1273038). * CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273030). * CVE-2026-64001: ALSA: pcm: oss: Fix setup list UAF on proc write error (bsc#1273734). * CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). * CVE-2026-64004: net/iucv: fix locking in .getsockopt (bsc#1273804). * CVE-2026-64005: net/smc: Do not re-initialize smc hashtables (bsc#1273831). * CVE-2026-64006: netfilter: nf_tables: fix dst corruption in same register operation (bsc#1273834). * CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). * CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882). * CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891). * CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762). * CVE-2026-64029: ALSA: seq: Serialize UMP output teardown with event_input (bsc#1273766). * CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). * CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). * CVE-2026-64052: block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() (bsc#1272983). * CVE-2026-64073: irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT (bsc#1273490). * CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488). * CVE-2026-64102: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (bsc#1272516). * CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748). * CVE-2026-64112: rbd: eliminate a race in lock_dwork draining on unmap (bsc#1273741). * CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning (bsc#1272262). * CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). * CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). * CVE-2026-64118: qed: fix double free in qed_cxt_tables_alloc() (bsc#1273749). * CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273743). * CVE-2026-64125: net: bcmgenet: keep RBUF EEE/PM disabled (bsc#1272346). * CVE-2026-64131: mm/memory: fix spurious warning when unmapping device- private/exclusive pages (bsc#1274063). * CVE-2026-64148: pds_core: check health in devcmd wait (bsc#1273956). * CVE-2026-64164: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (bsc#1273957). * CVE-2026-64185: sysfs: don't remove existing directory on update failure (bsc#1272200). * CVE-2026-64188: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (bsc#1272150). * CVE-2026-64190: net: team: fix NULL pointer dereference in team_xmit during mode change (bsc#1272210). * CVE-2026-64192: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (bsc#1272213). * CVE-2026-64214: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() (bsc#1272799). * CVE-2026-64217: netfs: Fix overrun check in netfs_extract_user_iter() (bsc#1272798). * CVE-2026-64222: octeontx2-pf: avoid double free of pool->stack on AQ init failure (bsc#1272788). * CVE-2026-64225: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (bsc#1272786). * CVE-2026-64245: fbdev: modedb: fix a possible UAF in fb_find_mode() (bsc#1273905). * CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). * CVE-2026-64286: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (bsc#1274058). * CVE-2026-64287: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (bsc#1273325). * CVE-2026-64294: mm: do file ownership checks with the proper mount idmap (bsc#1273525). * CVE-2026-64296: exfat: bound uniname advance in exfat_find_dir_entry() (bsc#1273975). * CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944). * CVE-2026-64312: crypto: pcrypt - restore callback for non-parallel fallback (bsc#1273968). * CVE-2026-64315: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1274028). * CVE-2026-64316: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1273598). * CVE-2026-64317: isofs: bound Rock Ridge symlink components to the SL record (bsc#1273936). * CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count (bsc#1273958). * CVE-2026-64323: udf: validate VAT header length against the VAT inode size (bsc#1273305). * CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). * CVE-2026-64375: proc: protect ptrace_may_access() with exec_update_lock (FD links) (bsc#1273868). * CVE-2026-64378: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() (bsc#1273603). * CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard() (bsc#1273860). * CVE-2026-64382: smb: client: fix double-free in SMB2_open() replay (bsc#1273291). * CVE-2026-64383: smb: client: fix double-free in SMB2_flush() replay (bsc#1273426). * CVE-2026-64384: smb: client: fix change notify replay double-free (bsc#1274541). * CVE-2026-64385: smb: client: fix double-free in SMB2_ioctl() replay (bsc#1274539). * CVE-2026-64386: smb: client: fix query_info() replay double-free (bsc#1274543). * CVE-2026-64387: smb: client: fix query directory replay double-free (bsc#1274545). * CVE-2026-64388: smb/client: fix chown/chgrp with SMB3 POSIX Extensions (bsc#1274061). * CVE-2026-64411: netfilter: ebtables: terminate table name before find_table_lock() (bsc#1274077). * CVE-2026-64412: netfilter: ebtables: module names must be null-terminated (bsc#1273780). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). * CVE-2026-64434: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (bsc#1273880). * CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states (bsc#1274277). * CVE-2026-64448: smb: client: restrict implied bcc[0] exemption to responses without data area (bsc#1273982). * CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). * CVE-2026-64463: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres (bsc#1273273). * CVE-2026-64472: vfio/mlx5: Fix racy bitfields and tighten struct layout (bsc#1274075). * CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547). * CVE-2026-64537: bridge: cfm: reject invalid CCM interval at configuration time (bsc#1273289). * CVE-2026-64538: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change() (bsc#1273335). * CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). * CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). * CVE-2026-64545: net, bpf: check master for NULL in xdp_master_redirect() (bsc#1273318). * CVE-2026-64548: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (bsc#1273337). * CVE-2026-64551: sctp: validate STALE_COOKIE cause length before reading staleness (bsc#1273813). * CVE-2026-64552: virtio-net: fix len check in receive_big() (bsc#1273323). * CVE-2026-64553: net: psample: fix info leak in PSAMPLE_ATTR_DATA (bsc#1273336). * CVE-2026-64554: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (bsc#1273340). * CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930). * CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). * CVE-2026-64567: btrfs: reject free space cache with more entries than pages (bsc#1274006). * CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). * CVE-2026-64576: nexthop: initialize extack in nh_res_bucket_migrate() (bsc#1274030). * CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031). * CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). * CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (bsc#1274040). * CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497). * CVE-2026-64597: smb: client: fix double-free in SMB2_close() replay (bsc#1274297). * CVE-2026-64598: smb/client: Fix error code in smb2_aead_req_alloc() (bsc#1274298). * CVE-2026-68081: KVM: nVMX: Add helper to put (unmap) vmcs12 pages (bsc#1274580). * CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers() (bsc#1274581). * CVE-2026-68086: mm/khugepaged: write all dirty file folios when collapsing (bsc#1274713). * CVE-2026-68116: vxlan: mdb: Fix source list corruption on a failed replace (bsc#1274876). * CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (bsc#1274881). * CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). * CVE-2026-68123: openvswitch: fix GSO userspace truncation underflow (bsc#1275169). * CVE-2026-68127: ila: reload IPv6 header after pskb_may_pull in checksum adjust (bsc#1275237). * CVE-2026-68129: gve: fix Rx queue stall on alloc failure (bsc#1275517). * CVE-2026-68132: super: fix emergency thaw deadlock on frozen block devices (bsc#1275553). * CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). * CVE-2026-68139: net/mlx5e: Use sender devcom for MPV master-up (bsc#1275578). * CVE-2026-68142: geneve: require CAP_NET_ADMIN in the device netns for changelink (bsc#1275582). * CVE-2026-68143: net: slip: serialize receive against buffer reallocation (bsc#1275583). * CVE-2026-68145: iomap: fix out-of-bounds bitmap_set() with zero-length range (bsc#1275584). * CVE-2026-68149: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (bsc#1275294). * CVE-2026-68153: libceph: remove debugfs files before client teardown (bsc#1275301). * CVE-2026-68154: libceph: reject zero bucket types in crush_decode (bsc#1275303). * CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). * CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after authorizer update (bsc#1275305). * CVE-2026-68157: libceph: guard missing CRUSH type name lookup (bsc#1275306). * CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). * CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). * CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472). * CVE-2026-68161: sctp: close UDP tunnel sockets during netns teardown (bsc#1274892). * CVE-2026-68166: userfaultfd: prevent registration of special VMAs (bsc#1274930). * CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). * CVE-2026-68205: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (bsc#1274934). * CVE-2026-68238: drm/amdgpu: Release VFCT ACPI table reference (bsc#1275704). * CVE-2026-68247: drm/i915/bios: range check LFP Data Block panel_type2 (bsc#1275817). * CVE-2026-68254: drm/i915/vrr: require valid min/max vfreq for VRR (bsc#1275150). * CVE-2026-68284: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (bsc#1275970). * CVE-2026-68286: drop_monitor: perform u64_stats updates under IRQ-disabled section (bsc#1275973). * CVE-2026-68288: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (bsc#1275975). * CVE-2026-68289: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (bsc#1275976). * CVE-2026-68293: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (bsc#1275091). * CVE-2026-68297: tipc: fix u16 MTU truncation in media and bearer MTU validation (bsc#1275040). * CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (bsc#1275088). * CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL (bsc#1275083). * CVE-2026-68312: cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths (bsc#1274663). * CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit (bsc#1274665). * CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq() (bsc#1274662). * CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (bsc#1274659). * CVE-2026-68322: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (bsc#1274656). * CVE-2026-68324: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (bsc#1274649). * CVE-2026-68325: iommu/amd: Bound the early ACPI HID map (bsc#1274651). * CVE-2026-68328: nfp: Check resource mutex allocation (bsc#1274646). * CVE-2026-68329: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (bsc#1274645). * CVE-2026-68331: dpaa2-eth: put MAC endpoint device on disconnect (bsc#1274642). * CVE-2026-68333: dpaa2-switch: put MAC endpoint device on disconnect (bsc#1274644). * CVE-2026-68335: rds: drop incoming messages that cross network namespace boundaries (bsc#1274640). * CVE-2026-68336: bonding: fix devconf_all NULL dereference when IPv6 is disabled (bsc#1274639). * CVE-2026-68343: smb: client: validate DFS referral PathConsumed (bsc#1274629). * CVE-2026-68377: net/sched: act_tunnel_key: Defer dst_release to RCU callback (bsc#1274831). * CVE-2026-68386: bpf, sockmap: Reject unhashed UDP sockets on sockmap update (bsc#1274814). * CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). * CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). * CVE-2026-68408: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (bsc#1274709). * CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). * CVE-2026-68418: RDMA/irdma: Prevent user-triggered null deref on QP create (bsc#1274690). * CVE-2026-68419: RDMA/irdma: Prevent rereg_mr for non-mem regions (bsc#1274698). * CVE-2026-68422: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (bsc#1274706). * CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1274700). * CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). * CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink (bsc#1274800). * CVE-2026-68433: libceph: bound get_version reply decode to front len (bsc#1274801). * CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert (bsc#1274834). * CVE-2026-68470: wifi: cfg80211/mac80211: correctly parse S1G beacon optional elements (bsc#1276500). * CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). * CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). * CVE-2026-72035: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1276961). * CVE-2026-72036: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1277034). * CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). * CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155). * CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). * CVE-2026-72084: scsi: target: Bound PR-OUT TransportID parsing to the received buffer (bsc#1275540). * CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523). * CVE-2026-72132: NFS: Charge unstable writes by request size, not folio size (bsc#1277551). * CVE-2026-72221: sunrpc: wait for in-flight TLS handshake callback when cancel loses race (bsc#1275665). * CVE-2026-72222: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback (bsc#1275669). * CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). * CVE-2026-72254: netfilter: nft_fib: reject fib expression on the netdev egress hook (bsc#1277204). * CVE-2026-72262: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (bsc#1277678). * CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). * CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). * CVE-2026-72296: net: ife: require ETH_HLEN to be pullable in ife_decode() (bsc#1275923). * CVE-2026-72307: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (bsc#1277160). * CVE-2026-72308: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (bsc#1277159). * CVE-2026-72317: SUNRPC: pin upper rpc_clnt across the TLS connect_worker (bsc#1275925). * CVE-2026-72341: net/mlx5e: Fix publication race for priv->channel_stats[] (bsc#1277660). * CVE-2026-72342: net/mlx5e: Fix HV VHCA stats agent registration race (bsc#1277775). * CVE-2026-72343: net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation (bsc#1277776). * CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). * CVE-2026-72463: xfrm: Fix dev use-after-free in xfrm async resumption (bsc#1268276 bsc#1277064). * CVE-2026-72464: xprtrdma: Remove temp allocation of rpcrdma_rep objects (bsc#1277069). * CVE-2026-72466: xprtrdma: Fix bcall rep leak and unbounded peek (bsc#1277057). * CVE-2026-72467: xprtrdma: Check frwr_wp_create() during connect (bsc#1277059). * CVE-2026-72469: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE (bsc#1277047). * CVE-2026-72473: xprtrdma: Avoid 250 ms delay on backlog wakeup (bsc#1277037). * CVE-2026-72494: RDMA/irdma: Replace waitqueue and flag with completion (bsc#1276941). * CVE-2026-72495: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages (bsc#1276937). * CVE-2026-72496: RDMA/bnxt_re: Proper rollback if the ioremap fails (bsc#1276943). * CVE-2026-72499: RDMA/bnxt_re: Free CQ toggle page after firmware teardown (bsc#1276551). * CVE-2026-72501: RDMA/bnxt_re: Initialize dpi variable to zero (bsc#1276546). * CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (bsc#1276542). * CVE-2026-74269: bnxt: fix head underflow on XDP head-grow (bsc#1276507). * CVE-2026-74296: RDMA/mlx5: Release the HW-provided UAR index rather than the SW one (bsc#1276452). * CVE-2026-74297: RDMA/mlx5: Fix undefined shift of user RQ WQE size (bsc#1276446). * CVE-2026-74318: btrfs: fix deadlock cloning inline extent when using flushoncommit (bsc#1276864). * CVE-2026-74321: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (bsc#1277202). * CVE-2026-74334: RDMA/nldev: Fix locking when accessing mr->pd (bsc#1277095). * CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). * CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). * CVE-2026-74395: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (bsc#1277077). * CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073). * CVE-2026-74474: vxlan: use pskb_network_may_pull() for transmit path header pulls (bsc#1276335). * CVE-2026-74481: mm/page_reporting: use system_freezable_wq to fix UAF during suspend (bsc#1276355). * CVE-2026-74482: mm/huge_memory: unlock i_mmap_rwsem before releasing after- split folios (bsc#1276346). * CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350). * CVE-2026-74495: igbvf: Fix leak in TX DMA error cleanup (bsc#1275864). * CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). * CVE-2026-74509: Bluetooth: hci_sync: Fix advertising data UAFs (bsc#1275946). * CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation (bsc#1275950). * CVE-2026-74512: audit: fix potential use-after-free in audit_del_rule() (bsc#1275954). * CVE-2026-74516: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (bsc#1275797). * CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). * CVE-2026-74527: octeontx2-af: Block VFs from clobbering special CGX PKIND state (bsc#1275805). * CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). * CVE-2026-74548: forcedeth: fix UAF of txrx_stats in nv_remove (bsc#1275695). * CVE-2026-74550: net: do not send ICMP/NDISC Redirects when peer allocation fails (bsc#1275688). * CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). * CVE-2026-74563: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() (bsc#1275574). * CVE-2026-74566: keys: make keyring key-chunk byte order agree with keyring_diff_objects() (bsc#1275566). * CVE-2026-74567: keys: fix out-of-bounds read in keyring_get_key_chunk() (bsc#1275569). * CVE-2026-74571: btrfs: skip global block reserve accounting for rescue mounts (bsc#1275561). * CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782). * CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). * CVE-2026-74584: RDMA/bnxt_re: zero shared page before exposing to userspace (bsc#1277066). * CVE-2026-74610: tls: don't leave a full plaintext sk_msg ring unpushed (bsc#1277054). * CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). * CVE-2026-74692: net/smc: fix TOCTOU race between smc_listen_out() and listener close (bsc#1276927). * CVE-2026-74694: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (bsc#1277625). * CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). * CVE-2026-74717: net/mlx5: fw_tracer, return NULL on create error (bsc#1276569). * CVE-2026-74722: btrfs: fix memory leak in btrfs_do_encoded_write() (bsc#1276561). * CVE-2026-80529: xfs: don't swallow dquot recovery verification errors (bsc#1277688). * CVE-2026-80534: xfs: fix ilock leak on error in xfs_dq_get_next_id (bsc#1277022). * CVE-2026-80590: inet: frags: strip GSO state from fragments before reassembly (bsc#1277275). * CVE-2026-80654: soc: xilinx: Shutdown and free rx mailbox channel (bsc#1277516). The following non security issues were fixed: * accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() (git-fixes). * accessibility: speakup: unregister tty ldisc on later init failures (git- fixes). * ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer (git-fixes). * ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root (git- fixes). * ACPI: pfr_update: fix stack buffer overflow in query_capability() (git- fixes). * ACPI: processor: idle: Expand _LPI package sanity checks (git-fixes). * ACPI: processor: validate MADT IOAPIC entry bounds (git-fixes). * ACPI: scan: fix bus ID cleanup on device_add() failures (git-fixes). * ACPI: video: Release PCI device reference after lookup (git-fixes). * add my missing Reviewed-by: tag. * ALSA: 6fire: bound the MIDI event length from the device (git-fixes). * ALSA: 6fire: Fix UAF at error handling during probe (stable-fixes). * ALSA: bcd2000: clear the URB pointers on disconnect (git-fixes). * ALSA: core: Fix use-after-free in snd_card_do_free() (git-fixes). * ALSA: dummy: Check card index validity at probe (stable-fixes). * ALSA: hda/ext: preserve PPLCCTL bits when clearing reset (git-fixes). * ALSA: hda: Fix connection list comparison in proc output (git-fixes). * ALSA: hpi: Check transport errors during HPI6000 adapter initialization (git-fixes). * ALSA: pcxhr: initialize mutexes before requesting threaded IRQ (git-fixes). * ALSA: seq: midi: Optimize event_input locking with RCU (git-fixes). * ALSA: seq: midi: Serialize input teardown with event_input (git-fixes). * ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion (git-fixes). * ALSA: usb-audio: Complete cleanup after system-resume errors (git-fixes). * ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (git-fixes). * ALSA: usb-audio: fix OOB write on Type II inbound URBs (git-fixes). * ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (git-fixes). * ALSA: usx2y: bound the hwdep mmap fault offset (git-fixes). * ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() (git- fixes). * apparmor: advertise the tcp fast open fix is applied (git-fixes). * ASoC: adau1761: sort the register default table (git-fixes). * ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC (git-fixes). * ASoC: apple: mca: increase SERDES reset delay (git-fixes). * ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (git-fixes). * ASoC: cs35l33: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l34: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l41: sort the register default table (git-fixes). * ASoC: cs35l45: sort the register default table (git-fixes). * ASoC: cs4265: sort the register default table (git-fixes). * ASoC: cx2072x: sort the register default table (git-fixes). * ASoC: dapm: Fix off-by-one check on the second enum channel (git-fixes). * ASoC: fix unmet dependencies on PPC_BESTCOMM and SND_SOC_AC97_BUS (git- fixes). * ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready (git- fixes). * ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure (git-fixes). * ASoC: fsl_audmix: rework runtime PM handling in probe (git-fixes). * ASoC: fsl_easrc: sort the register default table (git-fixes). * AsoC: intel: sst: fix PCI device reference leak on probe failure (git- fixes). * ASoC: max9860: sort the register default table (git-fixes). * ASoC: meson: Keep link pointers valid on realloc failure (git-fixes). * ASoC: ml26124: sort the register default table (git-fixes). * ASoC: pcm512x: sort the register default table (git-fixes). * ASoC: pxa: Use devm_clk_get_optional() for extclk clock (git-fixes). * ASoC: qcom: q6apm: keep the graph start count in sync with the DSP (git- fixes). * ASoC: rt274: sort the register default table (git-fixes). * ASoC: rt286: sort the register default table (git-fixes). * ASoC: rt298: sort the register default table (git-fixes). * ASoC: rt700-sdw: always drain jack work on remove (git-fixes). * ASoC: rt700: drop duplicate reg_default entry (git-fixes). * ASoC: rt700: sort the register default table (git-fixes). * ASoC: rt711-sdca: sort the register default tables (git-fixes). * ASoC: rt711: sort the register default table (git-fixes). * ASoC: rt712-sdca-dmic: sort the register default table (git-fixes). * ASoC: rt715-sdca: drop duplicate reg_default entries (git-fixes). * ASoC: rt715-sdca: sort the register default tables (git-fixes). * ASoC: rt715: sort the register default table (git-fixes). * ASoC: rt1316-sdw: sort the register default table (git-fixes). * ASoC: rt1318-sdw: sort the register default table (git-fixes). * ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get (git-fixes). * ASoC: sgtl5000: sort the register default table (git-fixes). * ASoC: SOF: pcm: Move period/buffer configuration print after platform open (stable-fixes). * ASoC: sof: pcm: use snd_pcm_direction_name() (stable-fixes). * ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() (git- fixes). * ASoC: SOF: validate topology volume range before allocation (git-fixes). * ASoC: sti-sas: sort the register default table (git-fixes). * ASoC: tas2552: sort the register default table (git-fixes). * ASoC: tas2764: sort the register default table (git-fixes). * ASoC: tas2780: sort the register default table (git-fixes). * ASoC: tegra210_i2s: sort the register default table (git-fixes). * ASoC: tegra210_mixer: sort the register default table (git-fixes). * ASoC: tegra: Fix the MIXER enable default value (git-fixes). * ASoC: tegra: Sort MBDRC register defaults (git-fixes). * ASoC: xilinx: formatter_pcm: fix stream_data leak on open error (git-fixes). * ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (git-fixes). * batman-adv: bla: fix freeing of claims on meshif deletion (git-fixes). * batman-adv: bla: prevent CRC corruptions after claim flush (git-fixes). * batman-adv: dat: avoid unaligned fault in IP extraction (git-fixes). * batman-adv: fix stale receive device on merged fragments (git-fixes). * Bluetooth: btintel: Fix diagnostics event detection (git-fixes). * Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path (git-fixes). * Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX (git- fixes). * Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event (git- fixes). * Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() (git- fixes). * Bluetooth: do not leak an hci_conn when a second LE connect is rejected (git-fixes). * Bluetooth: eir: Fix OOB read in eir_get_service_data() (git-fixes). * Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (git-fixes). * Bluetooth: hci_conn: re-enable advertising only for peripheral role (git- fixes). * Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection (git- fixes). * Bluetooth: hci_event: fix LE list UAF on reset (git-fixes). * Bluetooth: hci_event: validate LE Set CIG Parameters response (git-fixes). * Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths (git-fixes). * Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (stable-fixes). * Bluetooth: hci_uart: Fix false success return in hci_uart_setup() (git- fixes). * Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready (git-fixes). * Bluetooth: MGMT: free the mesh send cancel command when it is cancelled (git-fixes). * Bluetooth: MSFT: validate evt_prefix_len against the response length (git- fixes). * Bluetooth: RFCOMM: serialize security confirmation handling (git-fixes). * Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (git- fixes). * Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop (git-fixes). * Bluetooth: virtio_bt: avoid OOB read of build info string (git-fixes). * bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation (git-fixes). * bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET (git-fixes). * bus: ti-sysc: Fix /chosen node reference leak (git-fixes). * cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64) (git-fixes). * can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (stable-fixes). * crypto: aspeed - Propagate platform_get_irq() errors (git-fixes). * crypto: atmel-sha204a - fix heap info leak on I2C transfer failure (git- fixes). * crypto: atmel-tdes - use scatterlist length before DMA mapping (git-fixes). * crypto: ccm - Set rfc4309 maxauthsize from child (git-fixes). * crypto: ccp - Fix memory leak in SEV INIT_EX path (git-fixes). * crypto: ccp - Fix possible deadlock in SEV init failure path (git-fixes). * crypto: doc - Remove extra parenthesis (git-fixes). * crypto: hisilicon/sec2 - fix CCM algorithm long packet failure (git-fixes). * crypto: keembay - Initialize completion before requesting IRQ (git-fixes). * crypto: keembay - publish OF module alias for OCS AES/SM4 (git-fixes). * crypto: mxs-dcp - fix source scatterlist length access (git-fixes). * crypto: qat - cancel work on re-enable SR-IOV timeout (git-fixes). * crypto: qat - clear AES key schedule from stack (git-fixes). * crypto: qce - fix CCM AAD buffer underallocation (git-fixes). * crypto: qce - fix error path in devm_qce_register_algs (git-fixes). * crypto: rk3288 - fail ahash requests on HASH idle timeout (git-fixes). * crypto: sa2ul - stop probe if context pool creation fails (git-fixes). * crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping (git- fixes). * device property: fix infinite loop in fwnode_for_each_child_node() (git- fixes). * dmaengine: dw-edma: Clear stale requests on termination (git-fixes). * dmaengine: dw-edma: Complete descriptors before pausing (git-fixes). * dmaengine: dw-edma: Initialize IRQ data before requesting IRQs (git-fixes). * dmaengine: dw-edma: Serialize abort state updates (git-fixes). * dmaengine: dw-edma: Serialize channel state checks (git-fixes). * dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe (git-fixes). * dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure (git-fixes). * dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal (git-fixes). * dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers (git-fixes). * dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout (git-fixes). * driver core: soc: Unregister bus on early device registration failure (git- fixes). * drm/amd/display: avoid divide-by-zero in __is_lut_linear() (git-fixes). * drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read (git- fixes). * drm/amdgpu/gfx6: Fixup emit_cntxcntl() (git-fixes). * drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets (git-fixes). * drm/amdgpu/gfx6: Use PFP on the compute queues too (git-fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup (git- fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup (git- fixes). * drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check (git- fixes). * drm/amdgpu: cap GTT size to physical RAM on APUs (stable-fixes). * drm/amdgpu: check ASPM on the dGPU host link (git-fixes). * drm/amdgpu: disallow multiple FENCE chunks in one submit (git-fixes). * drm/amdgpu: fix aperture iounmap skipped on device removal (git-fixes). * drm/amdgpu: fix autosuspend cleanup during removal (git-fixes). * drm/amdgpu: Fix UVD decode image min size calculation (stable-fixes). * drm/amdgpu: Fix UVD dpb min size calculation for H264 (stable-fixes). * drm/amdgpu: Fix UVD min buffer sizes (stable-fixes). * drm/amdgpu: Fix VCE 3 ring align_mask (git-fixes). * drm/amdgpu: Implement insert_end for VCE 3 (git-fixes). * drm/amdgpu: Reject UVD message with dimensions above 4096 (stable-fixes). * drm/amdgpu: Reject UVD message with invalid number of h265 refs (stable- fixes). * drm/amdgpu: restore UMD profile pstate after runtime resume (stable-fixes). * drm/amdgpu: validate GEM_CREATE domain combinations (stable-fixes). * drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (stable-fixes). * drm/amdkfd: fix QID bit leak in pqm_create_queue() (stable-fixes). * drm/amdkfd: Handle invalid event type in CRIU event restore (stable-fixes). * drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure (git-fixes). * drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure (git-fixes). * drm/bridge: ps8640: propagate AUX transfer register errors (git-fixes). * drm/bridge: tc358767: clamp the reported AUX read size to the request (git- fixes). * drm/connector: Fix epoch_counter docs to reflect reality (git-fixes). * drm/hibmc: Fix list of formats on the primary plane (git-fixes). * drm/hibmc: Use drm_atomic_helper_check_plane_state() (git-fixes). * drm/i915/fbc: Extract intel_fbc_has_fences() (stable-fixes). * drm/lima: call drm_mm_init() with a valid allocation range (git-fixes). * drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: Drop dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value (git- fixes). * drm/panel-edp: fix i2c adapter leak on probe failure (git-fixes). * drm/panel: samsung-s6d16d0: Power off on prepare failure (git-fixes). * drm/radeon: fix autosuspend cleanup during teardown (git-fixes). * drm/radeon: restore hardware polling in fence_is_signaled to fix performance regression (git-fixes). * drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format (git-fixes). * drm/ssd130x: fix column and row end address in partial updates for ssd132x (git-fixes). * drm/sun4i: crtc: Propagate layer initialization error (git-fixes). * drm/sun4i: Drop node references while building component list (git-fixes). * drm/sun4i: dw-hdmi: Drop TCON TOP port reference (git-fixes). * drm/sun4i: fix refcount leak in sun4i_backend_init_sat() (git-fixes). * drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz (git-fixes). * drm/sun4i: tcon: Drop remote endpoint reference (git-fixes). * drm/sun4i: tcon: Drop TCON TOP device reference (git-fixes). * drm/sun4i: tcon: Set output mux for DSI and LVDS (git-fixes). * drm/sun4i: vi scaler: Fix coefficient selection (git-fixes). * drm/tegra: dsi: Re-add clear enable register if DSI was powered by bootloader (git-fixes). * drm/tve200: add OF module alias for autoloading (git-fixes). * drm: fix race between partial drm_dev_register() failure and ioctl (git- fixes). * drm: lcdif: Wait for vblank before disabling DMA (git-fixes). * drm: Remove unused header in drm_dumb_buffers.c (git-fixes). * ethtool: rss: fix hkey leak when indir_size is 0 (git-fixes). * fbdev: bitblit: bound-check glyph index in bit_cursor() (git-fixes). * fbdev: core: Fix pointer desynchronization in fb_io_read() (git-fixes). * fbdev: kyro: Validate overlay viewport coordinates (git-fixes). * fbdev: omapfb: panel-dsi-cm: initialize lock before registering display (git-fixes). * fbdev: ssd1307fb: defer I2C transfers from damage callbacks (git-fixes). * fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() (git-fixes). * fbdev: uvesafb: unregister connector callback on init failure (git-fixes). * firmware: arm_scmi: Avoid IDR updates while cleaning channels (git-fixes). * firmware: arm_scmi: Drop handle on protocol bind failures (git-fixes). * firmware: arm_scmi: Fix requested device removal race (git-fixes). * firmware: arm_scmi: Free transport channel on IDR failure (git-fixes). * firmware: arm_scmi: Protect device request lookup with RCU (git-fixes). * firmware: arm_scmi: Reject out of range DT protocol IDs (git-fixes). * firmware: arm_scmi: Unregister device notifier before IDR teardown (git- fixes). * firmware: arm_scmi: Use channel ID for transport teardown (git-fixes). * firmware_loader: do not queue completed sysfs fallback requests (git-fixes). * fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write (git- fixes). * fpga: dfl: fme: add error handling (git-fixes). * fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration (git- fixes). * gpu: host1x: Avoid stack over-read in debug output helpers (git-fixes). * gpu: host1x: Fix offset calculation in trace_write_gather (git-fixes). * HID: core: fix number/pointer type confusion on long items (git-fixes). * HID: core: fix OOB read of field->usage in hid_set_field() (git-fixes). * HID: hyperv: validate initial device info bounds (git-fixes). * HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure (git-fixes). * HID: lg4ff: validate report length before fixed offsets (git-fixes). * HID: logitech-dj: Fix maxfield check in DJ short report validation (git- fixes). * HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (git- fixes). * HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (stable-fixes). * HID: logitech-dj: Standardise hid_report_enum variable nomenclature (stable- fixes). * HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID (stable-fixes). * HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (git- fixes). * HID: mcp2221: validate report size in mcp2221_raw_event() (git-fixes). * HID: nintendo: Fix imu_timestamp_us double increment per report (git-fixes). * HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() (git- fixes). * HID: picolcd: clamp eeprom debugfs read to bytes actually received (git- fixes). * HID: roccat: bound device-supplied profile index (git-fixes). * HID: roccat: free buffered reports when destroying device (git-fixes). * HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature (git- fixes). * HID: sensor: custom: Fix field sysfs group cleanup on failure (git-fixes). * HID: sensor: custom: Fix use-after-free in enable_sensor (git-fixes). * HID: tmff: Use 64-bit arithmetic for force feedback scaling (git-fixes). * hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (git-fixes). * hwmon: (lm25066) Use i2c_get_match_data() (stable-fixes). * hwmon: (max6621) fix negative temperature offset and crit readings (git- fixes). * hwmon: (max6621) fix temperature clamp range (git-fixes). * hwmon: (nzxt-smart2) Check return value of init_device() in probe (git- fixes). * hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (git-fixes). * hwrng: ks-sa - Fix runtime PM cleanup on registration failure (git-fixes). * hwrng: omap - Fix probe error path cleanup (git-fixes). * hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() (git- fixes). * i2c: bcm-iproc: remove printout on handled timeouts (stable-fixes). * i2c: iproc: reset bus after timeout if START_BUSY is stuck (git-fixes). * i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure (git-fixes). * i2c: mux: Fix channel node leak on adapter add failure (git-fixes). * i2c: ocores: Disable clock on failed resume (git-fixes). * i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices (git-fixes). * i3c: master: Fix device_register() error path (git-fixes). * i3c: master: Fix info leak and UAF in device unregister path (git-fixes). * i3c: master: svc: bound IBI payload to the requested max_payload_len (git- fixes). * ibmvnic: Only record tx completed bytes once per handler (bsc#1274620). * iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE (git-fixes). * iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable (git-fixes). * iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF (git-fixes). * iio: chemical: sgp30: Handle IAQ thread creation failure (git-fixes). * iio: dac: m62332: Fix regulator reference count imbalance (git-fixes). * iio: gyro: mpu3050: fix sign of raw angular velocity readings (git-fixes). * iio: light: cm32181: return zero after writing calibscale (git-fixes). * iio: light: gp2ap002: Disable regulators on resume failure (git-fixes). * iio: light: gp2ap002: re-enable irq if runtime suspend fails (git-fixes). * iio: light: isl29028: return zero in write_raw() on success (git-fixes). * iio: light: tsl2583: return zero in write_raw() on success (git-fixes). * iio: light: tsl2772: fix ALS calibscale readback (git-fixes). * iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure (git-fixes). * iio: pressure: dps310: fix NULL pointer dereference on ACPI probe (git- fixes). * iio: pressure: mpl115: Fix runtime PM cleanup (git-fixes). * iio: srf04: fix pm_runtime handling on probe error path (git-fixes). * iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() (git-fixes). * Input: atkbd - skip deactivate for HONOR ZQC-P (git-fixes). * Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (stable-fixes). * Input: evdev - fix information leak in evdev_pass_values() (stable-fixes). * Input: evdev - sanitize event type index when fetching event masks (stable- fixes). * Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (git-fixes). * Input: focaltech - use signed coordinates to prevent underflow (git-fixes). * Input: hynitron_cstxxx - validate touch count and finger IDs (git-fixes). * Input: iforce - validate input packet lengths (stable-fixes). * Input: iqs5xx - validate firmware record destination span (git-fixes). * Input: mms114 - fix Y-resolution configuration (git-fixes). * Input: psxpad-spi - set driver data before use (git-fixes). * Input: sur40 - fix input device registration ordering (stable-fixes). * Input: sur40 - fix V4L error path cleanup (stable-fixes). * Input: synaptics-rmi4 - block s_input when F54 queue is busy (git-fixes). * Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (git-fixes). * Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (git- fixes). * Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (git- fixes). * Input: synaptics-rmi4 - zero report size on F54 work error (git-fixes). * Input: xpad - add support for ZENAIM LEVERLESS (stable-fixes). * interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (git-fixes). * ipmi: ipmb: validate write message length (git-fixes). * ipmi: si: Fix NULL pointer dereference after failed registration (git- fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (git-fixes). * leds: pca9532: Fix inverted GPIO output polarity (git-fixes). * leds: pca9532: Fix phantom device registration on missing hardware (git- fixes). * lib/string: fix memchr_inv() for large ranges (git-fixes). * lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() (git-fixes). * mailbox: qcom-ipcc: fix duplicate channel allocation across holes (git- fixes). * mailbox: rockchip: disable pclk on probe failure and unbind (git-fixes). * maple_tree: fix argument name in header (git-fixes). * md/raid1: create serial pool adding rdev to array with serialize_policy=1 (bsc#1272261). * media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref (git-fixes). * media: cec-pin: Fix event FIFO ordering (git-fixes). * media: cec: disable delayed work before freeing an interrupted transmit (git-fixes). * media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash (git-fixes). * media: cec: Serialize exclusive follower delivery (git-fixes). * media: cec: stm32: prevent out-of-bounds write on RX overflow (git-fixes). * media: cedrus: fix memory leak in cedrus_init_ctrls() (git-fixes). * media: cobalt: Avoid freeing ALSA private data twice (git-fixes). * media: cx231xx: reject geometry changes while the VBI queue is busy (git- fixes). * media: cx23885: cancel NetUP CI work before teardown (git-fixes). * media: em28xx: defer audio-only extension registration (git-fixes). * media: em28xx: fix use-after-free of dev_next->devlist on disconnect (git- fixes). * media: go7007: defer the ALSA v4l2 put until card release (git-fixes). * media: i2c: ov02a10: fix endpoint parsing use-after-free (git-fixes). * media: i2c: ov7740: fix use-after-destroy in remove (git-fixes). * media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define (git- fixes). * media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define (git-fixes). * media: mc-entity: Add missing kerneldoc (git-fixes). * media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common (git- fixes). * media: nxp: imx8-isi: Correct color map between V4L2 and ISI (git-fixes). * media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing (git-fixes). * media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks (git-fixes). * media: rc: sunxi-cir: Unregister rc device on probe failure (git-fixes). * media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure (git-fixes). * media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak (git-fixes). * media: s2255: bound JPEG frame size before copying into the buffer (git- fixes). * media: s2255: check firmware size before reading trailing marker (git- fixes). * media: saa7164: fix cleanup on resource allocation failure (git-fixes). * media: tda18250: fix possible integer overflow (git-fixes). * media: usbtv: keep device alive while ALSA card exists (git-fixes). * media: v4l2-ctrls: Allow unknown HDR10 white point and luminance (git- fixes). * media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link (git-fixes). * media: venus: fix payload size calculation in parse_raw_formats() (git- fixes). * media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() (git-fixes). * media: vicodec: fix out-of-bounds write in FWHT encoder (git-fixes). * media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure (git-fixes). * media: vimc: fix pixel format lookup in enum_framesizes (git-fixes). * media: zoran: Avoid freeing a registered video_device twice (git-fixes). * mei: pull kvfree out of spinlock (git-fixes). * mfd: iqs62x: Reject zero-length firmware records (git-fixes). * mfd: rave-sp: validate received frame payload lengths (git-fixes). * misc: bcm-vk: Use acquire/release for msgq_inited (git-fixes). * misc: fastrpc: fix channel ctx ref leak when session alloc fails (git- fixes). * misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (git-fixes). * misc: fastrpc: Remove buffer from list prior to unmap operation (git-fixes). * misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke (git- fixes). * misc: rtsx: add missing write register handling (git-fixes). * misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() (git- fixes). * mkspec-dtb: Move DTS prefix into package list. * mkspec-dtb: Move provides-obsoletes to package list. * mkspec-dtb: Put per-architecture package lists into a hash. * mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (git- fixes). * mmc: sdhci: unmap the bounce buffer before device release (git-fixes). * mmc: via-sdmmc: stop card-detect handling on probe failure (git-fixes). * mtd: afs: validate v2 image info bounds (git-fixes). * mtd: mtdoops: free page bitmap when the backing MTD is removed (git-fixes). * mtd: mtdswap: Avoid freeing registered blktrans device twice (git-fixes). * mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() (git-fixes). * mtd: rawnand: validate ONFI extended parameter page sections (git-fixes). * net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes). * net: mana: Add handler for sriov configure (bsc#1272756). * net: mana: Cap MSI-X vectors to the device MSI-X table size (git-fixes). * net: mana: Extend RX CQE coalescing up to 8 packets (git-fixes). * net: mana: Fall back to scattered pages for GDMA queues (git-fixes). * net: mana: force full-page RX buffers via ethtool private flag (bsc#1269792). * net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792). * net: mana: Route ring-buffer access through offset-based helpers (git- fixes). * net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). * net: thunderbolt: Count delivered packets in rx_packets and rx_bytes (git- fixes). * net: thunderbolt: Mark the connection down when bringing it up fails (git- fixes). * net: thunderbolt: Release the Rx HopID that was handed out on mismatch (git- fixes). * net: thunderbolt: Tear down DMA paths before stopping the rings (git-fixes). * net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (git-fixes). * net: usb: ipheth: fix carrier_work UAF on disconnect (git-fixes). * nfc: digital: clamp SENSF_RES length to the destination buffer (git-fixes). * nfc: digital: Do not dump a NULL response in command completion (git-fixes). * nfc: fdp: bound the device-reported read length and fix an skb leak (git- fixes). * nfc: llcp: avoid userspace overflow on invalid optlen (git-fixes). * nfc: llcp: bound SNL TLV parsing to the skb and add length checks (git- fixes). * nfc: llcp: bound the connect_sn TLV walk to the skb (git-fixes). * nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (git-fixes). * nfc: llcp: read llcp_sock->local under the socket lock in getsockopt (git- fixes). * nfc: llcp: reject PDUs shorter than the LLCP header (git-fixes). * nfc: microread: validate target discovery payload lengths (git-fixes). * nfc: nci: fix double completion race in nci_data_exchange_complete (git- fixes). * nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (git- fixes). * nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (git- fixes). * nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing (git- fixes). * nfc: nci: free destination parameters when closing a connection (git-fixes). * nfc: pn533: hold a reference to the request skb during send_frame (git- fixes). * nfc: pn533: purge fragmented skbs during cleanup (git-fixes). * nfc: st21nfca: validate ATR_REQ length against the received frame (git- fixes). * nouveau/gem: reserve the bo in the info ioctl around the vma lookup (git- fixes). * PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] (git-fixes). * PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk (git- fixes). * PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git- fixes). * PCI: j721e: Fix incorrect max_lanes for J7200 (git-fixes). * PCI: meson: Fix GPIO state while requesting PERST# (git-fixes). * phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs (git- fixes). * phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend (git-fixes). * phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table (git- fixes). * phy: sunplus: fix error handling in sp_uphy_init() (git-fixes). * pinctrl: bcm2835: Don't remove an unregistered GPIO chip (git-fixes). * pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip (git-fixes). * pinctrl: rockchip: Reset the pin count when recalculating SoC data (git- fixes). * platform/chrome: cros_ec_debugfs: Clean up console log on probe failure (git-fixes). * platform/chrome: cros_ec_debugfs: Unregister panic notifier (git-fixes). * platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count (git- fixes). * platform/chrome: sensorhub: Bound the EC-reported sensor number (git-fixes). * platform/chrome: sensorhub: Fix dropped timestamp events and log spam (git- fixes). * platform/chrome: sensorhub: Fix memory overread in ring handler (git-fixes). * platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL (git- fixes). * platform/surface: acpi-notify: Check ACPI companion before use (git-fixes). * platform/x86: dell-privacy: Fix race condition (git-fixes). * platform/x86: dell-wmi-base: Fix resource leak on module load failure (git- fixes). * platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (git-fixes). * platform/x86: dell-wmi-sysman: Fix instance ID bounds (git-fixes). * platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path (git-fixes). * platform/x86: ISST: Just allow 2 bits for SST feature enable (git-fixes). * platform/x86: ISST: Validate level in perf mask ioctls (git-fixes). * platform/x86: ISST: Validate logical CPU id and clos id (git-fixes). * platform/x86: ISST: Validate socket ID in clos_assoc ioctl (git-fixes). * PM: sleep: Fix off-by-one in wakelocks number limit check (git-fixes). * power: supply: bd99954: Drop bad register fields (git-fixes). * power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq27520g4: fix REG_TTES address (git-fixes). * power: supply: bq256xx: drain usb_work before freeing the charger (git- fixes). * power: supply: bq24257: fix use-after-free on remove (git-fixes). * power: supply: bq25890: Fix power_supply reference leak (git-fixes). * power: supply: cros_usbpd-charger: bound the EC-reported port count (git- fixes). * power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS (git- fixes). * power: supply: isp1704_charger: cancel work on remove (git-fixes). * power: supply: lp8727: fix use-after-free in lp8727_release_irq() (git- fixes). * power: supply: max17040: drop incorrect I2C functionality check (git-fixes). * power: supply: max17040: synchronize work cancellation on suspend (git- fixes). * power: supply: qcom_battmgr: terminate the strings from firmware (git- fixes). * power: supply: rt9455: quiesce delayed work before teardown (git-fixes). * power: supply: sbs-battery: Use a per-device serial number buffer (git- fixes). * power: supply: twl4030_charger: cancel workers via devm (git-fixes). * power: supply: ucs1002: fix use-after-free on remove (git-fixes). * powercap: intel_rapl_tpmi: Handle PMU registration failure during probe (git-fixes). * powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash (bsc#1271256). * powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). * powerpc/pseries: pci - logic bug (bsc#1274749 ltc#221282 bsc#1274755 ltc#221284 bsc#1274756 ltc#221283). * ppdev: prevent overflow when setting port timeout (git-fixes). * qede: fix out-of-bounds check for cqe->len_list (git-fixes). * rapidio: clear mport->net when rio_add_net() fails (git-fixes). * rapidio: mport_cdev: fix use-after-free in dma_req_free() (git-fixes). * RDMA/irdma: Remove redundant legacy_mode checks (git-fixes). * RDMA/mana_ib: drain QP references after partial table insertion (git-fixes). * RDMA/mana_ib: unify QP lookup table (git-fixes). * RDMA/mlx5: Fix integer overflow of user QP buffer size (git-fixes). * regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (git-fixes). * regulator: core: use system_freezable_wq for init complete work (git-fixes). * regulator: devres: add API for reference voltage supplies (stable-fixes). * regulator: devres: fix devm_regulator_get_enable_read_voltage() return (git- fixes). * regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata (git-fixes). * regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling (git-fixes). * remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev (git-fixes). * remoteproc: qcom_q6v5_adsp: Fix reference leak for device node (git-fixes). * remoteproc: scp: Fix device reference leak on failed lookup (git-fixes). * Revert "drm/amdgpu: fix aperture mapping leak" (git-fixes). * Revert "media: v4l2-dev: fix error handling in __video_register_device()" (git-fixes). * Revert "thermal/drivers/hwmon: Cleanup coding style a bit" (stable-fixes). * rpmsg: core: Fix incorrect return value documentation (git-fixes). * rpmsg: glink: smem: order FIFO read after availability check (git-fixes). * rtc: gamecube: check return value of devm_rtc_register_device() (git-fixes). * rtc: pcf8563: fix clock provider leak on unbind (git-fixes). * rtc: pcf85363: Add error checking to regmap calls in probe() (git-fixes). * rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers (git-fixes). * rtc: rzn1: Fix weekday underflow when alarm crosses month boundary (git- fixes). * rtc: zynqmp: Return optional clock lookup errors (git-fixes). * scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes). * sctp: avoid auth_enable sysctl UAF during netns teardown (git-fixes). * serial: 8250_dma: Clear stale RX state on shutdown (git-fixes). * serial: amba-pl011: unprepare console clock on unregister (git-fixes). * serial: core: clear freed pointers on uart_register_driver() failure (git- fixes). * serial: qcom-geni: fix TX DMA buffer flush (git-fixes). * serial: sc16is7xx: fix copy-paste errors in EFR_SWFLOWx_BIT constants (stable-fixes). * smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). * smb: client: reject overlapping data areas in SMB2 responses (git-fixes). * smb: client: require net admin for CIFS SWN netlink (bsc#1273966). * smb: client: resolve SWN tcon from live registrations (bsc#1273872). * soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() (git- fixes). * soc: qcom: rpmh-rsc: manage PM notifiers with devres (git-fixes). * soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() (git-fixes). * software node: Fix software_node_get_reference_args() with index -1 (git- fixes). * soundwire: qcom: Fix port exhaustion check in stream_alloc_ports (git- fixes). * speakup: keyhelp: guard letter_offsets possible out-of-range indexing (git- fixes). * spi: img-spfi: don't disable runtime PM on DMA deferred probe (git-fixes). * spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (stable-fixes). * spi: sprd-adi: Fix probe succeeding without registering the controller (git- fixes). * staging: fbtft: Use sysfs_emit_at() to print to sysfs file (git-fixes). * staging: media: tegra-video: vi: fix probe failure on skipped last port (git-fixes). * staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown (git- fixes). * staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() (git-fixes). * staging: rtl8723bs: fix missing shared-key auth challenge length check (git- fixes). * staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (git-fixes). * staging: rtl8723bs: fix OOB read in WMM_param_handler() (git-fixes). * staging: rtl8723bs: use kfree_sensitive() for key material (git-fixes). * staging: rtl8723bs: validate monitor transmit frame lengths (git-fixes). * staging: sm750fb: gate dualview dataflow using g_dualview (git-fixes). * thermal/drivers/imx: Disable clock on runtime resume failure (git-fixes). * thermal/drivers/qoriq: Disable clock on resume failure (git-fixes). * thermal: intel: int3400: clean up ODVP on probe failures (git-fixes). * thunderbolt: Bound the DROM dual link port number before indexing sw->ports (git-fixes). * thunderbolt: icm: Preserve USB4 proxy data-valid bit (git-fixes). * tlclk: if sscanf() fails, fall back to 0, not random value (git-fixes). * tpm: st33zp24: Return zero on status read failure (git-fixes). * tpm: st33zp24: Validate locality read result (git-fixes). * tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (git-fixes). * tty: clear cdev pointer after cdev_add() failure (git-fixes). * tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 (git-fixes). * tty: skip cdev_del() when no cdev is registered (git-fixes). * uio: Fix stale info pointer in failed registration path (git-fixes). * usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (git-fixes). * usb: atm: usbatm: fix invalid ci_range initialization (git-fixes). * USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (git-fixes). * usb: cdnsp: fix incorrect endian conversions for APB timeout register (git- fixes). * usb: dwc2: add missing @remotewakeup kernel-doc parameter (git-fixes). * usb: dwc2: gadget: Exit partial power down state when changing USB pull-up (git-fixes). * usb: gadget: configfs: fix out-of-bounds read of qw_sign (git-fixes). * usb: gadget: f_fs: Prevent deadlock during ep0 read loop (git-fixes). * usb: gadget: f_ncm: Use unsigned int for ndp_index (git-fixes). * usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() (git-fixes). * usb: gadget: f_uac1_legacy: remove broken string configfs attributes (git- fixes). * usb: gadget: pch_udc: remove excess kernel-doc member for registered (git- fixes). * usb: gadget: r8a66597: avoid double free of ep0_req in probe error path (git-fixes). * usb: gadget: snps_udc_plat: clean up PHY on probe deferral (git-fixes). * usb: gadget: u_audio: Fix use-after-free on sound card disconnect (git- fixes). * usb: gadget: uac: validate rate list length before storing (git-fixes). * usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() (git-fixes). * usb: mtu3: allow system suspend during active gadget connection (git-fixes). * usb: musb: omap2430: clean up probe error handling (stable-fixes). * USB: phy: fsl-usb: fix missing static keywords (git-fixes). * usb: renesas_usbhs: Fix power-off ordering on unbind (git-fixes). * USB: serial: digi_acceleport: fix port registration order (git-fixes). * USB: serial: ftdi_sio: add support for E+H FXA291 (stable-fixes). * USB: serial: option: add TDTECH MT5710-CN (stable-fixes). * USB: serial: option: fix slab OOB read in interrupt URB callback (git- fixes). * USB: serial: spcp8x5: drop broken carrier detect support (git-fixes). * USB: storage: add NO_ATA_1X quirk for Longmai USB Key (stable-fixes). * usb: typec: ucsi: unregister debugfs entries on teardown (git-fixes). * usb: usbfs: fix use-after-free of usb_device in usbdev_release() (git- fixes). * usb: xhci: Handle USB3 port events when there is one roothub (git-fixes). * vt: add permission check for KDSKBMETA ioctl (stable-fixes). * vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (stable- fixes). * w1: ds28e17: reject an oversize length on an I2C block read (git-fixes). * w1: ds2482: Fix signedness bug in ds2482_w1_triplet() (git-fixes). * wifi: ath6kl: avoid buffer overreads in WMI event handlers (git-fixes). * wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (git-fixes). * wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump (git-fixes). * wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() (git-fixes). * wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate (git- fixes). * wifi: ath11k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() (git-fixes). * wifi: ath12k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (git-fixes). * wifi: brcmfmac: fix P2P action frame handling without device vif (git- fixes). * wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs (git-fixes). * wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments (git-fixes). * wifi: iwlwifi: mei: pass correct argument to function (git-fixes). * wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser (git-fixes). * wifi: mac80211: send TWT teardown to peer after setup TX failure (git- fixes). * wifi: mac80211: skip default WMM setup for AP_VLAN links (git-fixes). * wifi: mac80211: skip unused probe response countdown offsets (git-fixes). * wifi: mt76: fix 4th chain ACK RSSI bitmask in sta_poll (git-fixes). * wifi: mt76: fix ER-SU 106-tone RU check in RX rate decode (git-fixes). * wifi: mt76: fix HE DCM max-RU capability encoding (git-fixes). * wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length (git- fixes). * wifi: mt76: mt792x: Fix memory leak in SDIO TX path (git-fixes). * wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (git- fixes). * wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss (git- fixes). * wifi: mt76: mt7915: fix double hif2 init on the non-WED path (git-fixes). * wifi: mt76: mt7915: fix ext PHY use-after-free on register error path (git- fixes). * wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 (git- fixes). * wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie (git-fixes). * wifi: mt76: mt7915: release hif2 reference on probe IRQ failure (git-fixes). * wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement (git- fixes). * wifi: mt76: mt7915: unwind state on add_interface failure (git-fixes). * wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields (git- fixes). * wifi: mt76: mt7915: write RX header translation bit to the correct register (git-fixes). * wifi: mt76: mt7921: validate CLC firmware records (git-fixes). * wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (git- fixes). * wifi: mt76: mt7925: fix msg len mismatch between driver and firmware (git- fixes). * wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config (git- fixes). * wifi: mt76: mt7996: don't report a zero TX bitrate (git-fixes). * wifi: mt76: mt7996: fix reg addr remap when addr is 0 (git-fixes). * wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV (git- fixes). * wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset (git-fixes). * wifi: mt76: mt7996: validate RX band_idx before dereferencing phys (git- fixes). * wifi: mt76: report data NSS for STBC frames in RX rate decode (git-fixes). * wifi: mwifiex: Detach sync cmd buffer on interrupted wait (git-fixes). * wifi: rtlwifi: pci: fix error path in rtl_pci_probe() (git-fixes). * wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (git-fixes). * wifi: rtw89: fix HE extended capability length check (git-fixes). * wifi: zd1211rw: reject secondary interfaces to prevent conflicts (git- fixes). * x86/bugs: Clarify that syscall hardening isn't a BHI mitigation (git-fixes). * xhci: dbgtty: Fix unregister on tty_alloc_driver() failure (git-fixes). * xhci: dbgtty: Fix unregister on tty_register_driver() failure (git-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.0 zypper in -t patch SUSE-SLE-Micro-Extras-6.0-kernel-601=1 ## Package List: * SUSE Linux Micro Extras 6.0 (nosrc) * kernel-default-6.4.0-52.1 * kernel-64kb-6.4.0-52.1 * SUSE Linux Micro Extras 6.0 (aarch64) * kernel-64kb-debugsource-6.4.0-52.1 * kernel-64kb-devel-6.4.0-52.1 * SUSE Linux Micro Extras 6.0 (aarch64 s390x x86_64) * kernel-obs-build-6.4.0-52.1 * kernel-syms-6.4.0-52.1 * kernel-default-devel-6.4.0-52.1 * kernel-default-debugsource-6.4.0-52.1 * kernel-obs-build-debugsource-6.4.0-52.1 * SUSE Linux Micro Extras 6.0 (x86_64) * kernel-default-devel-debuginfo-6.4.0-52.1 ## References: * https://www.suse.com/security/cve/CVE-2024-44981.html * https://www.suse.com/security/cve/CVE-2024-57841.html * https://www.suse.com/security/cve/CVE-2025-38469.html * https://www.suse.com/security/cve/CVE-2025-39964.html * https://www.suse.com/security/cve/CVE-2025-40022.html * https://www.suse.com/security/cve/CVE-2025-68179.html * https://www.suse.com/security/cve/CVE-2025-68214.html * https://www.suse.com/security/cve/CVE-2025-71075.html * https://www.suse.com/security/cve/CVE-2025-71104.html * https://www.suse.com/security/cve/CVE-2026-23210.html * https://www.suse.com/security/cve/CVE-2026-23230.html * https://www.suse.com/security/cve/CVE-2026-23454.html * https://www.suse.com/security/cve/CVE-2026-31392.html * https://www.suse.com/security/cve/CVE-2026-31418.html * https://www.suse.com/security/cve/CVE-2026-31531.html * https://www.suse.com/security/cve/CVE-2026-31557.html * https://www.suse.com/security/cve/CVE-2026-31663.html * https://www.suse.com/security/cve/CVE-2026-43116.html * https://www.suse.com/security/cve/CVE-2026-43125.html * https://www.suse.com/security/cve/CVE-2026-43163.html * https://www.suse.com/security/cve/CVE-2026-43271.html * https://www.suse.com/security/cve/CVE-2026-43273.html * https://www.suse.com/security/cve/CVE-2026-43278.html * https://www.suse.com/security/cve/CVE-2026-43319.html * https://www.suse.com/security/cve/CVE-2026-43363.html * https://www.suse.com/security/cve/CVE-2026-43416.html * https://www.suse.com/security/cve/CVE-2026-45897.html * https://www.suse.com/security/cve/CVE-2026-45968.html * https://www.suse.com/security/cve/CVE-2026-46070.html * https://www.suse.com/security/cve/CVE-2026-46091.html * https://www.suse.com/security/cve/CVE-2026-46107.html * https://www.suse.com/security/cve/CVE-2026-46115.html * https://www.suse.com/security/cve/CVE-2026-46195.html * https://www.suse.com/security/cve/CVE-2026-52920.html * https://www.suse.com/security/cve/CVE-2026-52925.html * https://www.suse.com/security/cve/CVE-2026-52929.html * https://www.suse.com/security/cve/CVE-2026-52935.html * https://www.suse.com/security/cve/CVE-2026-52939.html * https://www.suse.com/security/cve/CVE-2026-52946.html * https://www.suse.com/security/cve/CVE-2026-52975.html * https://www.suse.com/security/cve/CVE-2026-52977.html * https://www.suse.com/security/cve/CVE-2026-52990.html * https://www.suse.com/security/cve/CVE-2026-52994.html * https://www.suse.com/security/cve/CVE-2026-53001.html * https://www.suse.com/security/cve/CVE-2026-53033.html * https://www.suse.com/security/cve/CVE-2026-53059.html * https://www.suse.com/security/cve/CVE-2026-53076.html * https://www.suse.com/security/cve/CVE-2026-53077.html * https://www.suse.com/security/cve/CVE-2026-53089.html * https://www.suse.com/security/cve/CVE-2026-53091.html * https://www.suse.com/security/cve/CVE-2026-53094.html * https://www.suse.com/security/cve/CVE-2026-53096.html * https://www.suse.com/security/cve/CVE-2026-53110.html * https://www.suse.com/security/cve/CVE-2026-53111.html * https://www.suse.com/security/cve/CVE-2026-53126.html * https://www.suse.com/security/cve/CVE-2026-53154.html * https://www.suse.com/security/cve/CVE-2026-53163.html * https://www.suse.com/security/cve/CVE-2026-53207.html * https://www.suse.com/security/cve/CVE-2026-53219.html * https://www.suse.com/security/cve/CVE-2026-53220.html * https://www.suse.com/security/cve/CVE-2026-53223.html * https://www.suse.com/security/cve/CVE-2026-53228.html * https://www.suse.com/security/cve/CVE-2026-53238.html * https://www.suse.com/security/cve/CVE-2026-53260.html * https://www.suse.com/security/cve/CVE-2026-53264.html * https://www.suse.com/security/cve/CVE-2026-53269.html * https://www.suse.com/security/cve/CVE-2026-53273.html * https://www.suse.com/security/cve/CVE-2026-53309.html * https://www.suse.com/security/cve/CVE-2026-53330.html * https://www.suse.com/security/cve/CVE-2026-53336.html * https://www.suse.com/security/cve/CVE-2026-53337.html * https://www.suse.com/security/cve/CVE-2026-53353.html * https://www.suse.com/security/cve/CVE-2026-53365.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://www.suse.com/security/cve/CVE-2026-53381.html * https://www.suse.com/security/cve/CVE-2026-53388.html * https://www.suse.com/security/cve/CVE-2026-63801.html * https://www.suse.com/security/cve/CVE-2026-63808.html * https://www.suse.com/security/cve/CVE-2026-63810.html * https://www.suse.com/security/cve/CVE-2026-63823.html * https://www.suse.com/security/cve/CVE-2026-63827.html * https://www.suse.com/security/cve/CVE-2026-63828.html * https://www.suse.com/security/cve/CVE-2026-63860.html * https://www.suse.com/security/cve/CVE-2026-63865.html * https://www.suse.com/security/cve/CVE-2026-63868.html * https://www.suse.com/security/cve/CVE-2026-63879.html * https://www.suse.com/security/cve/CVE-2026-63881.html * https://www.suse.com/security/cve/CVE-2026-63886.html * https://www.suse.com/security/cve/CVE-2026-63887.html * https://www.suse.com/security/cve/CVE-2026-63888.html * https://www.suse.com/security/cve/CVE-2026-63889.html * https://www.suse.com/security/cve/CVE-2026-63891.html * https://www.suse.com/security/cve/CVE-2026-63898.html * https://www.suse.com/security/cve/CVE-2026-63920.html * https://www.suse.com/security/cve/CVE-2026-63925.html * https://www.suse.com/security/cve/CVE-2026-63926.html * https://www.suse.com/security/cve/CVE-2026-63928.html * https://www.suse.com/security/cve/CVE-2026-63944.html * https://www.suse.com/security/cve/CVE-2026-63969.html * https://www.suse.com/security/cve/CVE-2026-63970.html * https://www.suse.com/security/cve/CVE-2026-63972.html * https://www.suse.com/security/cve/CVE-2026-63973.html * https://www.suse.com/security/cve/CVE-2026-63980.html * https://www.suse.com/security/cve/CVE-2026-63985.html * https://www.suse.com/security/cve/CVE-2026-63990.html * https://www.suse.com/security/cve/CVE-2026-63992.html * https://www.suse.com/security/cve/CVE-2026-63999.html * https://www.suse.com/security/cve/CVE-2026-64000.html * https://www.suse.com/security/cve/CVE-2026-64001.html * https://www.suse.com/security/cve/CVE-2026-64002.html * https://www.suse.com/security/cve/CVE-2026-64004.html * https://www.suse.com/security/cve/CVE-2026-64005.html * https://www.suse.com/security/cve/CVE-2026-64006.html * https://www.suse.com/security/cve/CVE-2026-64007.html * https://www.suse.com/security/cve/CVE-2026-64010.html * https://www.suse.com/security/cve/CVE-2026-64011.html * https://www.suse.com/security/cve/CVE-2026-64014.html * https://www.suse.com/security/cve/CVE-2026-64015.html * https://www.suse.com/security/cve/CVE-2026-64018.html * https://www.suse.com/security/cve/CVE-2026-64029.html * https://www.suse.com/security/cve/CVE-2026-64034.html * https://www.suse.com/security/cve/CVE-2026-64039.html * https://www.suse.com/security/cve/CVE-2026-64047.html * https://www.suse.com/security/cve/CVE-2026-64048.html * https://www.suse.com/security/cve/CVE-2026-64051.html * https://www.suse.com/security/cve/CVE-2026-64052.html * https://www.suse.com/security/cve/CVE-2026-64073.html * https://www.suse.com/security/cve/CVE-2026-64083.html * https://www.suse.com/security/cve/CVE-2026-64084.html * https://www.suse.com/security/cve/CVE-2026-64085.html * https://www.suse.com/security/cve/CVE-2026-64086.html * https://www.suse.com/security/cve/CVE-2026-64087.html * https://www.suse.com/security/cve/CVE-2026-64088.html * https://www.suse.com/security/cve/CVE-2026-64097.html * https://www.suse.com/security/cve/CVE-2026-64098.html * https://www.suse.com/security/cve/CVE-2026-64102.html * https://www.suse.com/security/cve/CVE-2026-64109.html * https://www.suse.com/security/cve/CVE-2026-64112.html * https://www.suse.com/security/cve/CVE-2026-64113.html * https://www.suse.com/security/cve/CVE-2026-64114.html * https://www.suse.com/security/cve/CVE-2026-64115.html * https://www.suse.com/security/cve/CVE-2026-64118.html * https://www.suse.com/security/cve/CVE-2026-64121.html * https://www.suse.com/security/cve/CVE-2026-64125.html * https://www.suse.com/security/cve/CVE-2026-64126.html * https://www.suse.com/security/cve/CVE-2026-64128.html * https://www.suse.com/security/cve/CVE-2026-64131.html * https://www.suse.com/security/cve/CVE-2026-64133.html * https://www.suse.com/security/cve/CVE-2026-64135.html * https://www.suse.com/security/cve/CVE-2026-64137.html * https://www.suse.com/security/cve/CVE-2026-64148.html * https://www.suse.com/security/cve/CVE-2026-64155.html * https://www.suse.com/security/cve/CVE-2026-64164.html * https://www.suse.com/security/cve/CVE-2026-64166.html * https://www.suse.com/security/cve/CVE-2026-64168.html * https://www.suse.com/security/cve/CVE-2026-64178.html * https://www.suse.com/security/cve/CVE-2026-64185.html * https://www.suse.com/security/cve/CVE-2026-64188.html * https://www.suse.com/security/cve/CVE-2026-64190.html * https://www.suse.com/security/cve/CVE-2026-64192.html * https://www.suse.com/security/cve/CVE-2026-64214.html * https://www.suse.com/security/cve/CVE-2026-64217.html * https://www.suse.com/security/cve/CVE-2026-64218.html * https://www.suse.com/security/cve/CVE-2026-64219.html * https://www.suse.com/security/cve/CVE-2026-64222.html * https://www.suse.com/security/cve/CVE-2026-64225.html * https://www.suse.com/security/cve/CVE-2026-64237.html * https://www.suse.com/security/cve/CVE-2026-64243.html * https://www.suse.com/security/cve/CVE-2026-64245.html * https://www.suse.com/security/cve/CVE-2026-64246.html * https://www.suse.com/security/cve/CVE-2026-64247.html * https://www.suse.com/security/cve/CVE-2026-64249.html * https://www.suse.com/security/cve/CVE-2026-64257.html * https://www.suse.com/security/cve/CVE-2026-64266.html * https://www.suse.com/security/cve/CVE-2026-64268.html * https://www.suse.com/security/cve/CVE-2026-64271.html * https://www.suse.com/security/cve/CVE-2026-64273.html * https://www.suse.com/security/cve/CVE-2026-64274.html * https://www.suse.com/security/cve/CVE-2026-64275.html * https://www.suse.com/security/cve/CVE-2026-64276.html * https://www.suse.com/security/cve/CVE-2026-64277.html * https://www.suse.com/security/cve/CVE-2026-64286.html * https://www.suse.com/security/cve/CVE-2026-64287.html * https://www.suse.com/security/cve/CVE-2026-64294.html * https://www.suse.com/security/cve/CVE-2026-64296.html * https://www.suse.com/security/cve/CVE-2026-64303.html * https://www.suse.com/security/cve/CVE-2026-64304.html * https://www.suse.com/security/cve/CVE-2026-64305.html * https://www.suse.com/security/cve/CVE-2026-64306.html * https://www.suse.com/security/cve/CVE-2026-64312.html * https://www.suse.com/security/cve/CVE-2026-64313.html * https://www.suse.com/security/cve/CVE-2026-64315.html * https://www.suse.com/security/cve/CVE-2026-64316.html * https://www.suse.com/security/cve/CVE-2026-64317.html * https://www.suse.com/security/cve/CVE-2026-64322.html * https://www.suse.com/security/cve/CVE-2026-64323.html * https://www.suse.com/security/cve/CVE-2026-64329.html * https://www.suse.com/security/cve/CVE-2026-64331.html * https://www.suse.com/security/cve/CVE-2026-64332.html * https://www.suse.com/security/cve/CVE-2026-64333.html * https://www.suse.com/security/cve/CVE-2026-64334.html * https://www.suse.com/security/cve/CVE-2026-64335.html * https://www.suse.com/security/cve/CVE-2026-64337.html * https://www.suse.com/security/cve/CVE-2026-64338.html * https://www.suse.com/security/cve/CVE-2026-64340.html * https://www.suse.com/security/cve/CVE-2026-64341.html * https://www.suse.com/security/cve/CVE-2026-64342.html * https://www.suse.com/security/cve/CVE-2026-64343.html * https://www.suse.com/security/cve/CVE-2026-64344.html * https://www.suse.com/security/cve/CVE-2026-64346.html * https://www.suse.com/security/cve/CVE-2026-64348.html * https://www.suse.com/security/cve/CVE-2026-64350.html * https://www.suse.com/security/cve/CVE-2026-64351.html * https://www.suse.com/security/cve/CVE-2026-64355.html * https://www.suse.com/security/cve/CVE-2026-64358.html * https://www.suse.com/security/cve/CVE-2026-64362.html * https://www.suse.com/security/cve/CVE-2026-64365.html * https://www.suse.com/security/cve/CVE-2026-64375.html * https://www.suse.com/security/cve/CVE-2026-64376.html * https://www.suse.com/security/cve/CVE-2026-64378.html * https://www.suse.com/security/cve/CVE-2026-64381.html * https://www.suse.com/security/cve/CVE-2026-64382.html * https://www.suse.com/security/cve/CVE-2026-64383.html * https://www.suse.com/security/cve/CVE-2026-64384.html * https://www.suse.com/security/cve/CVE-2026-64385.html * https://www.suse.com/security/cve/CVE-2026-64386.html * https://www.suse.com/security/cve/CVE-2026-64387.html * https://www.suse.com/security/cve/CVE-2026-64388.html * https://www.suse.com/security/cve/CVE-2026-64401.html * https://www.suse.com/security/cve/CVE-2026-64403.html * https://www.suse.com/security/cve/CVE-2026-64406.html * https://www.suse.com/security/cve/CVE-2026-64408.html * https://www.suse.com/security/cve/CVE-2026-64409.html * https://www.suse.com/security/cve/CVE-2026-64411.html * https://www.suse.com/security/cve/CVE-2026-64412.html * https://www.suse.com/security/cve/CVE-2026-64420.html * https://www.suse.com/security/cve/CVE-2026-64421.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64427.html * https://www.suse.com/security/cve/CVE-2026-64429.html * https://www.suse.com/security/cve/CVE-2026-64433.html * https://www.suse.com/security/cve/CVE-2026-64434.html * https://www.suse.com/security/cve/CVE-2026-64436.html * https://www.suse.com/security/cve/CVE-2026-64440.html * https://www.suse.com/security/cve/CVE-2026-64442.html * https://www.suse.com/security/cve/CVE-2026-64443.html * https://www.suse.com/security/cve/CVE-2026-64444.html * https://www.suse.com/security/cve/CVE-2026-64445.html * https://www.suse.com/security/cve/CVE-2026-64448.html * https://www.suse.com/security/cve/CVE-2026-64450.html * https://www.suse.com/security/cve/CVE-2026-64454.html * https://www.suse.com/security/cve/CVE-2026-64455.html * https://www.suse.com/security/cve/CVE-2026-64463.html * https://www.suse.com/security/cve/CVE-2026-64470.html * https://www.suse.com/security/cve/CVE-2026-64471.html * https://www.suse.com/security/cve/CVE-2026-64472.html * https://www.suse.com/security/cve/CVE-2026-64478.html * https://www.suse.com/security/cve/CVE-2026-64479.html * https://www.suse.com/security/cve/CVE-2026-64480.html * https://www.suse.com/security/cve/CVE-2026-64481.html * https://www.suse.com/security/cve/CVE-2026-64482.html * https://www.suse.com/security/cve/CVE-2026-64483.html * https://www.suse.com/security/cve/CVE-2026-64484.html * https://www.suse.com/security/cve/CVE-2026-64486.html * https://www.suse.com/security/cve/CVE-2026-64487.html * https://www.suse.com/security/cve/CVE-2026-64489.html * https://www.suse.com/security/cve/CVE-2026-64494.html * https://www.suse.com/security/cve/CVE-2026-64495.html * https://www.suse.com/security/cve/CVE-2026-64496.html * https://www.suse.com/security/cve/CVE-2026-64497.html * https://www.suse.com/security/cve/CVE-2026-64500.html * https://www.suse.com/security/cve/CVE-2026-64503.html * https://www.suse.com/security/cve/CVE-2026-64504.html * https://www.suse.com/security/cve/CVE-2026-64505.html * https://www.suse.com/security/cve/CVE-2026-64511.html * https://www.suse.com/security/cve/CVE-2026-64512.html * https://www.suse.com/security/cve/CVE-2026-64513.html * https://www.suse.com/security/cve/CVE-2026-64524.html * https://www.suse.com/security/cve/CVE-2026-64527.html * https://www.suse.com/security/cve/CVE-2026-64536.html * https://www.suse.com/security/cve/CVE-2026-64537.html * https://www.suse.com/security/cve/CVE-2026-64538.html * https://www.suse.com/security/cve/CVE-2026-64539.html * https://www.suse.com/security/cve/CVE-2026-64540.html * https://www.suse.com/security/cve/CVE-2026-64541.html * https://www.suse.com/security/cve/CVE-2026-64543.html * https://www.suse.com/security/cve/CVE-2026-64544.html * https://www.suse.com/security/cve/CVE-2026-64545.html * https://www.suse.com/security/cve/CVE-2026-64546.html * https://www.suse.com/security/cve/CVE-2026-64547.html * https://www.suse.com/security/cve/CVE-2026-64548.html * https://www.suse.com/security/cve/CVE-2026-64549.html * https://www.suse.com/security/cve/CVE-2026-64551.html * https://www.suse.com/security/cve/CVE-2026-64552.html * https://www.suse.com/security/cve/CVE-2026-64553.html * https://www.suse.com/security/cve/CVE-2026-64554.html * https://www.suse.com/security/cve/CVE-2026-64562.html * https://www.suse.com/security/cve/CVE-2026-64563.html * https://www.suse.com/security/cve/CVE-2026-64565.html * https://www.suse.com/security/cve/CVE-2026-64567.html * https://www.suse.com/security/cve/CVE-2026-64571.html * https://www.suse.com/security/cve/CVE-2026-64572.html * https://www.suse.com/security/cve/CVE-2026-64573.html * https://www.suse.com/security/cve/CVE-2026-64574.html * https://www.suse.com/security/cve/CVE-2026-64576.html * https://www.suse.com/security/cve/CVE-2026-64577.html * https://www.suse.com/security/cve/CVE-2026-64581.html * https://www.suse.com/security/cve/CVE-2026-64582.html * https://www.suse.com/security/cve/CVE-2026-64583.html * https://www.suse.com/security/cve/CVE-2026-64584.html * https://www.suse.com/security/cve/CVE-2026-64585.html * https://www.suse.com/security/cve/CVE-2026-64593.html * https://www.suse.com/security/cve/CVE-2026-64597.html * https://www.suse.com/security/cve/CVE-2026-64598.html * https://www.suse.com/security/cve/CVE-2026-64599.html * https://www.suse.com/security/cve/CVE-2026-64602.html * https://www.suse.com/security/cve/CVE-2026-64604.html * https://www.suse.com/security/cve/CVE-2026-68081.html * https://www.suse.com/security/cve/CVE-2026-68082.html * https://www.suse.com/security/cve/CVE-2026-68085.html * https://www.suse.com/security/cve/CVE-2026-68086.html * https://www.suse.com/security/cve/CVE-2026-68088.html * https://www.suse.com/security/cve/CVE-2026-68091.html * https://www.suse.com/security/cve/CVE-2026-68093.html * https://www.suse.com/security/cve/CVE-2026-68102.html * https://www.suse.com/security/cve/CVE-2026-68104.html * https://www.suse.com/security/cve/CVE-2026-68106.html * https://www.suse.com/security/cve/CVE-2026-68107.html * https://www.suse.com/security/cve/CVE-2026-68108.html * https://www.suse.com/security/cve/CVE-2026-68110.html * https://www.suse.com/security/cve/CVE-2026-68111.html * https://www.suse.com/security/cve/CVE-2026-68112.html * https://www.suse.com/security/cve/CVE-2026-68115.html * https://www.suse.com/security/cve/CVE-2026-68116.html * https://www.suse.com/security/cve/CVE-2026-68117.html * https://www.suse.com/security/cve/CVE-2026-68121.html * https://www.suse.com/security/cve/CVE-2026-68123.html * https://www.suse.com/security/cve/CVE-2026-68125.html * https://www.suse.com/security/cve/CVE-2026-68126.html * https://www.suse.com/security/cve/CVE-2026-68127.html * https://www.suse.com/security/cve/CVE-2026-68129.html * https://www.suse.com/security/cve/CVE-2026-68132.html * https://www.suse.com/security/cve/CVE-2026-68133.html * https://www.suse.com/security/cve/CVE-2026-68136.html * https://www.suse.com/security/cve/CVE-2026-68137.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://www.suse.com/security/cve/CVE-2026-68139.html * https://www.suse.com/security/cve/CVE-2026-68142.html * https://www.suse.com/security/cve/CVE-2026-68143.html * https://www.suse.com/security/cve/CVE-2026-68145.html * https://www.suse.com/security/cve/CVE-2026-68149.html * https://www.suse.com/security/cve/CVE-2026-68153.html * https://www.suse.com/security/cve/CVE-2026-68154.html * https://www.suse.com/security/cve/CVE-2026-68155.html * https://www.suse.com/security/cve/CVE-2026-68156.html * https://www.suse.com/security/cve/CVE-2026-68157.html * https://www.suse.com/security/cve/CVE-2026-68158.html * https://www.suse.com/security/cve/CVE-2026-68159.html * https://www.suse.com/security/cve/CVE-2026-68160.html * https://www.suse.com/security/cve/CVE-2026-68161.html * https://www.suse.com/security/cve/CVE-2026-68162.html * https://www.suse.com/security/cve/CVE-2026-68166.html * https://www.suse.com/security/cve/CVE-2026-68180.html * https://www.suse.com/security/cve/CVE-2026-68181.html * https://www.suse.com/security/cve/CVE-2026-68182.html * https://www.suse.com/security/cve/CVE-2026-68184.html * https://www.suse.com/security/cve/CVE-2026-68188.html * https://www.suse.com/security/cve/CVE-2026-68189.html * https://www.suse.com/security/cve/CVE-2026-68192.html * https://www.suse.com/security/cve/CVE-2026-68193.html * https://www.suse.com/security/cve/CVE-2026-68194.html * https://www.suse.com/security/cve/CVE-2026-68195.html * https://www.suse.com/security/cve/CVE-2026-68196.html * https://www.suse.com/security/cve/CVE-2026-68197.html * https://www.suse.com/security/cve/CVE-2026-68199.html * https://www.suse.com/security/cve/CVE-2026-68202.html * https://www.suse.com/security/cve/CVE-2026-68204.html * https://www.suse.com/security/cve/CVE-2026-68205.html * https://www.suse.com/security/cve/CVE-2026-68206.html * https://www.suse.com/security/cve/CVE-2026-68207.html * https://www.suse.com/security/cve/CVE-2026-68209.html * https://www.suse.com/security/cve/CVE-2026-68210.html * https://www.suse.com/security/cve/CVE-2026-68212.html * https://www.suse.com/security/cve/CVE-2026-68213.html * https://www.suse.com/security/cve/CVE-2026-68214.html * https://www.suse.com/security/cve/CVE-2026-68215.html * https://www.suse.com/security/cve/CVE-2026-68216.html * https://www.suse.com/security/cve/CVE-2026-68217.html * https://www.suse.com/security/cve/CVE-2026-68218.html * https://www.suse.com/security/cve/CVE-2026-68219.html * https://www.suse.com/security/cve/CVE-2026-68220.html * https://www.suse.com/security/cve/CVE-2026-68222.html * https://www.suse.com/security/cve/CVE-2026-68223.html * https://www.suse.com/security/cve/CVE-2026-68226.html * https://www.suse.com/security/cve/CVE-2026-68227.html * https://www.suse.com/security/cve/CVE-2026-68229.html * https://www.suse.com/security/cve/CVE-2026-68231.html * https://www.suse.com/security/cve/CVE-2026-68234.html * https://www.suse.com/security/cve/CVE-2026-68236.html * https://www.suse.com/security/cve/CVE-2026-68238.html * https://www.suse.com/security/cve/CVE-2026-68243.html * https://www.suse.com/security/cve/CVE-2026-68244.html * https://www.suse.com/security/cve/CVE-2026-68246.html * https://www.suse.com/security/cve/CVE-2026-68247.html * https://www.suse.com/security/cve/CVE-2026-68248.html * https://www.suse.com/security/cve/CVE-2026-68249.html * https://www.suse.com/security/cve/CVE-2026-68250.html * https://www.suse.com/security/cve/CVE-2026-68251.html * https://www.suse.com/security/cve/CVE-2026-68254.html * https://www.suse.com/security/cve/CVE-2026-68255.html * https://www.suse.com/security/cve/CVE-2026-68256.html * https://www.suse.com/security/cve/CVE-2026-68259.html * https://www.suse.com/security/cve/CVE-2026-68269.html * https://www.suse.com/security/cve/CVE-2026-68271.html * https://www.suse.com/security/cve/CVE-2026-68272.html * https://www.suse.com/security/cve/CVE-2026-68277.html * https://www.suse.com/security/cve/CVE-2026-68278.html * https://www.suse.com/security/cve/CVE-2026-68279.html * https://www.suse.com/security/cve/CVE-2026-68280.html * https://www.suse.com/security/cve/CVE-2026-68284.html * https://www.suse.com/security/cve/CVE-2026-68286.html * https://www.suse.com/security/cve/CVE-2026-68288.html * https://www.suse.com/security/cve/CVE-2026-68289.html * https://www.suse.com/security/cve/CVE-2026-68293.html * https://www.suse.com/security/cve/CVE-2026-68297.html * https://www.suse.com/security/cve/CVE-2026-68299.html * https://www.suse.com/security/cve/CVE-2026-68300.html * https://www.suse.com/security/cve/CVE-2026-68303.html * https://www.suse.com/security/cve/CVE-2026-68304.html * https://www.suse.com/security/cve/CVE-2026-68306.html * https://www.suse.com/security/cve/CVE-2026-68308.html * https://www.suse.com/security/cve/CVE-2026-68309.html * https://www.suse.com/security/cve/CVE-2026-68310.html * https://www.suse.com/security/cve/CVE-2026-68312.html * https://www.suse.com/security/cve/CVE-2026-68313.html * https://www.suse.com/security/cve/CVE-2026-68315.html * https://www.suse.com/security/cve/CVE-2026-68320.html * https://www.suse.com/security/cve/CVE-2026-68322.html * https://www.suse.com/security/cve/CVE-2026-68324.html * https://www.suse.com/security/cve/CVE-2026-68325.html * https://www.suse.com/security/cve/CVE-2026-68326.html * https://www.suse.com/security/cve/CVE-2026-68327.html * https://www.suse.com/security/cve/CVE-2026-68328.html * https://www.suse.com/security/cve/CVE-2026-68329.html * https://www.suse.com/security/cve/CVE-2026-68331.html * https://www.suse.com/security/cve/CVE-2026-68333.html * https://www.suse.com/security/cve/CVE-2026-68335.html * https://www.suse.com/security/cve/CVE-2026-68336.html * https://www.suse.com/security/cve/CVE-2026-68339.html * https://www.suse.com/security/cve/CVE-2026-68340.html * https://www.suse.com/security/cve/CVE-2026-68343.html * https://www.suse.com/security/cve/CVE-2026-68346.html * https://www.suse.com/security/cve/CVE-2026-68348.html * https://www.suse.com/security/cve/CVE-2026-68349.html * https://www.suse.com/security/cve/CVE-2026-68350.html * https://www.suse.com/security/cve/CVE-2026-68351.html * https://www.suse.com/security/cve/CVE-2026-68352.html * https://www.suse.com/security/cve/CVE-2026-68353.html * https://www.suse.com/security/cve/CVE-2026-68354.html * https://www.suse.com/security/cve/CVE-2026-68355.html * https://www.suse.com/security/cve/CVE-2026-68357.html * https://www.suse.com/security/cve/CVE-2026-68359.html * https://www.suse.com/security/cve/CVE-2026-68360.html * https://www.suse.com/security/cve/CVE-2026-68361.html * https://www.suse.com/security/cve/CVE-2026-68362.html * https://www.suse.com/security/cve/CVE-2026-68363.html * https://www.suse.com/security/cve/CVE-2026-68365.html * https://www.suse.com/security/cve/CVE-2026-68366.html * https://www.suse.com/security/cve/CVE-2026-68368.html * https://www.suse.com/security/cve/CVE-2026-68369.html * https://www.suse.com/security/cve/CVE-2026-68370.html * https://www.suse.com/security/cve/CVE-2026-68372.html * https://www.suse.com/security/cve/CVE-2026-68373.html * https://www.suse.com/security/cve/CVE-2026-68377.html * https://www.suse.com/security/cve/CVE-2026-68386.html * https://www.suse.com/security/cve/CVE-2026-68391.html * https://www.suse.com/security/cve/CVE-2026-68392.html * https://www.suse.com/security/cve/CVE-2026-68397.html * https://www.suse.com/security/cve/CVE-2026-68398.html * https://www.suse.com/security/cve/CVE-2026-68399.html * https://www.suse.com/security/cve/CVE-2026-68402.html * https://www.suse.com/security/cve/CVE-2026-68403.html * https://www.suse.com/security/cve/CVE-2026-68405.html * https://www.suse.com/security/cve/CVE-2026-68406.html * https://www.suse.com/security/cve/CVE-2026-68407.html * https://www.suse.com/security/cve/CVE-2026-68408.html * https://www.suse.com/security/cve/CVE-2026-68410.html * https://www.suse.com/security/cve/CVE-2026-68413.html * https://www.suse.com/security/cve/CVE-2026-68414.html * https://www.suse.com/security/cve/CVE-2026-68417.html * https://www.suse.com/security/cve/CVE-2026-68418.html * https://www.suse.com/security/cve/CVE-2026-68419.html * https://www.suse.com/security/cve/CVE-2026-68422.html * https://www.suse.com/security/cve/CVE-2026-68425.html * https://www.suse.com/security/cve/CVE-2026-68426.html * https://www.suse.com/security/cve/CVE-2026-68427.html * https://www.suse.com/security/cve/CVE-2026-68428.html * https://www.suse.com/security/cve/CVE-2026-68429.html * https://www.suse.com/security/cve/CVE-2026-68430.html * https://www.suse.com/security/cve/CVE-2026-68432.html * https://www.suse.com/security/cve/CVE-2026-68433.html * https://www.suse.com/security/cve/CVE-2026-68434.html * https://www.suse.com/security/cve/CVE-2026-68444.html * https://www.suse.com/security/cve/CVE-2026-68445.html * https://www.suse.com/security/cve/CVE-2026-68446.html * https://www.suse.com/security/cve/CVE-2026-68450.html * https://www.suse.com/security/cve/CVE-2026-68470.html * https://www.suse.com/security/cve/CVE-2026-68480.html * https://www.suse.com/security/cve/CVE-2026-72020.html * https://www.suse.com/security/cve/CVE-2026-72035.html * https://www.suse.com/security/cve/CVE-2026-72036.html * https://www.suse.com/security/cve/CVE-2026-72069.html * https://www.suse.com/security/cve/CVE-2026-72072.html * https://www.suse.com/security/cve/CVE-2026-72083.html * https://www.suse.com/security/cve/CVE-2026-72084.html * https://www.suse.com/security/cve/CVE-2026-72123.html * https://www.suse.com/security/cve/CVE-2026-72132.html * https://www.suse.com/security/cve/CVE-2026-72221.html * https://www.suse.com/security/cve/CVE-2026-72222.html * https://www.suse.com/security/cve/CVE-2026-72251.html * https://www.suse.com/security/cve/CVE-2026-72254.html * https://www.suse.com/security/cve/CVE-2026-72262.html * https://www.suse.com/security/cve/CVE-2026-72288.html * https://www.suse.com/security/cve/CVE-2026-72289.html * https://www.suse.com/security/cve/CVE-2026-72296.html * https://www.suse.com/security/cve/CVE-2026-72307.html * https://www.suse.com/security/cve/CVE-2026-72308.html * https://www.suse.com/security/cve/CVE-2026-72317.html * https://www.suse.com/security/cve/CVE-2026-72341.html * https://www.suse.com/security/cve/CVE-2026-72342.html * https://www.suse.com/security/cve/CVE-2026-72343.html * https://www.suse.com/security/cve/CVE-2026-72389.html * https://www.suse.com/security/cve/CVE-2026-72463.html * https://www.suse.com/security/cve/CVE-2026-72464.html * https://www.suse.com/security/cve/CVE-2026-72466.html * https://www.suse.com/security/cve/CVE-2026-72467.html * https://www.suse.com/security/cve/CVE-2026-72469.html * https://www.suse.com/security/cve/CVE-2026-72473.html * https://www.suse.com/security/cve/CVE-2026-72494.html * https://www.suse.com/security/cve/CVE-2026-72495.html * https://www.suse.com/security/cve/CVE-2026-72496.html * https://www.suse.com/security/cve/CVE-2026-72499.html * https://www.suse.com/security/cve/CVE-2026-72501.html * https://www.suse.com/security/cve/CVE-2026-72502.html * https://www.suse.com/security/cve/CVE-2026-74269.html * https://www.suse.com/security/cve/CVE-2026-74296.html * https://www.suse.com/security/cve/CVE-2026-74297.html * https://www.suse.com/security/cve/CVE-2026-74318.html * https://www.suse.com/security/cve/CVE-2026-74321.html * https://www.suse.com/security/cve/CVE-2026-74334.html * https://www.suse.com/security/cve/CVE-2026-74345.html * https://www.suse.com/security/cve/CVE-2026-74394.html * https://www.suse.com/security/cve/CVE-2026-74395.html * https://www.suse.com/security/cve/CVE-2026-74454.html * https://www.suse.com/security/cve/CVE-2026-74474.html * https://www.suse.com/security/cve/CVE-2026-74481.html * https://www.suse.com/security/cve/CVE-2026-74482.html * https://www.suse.com/security/cve/CVE-2026-74488.html * https://www.suse.com/security/cve/CVE-2026-74495.html * https://www.suse.com/security/cve/CVE-2026-74496.html * https://www.suse.com/security/cve/CVE-2026-74509.html * https://www.suse.com/security/cve/CVE-2026-74510.html * https://www.suse.com/security/cve/CVE-2026-74512.html * https://www.suse.com/security/cve/CVE-2026-74516.html * https://www.suse.com/security/cve/CVE-2026-74518.html * https://www.suse.com/security/cve/CVE-2026-74527.html * https://www.suse.com/security/cve/CVE-2026-74537.html * https://www.suse.com/security/cve/CVE-2026-74548.html * https://www.suse.com/security/cve/CVE-2026-74550.html * https://www.suse.com/security/cve/CVE-2026-74556.html * https://www.suse.com/security/cve/CVE-2026-74563.html * https://www.suse.com/security/cve/CVE-2026-74566.html * https://www.suse.com/security/cve/CVE-2026-74567.html * https://www.suse.com/security/cve/CVE-2026-74571.html * https://www.suse.com/security/cve/CVE-2026-74581.html * https://www.suse.com/security/cve/CVE-2026-74582.html * https://www.suse.com/security/cve/CVE-2026-74584.html * https://www.suse.com/security/cve/CVE-2026-74610.html * https://www.suse.com/security/cve/CVE-2026-74669.html * https://www.suse.com/security/cve/CVE-2026-74692.html * https://www.suse.com/security/cve/CVE-2026-74694.html * https://www.suse.com/security/cve/CVE-2026-74695.html * https://www.suse.com/security/cve/CVE-2026-74717.html * https://www.suse.com/security/cve/CVE-2026-74722.html * https://www.suse.com/security/cve/CVE-2026-80529.html * https://www.suse.com/security/cve/CVE-2026-80534.html * https://www.suse.com/security/cve/CVE-2026-80590.html * https://www.suse.com/security/cve/CVE-2026-80654.html * https://bugzilla.suse.com/show_bug.cgi?id=1230238 * https://bugzilla.suse.com/show_bug.cgi?id=1235944 * https://bugzilla.suse.com/show_bug.cgi?id=1247455 * https://bugzilla.suse.com/show_bug.cgi?id=1250748 * https://bugzilla.suse.com/show_bug.cgi?id=1251966 * https://bugzilla.suse.com/show_bug.cgi?id=1252682 * https://bugzilla.suse.com/show_bug.cgi?id=1254306 * https://bugzilla.suse.com/show_bug.cgi?id=1255225 * https://bugzilla.suse.com/show_bug.cgi?id=1255250 * https://bugzilla.suse.com/show_bug.cgi?id=1256629 * https://bugzilla.suse.com/show_bug.cgi?id=1256708 * https://bugzilla.suse.com/show_bug.cgi?id=1257154 * https://bugzilla.suse.com/show_bug.cgi?id=1258430 * https://bugzilla.suse.com/show_bug.cgi?id=1258517 * https://bugzilla.suse.com/show_bug.cgi?id=1260522 * https://bugzilla.suse.com/show_bug.cgi?id=1261780 * https://bugzilla.suse.com/show_bug.cgi?id=1261788 * https://bugzilla.suse.com/show_bug.cgi?id=1262073 * https://bugzilla.suse.com/show_bug.cgi?id=1263004 * https://bugzilla.suse.com/show_bug.cgi?id=1263061 * https://bugzilla.suse.com/show_bug.cgi?id=1263133 * https://bugzilla.suse.com/show_bug.cgi?id=1264335 * https://bugzilla.suse.com/show_bug.cgi?id=1264446 * https://bugzilla.suse.com/show_bug.cgi?id=1264541 * https://bugzilla.suse.com/show_bug.cgi?id=1264584 * https://bugzilla.suse.com/show_bug.cgi?id=1264587 * https://bugzilla.suse.com/show_bug.cgi?id=1264619 * https://bugzilla.suse.com/show_bug.cgi?id=1264788 * https://bugzilla.suse.com/show_bug.cgi?id=1265068 * https://bugzilla.suse.com/show_bug.cgi?id=1265121 * https://bugzilla.suse.com/show_bug.cgi?id=1265449 * https://bugzilla.suse.com/show_bug.cgi?id=1265928 * https://bugzilla.suse.com/show_bug.cgi?id=1266402 * https://bugzilla.suse.com/show_bug.cgi?id=1266860 * https://bugzilla.suse.com/show_bug.cgi?id=1266874 * https://bugzilla.suse.com/show_bug.cgi?id=1266897 * https://bugzilla.suse.com/show_bug.cgi?id=1267023 * https://bugzilla.suse.com/show_bug.cgi?id=1267238 * https://bugzilla.suse.com/show_bug.cgi?id=1267501 * https://bugzilla.suse.com/show_bug.cgi?id=1267612 * https://bugzilla.suse.com/show_bug.cgi?id=1268276 * https://bugzilla.suse.com/show_bug.cgi?id=1268972 * https://bugzilla.suse.com/show_bug.cgi?id=1268979 * https://bugzilla.suse.com/show_bug.cgi?id=1268987 * https://bugzilla.suse.com/show_bug.cgi?id=1269004 * https://bugzilla.suse.com/show_bug.cgi?id=1269013 * https://bugzilla.suse.com/show_bug.cgi?id=1269108 * https://bugzilla.suse.com/show_bug.cgi?id=1269113 * https://bugzilla.suse.com/show_bug.cgi?id=1269114 * https://bugzilla.suse.com/show_bug.cgi?id=1269126 * https://bugzilla.suse.com/show_bug.cgi?id=1269167 * https://bugzilla.suse.com/show_bug.cgi?id=1269234 * https://bugzilla.suse.com/show_bug.cgi?id=1269238 * https://bugzilla.suse.com/show_bug.cgi?id=1269242 * https://bugzilla.suse.com/show_bug.cgi?id=1269256 * https://bugzilla.suse.com/show_bug.cgi?id=1269301 * https://bugzilla.suse.com/show_bug.cgi?id=1269306 * https://bugzilla.suse.com/show_bug.cgi?id=1269381 * https://bugzilla.suse.com/show_bug.cgi?id=1269388 * https://bugzilla.suse.com/show_bug.cgi?id=1269412 * https://bugzilla.suse.com/show_bug.cgi?id=1269530 * https://bugzilla.suse.com/show_bug.cgi?id=1269579 * https://bugzilla.suse.com/show_bug.cgi?id=1269590 * https://bugzilla.suse.com/show_bug.cgi?id=1269635 * https://bugzilla.suse.com/show_bug.cgi?id=1269655 * https://bugzilla.suse.com/show_bug.cgi?id=1269665 * https://bugzilla.suse.com/show_bug.cgi?id=1269686 * https://bugzilla.suse.com/show_bug.cgi?id=1269695 * https://bugzilla.suse.com/show_bug.cgi?id=1269713 * https://bugzilla.suse.com/show_bug.cgi?id=1269731 * https://bugzilla.suse.com/show_bug.cgi?id=1269774 * https://bugzilla.suse.com/show_bug.cgi?id=1269783 * https://bugzilla.suse.com/show_bug.cgi?id=1269792 * https://bugzilla.suse.com/show_bug.cgi?id=1269815 * https://bugzilla.suse.com/show_bug.cgi?id=1269965 * https://bugzilla.suse.com/show_bug.cgi?id=1269969 * https://bugzilla.suse.com/show_bug.cgi?id=1269981 * https://bugzilla.suse.com/show_bug.cgi?id=1269985 * https://bugzilla.suse.com/show_bug.cgi?id=1270090 * https://bugzilla.suse.com/show_bug.cgi?id=1270108 * https://bugzilla.suse.com/show_bug.cgi?id=1270111 * https://bugzilla.suse.com/show_bug.cgi?id=1270251 * https://bugzilla.suse.com/show_bug.cgi?id=1271256 * https://bugzilla.suse.com/show_bug.cgi?id=1271365 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 * https://bugzilla.suse.com/show_bug.cgi?id=1271825 * https://bugzilla.suse.com/show_bug.cgi?id=1271830 * https://bugzilla.suse.com/show_bug.cgi?id=1272150 * https://bugzilla.suse.com/show_bug.cgi?id=1272175 * https://bugzilla.suse.com/show_bug.cgi?id=1272179 * https://bugzilla.suse.com/show_bug.cgi?id=1272182 * https://bugzilla.suse.com/show_bug.cgi?id=1272200 * https://bugzilla.suse.com/show_bug.cgi?id=1272210 * https://bugzilla.suse.com/show_bug.cgi?id=1272213 * https://bugzilla.suse.com/show_bug.cgi?id=1272230 * https://bugzilla.suse.com/show_bug.cgi?id=1272260 * https://bugzilla.suse.com/show_bug.cgi?id=1272261 * https://bugzilla.suse.com/show_bug.cgi?id=1272262 * https://bugzilla.suse.com/show_bug.cgi?id=1272297 * https://bugzilla.suse.com/show_bug.cgi?id=1272346 * https://bugzilla.suse.com/show_bug.cgi?id=1272381 * https://bugzilla.suse.com/show_bug.cgi?id=1272385 * https://bugzilla.suse.com/show_bug.cgi?id=1272390 * https://bugzilla.suse.com/show_bug.cgi?id=1272423 * https://bugzilla.suse.com/show_bug.cgi?id=1272429 * https://bugzilla.suse.com/show_bug.cgi?id=1272484 * https://bugzilla.suse.com/show_bug.cgi?id=1272486 * https://bugzilla.suse.com/show_bug.cgi?id=1272497 * https://bugzilla.suse.com/show_bug.cgi?id=1272516 * https://bugzilla.suse.com/show_bug.cgi?id=1272569 * https://bugzilla.suse.com/show_bug.cgi?id=1272571 * https://bugzilla.suse.com/show_bug.cgi?id=1272641 * https://bugzilla.suse.com/show_bug.cgi?id=1272643 * https://bugzilla.suse.com/show_bug.cgi?id=1272662 * https://bugzilla.suse.com/show_bug.cgi?id=1272673 * https://bugzilla.suse.com/show_bug.cgi?id=1272680 * https://bugzilla.suse.com/show_bug.cgi?id=1272682 * https://bugzilla.suse.com/show_bug.cgi?id=1272756 * https://bugzilla.suse.com/show_bug.cgi?id=1272786 * https://bugzilla.suse.com/show_bug.cgi?id=1272788 * https://bugzilla.suse.com/show_bug.cgi?id=1272798 * https://bugzilla.suse.com/show_bug.cgi?id=1272799 * https://bugzilla.suse.com/show_bug.cgi?id=1272868 * https://bugzilla.suse.com/show_bug.cgi?id=1272877 * https://bugzilla.suse.com/show_bug.cgi?id=1272891 * https://bugzilla.suse.com/show_bug.cgi?id=1272963 * https://bugzilla.suse.com/show_bug.cgi?id=1272983 * https://bugzilla.suse.com/show_bug.cgi?id=1273008 * https://bugzilla.suse.com/show_bug.cgi?id=1273019 * https://bugzilla.suse.com/show_bug.cgi?id=1273027 * https://bugzilla.suse.com/show_bug.cgi?id=1273028 * https://bugzilla.suse.com/show_bug.cgi?id=1273030 * https://bugzilla.suse.com/show_bug.cgi?id=1273038 * https://bugzilla.suse.com/show_bug.cgi?id=1273053 * https://bugzilla.suse.com/show_bug.cgi?id=1273054 * https://bugzilla.suse.com/show_bug.cgi?id=1273060 * https://bugzilla.suse.com/show_bug.cgi?id=1273105 * https://bugzilla.suse.com/show_bug.cgi?id=1273249 * https://bugzilla.suse.com/show_bug.cgi?id=1273250 * https://bugzilla.suse.com/show_bug.cgi?id=1273260 * https://bugzilla.suse.com/show_bug.cgi?id=1273273 * https://bugzilla.suse.com/show_bug.cgi?id=1273274 * https://bugzilla.suse.com/show_bug.cgi?id=1273276 * https://bugzilla.suse.com/show_bug.cgi?id=1273281 * https://bugzilla.suse.com/show_bug.cgi?id=1273284 * https://bugzilla.suse.com/show_bug.cgi?id=1273285 * https://bugzilla.suse.com/show_bug.cgi?id=1273289 * https://bugzilla.suse.com/show_bug.cgi?id=1273291 * https://bugzilla.suse.com/show_bug.cgi?id=1273294 * https://bugzilla.suse.com/show_bug.cgi?id=1273302 * https://bugzilla.suse.com/show_bug.cgi?id=1273303 * https://bugzilla.suse.com/show_bug.cgi?id=1273305 * https://bugzilla.suse.com/show_bug.cgi?id=1273310 * https://bugzilla.suse.com/show_bug.cgi?id=1273311 * https://bugzilla.suse.com/show_bug.cgi?id=1273316 * https://bugzilla.suse.com/show_bug.cgi?id=1273318 * https://bugzilla.suse.com/show_bug.cgi?id=1273319 * https://bugzilla.suse.com/show_bug.cgi?id=1273323 * https://bugzilla.suse.com/show_bug.cgi?id=1273325 * https://bugzilla.suse.com/show_bug.cgi?id=1273327 * https://bugzilla.suse.com/show_bug.cgi?id=1273334 * https://bugzilla.suse.com/show_bug.cgi?id=1273335 * https://bugzilla.suse.com/show_bug.cgi?id=1273336 * https://bugzilla.suse.com/show_bug.cgi?id=1273337 * https://bugzilla.suse.com/show_bug.cgi?id=1273338 * https://bugzilla.suse.com/show_bug.cgi?id=1273340 * https://bugzilla.suse.com/show_bug.cgi?id=1273341 * https://bugzilla.suse.com/show_bug.cgi?id=1273346 * https://bugzilla.suse.com/show_bug.cgi?id=1273422 * https://bugzilla.suse.com/show_bug.cgi?id=1273426 * https://bugzilla.suse.com/show_bug.cgi?id=1273443 * https://bugzilla.suse.com/show_bug.cgi?id=1273463 * https://bugzilla.suse.com/show_bug.cgi?id=1273468 * https://bugzilla.suse.com/show_bug.cgi?id=1273469 * https://bugzilla.suse.com/show_bug.cgi?id=1273471 * https://bugzilla.suse.com/show_bug.cgi?id=1273479 * https://bugzilla.suse.com/show_bug.cgi?id=1273480 * https://bugzilla.suse.com/show_bug.cgi?id=1273482 * https://bugzilla.suse.com/show_bug.cgi?id=1273484 * https://bugzilla.suse.com/show_bug.cgi?id=1273488 * https://bugzilla.suse.com/show_bug.cgi?id=1273490 * https://bugzilla.suse.com/show_bug.cgi?id=1273501 * https://bugzilla.suse.com/show_bug.cgi?id=1273503 * https://bugzilla.suse.com/show_bug.cgi?id=1273504 * https://bugzilla.suse.com/show_bug.cgi?id=1273506 * https://bugzilla.suse.com/show_bug.cgi?id=1273523 * https://bugzilla.suse.com/show_bug.cgi?id=1273525 * https://bugzilla.suse.com/show_bug.cgi?id=1273533 * https://bugzilla.suse.com/show_bug.cgi?id=1273536 * https://bugzilla.suse.com/show_bug.cgi?id=1273542 * https://bugzilla.suse.com/show_bug.cgi?id=1273555 * https://bugzilla.suse.com/show_bug.cgi?id=1273578 * https://bugzilla.suse.com/show_bug.cgi?id=1273579 * https://bugzilla.suse.com/show_bug.cgi?id=1273582 * https://bugzilla.suse.com/show_bug.cgi?id=1273596 * https://bugzilla.suse.com/show_bug.cgi?id=1273597 * https://bugzilla.suse.com/show_bug.cgi?id=1273598 * https://bugzilla.suse.com/show_bug.cgi?id=1273600 * https://bugzilla.suse.com/show_bug.cgi?id=1273601 * https://bugzilla.suse.com/show_bug.cgi?id=1273602 * https://bugzilla.suse.com/show_bug.cgi?id=1273603 * https://bugzilla.suse.com/show_bug.cgi?id=1273682 * https://bugzilla.suse.com/show_bug.cgi?id=1273734 * https://bugzilla.suse.com/show_bug.cgi?id=1273738 * https://bugzilla.suse.com/show_bug.cgi?id=1273739 * https://bugzilla.suse.com/show_bug.cgi?id=1273741 * https://bugzilla.suse.com/show_bug.cgi?id=1273742 * https://bugzilla.suse.com/show_bug.cgi?id=1273743 * https://bugzilla.suse.com/show_bug.cgi?id=1273745 * https://bugzilla.suse.com/show_bug.cgi?id=1273748 * https://bugzilla.suse.com/show_bug.cgi?id=1273749 * https://bugzilla.suse.com/show_bug.cgi?id=1273755 * https://bugzilla.suse.com/show_bug.cgi?id=1273762 * https://bugzilla.suse.com/show_bug.cgi?id=1273765 * https://bugzilla.suse.com/show_bug.cgi?id=1273766 * https://bugzilla.suse.com/show_bug.cgi?id=1273769 * https://bugzilla.suse.com/show_bug.cgi?id=1273774 * https://bugzilla.suse.com/show_bug.cgi?id=1273778 * https://bugzilla.suse.com/show_bug.cgi?id=1273780 * https://bugzilla.suse.com/show_bug.cgi?id=1273790 * https://bugzilla.suse.com/show_bug.cgi?id=1273796 * https://bugzilla.suse.com/show_bug.cgi?id=1273804 * https://bugzilla.suse.com/show_bug.cgi?id=1273810 * https://bugzilla.suse.com/show_bug.cgi?id=1273811 * https://bugzilla.suse.com/show_bug.cgi?id=1273813 * https://bugzilla.suse.com/show_bug.cgi?id=1273817 * https://bugzilla.suse.com/show_bug.cgi?id=1273822 * https://bugzilla.suse.com/show_bug.cgi?id=1273824 * https://bugzilla.suse.com/show_bug.cgi?id=1273831 * https://bugzilla.suse.com/show_bug.cgi?id=1273832 * https://bugzilla.suse.com/show_bug.cgi?id=1273834 * https://bugzilla.suse.com/show_bug.cgi?id=1273838 * https://bugzilla.suse.com/show_bug.cgi?id=1273844 * https://bugzilla.suse.com/show_bug.cgi?id=1273849 * https://bugzilla.suse.com/show_bug.cgi?id=1273860 * https://bugzilla.suse.com/show_bug.cgi?id=1273862 * https://bugzilla.suse.com/show_bug.cgi?id=1273867 * https://bugzilla.suse.com/show_bug.cgi?id=1273868 * https://bugzilla.suse.com/show_bug.cgi?id=1273869 * https://bugzilla.suse.com/show_bug.cgi?id=1273872 * https://bugzilla.suse.com/show_bug.cgi?id=1273876 * https://bugzilla.suse.com/show_bug.cgi?id=1273877 * https://bugzilla.suse.com/show_bug.cgi?id=1273880 * https://bugzilla.suse.com/show_bug.cgi?id=1273882 * https://bugzilla.suse.com/show_bug.cgi?id=1273890 * https://bugzilla.suse.com/show_bug.cgi?id=1273891 * https://bugzilla.suse.com/show_bug.cgi?id=1273892 * https://bugzilla.suse.com/show_bug.cgi?id=1273895 * https://bugzilla.suse.com/show_bug.cgi?id=1273896 * https://bugzilla.suse.com/show_bug.cgi?id=1273903 * https://bugzilla.suse.com/show_bug.cgi?id=1273905 * https://bugzilla.suse.com/show_bug.cgi?id=1273930 * https://bugzilla.suse.com/show_bug.cgi?id=1273933 * https://bugzilla.suse.com/show_bug.cgi?id=1273934 * https://bugzilla.suse.com/show_bug.cgi?id=1273935 * https://bugzilla.suse.com/show_bug.cgi?id=1273936 * https://bugzilla.suse.com/show_bug.cgi?id=1273939 * https://bugzilla.suse.com/show_bug.cgi?id=1273940 * https://bugzilla.suse.com/show_bug.cgi?id=1273941 * https://bugzilla.suse.com/show_bug.cgi?id=1273942 * https://bugzilla.suse.com/show_bug.cgi?id=1273944 * https://bugzilla.suse.com/show_bug.cgi?id=1273945 * https://bugzilla.suse.com/show_bug.cgi?id=1273946 * https://bugzilla.suse.com/show_bug.cgi?id=1273956 * https://bugzilla.suse.com/show_bug.cgi?id=1273957 * https://bugzilla.suse.com/show_bug.cgi?id=1273958 * https://bugzilla.suse.com/show_bug.cgi?id=1273966 * https://bugzilla.suse.com/show_bug.cgi?id=1273967 * https://bugzilla.suse.com/show_bug.cgi?id=1273968 * https://bugzilla.suse.com/show_bug.cgi?id=1273972 * https://bugzilla.suse.com/show_bug.cgi?id=1273974 * https://bugzilla.suse.com/show_bug.cgi?id=1273975 * https://bugzilla.suse.com/show_bug.cgi?id=1273977 * https://bugzilla.suse.com/show_bug.cgi?id=1273982 * https://bugzilla.suse.com/show_bug.cgi?id=1273988 * https://bugzilla.suse.com/show_bug.cgi?id=1273990 * https://bugzilla.suse.com/show_bug.cgi?id=1273991 * https://bugzilla.suse.com/show_bug.cgi?id=1273995 * https://bugzilla.suse.com/show_bug.cgi?id=1274001 * https://bugzilla.suse.com/show_bug.cgi?id=1274003 * https://bugzilla.suse.com/show_bug.cgi?id=1274006 * https://bugzilla.suse.com/show_bug.cgi?id=1274011 * https://bugzilla.suse.com/show_bug.cgi?id=1274012 * https://bugzilla.suse.com/show_bug.cgi?id=1274014 * https://bugzilla.suse.com/show_bug.cgi?id=1274017 * https://bugzilla.suse.com/show_bug.cgi?id=1274019 * https://bugzilla.suse.com/show_bug.cgi?id=1274020 * https://bugzilla.suse.com/show_bug.cgi?id=1274026 * https://bugzilla.suse.com/show_bug.cgi?id=1274028 * https://bugzilla.suse.com/show_bug.cgi?id=1274030 * https://bugzilla.suse.com/show_bug.cgi?id=1274031 * https://bugzilla.suse.com/show_bug.cgi?id=1274035 * https://bugzilla.suse.com/show_bug.cgi?id=1274040 * https://bugzilla.suse.com/show_bug.cgi?id=1274041 * https://bugzilla.suse.com/show_bug.cgi?id=1274057 * https://bugzilla.suse.com/show_bug.cgi?id=1274058 * https://bugzilla.suse.com/show_bug.cgi?id=1274061 * https://bugzilla.suse.com/show_bug.cgi?id=1274063 * https://bugzilla.suse.com/show_bug.cgi?id=1274065 * https://bugzilla.suse.com/show_bug.cgi?id=1274067 * https://bugzilla.suse.com/show_bug.cgi?id=1274075 * https://bugzilla.suse.com/show_bug.cgi?id=1274076 * https://bugzilla.suse.com/show_bug.cgi?id=1274077 * https://bugzilla.suse.com/show_bug.cgi?id=1274078 * https://bugzilla.suse.com/show_bug.cgi?id=1274208 * https://bugzilla.suse.com/show_bug.cgi?id=1274226 * https://bugzilla.suse.com/show_bug.cgi?id=1274239 * https://bugzilla.suse.com/show_bug.cgi?id=1274243 * https://bugzilla.suse.com/show_bug.cgi?id=1274258 * https://bugzilla.suse.com/show_bug.cgi?id=1274265 * https://bugzilla.suse.com/show_bug.cgi?id=1274274 * https://bugzilla.suse.com/show_bug.cgi?id=1274277 * https://bugzilla.suse.com/show_bug.cgi?id=1274278 * https://bugzilla.suse.com/show_bug.cgi?id=1274281 * https://bugzilla.suse.com/show_bug.cgi?id=1274283 * https://bugzilla.suse.com/show_bug.cgi?id=1274286 * https://bugzilla.suse.com/show_bug.cgi?id=1274290 * https://bugzilla.suse.com/show_bug.cgi?id=1274294 * https://bugzilla.suse.com/show_bug.cgi?id=1274296 * https://bugzilla.suse.com/show_bug.cgi?id=1274297 * https://bugzilla.suse.com/show_bug.cgi?id=1274298 * https://bugzilla.suse.com/show_bug.cgi?id=1274314 * https://bugzilla.suse.com/show_bug.cgi?id=1274321 * https://bugzilla.suse.com/show_bug.cgi?id=1274491 * https://bugzilla.suse.com/show_bug.cgi?id=1274497 * https://bugzilla.suse.com/show_bug.cgi?id=1274539 * https://bugzilla.suse.com/show_bug.cgi?id=1274541 * https://bugzilla.suse.com/show_bug.cgi?id=1274543 * https://bugzilla.suse.com/show_bug.cgi?id=1274545 * https://bugzilla.suse.com/show_bug.cgi?id=1274547 * https://bugzilla.suse.com/show_bug.cgi?id=1274550 * https://bugzilla.suse.com/show_bug.cgi?id=1274573 * https://bugzilla.suse.com/show_bug.cgi?id=1274578 * https://bugzilla.suse.com/show_bug.cgi?id=1274580 * https://bugzilla.suse.com/show_bug.cgi?id=1274581 * https://bugzilla.suse.com/show_bug.cgi?id=1274620 * https://bugzilla.suse.com/show_bug.cgi?id=1274622 * https://bugzilla.suse.com/show_bug.cgi?id=1274624 * https://bugzilla.suse.com/show_bug.cgi?id=1274629 * https://bugzilla.suse.com/show_bug.cgi?id=1274632 * https://bugzilla.suse.com/show_bug.cgi?id=1274636 * https://bugzilla.suse.com/show_bug.cgi?id=1274639 * https://bugzilla.suse.com/show_bug.cgi?id=1274640 * https://bugzilla.suse.com/show_bug.cgi?id=1274642 * https://bugzilla.suse.com/show_bug.cgi?id=1274644 * https://bugzilla.suse.com/show_bug.cgi?id=1274645 * https://bugzilla.suse.com/show_bug.cgi?id=1274646 * https://bugzilla.suse.com/show_bug.cgi?id=1274649 * https://bugzilla.suse.com/show_bug.cgi?id=1274650 * https://bugzilla.suse.com/show_bug.cgi?id=1274651 * https://bugzilla.suse.com/show_bug.cgi?id=1274656 * https://bugzilla.suse.com/show_bug.cgi?id=1274659 * https://bugzilla.suse.com/show_bug.cgi?id=1274662 * https://bugzilla.suse.com/show_bug.cgi?id=1274663 * https://bugzilla.suse.com/show_bug.cgi?id=1274665 * https://bugzilla.suse.com/show_bug.cgi?id=1274667 * https://bugzilla.suse.com/show_bug.cgi?id=1274670 * https://bugzilla.suse.com/show_bug.cgi?id=1274675 * https://bugzilla.suse.com/show_bug.cgi?id=1274677 * https://bugzilla.suse.com/show_bug.cgi?id=1274678 * https://bugzilla.suse.com/show_bug.cgi?id=1274679 * https://bugzilla.suse.com/show_bug.cgi?id=1274681 * https://bugzilla.suse.com/show_bug.cgi?id=1274682 * https://bugzilla.suse.com/show_bug.cgi?id=1274690 * https://bugzilla.suse.com/show_bug.cgi?id=1274694 * https://bugzilla.suse.com/show_bug.cgi?id=1274696 * https://bugzilla.suse.com/show_bug.cgi?id=1274698 * https://bugzilla.suse.com/show_bug.cgi?id=1274699 * https://bugzilla.suse.com/show_bug.cgi?id=1274700 * https://bugzilla.suse.com/show_bug.cgi?id=1274702 * https://bugzilla.suse.com/show_bug.cgi?id=1274703 * https://bugzilla.suse.com/show_bug.cgi?id=1274705 * https://bugzilla.suse.com/show_bug.cgi?id=1274706 * https://bugzilla.suse.com/show_bug.cgi?id=1274709 * https://bugzilla.suse.com/show_bug.cgi?id=1274710 * https://bugzilla.suse.com/show_bug.cgi?id=1274713 * https://bugzilla.suse.com/show_bug.cgi?id=1274716 * https://bugzilla.suse.com/show_bug.cgi?id=1274721 * https://bugzilla.suse.com/show_bug.cgi?id=1274725 * https://bugzilla.suse.com/show_bug.cgi?id=1274737 * https://bugzilla.suse.com/show_bug.cgi?id=1274738 * https://bugzilla.suse.com/show_bug.cgi?id=1274749 * https://bugzilla.suse.com/show_bug.cgi?id=1274752 * https://bugzilla.suse.com/show_bug.cgi?id=1274753 * https://bugzilla.suse.com/show_bug.cgi?id=1274754 * https://bugzilla.suse.com/show_bug.cgi?id=1274755 * https://bugzilla.suse.com/show_bug.cgi?id=1274756 * https://bugzilla.suse.com/show_bug.cgi?id=1274764 * https://bugzilla.suse.com/show_bug.cgi?id=1274768 * https://bugzilla.suse.com/show_bug.cgi?id=1274770 * https://bugzilla.suse.com/show_bug.cgi?id=1274787 * https://bugzilla.suse.com/show_bug.cgi?id=1274800 * https://bugzilla.suse.com/show_bug.cgi?id=1274801 * https://bugzilla.suse.com/show_bug.cgi?id=1274802 * https://bugzilla.suse.com/show_bug.cgi?id=1274804 * https://bugzilla.suse.com/show_bug.cgi?id=1274805 * https://bugzilla.suse.com/show_bug.cgi?id=1274807 * https://bugzilla.suse.com/show_bug.cgi?id=1274808 * https://bugzilla.suse.com/show_bug.cgi?id=1274811 * https://bugzilla.suse.com/show_bug.cgi?id=1274813 * https://bugzilla.suse.com/show_bug.cgi?id=1274814 * https://bugzilla.suse.com/show_bug.cgi?id=1274831 * https://bugzilla.suse.com/show_bug.cgi?id=1274834 * https://bugzilla.suse.com/show_bug.cgi?id=1274847 * https://bugzilla.suse.com/show_bug.cgi?id=1274853 * https://bugzilla.suse.com/show_bug.cgi?id=1274868 * https://bugzilla.suse.com/show_bug.cgi?id=1274869 * https://bugzilla.suse.com/show_bug.cgi?id=1274872 * https://bugzilla.suse.com/show_bug.cgi?id=1274873 * https://bugzilla.suse.com/show_bug.cgi?id=1274874 * https://bugzilla.suse.com/show_bug.cgi?id=1274876 * https://bugzilla.suse.com/show_bug.cgi?id=1274879 * https://bugzilla.suse.com/show_bug.cgi?id=1274881 * https://bugzilla.suse.com/show_bug.cgi?id=1274883 * https://bugzilla.suse.com/show_bug.cgi?id=1274886 * https://bugzilla.suse.com/show_bug.cgi?id=1274888 * https://bugzilla.suse.com/show_bug.cgi?id=1274891 * https://bugzilla.suse.com/show_bug.cgi?id=1274892 * https://bugzilla.suse.com/show_bug.cgi?id=1274893 * https://bugzilla.suse.com/show_bug.cgi?id=1274894 * https://bugzilla.suse.com/show_bug.cgi?id=1274896 * https://bugzilla.suse.com/show_bug.cgi?id=1274897 * https://bugzilla.suse.com/show_bug.cgi?id=1274898 * https://bugzilla.suse.com/show_bug.cgi?id=1274899 * https://bugzilla.suse.com/show_bug.cgi?id=1274901 * https://bugzilla.suse.com/show_bug.cgi?id=1274902 * https://bugzilla.suse.com/show_bug.cgi?id=1274905 * https://bugzilla.suse.com/show_bug.cgi?id=1274907 * https://bugzilla.suse.com/show_bug.cgi?id=1274908 * https://bugzilla.suse.com/show_bug.cgi?id=1274913 * https://bugzilla.suse.com/show_bug.cgi?id=1274914 * https://bugzilla.suse.com/show_bug.cgi?id=1274920 * https://bugzilla.suse.com/show_bug.cgi?id=1274921 * https://bugzilla.suse.com/show_bug.cgi?id=1274924 * https://bugzilla.suse.com/show_bug.cgi?id=1274925 * https://bugzilla.suse.com/show_bug.cgi?id=1274929 * https://bugzilla.suse.com/show_bug.cgi?id=1274930 * https://bugzilla.suse.com/show_bug.cgi?id=1274933 * https://bugzilla.suse.com/show_bug.cgi?id=1274934 * https://bugzilla.suse.com/show_bug.cgi?id=1274935 * https://bugzilla.suse.com/show_bug.cgi?id=1274941 * https://bugzilla.suse.com/show_bug.cgi?id=1274945 * https://bugzilla.suse.com/show_bug.cgi?id=1274947 * https://bugzilla.suse.com/show_bug.cgi?id=1274951 * https://bugzilla.suse.com/show_bug.cgi?id=1274953 * https://bugzilla.suse.com/show_bug.cgi?id=1274958 * https://bugzilla.suse.com/show_bug.cgi?id=1274968 * https://bugzilla.suse.com/show_bug.cgi?id=1274981 * https://bugzilla.suse.com/show_bug.cgi?id=1275040 * https://bugzilla.suse.com/show_bug.cgi?id=1275069 * https://bugzilla.suse.com/show_bug.cgi?id=1275071 * https://bugzilla.suse.com/show_bug.cgi?id=1275073 * https://bugzilla.suse.com/show_bug.cgi?id=1275076 * https://bugzilla.suse.com/show_bug.cgi?id=1275080 * https://bugzilla.suse.com/show_bug.cgi?id=1275083 * https://bugzilla.suse.com/show_bug.cgi?id=1275088 * https://bugzilla.suse.com/show_bug.cgi?id=1275091 * https://bugzilla.suse.com/show_bug.cgi?id=1275125 * https://bugzilla.suse.com/show_bug.cgi?id=1275126 * https://bugzilla.suse.com/show_bug.cgi?id=1275131 * https://bugzilla.suse.com/show_bug.cgi?id=1275132 * https://bugzilla.suse.com/show_bug.cgi?id=1275150 * https://bugzilla.suse.com/show_bug.cgi?id=1275152 * https://bugzilla.suse.com/show_bug.cgi?id=1275154 * https://bugzilla.suse.com/show_bug.cgi?id=1275155 * https://bugzilla.suse.com/show_bug.cgi?id=1275157 * https://bugzilla.suse.com/show_bug.cgi?id=1275158 * https://bugzilla.suse.com/show_bug.cgi?id=1275161 * https://bugzilla.suse.com/show_bug.cgi?id=1275163 * https://bugzilla.suse.com/show_bug.cgi?id=1275164 * https://bugzilla.suse.com/show_bug.cgi?id=1275169 * https://bugzilla.suse.com/show_bug.cgi?id=1275173 * https://bugzilla.suse.com/show_bug.cgi?id=1275176 * https://bugzilla.suse.com/show_bug.cgi?id=1275185 * https://bugzilla.suse.com/show_bug.cgi?id=1275190 * https://bugzilla.suse.com/show_bug.cgi?id=1275236 * https://bugzilla.suse.com/show_bug.cgi?id=1275237 * https://bugzilla.suse.com/show_bug.cgi?id=1275239 * https://bugzilla.suse.com/show_bug.cgi?id=1275294 * https://bugzilla.suse.com/show_bug.cgi?id=1275301 * https://bugzilla.suse.com/show_bug.cgi?id=1275303 * https://bugzilla.suse.com/show_bug.cgi?id=1275304 * https://bugzilla.suse.com/show_bug.cgi?id=1275305 * https://bugzilla.suse.com/show_bug.cgi?id=1275306 * https://bugzilla.suse.com/show_bug.cgi?id=1275307 * https://bugzilla.suse.com/show_bug.cgi?id=1275470 * https://bugzilla.suse.com/show_bug.cgi?id=1275472 * https://bugzilla.suse.com/show_bug.cgi?id=1275474 * https://bugzilla.suse.com/show_bug.cgi?id=1275479 * https://bugzilla.suse.com/show_bug.cgi?id=1275483 * https://bugzilla.suse.com/show_bug.cgi?id=1275486 * https://bugzilla.suse.com/show_bug.cgi?id=1275487 * https://bugzilla.suse.com/show_bug.cgi?id=1275506 * https://bugzilla.suse.com/show_bug.cgi?id=1275509 * https://bugzilla.suse.com/show_bug.cgi?id=1275511 * https://bugzilla.suse.com/show_bug.cgi?id=1275517 * https://bugzilla.suse.com/show_bug.cgi?id=1275528 * https://bugzilla.suse.com/show_bug.cgi?id=1275535 * https://bugzilla.suse.com/show_bug.cgi?id=1275540 * https://bugzilla.suse.com/show_bug.cgi?id=1275553 * https://bugzilla.suse.com/show_bug.cgi?id=1275555 * https://bugzilla.suse.com/show_bug.cgi?id=1275561 * https://bugzilla.suse.com/show_bug.cgi?id=1275566 * https://bugzilla.suse.com/show_bug.cgi?id=1275569 * https://bugzilla.suse.com/show_bug.cgi?id=1275574 * https://bugzilla.suse.com/show_bug.cgi?id=1275578 * https://bugzilla.suse.com/show_bug.cgi?id=1275582 * https://bugzilla.suse.com/show_bug.cgi?id=1275583 * https://bugzilla.suse.com/show_bug.cgi?id=1275584 * https://bugzilla.suse.com/show_bug.cgi?id=1275591 * https://bugzilla.suse.com/show_bug.cgi?id=1275595 * https://bugzilla.suse.com/show_bug.cgi?id=1275633 * https://bugzilla.suse.com/show_bug.cgi?id=1275636 * https://bugzilla.suse.com/show_bug.cgi?id=1275650 * https://bugzilla.suse.com/show_bug.cgi?id=1275659 * https://bugzilla.suse.com/show_bug.cgi?id=1275665 * https://bugzilla.suse.com/show_bug.cgi?id=1275669 * https://bugzilla.suse.com/show_bug.cgi?id=1275687 * https://bugzilla.suse.com/show_bug.cgi?id=1275688 * https://bugzilla.suse.com/show_bug.cgi?id=1275695 * https://bugzilla.suse.com/show_bug.cgi?id=1275696 * https://bugzilla.suse.com/show_bug.cgi?id=1275704 * https://bugzilla.suse.com/show_bug.cgi?id=1275782 * https://bugzilla.suse.com/show_bug.cgi?id=1275784 * https://bugzilla.suse.com/show_bug.cgi?id=1275787 * https://bugzilla.suse.com/show_bug.cgi?id=1275788 * https://bugzilla.suse.com/show_bug.cgi?id=1275790 * https://bugzilla.suse.com/show_bug.cgi?id=1275797 * https://bugzilla.suse.com/show_bug.cgi?id=1275798 * https://bugzilla.suse.com/show_bug.cgi?id=1275805 * https://bugzilla.suse.com/show_bug.cgi?id=1275817 * https://bugzilla.suse.com/show_bug.cgi?id=1275818 * https://bugzilla.suse.com/show_bug.cgi?id=1275819 * https://bugzilla.suse.com/show_bug.cgi?id=1275820 * https://bugzilla.suse.com/show_bug.cgi?id=1275821 * https://bugzilla.suse.com/show_bug.cgi?id=1275827 * https://bugzilla.suse.com/show_bug.cgi?id=1275864 * https://bugzilla.suse.com/show_bug.cgi?id=1275867 * https://bugzilla.suse.com/show_bug.cgi?id=1275869 * https://bugzilla.suse.com/show_bug.cgi?id=1275870 * https://bugzilla.suse.com/show_bug.cgi?id=1275871 * https://bugzilla.suse.com/show_bug.cgi?id=1275872 * https://bugzilla.suse.com/show_bug.cgi?id=1275886 * https://bugzilla.suse.com/show_bug.cgi?id=1275905 * https://bugzilla.suse.com/show_bug.cgi?id=1275923 * https://bugzilla.suse.com/show_bug.cgi?id=1275925 * https://bugzilla.suse.com/show_bug.cgi?id=1275946 * https://bugzilla.suse.com/show_bug.cgi?id=1275950 * https://bugzilla.suse.com/show_bug.cgi?id=1275954 * https://bugzilla.suse.com/show_bug.cgi?id=1275970 * https://bugzilla.suse.com/show_bug.cgi?id=1275973 * https://bugzilla.suse.com/show_bug.cgi?id=1275975 * https://bugzilla.suse.com/show_bug.cgi?id=1275976 * https://bugzilla.suse.com/show_bug.cgi?id=1276029 * https://bugzilla.suse.com/show_bug.cgi?id=1276257 * https://bugzilla.suse.com/show_bug.cgi?id=1276263 * https://bugzilla.suse.com/show_bug.cgi?id=1276270 * https://bugzilla.suse.com/show_bug.cgi?id=1276273 * https://bugzilla.suse.com/show_bug.cgi?id=1276277 * https://bugzilla.suse.com/show_bug.cgi?id=1276335 * https://bugzilla.suse.com/show_bug.cgi?id=1276346 * https://bugzilla.suse.com/show_bug.cgi?id=1276350 * https://bugzilla.suse.com/show_bug.cgi?id=1276355 * https://bugzilla.suse.com/show_bug.cgi?id=1276446 * https://bugzilla.suse.com/show_bug.cgi?id=1276452 * https://bugzilla.suse.com/show_bug.cgi?id=1276500 * https://bugzilla.suse.com/show_bug.cgi?id=1276507 * https://bugzilla.suse.com/show_bug.cgi?id=1276542 * https://bugzilla.suse.com/show_bug.cgi?id=1276546 * https://bugzilla.suse.com/show_bug.cgi?id=1276551 * https://bugzilla.suse.com/show_bug.cgi?id=1276561 * https://bugzilla.suse.com/show_bug.cgi?id=1276569 * https://bugzilla.suse.com/show_bug.cgi?id=1276665 * https://bugzilla.suse.com/show_bug.cgi?id=1276864 * https://bugzilla.suse.com/show_bug.cgi?id=1276927 * https://bugzilla.suse.com/show_bug.cgi?id=1276931 * https://bugzilla.suse.com/show_bug.cgi?id=1276937 * https://bugzilla.suse.com/show_bug.cgi?id=1276941 * https://bugzilla.suse.com/show_bug.cgi?id=1276943 * https://bugzilla.suse.com/show_bug.cgi?id=1276961 * https://bugzilla.suse.com/show_bug.cgi?id=1277022 * https://bugzilla.suse.com/show_bug.cgi?id=1277034 * https://bugzilla.suse.com/show_bug.cgi?id=1277037 * https://bugzilla.suse.com/show_bug.cgi?id=1277047 * https://bugzilla.suse.com/show_bug.cgi?id=1277054 * https://bugzilla.suse.com/show_bug.cgi?id=1277057 * https://bugzilla.suse.com/show_bug.cgi?id=1277059 * https://bugzilla.suse.com/show_bug.cgi?id=1277064 * https://bugzilla.suse.com/show_bug.cgi?id=1277066 * https://bugzilla.suse.com/show_bug.cgi?id=1277069 * https://bugzilla.suse.com/show_bug.cgi?id=1277073 * https://bugzilla.suse.com/show_bug.cgi?id=1277077 * https://bugzilla.suse.com/show_bug.cgi?id=1277095 * https://bugzilla.suse.com/show_bug.cgi?id=1277155 * https://bugzilla.suse.com/show_bug.cgi?id=1277159 * https://bugzilla.suse.com/show_bug.cgi?id=1277160 * https://bugzilla.suse.com/show_bug.cgi?id=1277202 * https://bugzilla.suse.com/show_bug.cgi?id=1277204 * https://bugzilla.suse.com/show_bug.cgi?id=1277275 * https://bugzilla.suse.com/show_bug.cgi?id=1277285 * https://bugzilla.suse.com/show_bug.cgi?id=1277391 * https://bugzilla.suse.com/show_bug.cgi?id=1277408 * https://bugzilla.suse.com/show_bug.cgi?id=1277516 * https://bugzilla.suse.com/show_bug.cgi?id=1277523 * https://bugzilla.suse.com/show_bug.cgi?id=1277551 * https://bugzilla.suse.com/show_bug.cgi?id=1277625 * https://bugzilla.suse.com/show_bug.cgi?id=1277660 * https://bugzilla.suse.com/show_bug.cgi?id=1277678 * https://bugzilla.suse.com/show_bug.cgi?id=1277688 * https://bugzilla.suse.com/show_bug.cgi?id=1277775 * https://bugzilla.suse.com/show_bug.cgi?id=1277776 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 12:59:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 12:59:29 -0000 Subject: SUSE-SU-2026:23489-1: important: Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178895876939.1855.7998921722506048775@aaf27ed6f0fb> # Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23489-1 Release Date: 2026-09-08T13:49:37Z Rating: important References: * bsc#1270023 * bsc#1270024 * bsc#1271543 * bsc#1271867 Cross-References: * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-50.2 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-612=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_27-debugsource-2-1.1 * kernel-livepatch-6_4_0-50-default-2-1.1 * kernel-livepatch-6_4_0-50-default-debuginfo-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:00:17 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:00:17 -0000 Subject: SUSE-SU-2026:23488-1: important: Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178895881709.1855.12851779748046089816@aaf27ed6f0fb> # Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23488-1 Release Date: 2026-09-08T13:49:37Z Rating: important References: * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271370 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-46242 * CVE-2026-52956 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-53366 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-49.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-611=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-49-default-2-1.1 * kernel-livepatch-MICRO-6-0_Update_26-debugsource-2-1.1 * kernel-livepatch-6_4_0-49-default-debuginfo-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:01:08 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:01:08 -0000 Subject: SUSE-SU-2026:23487-1: important: Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178895886872.1855.5126493694967778015@aaf27ed6f0fb> # Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23487-1 Release Date: 2026-09-08T13:49:37Z Rating: important References: * bsc#1268281 * bsc#1269034 * bsc#1269822 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-53133 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves nine vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-48.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-610=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-48-default-3-1.1 * kernel-livepatch-MICRO-6-0_Update_25-debugsource-3-1.1 * kernel-livepatch-6_4_0-48-default-debuginfo-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:02:02 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:02:02 -0000 Subject: SUSE-SU-2026:23486-1: important: Security update for the Linux Kernel (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178895892257.1855.9151784985550457570@aaf27ed6f0fb> # Security update for the Linux Kernel (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23486-1 Release Date: 2026-09-08T13:49:37Z Rating: important References: * bsc#1267362 * bsc#1268281 * bsc#1269034 * bsc#1269196 * bsc#1269822 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-47.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-609=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-47-default-4-1.1 * kernel-livepatch-MICRO-6-0_Update_24-debugsource-4-1.1 * kernel-livepatch-6_4_0-47-default-debuginfo-4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:02:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:02:59 -0000 Subject: SUSE-SU-2026:23485-1: important: Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178895897903.1855.2566027628607208958@aaf27ed6f0fb> # Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23485-1 Release Date: 2026-09-08T13:49:37Z Rating: important References: * bsc#1267362 * bsc#1268281 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-43109 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 13 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues: The following security issues were fixed: * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-608=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-46-default-5-1.1 * kernel-livepatch-6_4_0-46-default-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0_Update_23-debugsource-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:04:02 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:04:02 -0000 Subject: SUSE-SU-2026:23484-1: important: Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178895904288.1855.11759962938777061432@aaf27ed6f0fb> # Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23484-1 Release Date: 2026-09-08T13:49:37Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 18 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-607=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-45-default-debuginfo-5-1.1 * kernel-livepatch-6_4_0-45-default-5-1.1 * kernel-livepatch-MICRO-6-0_Update_22-debugsource-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:05:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:05:06 -0000 Subject: SUSE-SU-2026:23483-1: important: Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178895910681.1855.14059248453770603689@aaf27ed6f0fb> # Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23483-1 Release Date: 2026-09-08T13:49:37Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 18 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-44.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-606=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-44-default-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0_Update_21-debugsource-5-1.1 * kernel-livepatch-6_4_0-44-default-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:06:17 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:06:17 -0000 Subject: SUSE-SU-2026:23482-1: important: Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178895917755.1855.2361471950613740963@aaf27ed6f0fb> # Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23482-1 Release Date: 2026-09-08T13:48:22Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues: The following security issues were fixed: * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-605=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-38-rt-debuginfo-11-1.1 * kernel-livepatch-6_4_0-38-rt-11-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_14-debugsource-11-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:20:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:20:50 -0000 Subject: SUSE-SU-2026:23481-1: important: Security update for the Linux Kernel Message-ID: <178896005012.1855.9049292368072441339@aaf27ed6f0fb> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:23481-1 Release Date: 2026-09-08T11:39:42Z Rating: important References: * bsc#1230238 * bsc#1235944 * bsc#1247455 * bsc#1250748 * bsc#1251966 * bsc#1252682 * bsc#1254306 * bsc#1255225 * bsc#1255250 * bsc#1256629 * bsc#1256708 * bsc#1257154 * bsc#1258430 * bsc#1258517 * bsc#1260522 * bsc#1261780 * bsc#1261788 * bsc#1262073 * bsc#1263004 * bsc#1263061 * bsc#1263133 * bsc#1264335 * bsc#1264446 * bsc#1264541 * bsc#1264584 * bsc#1264587 * bsc#1264619 * bsc#1264788 * bsc#1265068 * bsc#1265121 * bsc#1265449 * bsc#1265928 * bsc#1266402 * bsc#1266860 * bsc#1266874 * bsc#1266897 * bsc#1267023 * bsc#1267238 * bsc#1267501 * bsc#1267612 * bsc#1268276 * bsc#1268972 * bsc#1268979 * bsc#1268987 * bsc#1269004 * bsc#1269013 * bsc#1269108 * bsc#1269113 * bsc#1269114 * bsc#1269126 * bsc#1269167 * bsc#1269234 * bsc#1269238 * bsc#1269242 * bsc#1269256 * bsc#1269301 * bsc#1269306 * bsc#1269381 * bsc#1269388 * bsc#1269412 * bsc#1269530 * bsc#1269579 * bsc#1269590 * bsc#1269635 * bsc#1269655 * bsc#1269665 * bsc#1269686 * bsc#1269695 * bsc#1269713 * bsc#1269731 * bsc#1269774 * bsc#1269783 * bsc#1269792 * bsc#1269815 * bsc#1269965 * bsc#1269969 * bsc#1269981 * bsc#1269985 * bsc#1270090 * bsc#1270108 * bsc#1270111 * bsc#1270251 * bsc#1271256 * bsc#1271365 * bsc#1271366 * bsc#1271825 * bsc#1271830 * bsc#1272150 * bsc#1272175 * bsc#1272179 * bsc#1272182 * bsc#1272200 * bsc#1272210 * bsc#1272213 * bsc#1272230 * bsc#1272260 * bsc#1272261 * bsc#1272262 * bsc#1272297 * bsc#1272346 * bsc#1272381 * bsc#1272385 * bsc#1272390 * bsc#1272423 * bsc#1272429 * bsc#1272484 * bsc#1272486 * bsc#1272497 * bsc#1272516 * bsc#1272569 * bsc#1272571 * bsc#1272641 * bsc#1272643 * bsc#1272662 * bsc#1272673 * bsc#1272680 * bsc#1272682 * bsc#1272756 * bsc#1272786 * bsc#1272788 * bsc#1272798 * bsc#1272799 * bsc#1272868 * bsc#1272877 * bsc#1272891 * bsc#1272963 * bsc#1272983 * bsc#1273008 * bsc#1273019 * bsc#1273027 * bsc#1273028 * bsc#1273030 * bsc#1273038 * bsc#1273053 * bsc#1273054 * bsc#1273060 * bsc#1273105 * bsc#1273249 * bsc#1273250 * bsc#1273260 * bsc#1273273 * bsc#1273274 * bsc#1273276 * bsc#1273281 * bsc#1273284 * bsc#1273285 * bsc#1273289 * bsc#1273291 * bsc#1273294 * bsc#1273302 * bsc#1273303 * bsc#1273305 * bsc#1273310 * bsc#1273311 * bsc#1273316 * bsc#1273318 * bsc#1273319 * bsc#1273323 * bsc#1273325 * bsc#1273327 * bsc#1273334 * bsc#1273335 * bsc#1273336 * bsc#1273337 * bsc#1273338 * bsc#1273340 * bsc#1273341 * bsc#1273346 * bsc#1273422 * bsc#1273426 * bsc#1273443 * bsc#1273463 * bsc#1273468 * bsc#1273469 * bsc#1273471 * bsc#1273479 * bsc#1273480 * bsc#1273482 * bsc#1273484 * bsc#1273488 * bsc#1273490 * bsc#1273501 * bsc#1273503 * bsc#1273504 * bsc#1273506 * bsc#1273523 * bsc#1273525 * bsc#1273533 * bsc#1273536 * bsc#1273542 * bsc#1273555 * bsc#1273578 * bsc#1273579 * bsc#1273582 * bsc#1273596 * bsc#1273597 * bsc#1273598 * bsc#1273600 * bsc#1273601 * bsc#1273602 * bsc#1273603 * bsc#1273682 * bsc#1273734 * bsc#1273738 * bsc#1273739 * bsc#1273741 * bsc#1273742 * bsc#1273743 * bsc#1273745 * bsc#1273748 * bsc#1273749 * bsc#1273755 * bsc#1273762 * bsc#1273765 * bsc#1273766 * bsc#1273769 * bsc#1273774 * bsc#1273778 * bsc#1273780 * bsc#1273790 * bsc#1273796 * bsc#1273804 * bsc#1273810 * bsc#1273811 * bsc#1273813 * bsc#1273817 * bsc#1273822 * bsc#1273824 * bsc#1273831 * bsc#1273832 * bsc#1273834 * bsc#1273838 * bsc#1273844 * bsc#1273849 * bsc#1273860 * bsc#1273862 * bsc#1273867 * bsc#1273868 * bsc#1273869 * bsc#1273872 * bsc#1273876 * bsc#1273877 * bsc#1273880 * bsc#1273882 * bsc#1273890 * bsc#1273891 * bsc#1273892 * bsc#1273895 * bsc#1273896 * bsc#1273903 * bsc#1273905 * bsc#1273930 * bsc#1273933 * bsc#1273934 * bsc#1273935 * bsc#1273936 * bsc#1273939 * bsc#1273940 * bsc#1273941 * bsc#1273942 * bsc#1273944 * bsc#1273945 * bsc#1273946 * bsc#1273956 * bsc#1273957 * bsc#1273958 * bsc#1273966 * bsc#1273967 * bsc#1273968 * bsc#1273972 * bsc#1273974 * bsc#1273975 * bsc#1273977 * bsc#1273982 * bsc#1273988 * bsc#1273990 * bsc#1273991 * bsc#1273995 * bsc#1274001 * bsc#1274003 * bsc#1274006 * bsc#1274011 * bsc#1274012 * bsc#1274014 * bsc#1274017 * bsc#1274019 * bsc#1274020 * bsc#1274026 * bsc#1274028 * bsc#1274030 * bsc#1274031 * bsc#1274035 * bsc#1274040 * bsc#1274041 * bsc#1274057 * bsc#1274058 * bsc#1274061 * bsc#1274063 * bsc#1274065 * bsc#1274067 * bsc#1274075 * bsc#1274076 * bsc#1274077 * bsc#1274078 * bsc#1274208 * bsc#1274226 * bsc#1274239 * bsc#1274243 * bsc#1274258 * bsc#1274265 * bsc#1274274 * bsc#1274277 * bsc#1274278 * bsc#1274281 * bsc#1274283 * bsc#1274286 * bsc#1274290 * bsc#1274294 * bsc#1274296 * bsc#1274297 * bsc#1274298 * bsc#1274314 * bsc#1274321 * bsc#1274491 * bsc#1274497 * bsc#1274539 * bsc#1274541 * bsc#1274543 * bsc#1274545 * bsc#1274547 * bsc#1274550 * bsc#1274573 * bsc#1274578 * bsc#1274580 * bsc#1274581 * bsc#1274620 * bsc#1274622 * bsc#1274624 * bsc#1274629 * bsc#1274632 * bsc#1274636 * bsc#1274639 * bsc#1274640 * bsc#1274642 * bsc#1274644 * bsc#1274645 * bsc#1274646 * bsc#1274649 * bsc#1274650 * bsc#1274651 * bsc#1274656 * bsc#1274659 * bsc#1274662 * bsc#1274663 * bsc#1274665 * bsc#1274667 * bsc#1274670 * bsc#1274675 * bsc#1274677 * bsc#1274678 * bsc#1274679 * bsc#1274681 * bsc#1274682 * bsc#1274690 * bsc#1274694 * bsc#1274696 * bsc#1274698 * bsc#1274699 * bsc#1274700 * bsc#1274702 * bsc#1274703 * bsc#1274705 * bsc#1274706 * bsc#1274709 * bsc#1274710 * bsc#1274713 * bsc#1274716 * bsc#1274721 * bsc#1274725 * bsc#1274737 * bsc#1274738 * bsc#1274749 * bsc#1274752 * bsc#1274753 * bsc#1274754 * bsc#1274755 * bsc#1274756 * bsc#1274764 * bsc#1274768 * bsc#1274770 * bsc#1274787 * bsc#1274800 * bsc#1274801 * bsc#1274802 * bsc#1274804 * bsc#1274805 * bsc#1274807 * bsc#1274808 * bsc#1274811 * bsc#1274813 * bsc#1274814 * bsc#1274831 * bsc#1274834 * bsc#1274847 * bsc#1274853 * bsc#1274868 * bsc#1274869 * bsc#1274872 * bsc#1274873 * bsc#1274874 * bsc#1274876 * bsc#1274879 * bsc#1274881 * bsc#1274883 * bsc#1274886 * bsc#1274888 * bsc#1274891 * bsc#1274892 * bsc#1274893 * bsc#1274894 * bsc#1274896 * bsc#1274897 * bsc#1274898 * bsc#1274899 * bsc#1274901 * bsc#1274902 * bsc#1274905 * bsc#1274907 * bsc#1274908 * bsc#1274913 * bsc#1274914 * bsc#1274920 * bsc#1274921 * bsc#1274924 * bsc#1274925 * bsc#1274929 * bsc#1274930 * bsc#1274933 * bsc#1274934 * bsc#1274935 * bsc#1274941 * bsc#1274945 * bsc#1274947 * bsc#1274951 * bsc#1274953 * bsc#1274958 * bsc#1274968 * bsc#1274981 * bsc#1275040 * bsc#1275069 * bsc#1275071 * bsc#1275073 * bsc#1275076 * bsc#1275080 * bsc#1275083 * bsc#1275088 * bsc#1275091 * bsc#1275125 * bsc#1275126 * bsc#1275131 * bsc#1275132 * bsc#1275150 * bsc#1275152 * bsc#1275154 * bsc#1275155 * bsc#1275157 * bsc#1275158 * bsc#1275161 * bsc#1275163 * bsc#1275164 * bsc#1275169 * bsc#1275173 * bsc#1275176 * bsc#1275185 * bsc#1275190 * bsc#1275236 * bsc#1275237 * bsc#1275239 * bsc#1275294 * bsc#1275301 * bsc#1275303 * bsc#1275304 * bsc#1275305 * bsc#1275306 * bsc#1275307 * bsc#1275470 * bsc#1275472 * bsc#1275474 * bsc#1275479 * bsc#1275483 * bsc#1275486 * bsc#1275487 * bsc#1275506 * bsc#1275509 * bsc#1275511 * bsc#1275517 * bsc#1275528 * bsc#1275535 * bsc#1275540 * bsc#1275553 * bsc#1275555 * bsc#1275561 * bsc#1275566 * bsc#1275569 * bsc#1275574 * bsc#1275578 * bsc#1275582 * bsc#1275583 * bsc#1275584 * bsc#1275591 * bsc#1275595 * bsc#1275633 * bsc#1275636 * bsc#1275650 * bsc#1275659 * bsc#1275665 * bsc#1275669 * bsc#1275687 * bsc#1275688 * bsc#1275695 * bsc#1275696 * bsc#1275704 * bsc#1275782 * bsc#1275784 * bsc#1275787 * bsc#1275788 * bsc#1275790 * bsc#1275797 * bsc#1275798 * bsc#1275805 * bsc#1275817 * bsc#1275818 * bsc#1275819 * bsc#1275820 * bsc#1275821 * bsc#1275827 * bsc#1275864 * bsc#1275867 * bsc#1275869 * bsc#1275870 * bsc#1275871 * bsc#1275872 * bsc#1275886 * bsc#1275905 * bsc#1275923 * bsc#1275925 * bsc#1275946 * bsc#1275950 * bsc#1275954 * bsc#1275970 * bsc#1275973 * bsc#1275975 * bsc#1275976 * bsc#1276029 * bsc#1276257 * bsc#1276263 * bsc#1276270 * bsc#1276273 * bsc#1276277 * bsc#1276335 * bsc#1276346 * bsc#1276350 * bsc#1276355 * bsc#1276446 * bsc#1276452 * bsc#1276500 * bsc#1276507 * bsc#1276542 * bsc#1276546 * bsc#1276551 * bsc#1276561 * bsc#1276569 * bsc#1276665 * bsc#1276864 * bsc#1276927 * bsc#1276931 * bsc#1276937 * bsc#1276941 * bsc#1276943 * bsc#1276961 * bsc#1277022 * bsc#1277034 * bsc#1277037 * bsc#1277047 * bsc#1277054 * bsc#1277057 * bsc#1277059 * bsc#1277064 * bsc#1277066 * bsc#1277069 * bsc#1277073 * bsc#1277077 * bsc#1277095 * bsc#1277155 * bsc#1277159 * bsc#1277160 * bsc#1277202 * bsc#1277204 * bsc#1277275 * bsc#1277285 * bsc#1277391 * bsc#1277408 * bsc#1277516 * bsc#1277523 * bsc#1277551 * bsc#1277625 * bsc#1277660 * bsc#1277678 * bsc#1277688 * bsc#1277775 * bsc#1277776 Cross-References: * CVE-2024-44981 * CVE-2024-57841 * CVE-2025-38469 * CVE-2025-39964 * CVE-2025-40022 * CVE-2025-68179 * CVE-2025-68214 * CVE-2025-71075 * CVE-2025-71104 * CVE-2026-23210 * CVE-2026-23230 * CVE-2026-23454 * CVE-2026-31392 * CVE-2026-31418 * CVE-2026-31531 * CVE-2026-31557 * CVE-2026-31663 * CVE-2026-43116 * CVE-2026-43125 * CVE-2026-43163 * CVE-2026-43271 * CVE-2026-43273 * CVE-2026-43278 * CVE-2026-43319 * CVE-2026-43363 * CVE-2026-43416 * CVE-2026-45897 * CVE-2026-45968 * CVE-2026-46070 * CVE-2026-46091 * CVE-2026-46107 * CVE-2026-46115 * CVE-2026-46195 * CVE-2026-52920 * CVE-2026-52925 * CVE-2026-52929 * CVE-2026-52935 * CVE-2026-52939 * CVE-2026-52946 * CVE-2026-52975 * CVE-2026-52977 * CVE-2026-52990 * CVE-2026-52994 * CVE-2026-53001 * CVE-2026-53033 * CVE-2026-53059 * CVE-2026-53076 * CVE-2026-53077 * CVE-2026-53089 * CVE-2026-53091 * CVE-2026-53094 * CVE-2026-53096 * CVE-2026-53110 * CVE-2026-53111 * CVE-2026-53126 * CVE-2026-53154 * CVE-2026-53163 * CVE-2026-53207 * CVE-2026-53219 * CVE-2026-53220 * CVE-2026-53223 * CVE-2026-53228 * CVE-2026-53238 * CVE-2026-53260 * CVE-2026-53264 * CVE-2026-53269 * CVE-2026-53273 * CVE-2026-53309 * CVE-2026-53330 * CVE-2026-53336 * CVE-2026-53337 * CVE-2026-53353 * CVE-2026-53365 * CVE-2026-53366 * CVE-2026-53381 * CVE-2026-53388 * CVE-2026-63801 * CVE-2026-63808 * CVE-2026-63810 * CVE-2026-63823 * CVE-2026-63827 * CVE-2026-63828 * CVE-2026-63860 * CVE-2026-63865 * CVE-2026-63868 * CVE-2026-63879 * CVE-2026-63881 * CVE-2026-63886 * CVE-2026-63887 * CVE-2026-63888 * CVE-2026-63889 * CVE-2026-63891 * CVE-2026-63898 * CVE-2026-63920 * CVE-2026-63925 * CVE-2026-63926 * CVE-2026-63928 * CVE-2026-63944 * CVE-2026-63969 * CVE-2026-63970 * CVE-2026-63972 * CVE-2026-63973 * CVE-2026-63980 * CVE-2026-63985 * CVE-2026-63990 * CVE-2026-63992 * CVE-2026-63999 * CVE-2026-64000 * CVE-2026-64001 * CVE-2026-64002 * CVE-2026-64004 * CVE-2026-64005 * CVE-2026-64006 * CVE-2026-64007 * CVE-2026-64010 * CVE-2026-64011 * CVE-2026-64014 * CVE-2026-64015 * CVE-2026-64018 * CVE-2026-64029 * CVE-2026-64034 * CVE-2026-64039 * CVE-2026-64047 * CVE-2026-64048 * CVE-2026-64051 * CVE-2026-64052 * CVE-2026-64073 * CVE-2026-64083 * CVE-2026-64084 * CVE-2026-64085 * CVE-2026-64086 * CVE-2026-64087 * CVE-2026-64088 * CVE-2026-64097 * CVE-2026-64098 * CVE-2026-64102 * CVE-2026-64109 * CVE-2026-64112 * CVE-2026-64113 * CVE-2026-64114 * CVE-2026-64115 * CVE-2026-64118 * CVE-2026-64121 * CVE-2026-64125 * CVE-2026-64126 * CVE-2026-64128 * CVE-2026-64131 * CVE-2026-64133 * CVE-2026-64135 * CVE-2026-64137 * CVE-2026-64148 * CVE-2026-64155 * CVE-2026-64164 * CVE-2026-64166 * CVE-2026-64168 * CVE-2026-64178 * CVE-2026-64185 * CVE-2026-64188 * CVE-2026-64190 * CVE-2026-64192 * CVE-2026-64214 * CVE-2026-64217 * CVE-2026-64218 * CVE-2026-64219 * CVE-2026-64222 * CVE-2026-64225 * CVE-2026-64237 * CVE-2026-64243 * CVE-2026-64245 * CVE-2026-64246 * CVE-2026-64247 * CVE-2026-64249 * CVE-2026-64257 * CVE-2026-64266 * CVE-2026-64268 * CVE-2026-64271 * CVE-2026-64273 * CVE-2026-64274 * CVE-2026-64275 * CVE-2026-64276 * CVE-2026-64277 * CVE-2026-64286 * CVE-2026-64287 * CVE-2026-64294 * CVE-2026-64296 * CVE-2026-64303 * CVE-2026-64304 * CVE-2026-64305 * CVE-2026-64306 * CVE-2026-64312 * CVE-2026-64313 * CVE-2026-64315 * CVE-2026-64316 * CVE-2026-64317 * CVE-2026-64322 * CVE-2026-64323 * CVE-2026-64329 * CVE-2026-64331 * CVE-2026-64332 * CVE-2026-64333 * CVE-2026-64334 * CVE-2026-64335 * CVE-2026-64337 * CVE-2026-64338 * CVE-2026-64340 * CVE-2026-64341 * CVE-2026-64342 * CVE-2026-64343 * CVE-2026-64344 * CVE-2026-64346 * CVE-2026-64348 * CVE-2026-64350 * CVE-2026-64351 * CVE-2026-64355 * CVE-2026-64358 * CVE-2026-64362 * CVE-2026-64365 * CVE-2026-64375 * CVE-2026-64376 * CVE-2026-64378 * CVE-2026-64381 * CVE-2026-64382 * CVE-2026-64383 * CVE-2026-64384 * CVE-2026-64385 * CVE-2026-64386 * CVE-2026-64387 * CVE-2026-64388 * CVE-2026-64401 * CVE-2026-64403 * CVE-2026-64406 * CVE-2026-64408 * CVE-2026-64409 * CVE-2026-64411 * CVE-2026-64412 * CVE-2026-64420 * CVE-2026-64421 * CVE-2026-64423 * CVE-2026-64427 * CVE-2026-64429 * CVE-2026-64433 * CVE-2026-64434 * CVE-2026-64436 * CVE-2026-64440 * CVE-2026-64442 * CVE-2026-64443 * CVE-2026-64444 * CVE-2026-64445 * CVE-2026-64448 * CVE-2026-64450 * CVE-2026-64454 * CVE-2026-64455 * CVE-2026-64463 * CVE-2026-64470 * CVE-2026-64471 * CVE-2026-64472 * CVE-2026-64478 * CVE-2026-64479 * CVE-2026-64480 * CVE-2026-64481 * CVE-2026-64482 * CVE-2026-64483 * CVE-2026-64484 * CVE-2026-64486 * CVE-2026-64487 * CVE-2026-64489 * CVE-2026-64494 * CVE-2026-64495 * CVE-2026-64496 * CVE-2026-64497 * CVE-2026-64500 * CVE-2026-64503 * CVE-2026-64504 * CVE-2026-64505 * CVE-2026-64511 * CVE-2026-64512 * CVE-2026-64513 * CVE-2026-64524 * CVE-2026-64527 * CVE-2026-64536 * CVE-2026-64537 * CVE-2026-64538 * CVE-2026-64539 * CVE-2026-64540 * CVE-2026-64541 * CVE-2026-64543 * CVE-2026-64544 * CVE-2026-64545 * CVE-2026-64546 * CVE-2026-64547 * CVE-2026-64548 * CVE-2026-64549 * CVE-2026-64551 * CVE-2026-64552 * CVE-2026-64553 * CVE-2026-64554 * CVE-2026-64562 * CVE-2026-64563 * CVE-2026-64565 * CVE-2026-64567 * CVE-2026-64571 * CVE-2026-64572 * CVE-2026-64573 * CVE-2026-64574 * CVE-2026-64576 * CVE-2026-64577 * CVE-2026-64581 * CVE-2026-64582 * CVE-2026-64583 * CVE-2026-64584 * CVE-2026-64585 * CVE-2026-64593 * CVE-2026-64597 * CVE-2026-64598 * CVE-2026-64599 * CVE-2026-64602 * CVE-2026-64604 * CVE-2026-68081 * CVE-2026-68082 * CVE-2026-68085 * CVE-2026-68086 * CVE-2026-68088 * CVE-2026-68091 * CVE-2026-68093 * CVE-2026-68102 * CVE-2026-68104 * CVE-2026-68106 * CVE-2026-68107 * CVE-2026-68108 * CVE-2026-68110 * CVE-2026-68111 * CVE-2026-68112 * CVE-2026-68115 * CVE-2026-68116 * CVE-2026-68117 * CVE-2026-68121 * CVE-2026-68123 * CVE-2026-68125 * CVE-2026-68126 * CVE-2026-68127 * CVE-2026-68129 * CVE-2026-68132 * CVE-2026-68133 * CVE-2026-68136 * CVE-2026-68137 * CVE-2026-68138 * CVE-2026-68139 * CVE-2026-68142 * CVE-2026-68143 * CVE-2026-68145 * CVE-2026-68149 * CVE-2026-68153 * CVE-2026-68154 * CVE-2026-68155 * CVE-2026-68156 * CVE-2026-68157 * CVE-2026-68158 * CVE-2026-68159 * CVE-2026-68160 * CVE-2026-68161 * CVE-2026-68162 * CVE-2026-68166 * CVE-2026-68180 * CVE-2026-68181 * CVE-2026-68182 * CVE-2026-68184 * CVE-2026-68188 * CVE-2026-68189 * CVE-2026-68192 * CVE-2026-68193 * CVE-2026-68194 * CVE-2026-68195 * CVE-2026-68196 * CVE-2026-68197 * CVE-2026-68199 * CVE-2026-68202 * CVE-2026-68204 * CVE-2026-68205 * CVE-2026-68206 * CVE-2026-68207 * CVE-2026-68209 * CVE-2026-68210 * CVE-2026-68212 * CVE-2026-68213 * CVE-2026-68214 * CVE-2026-68215 * CVE-2026-68216 * CVE-2026-68217 * CVE-2026-68218 * CVE-2026-68219 * CVE-2026-68220 * CVE-2026-68222 * CVE-2026-68223 * CVE-2026-68226 * CVE-2026-68227 * CVE-2026-68229 * CVE-2026-68231 * CVE-2026-68234 * CVE-2026-68236 * CVE-2026-68238 * CVE-2026-68243 * CVE-2026-68244 * CVE-2026-68246 * CVE-2026-68247 * CVE-2026-68248 * CVE-2026-68249 * CVE-2026-68250 * CVE-2026-68251 * CVE-2026-68254 * CVE-2026-68255 * CVE-2026-68256 * CVE-2026-68259 * CVE-2026-68269 * CVE-2026-68271 * CVE-2026-68272 * CVE-2026-68277 * CVE-2026-68278 * CVE-2026-68279 * CVE-2026-68280 * CVE-2026-68284 * CVE-2026-68286 * CVE-2026-68288 * CVE-2026-68289 * CVE-2026-68293 * CVE-2026-68297 * CVE-2026-68299 * CVE-2026-68300 * CVE-2026-68303 * CVE-2026-68304 * CVE-2026-68306 * CVE-2026-68308 * CVE-2026-68309 * CVE-2026-68310 * CVE-2026-68312 * CVE-2026-68313 * CVE-2026-68315 * CVE-2026-68320 * CVE-2026-68322 * CVE-2026-68324 * CVE-2026-68325 * CVE-2026-68326 * CVE-2026-68327 * CVE-2026-68328 * CVE-2026-68329 * CVE-2026-68331 * CVE-2026-68333 * CVE-2026-68335 * CVE-2026-68336 * CVE-2026-68339 * CVE-2026-68340 * CVE-2026-68343 * CVE-2026-68346 * CVE-2026-68348 * CVE-2026-68349 * CVE-2026-68350 * CVE-2026-68351 * CVE-2026-68352 * CVE-2026-68353 * CVE-2026-68354 * CVE-2026-68355 * CVE-2026-68357 * CVE-2026-68359 * CVE-2026-68360 * CVE-2026-68361 * CVE-2026-68362 * CVE-2026-68363 * CVE-2026-68365 * CVE-2026-68366 * CVE-2026-68368 * CVE-2026-68369 * CVE-2026-68370 * CVE-2026-68372 * CVE-2026-68373 * CVE-2026-68377 * CVE-2026-68386 * CVE-2026-68391 * CVE-2026-68392 * CVE-2026-68397 * CVE-2026-68398 * CVE-2026-68399 * CVE-2026-68402 * CVE-2026-68403 * CVE-2026-68405 * CVE-2026-68406 * CVE-2026-68407 * CVE-2026-68408 * CVE-2026-68410 * CVE-2026-68413 * CVE-2026-68414 * CVE-2026-68417 * CVE-2026-68418 * CVE-2026-68419 * CVE-2026-68422 * CVE-2026-68425 * CVE-2026-68426 * CVE-2026-68427 * CVE-2026-68428 * CVE-2026-68429 * CVE-2026-68430 * CVE-2026-68432 * CVE-2026-68433 * CVE-2026-68434 * CVE-2026-68444 * CVE-2026-68445 * CVE-2026-68446 * CVE-2026-68450 * CVE-2026-68470 * CVE-2026-68480 * CVE-2026-72020 * CVE-2026-72035 * CVE-2026-72036 * CVE-2026-72069 * CVE-2026-72072 * CVE-2026-72083 * CVE-2026-72084 * CVE-2026-72123 * CVE-2026-72132 * CVE-2026-72221 * CVE-2026-72222 * CVE-2026-72251 * CVE-2026-72254 * CVE-2026-72262 * CVE-2026-72288 * CVE-2026-72289 * CVE-2026-72296 * CVE-2026-72307 * CVE-2026-72308 * CVE-2026-72317 * CVE-2026-72341 * CVE-2026-72342 * CVE-2026-72343 * CVE-2026-72389 * CVE-2026-72463 * CVE-2026-72464 * CVE-2026-72466 * CVE-2026-72467 * CVE-2026-72469 * CVE-2026-72473 * CVE-2026-72494 * CVE-2026-72495 * CVE-2026-72496 * CVE-2026-72499 * CVE-2026-72501 * CVE-2026-72502 * CVE-2026-74269 * CVE-2026-74296 * CVE-2026-74297 * CVE-2026-74318 * CVE-2026-74321 * CVE-2026-74334 * CVE-2026-74345 * CVE-2026-74394 * CVE-2026-74395 * CVE-2026-74454 * CVE-2026-74474 * CVE-2026-74481 * CVE-2026-74482 * CVE-2026-74488 * CVE-2026-74495 * CVE-2026-74496 * CVE-2026-74509 * CVE-2026-74510 * CVE-2026-74512 * CVE-2026-74516 * CVE-2026-74518 * CVE-2026-74527 * CVE-2026-74537 * CVE-2026-74548 * CVE-2026-74550 * CVE-2026-74556 * CVE-2026-74563 * CVE-2026-74566 * CVE-2026-74567 * CVE-2026-74571 * CVE-2026-74581 * CVE-2026-74582 * CVE-2026-74584 * CVE-2026-74610 * CVE-2026-74669 * CVE-2026-74692 * CVE-2026-74694 * CVE-2026-74695 * CVE-2026-74717 * CVE-2026-74722 * CVE-2026-80529 * CVE-2026-80534 * CVE-2026-80590 * CVE-2026-80654 CVSS scores: * CVE-2024-44981 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L * CVE-2024-44981 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2024-44981 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-57841 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-38469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39964 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-39964 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-39964 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-39964 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40022 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-40022 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-68179 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68179 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68214 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71104 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2025-71104 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-71104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23210 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23230 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23230 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23230 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-23230 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23454 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23454 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23454 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31392 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-31392 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-31392 ( NVD ): 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L * CVE-2026-31418 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31418 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31531 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31557 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31663 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31663 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43116 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43125 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43163 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43271 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43271 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43271 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43319 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43319 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45897 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45897 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45897 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46070 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46070 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46091 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46091 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46091 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46107 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46107 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46107 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46115 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46115 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46195 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46195 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52920 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-52920 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-52925 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52925 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52925 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52939 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52939 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52977 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52977 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52990 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53033 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53059 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53059 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53059 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53076 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53076 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53077 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53077 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53077 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53089 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53089 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53091 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53091 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53091 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53091 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-53094 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53094 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53096 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53096 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53110 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53111 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53111 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53111 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53207 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53228 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53228 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53238 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53238 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53269 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53269 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53269 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53309 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53309 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53309 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53330 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53330 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53336 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53336 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53353 ( SUSE ): 0.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53353 ( SUSE ): 0.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N * CVE-2026-53353 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53365 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53365 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53365 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53381 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63801 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63801 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63801 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63808 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63808 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-63808 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63810 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63810 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63823 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63823 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63823 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63827 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63828 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63828 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63828 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-63860 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63860 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63860 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63865 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63865 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63865 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-63868 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63868 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63879 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63879 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63879 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63881 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63886 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63886 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63886 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63887 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63887 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63887 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63888 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63888 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63888 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63889 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63889 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63889 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63891 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63891 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63898 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63898 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63920 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63920 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63920 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63925 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63925 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63925 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-63926 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63926 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63926 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63928 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63928 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63944 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63944 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63969 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63969 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63970 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63970 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63972 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63972 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63972 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63973 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63973 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63980 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63985 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63985 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63985 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63990 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63990 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63992 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63992 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63992 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63999 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63999 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64000 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64000 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64000 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64001 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64001 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64002 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64002 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64002 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64004 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64004 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64005 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64005 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64005 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64006 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-64006 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-64007 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64007 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64007 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64010 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64011 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64014 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64014 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64015 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64015 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64018 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-64018 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-64018 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64029 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64029 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64029 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64034 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64039 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64039 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64039 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64047 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64047 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64048 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64048 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64048 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64051 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64051 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64051 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64052 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64052 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64052 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64073 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64073 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64073 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64083 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64083 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64083 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64084 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64084 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64084 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64085 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64085 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64085 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64086 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64086 ( SUSE ): 5.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64086 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64087 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64087 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64087 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64088 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64088 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64088 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64097 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64097 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64097 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64098 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64102 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-64102 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-64102 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64113 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64113 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64114 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64115 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64118 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64118 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64118 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64121 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64121 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64121 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64125 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64126 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64126 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L * CVE-2026-64126 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-64128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64128 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64135 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64137 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64137 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64137 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64148 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64148 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64148 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64155 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64164 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64166 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64178 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64178 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64185 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64185 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64188 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64188 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64188 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64190 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64190 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64190 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64217 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64217 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64217 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64218 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64219 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64222 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64222 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64222 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64225 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64225 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64225 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64237 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64237 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64245 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64246 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64246 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64246 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64247 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64247 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-64249 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64249 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64257 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64257 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-64257 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64266 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64266 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64268 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64271 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64271 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64271 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64273 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64275 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64275 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64277 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64286 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64286 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64287 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64303 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64303 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64303 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64304 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64305 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64305 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64306 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64313 ( SUSE ): 7.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-64313 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64313 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64315 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64316 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64316 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64317 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64317 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64317 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64322 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64322 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64322 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64323 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64323 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64329 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64329 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64329 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64331 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64331 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64333 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64333 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64334 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64334 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64334 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64335 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64335 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64335 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64337 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64337 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64338 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64340 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64340 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64340 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64341 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64342 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64343 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64344 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64346 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64348 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64348 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64348 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64350 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64350 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64350 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64351 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64351 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64351 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64355 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64355 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64358 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64358 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64365 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64375 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64375 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64376 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64376 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64376 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64381 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64381 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64382 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64382 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64383 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64383 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64384 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64385 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64386 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64387 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64388 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64388 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-64388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64401 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64401 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64403 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64403 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64403 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64406 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64408 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64409 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64409 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64411 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64411 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64411 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64412 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64412 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64412 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64420 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64421 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64421 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64427 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64427 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64434 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64436 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64436 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64440 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64440 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64440 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64442 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64442 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64443 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64443 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64444 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64444 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64444 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64445 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64448 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64448 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64450 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64454 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64471 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64478 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64478 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64479 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64480 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64481 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64481 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64482 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64482 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64483 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64484 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64484 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64486 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64487 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64489 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64497 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64500 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64503 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64504 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64505 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64511 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64511 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64512 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64513 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64527 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64537 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64537 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64538 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64540 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64540 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64540 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64541 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64541 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64541 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64544 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64544 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64545 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64547 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64547 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64547 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64548 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64548 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64549 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64551 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64551 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64552 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64552 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64552 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64553 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64562 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64562 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64563 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64563 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64565 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64565 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64567 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64567 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64567 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64571 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64571 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64572 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64572 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64573 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64573 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64574 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64576 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64576 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64576 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64577 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64577 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64577 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64581 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64581 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64581 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64582 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64583 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64583 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64584 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64585 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64593 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64593 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64598 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64598 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64599 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64599 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64602 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64604 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68081 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68081 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68082 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68082 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68082 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68085 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68085 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68085 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68086 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-68086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-68088 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68088 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68091 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68091 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68091 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68093 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-68093 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68102 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68102 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68104 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68106 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68106 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68106 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68107 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68107 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68107 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68108 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68108 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68108 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68110 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68110 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68111 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68111 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68115 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68115 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68116 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68116 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-68116 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68117 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68117 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68121 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68121 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68123 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68123 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68123 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68125 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68125 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68125 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68126 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68126 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68127 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68127 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68127 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68129 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68129 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68129 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68132 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68132 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68133 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68133 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68136 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68136 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68137 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68139 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68139 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68142 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68142 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-68142 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68143 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68143 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68143 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68145 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68145 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68145 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68149 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68149 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68149 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-68153 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68153 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68153 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68154 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68154 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68154 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68155 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68155 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68155 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68156 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68156 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68156 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68157 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68157 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68157 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68158 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68158 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68158 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68159 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68159 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68159 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68160 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68160 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68160 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68161 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68161 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68161 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68162 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68166 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68166 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68180 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68182 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68184 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68184 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68188 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68192 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68192 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68197 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68202 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68204 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68207 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68210 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68210 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68212 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68217 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68218 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68218 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68219 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68219 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68220 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68220 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68222 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68223 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68223 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68226 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68226 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68227 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68227 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68229 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68229 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-68229 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68231 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68231 ( SUSE ): 2.1 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68234 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68236 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68236 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68236 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68238 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68238 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68243 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68244 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68246 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68246 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68247 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68247 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68248 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68249 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68250 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68250 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68251 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68251 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68256 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68259 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68259 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68269 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68271 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68272 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68278 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68278 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68279 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68279 ( SUSE ): 2.4 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68280 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68280 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68284 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68284 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68286 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68286 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68288 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68288 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68289 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68293 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68293 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68299 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68308 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68309 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68310 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68312 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68313 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-68322 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68324 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68325 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68327 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68327 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68328 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68333 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68343 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68349 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68350 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68351 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68353 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68353 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68354 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68355 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68357 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68359 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68360 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68361 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68365 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68365 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-68366 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68368 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68369 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68370 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68372 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68377 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68377 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68386 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68391 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68391 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68392 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68392 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68402 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68402 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68403 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68405 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68406 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68407 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68408 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68410 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68413 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68414 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68414 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68422 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68425 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68425 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68426 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68426 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68427 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68427 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68427 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68428 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68430 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68430 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68433 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-68434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68444 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68445 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68445 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68445 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68446 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68446 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68470 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68470 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68470 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68480 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-72020 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72020 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72020 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72035 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72036 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72069 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72083 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72084 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72123 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72132 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72132 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72221 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72221 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72221 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72222 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72251 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72251 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72251 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72254 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72262 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72262 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72288 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72289 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72289 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72289 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72296 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72296 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72296 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-72307 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72307 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72308 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72308 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72317 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72317 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72317 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72341 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72342 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72342 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72343 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72343 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72389 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72463 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72463 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72464 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72464 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72467 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72473 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-72473 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72494 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72495 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72496 ( NVD ): 9.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H * CVE-2026-72499 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72499 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72501 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74269 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74269 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74318 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74345 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74345 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74345 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74394 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74395 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74395 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74454 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74454 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-74454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74474 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74474 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74481 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74482 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74482 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74488 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74488 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74495 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74495 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74509 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74509 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74516 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-74516 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74518 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74518 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74527 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-74527 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74537 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74537 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74550 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74550 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74556 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-74556 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74563 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74566 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-74567 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74567 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74571 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74581 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74581 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74582 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74584 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-74584 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-74584 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-74610 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-74610 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74610 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74692 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74694 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74694 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74695 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74695 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74717 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74717 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74722 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80534 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80534 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80590 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-80654 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80654 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 588 vulnerabilities and has 23 fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 kernel was updated to fix various security issues: The following security issues were fixed: * CVE-2024-57841: net: fix memory leak in tcp_conn_request() (bsc#1269731). * CVE-2025-68214: timers: Fix NULL function pointer race in timer_shutdown_sync() (bsc#1255225). * CVE-2025-71075: scsi: aic94xx: fix use-after-free in device removal path (bsc#1256629). * CVE-2026-31392: smb: client: fix krb5 mount with username option (bsc#1261788). * CVE-2026-31418: netfilter: ipset: drop logically empty buckets in mtype_del (bsc#1262073). * CVE-2026-31531: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() (bsc#1263004). * CVE-2026-31557: nvmet: move async event work off nvmet-wq (bsc#1263061). * CVE-2026-31663: xfrm: hold device only for the asynchronous decryption (bsc#1263133). * CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack (bsc#1264619). * CVE-2026-43125: dlm: validate length in dlm_search_rsb_tree (bsc#1264541). * CVE-2026-43163: md/bitmap: fix GPF in write_page caused by resize race (bsc#1264335). * CVE-2026-43271: md-cluster: fix NULL pointer dereference in process_metadata_update (bsc#1264587). * CVE-2026-43273: ceph: supply snapshot context in ceph_zero_partial_object() (bsc#1264446). * CVE-2026-43278: dm: clear cloned request bio pointer when last clone bio completes (bsc#1264584). * CVE-2026-43319: spi: spidev: fix lock inversion between spi_lock and buf_lock (bsc#1264788). * CVE-2026-43363: x86/apic: Disable x2apic on resume if the kernel expects so (bsc#1265068). * CVE-2026-43416: powerpc, perf: Check that current->mm is alive before getting user callchain (bsc#1265121). * CVE-2026-45897: bpf: Fix UAF in sock clone early bailouts (bsc#1266897). * CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). * CVE-2026-46070: md/raid5: validate payload size before accessing journal metadata (bsc#1267501). * CVE-2026-46091: media: rc: igorplugusb: heed coherency rules (bsc#1267238). * CVE-2026-46107: dm-thin: fix metadata refcount underflow (bsc#1267612). * CVE-2026-46115: block: add pgmap check to biovec_phys_mergeable (bsc#1266874). * CVE-2026-46195: smb: client: validate dacloffset before building DACL pointers (bsc#1266860). * CVE-2026-52920: netfilter: xt_policy: fix strict mode inbound policy matching (bsc#1269013). * CVE-2026-52925: vrf: Fix a potential NPD when removing a port from a VRF (bsc#1268987). * CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). * CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send (bsc#1268979). * CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion (bsc#1268972). * CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (bsc#1269113). * CVE-2026-52975: bonding: 802.3ad replace MAC_ADDRESS_EQUAL with __agg_has_partner (bsc#1269234). * CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). * CVE-2026-52990: fsnotify: fix inode reference leak in fsnotify_recalc_mask() (bsc#1269108). * CVE-2026-52994: vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting (bsc#1269126). * CVE-2026-53001: netfilter: xtables: restrict several matches to inet family (bsc#1269114). * CVE-2026-53033: bpf, sockmap: Take state lock for af_unix iter (bsc#1269388). * CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). * CVE-2026-53076: bpf: Fix OOB in pcpu_init_value (bsc#1269695). * CVE-2026-53077: net/rds: Restrict use of RDS/IB to the initial network namespace (bsc#1269412). * CVE-2026-53089: bpf: Fix use-after-free in offloaded map/prog info fill (bsc#1269783). * CVE-2026-53091: net: account for encap headers in qdisc pkt len (bsc#1269530). * CVE-2026-53094: bpf: Fix stale offload->prog pointer after constant blinding (bsc#1269965). * CVE-2026-53096: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (bsc#1269969). * CVE-2026-53110: selftests/bpf: Add ASSERT_OK_FD macro (bsc#1269985). * CVE-2026-53111: bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap (bsc#1269167). * CVE-2026-53126: blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() (bsc#1269635). * CVE-2026-53154: mm/hugetlb: restore reservation on error in hugetlb folio copy paths (bsc#1269665). * CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). * CVE-2026-53207: mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison (bsc#1269590). * CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers (bsc#1269686). * CVE-2026-53220: netfilter: revalidate bridge ports (bsc#1269381). * CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs (bsc#1269301). * CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads (bsc#1269256). * CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths (bsc#1269774). * CVE-2026-53260: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req() (bsc#1269731) * CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). * CVE-2026-53269: netfilter: synproxy: add mutex to guard hook reference counting (bsc#1269579). * CVE-2026-53273: tee: optee: prevent use-after-free when the client exits before the supplicant (bsc#1269713). * CVE-2026-53309: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (bsc#1269815). * CVE-2026-53330: drm/amd/display: Fix out-of-bounds read in (bsc#1270090). * CVE-2026-53336: nvmem: layouts: onie-tlv: fix hang on unknown types (bsc#1270108). * CVE-2026-53337: net: bonding: fix NULL pointer dereference in bond_do_ioctl() (bsc#1270251). * CVE-2026-53353: hsr: Remove WARN_ONCE() in hsr_addr_is_self() (bsc#1270111). * CVE-2026-53365: vsock/virtio: fix zerocopy completion for multi-skb sends (bsc#1271365). * CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). * CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). * CVE-2026-63808: exfat: fix potential use-after-free in exfat_find_dir_entry() (bsc#1272260). * CVE-2026-63810: block: Avoid mounting the bdev pseudo-filesystem in userspace (bsc#1272297). * CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). * CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179). * CVE-2026-63828: apparmor: mediate the implicit connect of TCP fast open sendmsg (bsc#1272175). * CVE-2026-63860: RDMA/core: Prefer NLA_NUL_STRING (bsc#1272429). * CVE-2026-63865: bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (bsc#1272486). * CVE-2026-63868: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (bsc#1272497). * CVE-2026-63879: drm/amdgpu: fix amdgpu_hmm_range_get_pages (bsc#1272569). * CVE-2026-63881: drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger (bsc#1272571). * CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). * CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). * CVE-2026-63889: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (bsc#1272423). * CVE-2026-63891: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (bsc#1272641). * CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). * CVE-2026-63925: macsec: fix replay protection at XPN lower-PN wrap (bsc#1273008). * CVE-2026-63926: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (bsc#1273019). * CVE-2026-63944: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (bsc#1272662). * CVE-2026-63969: ipv6: fix possible infinite loop in rt6_fill_node() (bsc#1272484). * CVE-2026-63970: vsock/virtio: bind uarg before filling zerocopy skb (bsc#1272673). * CVE-2026-63980: net/handshake: Use spin_lock_bh for hn_lock (bsc#1273028). * CVE-2026-63985: ethtool: eeprom: add more safeties to EEPROM Netlink fallback (bsc#1272963). * CVE-2026-63990: bonding: refuse to enslave CAN devices (bsc#1273027). * CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). * CVE-2026-63999: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure (bsc#1273038). * CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273030). * CVE-2026-64001: ALSA: pcm: oss: Fix setup list UAF on proc write error (bsc#1273734). * CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). * CVE-2026-64004: net/iucv: fix locking in .getsockopt (bsc#1273804). * CVE-2026-64005: net/smc: Do not re-initialize smc hashtables (bsc#1273831). * CVE-2026-64006: netfilter: nf_tables: fix dst corruption in same register operation (bsc#1273834). * CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). * CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882). * CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891). * CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762). * CVE-2026-64029: ALSA: seq: Serialize UMP output teardown with event_input (bsc#1273766). * CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). * CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). * CVE-2026-64052: block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() (bsc#1272983). * CVE-2026-64073: irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT (bsc#1273490). * CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488). * CVE-2026-64102: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (bsc#1272516). * CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748). * CVE-2026-64112: rbd: eliminate a race in lock_dwork draining on unmap (bsc#1273741). * CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning (bsc#1272262). * CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). * CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). * CVE-2026-64118: qed: fix double free in qed_cxt_tables_alloc() (bsc#1273749). * CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273743). * CVE-2026-64125: net: bcmgenet: keep RBUF EEE/PM disabled (bsc#1272346). * CVE-2026-64131: mm/memory: fix spurious warning when unmapping device- private/exclusive pages (bsc#1274063). * CVE-2026-64148: pds_core: check health in devcmd wait (bsc#1273956). * CVE-2026-64164: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (bsc#1273957). * CVE-2026-64185: sysfs: don't remove existing directory on update failure (bsc#1272200). * CVE-2026-64188: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (bsc#1272150). * CVE-2026-64190: net: team: fix NULL pointer dereference in team_xmit during mode change (bsc#1272210). * CVE-2026-64192: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (bsc#1272213). * CVE-2026-64214: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() (bsc#1272799). * CVE-2026-64217: netfs: Fix overrun check in netfs_extract_user_iter() (bsc#1272798). * CVE-2026-64222: octeontx2-pf: avoid double free of pool->stack on AQ init failure (bsc#1272788). * CVE-2026-64225: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (bsc#1272786). * CVE-2026-64245: fbdev: modedb: fix a possible UAF in fb_find_mode() (bsc#1273905). * CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). * CVE-2026-64286: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (bsc#1274058). * CVE-2026-64287: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (bsc#1273325). * CVE-2026-64294: mm: do file ownership checks with the proper mount idmap (bsc#1273525). * CVE-2026-64296: exfat: bound uniname advance in exfat_find_dir_entry() (bsc#1273975). * CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944). * CVE-2026-64312: crypto: pcrypt - restore callback for non-parallel fallback (bsc#1273968). * CVE-2026-64315: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1274028). * CVE-2026-64316: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1273598). * CVE-2026-64317: isofs: bound Rock Ridge symlink components to the SL record (bsc#1273936). * CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count (bsc#1273958). * CVE-2026-64323: udf: validate VAT header length against the VAT inode size (bsc#1273305). * CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). * CVE-2026-64375: proc: protect ptrace_may_access() with exec_update_lock (FD links) (bsc#1273868). * CVE-2026-64378: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() (bsc#1273603). * CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard() (bsc#1273860). * CVE-2026-64382: smb: client: fix double-free in SMB2_open() replay (bsc#1273291). * CVE-2026-64383: smb: client: fix double-free in SMB2_flush() replay (bsc#1273426). * CVE-2026-64384: smb: client: fix change notify replay double-free (bsc#1274541). * CVE-2026-64385: smb: client: fix double-free in SMB2_ioctl() replay (bsc#1274539). * CVE-2026-64386: smb: client: fix query_info() replay double-free (bsc#1274543). * CVE-2026-64387: smb: client: fix query directory replay double-free (bsc#1274545). * CVE-2026-64388: smb/client: fix chown/chgrp with SMB3 POSIX Extensions (bsc#1274061). * CVE-2026-64411: netfilter: ebtables: terminate table name before find_table_lock() (bsc#1274077). * CVE-2026-64412: netfilter: ebtables: module names must be null-terminated (bsc#1273780). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). * CVE-2026-64434: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (bsc#1273880). * CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states (bsc#1274277). * CVE-2026-64448: smb: client: restrict implied bcc[0] exemption to responses without data area (bsc#1273982). * CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). * CVE-2026-64463: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres (bsc#1273273). * CVE-2026-64472: vfio/mlx5: Fix racy bitfields and tighten struct layout (bsc#1274075). * CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547). * CVE-2026-64537: bridge: cfm: reject invalid CCM interval at configuration time (bsc#1273289). * CVE-2026-64538: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change() (bsc#1273335). * CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). * CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). * CVE-2026-64545: net, bpf: check master for NULL in xdp_master_redirect() (bsc#1273318). * CVE-2026-64548: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (bsc#1273337). * CVE-2026-64551: sctp: validate STALE_COOKIE cause length before reading staleness (bsc#1273813). * CVE-2026-64552: virtio-net: fix len check in receive_big() (bsc#1273323). * CVE-2026-64553: net: psample: fix info leak in PSAMPLE_ATTR_DATA (bsc#1273336). * CVE-2026-64554: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (bsc#1273340). * CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930). * CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). * CVE-2026-64567: btrfs: reject free space cache with more entries than pages (bsc#1274006). * CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). * CVE-2026-64576: nexthop: initialize extack in nh_res_bucket_migrate() (bsc#1274030). * CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031). * CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). * CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (bsc#1274040). * CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497). * CVE-2026-64597: smb: client: fix double-free in SMB2_close() replay (bsc#1274297). * CVE-2026-64598: smb/client: Fix error code in smb2_aead_req_alloc() (bsc#1274298). * CVE-2026-68081: KVM: nVMX: Add helper to put (unmap) vmcs12 pages (bsc#1274580). * CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers() (bsc#1274581). * CVE-2026-68086: mm/khugepaged: write all dirty file folios when collapsing (bsc#1274713). * CVE-2026-68116: vxlan: mdb: Fix source list corruption on a failed replace (bsc#1274876). * CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (bsc#1274881). * CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). * CVE-2026-68123: openvswitch: fix GSO userspace truncation underflow (bsc#1275169). * CVE-2026-68127: ila: reload IPv6 header after pskb_may_pull in checksum adjust (bsc#1275237). * CVE-2026-68129: gve: fix Rx queue stall on alloc failure (bsc#1275517). * CVE-2026-68132: super: fix emergency thaw deadlock on frozen block devices (bsc#1275553). * CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). * CVE-2026-68139: net/mlx5e: Use sender devcom for MPV master-up (bsc#1275578). * CVE-2026-68142: geneve: require CAP_NET_ADMIN in the device netns for changelink (bsc#1275582). * CVE-2026-68143: net: slip: serialize receive against buffer reallocation (bsc#1275583). * CVE-2026-68145: iomap: fix out-of-bounds bitmap_set() with zero-length range (bsc#1275584). * CVE-2026-68149: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (bsc#1275294). * CVE-2026-68153: libceph: remove debugfs files before client teardown (bsc#1275301). * CVE-2026-68154: libceph: reject zero bucket types in crush_decode (bsc#1275303). * CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). * CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after authorizer update (bsc#1275305). * CVE-2026-68157: libceph: guard missing CRUSH type name lookup (bsc#1275306). * CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). * CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). * CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472). * CVE-2026-68161: sctp: close UDP tunnel sockets during netns teardown (bsc#1274892). * CVE-2026-68166: userfaultfd: prevent registration of special VMAs (bsc#1274930). * CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). * CVE-2026-68205: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (bsc#1274934). * CVE-2026-68238: drm/amdgpu: Release VFCT ACPI table reference (bsc#1275704). * CVE-2026-68247: drm/i915/bios: range check LFP Data Block panel_type2 (bsc#1275817). * CVE-2026-68254: drm/i915/vrr: require valid min/max vfreq for VRR (bsc#1275150). * CVE-2026-68284: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (bsc#1275970). * CVE-2026-68286: drop_monitor: perform u64_stats updates under IRQ-disabled section (bsc#1275973). * CVE-2026-68288: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (bsc#1275975). * CVE-2026-68289: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (bsc#1275976). * CVE-2026-68293: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (bsc#1275091). * CVE-2026-68297: tipc: fix u16 MTU truncation in media and bearer MTU validation (bsc#1275040). * CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (bsc#1275088). * CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL (bsc#1275083). * CVE-2026-68312: cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths (bsc#1274663). * CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit (bsc#1274665). * CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq() (bsc#1274662). * CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (bsc#1274659). * CVE-2026-68322: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (bsc#1274656). * CVE-2026-68324: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (bsc#1274649). * CVE-2026-68325: iommu/amd: Bound the early ACPI HID map (bsc#1274651). * CVE-2026-68328: nfp: Check resource mutex allocation (bsc#1274646). * CVE-2026-68329: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (bsc#1274645). * CVE-2026-68331: dpaa2-eth: put MAC endpoint device on disconnect (bsc#1274642). * CVE-2026-68333: dpaa2-switch: put MAC endpoint device on disconnect (bsc#1274644). * CVE-2026-68335: rds: drop incoming messages that cross network namespace boundaries (bsc#1274640). * CVE-2026-68336: bonding: fix devconf_all NULL dereference when IPv6 is disabled (bsc#1274639). * CVE-2026-68343: smb: client: validate DFS referral PathConsumed (bsc#1274629). * CVE-2026-68377: net/sched: act_tunnel_key: Defer dst_release to RCU callback (bsc#1274831). * CVE-2026-68386: bpf, sockmap: Reject unhashed UDP sockets on sockmap update (bsc#1274814). * CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). * CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). * CVE-2026-68408: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (bsc#1274709). * CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). * CVE-2026-68418: RDMA/irdma: Prevent user-triggered null deref on QP create (bsc#1274690). * CVE-2026-68419: RDMA/irdma: Prevent rereg_mr for non-mem regions (bsc#1274698). * CVE-2026-68422: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (bsc#1274706). * CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1274700). * CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). * CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink (bsc#1274800). * CVE-2026-68433: libceph: bound get_version reply decode to front len (bsc#1274801). * CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert (bsc#1274834). * CVE-2026-68470: wifi: cfg80211/mac80211: correctly parse S1G beacon optional elements (bsc#1276500). * CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). * CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). * CVE-2026-72035: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1276961). * CVE-2026-72036: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1277034). * CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). * CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155). * CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). * CVE-2026-72084: scsi: target: Bound PR-OUT TransportID parsing to the received buffer (bsc#1275540). * CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523). * CVE-2026-72132: NFS: Charge unstable writes by request size, not folio size (bsc#1277551). * CVE-2026-72221: sunrpc: wait for in-flight TLS handshake callback when cancel loses race (bsc#1275665). * CVE-2026-72222: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback (bsc#1275669). * CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). * CVE-2026-72254: netfilter: nft_fib: reject fib expression on the netdev egress hook (bsc#1277204). * CVE-2026-72262: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (bsc#1277678). * CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). * CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). * CVE-2026-72296: net: ife: require ETH_HLEN to be pullable in ife_decode() (bsc#1275923). * CVE-2026-72307: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (bsc#1277160). * CVE-2026-72308: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (bsc#1277159). * CVE-2026-72317: SUNRPC: pin upper rpc_clnt across the TLS connect_worker (bsc#1275925). * CVE-2026-72341: net/mlx5e: Fix publication race for priv->channel_stats[] (bsc#1277660). * CVE-2026-72342: net/mlx5e: Fix HV VHCA stats agent registration race (bsc#1277775). * CVE-2026-72343: net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation (bsc#1277776). * CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). * CVE-2026-72463: xfrm: Fix dev use-after-free in xfrm async resumption (bsc#1268276 bsc#1277064). * CVE-2026-72464: xprtrdma: Remove temp allocation of rpcrdma_rep objects (bsc#1277069). * CVE-2026-72466: xprtrdma: Fix bcall rep leak and unbounded peek (bsc#1277057). * CVE-2026-72467: xprtrdma: Check frwr_wp_create() during connect (bsc#1277059). * CVE-2026-72469: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE (bsc#1277047). * CVE-2026-72473: xprtrdma: Avoid 250 ms delay on backlog wakeup (bsc#1277037). * CVE-2026-72494: RDMA/irdma: Replace waitqueue and flag with completion (bsc#1276941). * CVE-2026-72495: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages (bsc#1276937). * CVE-2026-72496: RDMA/bnxt_re: Proper rollback if the ioremap fails (bsc#1276943). * CVE-2026-72499: RDMA/bnxt_re: Free CQ toggle page after firmware teardown (bsc#1276551). * CVE-2026-72501: RDMA/bnxt_re: Initialize dpi variable to zero (bsc#1276546). * CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (bsc#1276542). * CVE-2026-74269: bnxt: fix head underflow on XDP head-grow (bsc#1276507). * CVE-2026-74296: RDMA/mlx5: Release the HW-provided UAR index rather than the SW one (bsc#1276452). * CVE-2026-74297: RDMA/mlx5: Fix undefined shift of user RQ WQE size (bsc#1276446). * CVE-2026-74318: btrfs: fix deadlock cloning inline extent when using flushoncommit (bsc#1276864). * CVE-2026-74321: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (bsc#1277202). * CVE-2026-74334: RDMA/nldev: Fix locking when accessing mr->pd (bsc#1277095). * CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). * CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). * CVE-2026-74395: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (bsc#1277077). * CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073). * CVE-2026-74474: vxlan: use pskb_network_may_pull() for transmit path header pulls (bsc#1276335). * CVE-2026-74481: mm/page_reporting: use system_freezable_wq to fix UAF during suspend (bsc#1276355). * CVE-2026-74482: mm/huge_memory: unlock i_mmap_rwsem before releasing after- split folios (bsc#1276346). * CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350). * CVE-2026-74495: igbvf: Fix leak in TX DMA error cleanup (bsc#1275864). * CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). * CVE-2026-74509: Bluetooth: hci_sync: Fix advertising data UAFs (bsc#1275946). * CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation (bsc#1275950). * CVE-2026-74512: audit: fix potential use-after-free in audit_del_rule() (bsc#1275954). * CVE-2026-74516: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (bsc#1275797). * CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). * CVE-2026-74527: octeontx2-af: Block VFs from clobbering special CGX PKIND state (bsc#1275805). * CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). * CVE-2026-74548: forcedeth: fix UAF of txrx_stats in nv_remove (bsc#1275695). * CVE-2026-74550: net: do not send ICMP/NDISC Redirects when peer allocation fails (bsc#1275688). * CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). * CVE-2026-74563: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() (bsc#1275574). * CVE-2026-74566: keys: make keyring key-chunk byte order agree with keyring_diff_objects() (bsc#1275566). * CVE-2026-74567: keys: fix out-of-bounds read in keyring_get_key_chunk() (bsc#1275569). * CVE-2026-74571: btrfs: skip global block reserve accounting for rescue mounts (bsc#1275561). * CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782). * CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). * CVE-2026-74584: RDMA/bnxt_re: zero shared page before exposing to userspace (bsc#1277066). * CVE-2026-74610: tls: don't leave a full plaintext sk_msg ring unpushed (bsc#1277054). * CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). * CVE-2026-74692: net/smc: fix TOCTOU race between smc_listen_out() and listener close (bsc#1276927). * CVE-2026-74694: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (bsc#1277625). * CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). * CVE-2026-74717: net/mlx5: fw_tracer, return NULL on create error (bsc#1276569). * CVE-2026-74722: btrfs: fix memory leak in btrfs_do_encoded_write() (bsc#1276561). * CVE-2026-80529: xfs: don't swallow dquot recovery verification errors (bsc#1277688). * CVE-2026-80534: xfs: fix ilock leak on error in xfs_dq_get_next_id (bsc#1277022). * CVE-2026-80590: inet: frags: strip GSO state from fragments before reassembly (bsc#1277275). * CVE-2026-80654: soc: xilinx: Shutdown and free rx mailbox channel (bsc#1277516). The following non security issues were fixed: * accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() (git-fixes). * accessibility: speakup: unregister tty ldisc on later init failures (git- fixes). * ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer (git-fixes). * ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root (git- fixes). * ACPI: pfr_update: fix stack buffer overflow in query_capability() (git- fixes). * ACPI: processor: idle: Expand _LPI package sanity checks (git-fixes). * ACPI: processor: validate MADT IOAPIC entry bounds (git-fixes). * ACPI: scan: fix bus ID cleanup on device_add() failures (git-fixes). * ACPI: video: Release PCI device reference after lookup (git-fixes). * add my missing Reviewed-by: tag. * ALSA: 6fire: bound the MIDI event length from the device (git-fixes). * ALSA: 6fire: Fix UAF at error handling during probe (stable-fixes). * ALSA: bcd2000: clear the URB pointers on disconnect (git-fixes). * ALSA: core: Fix use-after-free in snd_card_do_free() (git-fixes). * ALSA: dummy: Check card index validity at probe (stable-fixes). * ALSA: hda/ext: preserve PPLCCTL bits when clearing reset (git-fixes). * ALSA: hda: Fix connection list comparison in proc output (git-fixes). * ALSA: hpi: Check transport errors during HPI6000 adapter initialization (git-fixes). * ALSA: pcxhr: initialize mutexes before requesting threaded IRQ (git-fixes). * ALSA: seq: midi: Optimize event_input locking with RCU (git-fixes). * ALSA: seq: midi: Serialize input teardown with event_input (git-fixes). * ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion (git-fixes). * ALSA: usb-audio: Complete cleanup after system-resume errors (git-fixes). * ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (git-fixes). * ALSA: usb-audio: fix OOB write on Type II inbound URBs (git-fixes). * ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (git-fixes). * ALSA: usx2y: bound the hwdep mmap fault offset (git-fixes). * ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() (git- fixes). * apparmor: advertise the tcp fast open fix is applied (git-fixes). * ASoC: adau1761: sort the register default table (git-fixes). * ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC (git-fixes). * ASoC: apple: mca: increase SERDES reset delay (git-fixes). * ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (git-fixes). * ASoC: cs35l33: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l34: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l41: sort the register default table (git-fixes). * ASoC: cs35l45: sort the register default table (git-fixes). * ASoC: cs4265: sort the register default table (git-fixes). * ASoC: cx2072x: sort the register default table (git-fixes). * ASoC: dapm: Fix off-by-one check on the second enum channel (git-fixes). * ASoC: fix unmet dependencies on PPC_BESTCOMM and SND_SOC_AC97_BUS (git- fixes). * ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready (git- fixes). * ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure (git-fixes). * ASoC: fsl_audmix: rework runtime PM handling in probe (git-fixes). * ASoC: fsl_easrc: sort the register default table (git-fixes). * AsoC: intel: sst: fix PCI device reference leak on probe failure (git- fixes). * ASoC: max9860: sort the register default table (git-fixes). * ASoC: meson: Keep link pointers valid on realloc failure (git-fixes). * ASoC: ml26124: sort the register default table (git-fixes). * ASoC: pcm512x: sort the register default table (git-fixes). * ASoC: pxa: Use devm_clk_get_optional() for extclk clock (git-fixes). * ASoC: qcom: q6apm: keep the graph start count in sync with the DSP (git- fixes). * ASoC: rt274: sort the register default table (git-fixes). * ASoC: rt286: sort the register default table (git-fixes). * ASoC: rt298: sort the register default table (git-fixes). * ASoC: rt700-sdw: always drain jack work on remove (git-fixes). * ASoC: rt700: drop duplicate reg_default entry (git-fixes). * ASoC: rt700: sort the register default table (git-fixes). * ASoC: rt711-sdca: sort the register default tables (git-fixes). * ASoC: rt711: sort the register default table (git-fixes). * ASoC: rt712-sdca-dmic: sort the register default table (git-fixes). * ASoC: rt715-sdca: drop duplicate reg_default entries (git-fixes). * ASoC: rt715-sdca: sort the register default tables (git-fixes). * ASoC: rt715: sort the register default table (git-fixes). * ASoC: rt1316-sdw: sort the register default table (git-fixes). * ASoC: rt1318-sdw: sort the register default table (git-fixes). * ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get (git-fixes). * ASoC: sgtl5000: sort the register default table (git-fixes). * ASoC: SOF: pcm: Move period/buffer configuration print after platform open (stable-fixes). * ASoC: sof: pcm: use snd_pcm_direction_name() (stable-fixes). * ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() (git- fixes). * ASoC: SOF: validate topology volume range before allocation (git-fixes). * ASoC: sti-sas: sort the register default table (git-fixes). * ASoC: tas2552: sort the register default table (git-fixes). * ASoC: tas2764: sort the register default table (git-fixes). * ASoC: tas2780: sort the register default table (git-fixes). * ASoC: tegra210_i2s: sort the register default table (git-fixes). * ASoC: tegra210_mixer: sort the register default table (git-fixes). * ASoC: tegra: Fix the MIXER enable default value (git-fixes). * ASoC: tegra: Sort MBDRC register defaults (git-fixes). * ASoC: xilinx: formatter_pcm: fix stream_data leak on open error (git-fixes). * ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (git-fixes). * batman-adv: bla: fix freeing of claims on meshif deletion (git-fixes). * batman-adv: bla: prevent CRC corruptions after claim flush (git-fixes). * batman-adv: dat: avoid unaligned fault in IP extraction (git-fixes). * batman-adv: fix stale receive device on merged fragments (git-fixes). * Bluetooth: btintel: Fix diagnostics event detection (git-fixes). * Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path (git-fixes). * Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX (git- fixes). * Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event (git- fixes). * Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() (git- fixes). * Bluetooth: do not leak an hci_conn when a second LE connect is rejected (git-fixes). * Bluetooth: eir: Fix OOB read in eir_get_service_data() (git-fixes). * Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (git-fixes). * Bluetooth: hci_conn: re-enable advertising only for peripheral role (git- fixes). * Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection (git- fixes). * Bluetooth: hci_event: fix LE list UAF on reset (git-fixes). * Bluetooth: hci_event: validate LE Set CIG Parameters response (git-fixes). * Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths (git-fixes). * Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (stable-fixes). * Bluetooth: hci_uart: Fix false success return in hci_uart_setup() (git- fixes). * Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready (git-fixes). * Bluetooth: MGMT: free the mesh send cancel command when it is cancelled (git-fixes). * Bluetooth: MSFT: validate evt_prefix_len against the response length (git- fixes). * Bluetooth: RFCOMM: serialize security confirmation handling (git-fixes). * Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (git- fixes). * Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop (git-fixes). * Bluetooth: virtio_bt: avoid OOB read of build info string (git-fixes). * bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation (git-fixes). * bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET (git-fixes). * bus: ti-sysc: Fix /chosen node reference leak (git-fixes). * cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64) (git-fixes). * can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (stable-fixes). * crypto: aspeed - Propagate platform_get_irq() errors (git-fixes). * crypto: atmel-sha204a - fix heap info leak on I2C transfer failure (git- fixes). * crypto: atmel-tdes - use scatterlist length before DMA mapping (git-fixes). * crypto: ccm - Set rfc4309 maxauthsize from child (git-fixes). * crypto: ccp - Fix memory leak in SEV INIT_EX path (git-fixes). * crypto: ccp - Fix possible deadlock in SEV init failure path (git-fixes). * crypto: doc - Remove extra parenthesis (git-fixes). * crypto: hisilicon/sec2 - fix CCM algorithm long packet failure (git-fixes). * crypto: keembay - Initialize completion before requesting IRQ (git-fixes). * crypto: keembay - publish OF module alias for OCS AES/SM4 (git-fixes). * crypto: mxs-dcp - fix source scatterlist length access (git-fixes). * crypto: qat - cancel work on re-enable SR-IOV timeout (git-fixes). * crypto: qat - clear AES key schedule from stack (git-fixes). * crypto: qce - fix CCM AAD buffer underallocation (git-fixes). * crypto: qce - fix error path in devm_qce_register_algs (git-fixes). * crypto: rk3288 - fail ahash requests on HASH idle timeout (git-fixes). * crypto: sa2ul - stop probe if context pool creation fails (git-fixes). * crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping (git- fixes). * device property: fix infinite loop in fwnode_for_each_child_node() (git- fixes). * dmaengine: dw-edma: Clear stale requests on termination (git-fixes). * dmaengine: dw-edma: Complete descriptors before pausing (git-fixes). * dmaengine: dw-edma: Initialize IRQ data before requesting IRQs (git-fixes). * dmaengine: dw-edma: Serialize abort state updates (git-fixes). * dmaengine: dw-edma: Serialize channel state checks (git-fixes). * dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe (git-fixes). * dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure (git-fixes). * dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal (git-fixes). * dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers (git-fixes). * dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout (git-fixes). * driver core: soc: Unregister bus on early device registration failure (git- fixes). * drm/amd/display: avoid divide-by-zero in __is_lut_linear() (git-fixes). * drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read (git- fixes). * drm/amdgpu/gfx6: Fixup emit_cntxcntl() (git-fixes). * drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets (git-fixes). * drm/amdgpu/gfx6: Use PFP on the compute queues too (git-fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup (git- fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup (git- fixes). * drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check (git- fixes). * drm/amdgpu: cap GTT size to physical RAM on APUs (stable-fixes). * drm/amdgpu: check ASPM on the dGPU host link (git-fixes). * drm/amdgpu: disallow multiple FENCE chunks in one submit (git-fixes). * drm/amdgpu: fix aperture iounmap skipped on device removal (git-fixes). * drm/amdgpu: fix autosuspend cleanup during removal (git-fixes). * drm/amdgpu: Fix UVD decode image min size calculation (stable-fixes). * drm/amdgpu: Fix UVD dpb min size calculation for H264 (stable-fixes). * drm/amdgpu: Fix UVD min buffer sizes (stable-fixes). * drm/amdgpu: Fix VCE 3 ring align_mask (git-fixes). * drm/amdgpu: Implement insert_end for VCE 3 (git-fixes). * drm/amdgpu: Reject UVD message with dimensions above 4096 (stable-fixes). * drm/amdgpu: Reject UVD message with invalid number of h265 refs (stable- fixes). * drm/amdgpu: restore UMD profile pstate after runtime resume (stable-fixes). * drm/amdgpu: validate GEM_CREATE domain combinations (stable-fixes). * drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (stable-fixes). * drm/amdkfd: fix QID bit leak in pqm_create_queue() (stable-fixes). * drm/amdkfd: Handle invalid event type in CRIU event restore (stable-fixes). * drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure (git-fixes). * drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure (git-fixes). * drm/bridge: ps8640: propagate AUX transfer register errors (git-fixes). * drm/bridge: tc358767: clamp the reported AUX read size to the request (git- fixes). * drm/connector: Fix epoch_counter docs to reflect reality (git-fixes). * drm/hibmc: Fix list of formats on the primary plane (git-fixes). * drm/hibmc: Use drm_atomic_helper_check_plane_state() (git-fixes). * drm/i915/fbc: Extract intel_fbc_has_fences() (stable-fixes). * drm/lima: call drm_mm_init() with a valid allocation range (git-fixes). * drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: Drop dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value (git- fixes). * drm/panel-edp: fix i2c adapter leak on probe failure (git-fixes). * drm/panel: samsung-s6d16d0: Power off on prepare failure (git-fixes). * drm/radeon: fix autosuspend cleanup during teardown (git-fixes). * drm/radeon: restore hardware polling in fence_is_signaled to fix performance regression (git-fixes). * drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format (git-fixes). * drm/ssd130x: fix column and row end address in partial updates for ssd132x (git-fixes). * drm/sun4i: crtc: Propagate layer initialization error (git-fixes). * drm/sun4i: Drop node references while building component list (git-fixes). * drm/sun4i: dw-hdmi: Drop TCON TOP port reference (git-fixes). * drm/sun4i: fix refcount leak in sun4i_backend_init_sat() (git-fixes). * drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz (git-fixes). * drm/sun4i: tcon: Drop remote endpoint reference (git-fixes). * drm/sun4i: tcon: Drop TCON TOP device reference (git-fixes). * drm/sun4i: tcon: Set output mux for DSI and LVDS (git-fixes). * drm/sun4i: vi scaler: Fix coefficient selection (git-fixes). * drm/tegra: dsi: Re-add clear enable register if DSI was powered by bootloader (git-fixes). * drm/tve200: add OF module alias for autoloading (git-fixes). * drm: fix race between partial drm_dev_register() failure and ioctl (git- fixes). * drm: lcdif: Wait for vblank before disabling DMA (git-fixes). * drm: Remove unused header in drm_dumb_buffers.c (git-fixes). * ethtool: rss: fix hkey leak when indir_size is 0 (git-fixes). * fbdev: bitblit: bound-check glyph index in bit_cursor() (git-fixes). * fbdev: core: Fix pointer desynchronization in fb_io_read() (git-fixes). * fbdev: kyro: Validate overlay viewport coordinates (git-fixes). * fbdev: omapfb: panel-dsi-cm: initialize lock before registering display (git-fixes). * fbdev: ssd1307fb: defer I2C transfers from damage callbacks (git-fixes). * fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() (git-fixes). * fbdev: uvesafb: unregister connector callback on init failure (git-fixes). * firmware: arm_scmi: Avoid IDR updates while cleaning channels (git-fixes). * firmware: arm_scmi: Drop handle on protocol bind failures (git-fixes). * firmware: arm_scmi: Fix requested device removal race (git-fixes). * firmware: arm_scmi: Free transport channel on IDR failure (git-fixes). * firmware: arm_scmi: Protect device request lookup with RCU (git-fixes). * firmware: arm_scmi: Reject out of range DT protocol IDs (git-fixes). * firmware: arm_scmi: Unregister device notifier before IDR teardown (git- fixes). * firmware: arm_scmi: Use channel ID for transport teardown (git-fixes). * firmware_loader: do not queue completed sysfs fallback requests (git-fixes). * fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write (git- fixes). * fpga: dfl: fme: add error handling (git-fixes). * fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration (git- fixes). * gpu: host1x: Avoid stack over-read in debug output helpers (git-fixes). * gpu: host1x: Fix offset calculation in trace_write_gather (git-fixes). * HID: core: fix number/pointer type confusion on long items (git-fixes). * HID: core: fix OOB read of field->usage in hid_set_field() (git-fixes). * HID: hyperv: validate initial device info bounds (git-fixes). * HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure (git-fixes). * HID: lg4ff: validate report length before fixed offsets (git-fixes). * HID: logitech-dj: Fix maxfield check in DJ short report validation (git- fixes). * HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (git- fixes). * HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (stable-fixes). * HID: logitech-dj: Standardise hid_report_enum variable nomenclature (stable- fixes). * HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID (stable-fixes). * HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (git- fixes). * HID: mcp2221: validate report size in mcp2221_raw_event() (git-fixes). * HID: nintendo: Fix imu_timestamp_us double increment per report (git-fixes). * HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() (git- fixes). * HID: picolcd: clamp eeprom debugfs read to bytes actually received (git- fixes). * HID: roccat: bound device-supplied profile index (git-fixes). * HID: roccat: free buffered reports when destroying device (git-fixes). * HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature (git- fixes). * HID: sensor: custom: Fix field sysfs group cleanup on failure (git-fixes). * HID: sensor: custom: Fix use-after-free in enable_sensor (git-fixes). * HID: tmff: Use 64-bit arithmetic for force feedback scaling (git-fixes). * hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (git-fixes). * hwmon: (lm25066) Use i2c_get_match_data() (stable-fixes). * hwmon: (max6621) fix negative temperature offset and crit readings (git- fixes). * hwmon: (max6621) fix temperature clamp range (git-fixes). * hwmon: (nzxt-smart2) Check return value of init_device() in probe (git- fixes). * hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (git-fixes). * hwrng: ks-sa - Fix runtime PM cleanup on registration failure (git-fixes). * hwrng: omap - Fix probe error path cleanup (git-fixes). * hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() (git- fixes). * i2c: bcm-iproc: remove printout on handled timeouts (stable-fixes). * i2c: iproc: reset bus after timeout if START_BUSY is stuck (git-fixes). * i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure (git-fixes). * i2c: mux: Fix channel node leak on adapter add failure (git-fixes). * i2c: ocores: Disable clock on failed resume (git-fixes). * i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices (git-fixes). * i3c: master: Fix device_register() error path (git-fixes). * i3c: master: Fix info leak and UAF in device unregister path (git-fixes). * i3c: master: svc: bound IBI payload to the requested max_payload_len (git- fixes). * ibmvnic: Only record tx completed bytes once per handler (bsc#1274620). * iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE (git-fixes). * iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable (git-fixes). * iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF (git-fixes). * iio: chemical: sgp30: Handle IAQ thread creation failure (git-fixes). * iio: dac: m62332: Fix regulator reference count imbalance (git-fixes). * iio: gyro: mpu3050: fix sign of raw angular velocity readings (git-fixes). * iio: light: cm32181: return zero after writing calibscale (git-fixes). * iio: light: gp2ap002: Disable regulators on resume failure (git-fixes). * iio: light: gp2ap002: re-enable irq if runtime suspend fails (git-fixes). * iio: light: isl29028: return zero in write_raw() on success (git-fixes). * iio: light: tsl2583: return zero in write_raw() on success (git-fixes). * iio: light: tsl2772: fix ALS calibscale readback (git-fixes). * iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure (git-fixes). * iio: pressure: dps310: fix NULL pointer dereference on ACPI probe (git- fixes). * iio: pressure: mpl115: Fix runtime PM cleanup (git-fixes). * iio: srf04: fix pm_runtime handling on probe error path (git-fixes). * iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() (git-fixes). * Input: atkbd - skip deactivate for HONOR ZQC-P (git-fixes). * Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (stable-fixes). * Input: evdev - fix information leak in evdev_pass_values() (stable-fixes). * Input: evdev - sanitize event type index when fetching event masks (stable- fixes). * Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (git-fixes). * Input: focaltech - use signed coordinates to prevent underflow (git-fixes). * Input: hynitron_cstxxx - validate touch count and finger IDs (git-fixes). * Input: iforce - validate input packet lengths (stable-fixes). * Input: iqs5xx - validate firmware record destination span (git-fixes). * Input: mms114 - fix Y-resolution configuration (git-fixes). * Input: psxpad-spi - set driver data before use (git-fixes). * Input: sur40 - fix input device registration ordering (stable-fixes). * Input: sur40 - fix V4L error path cleanup (stable-fixes). * Input: synaptics-rmi4 - block s_input when F54 queue is busy (git-fixes). * Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (git-fixes). * Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (git- fixes). * Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (git- fixes). * Input: synaptics-rmi4 - zero report size on F54 work error (git-fixes). * Input: xpad - add support for ZENAIM LEVERLESS (stable-fixes). * interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (git-fixes). * ipmi: ipmb: validate write message length (git-fixes). * ipmi: si: Fix NULL pointer dereference after failed registration (git- fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (git-fixes). * leds: pca9532: Fix inverted GPIO output polarity (git-fixes). * leds: pca9532: Fix phantom device registration on missing hardware (git- fixes). * lib/string: fix memchr_inv() for large ranges (git-fixes). * lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() (git-fixes). * mailbox: qcom-ipcc: fix duplicate channel allocation across holes (git- fixes). * mailbox: rockchip: disable pclk on probe failure and unbind (git-fixes). * maple_tree: fix argument name in header (git-fixes). * md/raid1: create serial pool adding rdev to array with serialize_policy=1 (bsc#1272261). * media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref (git-fixes). * media: cec-pin: Fix event FIFO ordering (git-fixes). * media: cec: disable delayed work before freeing an interrupted transmit (git-fixes). * media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash (git-fixes). * media: cec: Serialize exclusive follower delivery (git-fixes). * media: cec: stm32: prevent out-of-bounds write on RX overflow (git-fixes). * media: cedrus: fix memory leak in cedrus_init_ctrls() (git-fixes). * media: cobalt: Avoid freeing ALSA private data twice (git-fixes). * media: cx231xx: reject geometry changes while the VBI queue is busy (git- fixes). * media: cx23885: cancel NetUP CI work before teardown (git-fixes). * media: em28xx: defer audio-only extension registration (git-fixes). * media: em28xx: fix use-after-free of dev_next->devlist on disconnect (git- fixes). * media: go7007: defer the ALSA v4l2 put until card release (git-fixes). * media: i2c: ov02a10: fix endpoint parsing use-after-free (git-fixes). * media: i2c: ov7740: fix use-after-destroy in remove (git-fixes). * media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define (git- fixes). * media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define (git-fixes). * media: mc-entity: Add missing kerneldoc (git-fixes). * media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common (git- fixes). * media: nxp: imx8-isi: Correct color map between V4L2 and ISI (git-fixes). * media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing (git-fixes). * media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks (git-fixes). * media: rc: sunxi-cir: Unregister rc device on probe failure (git-fixes). * media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure (git-fixes). * media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak (git-fixes). * media: s2255: bound JPEG frame size before copying into the buffer (git- fixes). * media: s2255: check firmware size before reading trailing marker (git- fixes). * media: saa7164: fix cleanup on resource allocation failure (git-fixes). * media: tda18250: fix possible integer overflow (git-fixes). * media: usbtv: keep device alive while ALSA card exists (git-fixes). * media: v4l2-ctrls: Allow unknown HDR10 white point and luminance (git- fixes). * media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link (git-fixes). * media: venus: fix payload size calculation in parse_raw_formats() (git- fixes). * media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() (git-fixes). * media: vicodec: fix out-of-bounds write in FWHT encoder (git-fixes). * media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure (git-fixes). * media: vimc: fix pixel format lookup in enum_framesizes (git-fixes). * media: zoran: Avoid freeing a registered video_device twice (git-fixes). * mei: pull kvfree out of spinlock (git-fixes). * mfd: iqs62x: Reject zero-length firmware records (git-fixes). * mfd: rave-sp: validate received frame payload lengths (git-fixes). * misc: bcm-vk: Use acquire/release for msgq_inited (git-fixes). * misc: fastrpc: fix channel ctx ref leak when session alloc fails (git- fixes). * misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (git-fixes). * misc: fastrpc: Remove buffer from list prior to unmap operation (git-fixes). * misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke (git- fixes). * misc: rtsx: add missing write register handling (git-fixes). * misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() (git- fixes). * mkspec-dtb: Move DTS prefix into package list. * mkspec-dtb: Move provides-obsoletes to package list. * mkspec-dtb: Put per-architecture package lists into a hash. * mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (git- fixes). * mmc: sdhci: unmap the bounce buffer before device release (git-fixes). * mmc: via-sdmmc: stop card-detect handling on probe failure (git-fixes). * mtd: afs: validate v2 image info bounds (git-fixes). * mtd: mtdoops: free page bitmap when the backing MTD is removed (git-fixes). * mtd: mtdswap: Avoid freeing registered blktrans device twice (git-fixes). * mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() (git-fixes). * mtd: rawnand: validate ONFI extended parameter page sections (git-fixes). * net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes). * net: mana: Add handler for sriov configure (bsc#1272756). * net: mana: Cap MSI-X vectors to the device MSI-X table size (git-fixes). * net: mana: Extend RX CQE coalescing up to 8 packets (git-fixes). * net: mana: Fall back to scattered pages for GDMA queues (git-fixes). * net: mana: force full-page RX buffers via ethtool private flag (bsc#1269792). * net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792). * net: mana: Route ring-buffer access through offset-based helpers (git- fixes). * net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). * net: thunderbolt: Count delivered packets in rx_packets and rx_bytes (git- fixes). * net: thunderbolt: Mark the connection down when bringing it up fails (git- fixes). * net: thunderbolt: Release the Rx HopID that was handed out on mismatch (git- fixes). * net: thunderbolt: Tear down DMA paths before stopping the rings (git-fixes). * net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (git-fixes). * net: usb: ipheth: fix carrier_work UAF on disconnect (git-fixes). * nfc: digital: clamp SENSF_RES length to the destination buffer (git-fixes). * nfc: digital: Do not dump a NULL response in command completion (git-fixes). * nfc: fdp: bound the device-reported read length and fix an skb leak (git- fixes). * nfc: llcp: avoid userspace overflow on invalid optlen (git-fixes). * nfc: llcp: bound SNL TLV parsing to the skb and add length checks (git- fixes). * nfc: llcp: bound the connect_sn TLV walk to the skb (git-fixes). * nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (git-fixes). * nfc: llcp: read llcp_sock->local under the socket lock in getsockopt (git- fixes). * nfc: llcp: reject PDUs shorter than the LLCP header (git-fixes). * nfc: microread: validate target discovery payload lengths (git-fixes). * nfc: nci: fix double completion race in nci_data_exchange_complete (git- fixes). * nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (git- fixes). * nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (git- fixes). * nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing (git- fixes). * nfc: nci: free destination parameters when closing a connection (git-fixes). * nfc: pn533: hold a reference to the request skb during send_frame (git- fixes). * nfc: pn533: purge fragmented skbs during cleanup (git-fixes). * nfc: st21nfca: validate ATR_REQ length against the received frame (git- fixes). * nouveau/gem: reserve the bo in the info ioctl around the vma lookup (git- fixes). * PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] (git-fixes). * PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk (git- fixes). * PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git- fixes). * PCI: j721e: Fix incorrect max_lanes for J7200 (git-fixes). * PCI: meson: Fix GPIO state while requesting PERST# (git-fixes). * phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs (git- fixes). * phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend (git-fixes). * phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table (git- fixes). * phy: sunplus: fix error handling in sp_uphy_init() (git-fixes). * pinctrl: bcm2835: Don't remove an unregistered GPIO chip (git-fixes). * pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip (git-fixes). * pinctrl: rockchip: Reset the pin count when recalculating SoC data (git- fixes). * platform/chrome: cros_ec_debugfs: Clean up console log on probe failure (git-fixes). * platform/chrome: cros_ec_debugfs: Unregister panic notifier (git-fixes). * platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count (git- fixes). * platform/chrome: sensorhub: Bound the EC-reported sensor number (git-fixes). * platform/chrome: sensorhub: Fix dropped timestamp events and log spam (git- fixes). * platform/chrome: sensorhub: Fix memory overread in ring handler (git-fixes). * platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL (git- fixes). * platform/surface: acpi-notify: Check ACPI companion before use (git-fixes). * platform/x86: dell-privacy: Fix race condition (git-fixes). * platform/x86: dell-wmi-base: Fix resource leak on module load failure (git- fixes). * platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (git-fixes). * platform/x86: dell-wmi-sysman: Fix instance ID bounds (git-fixes). * platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path (git-fixes). * platform/x86: ISST: Just allow 2 bits for SST feature enable (git-fixes). * platform/x86: ISST: Validate level in perf mask ioctls (git-fixes). * platform/x86: ISST: Validate logical CPU id and clos id (git-fixes). * platform/x86: ISST: Validate socket ID in clos_assoc ioctl (git-fixes). * PM: sleep: Fix off-by-one in wakelocks number limit check (git-fixes). * power: supply: bd99954: Drop bad register fields (git-fixes). * power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq27520g4: fix REG_TTES address (git-fixes). * power: supply: bq256xx: drain usb_work before freeing the charger (git- fixes). * power: supply: bq24257: fix use-after-free on remove (git-fixes). * power: supply: bq25890: Fix power_supply reference leak (git-fixes). * power: supply: cros_usbpd-charger: bound the EC-reported port count (git- fixes). * power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS (git- fixes). * power: supply: isp1704_charger: cancel work on remove (git-fixes). * power: supply: lp8727: fix use-after-free in lp8727_release_irq() (git- fixes). * power: supply: max17040: drop incorrect I2C functionality check (git-fixes). * power: supply: max17040: synchronize work cancellation on suspend (git- fixes). * power: supply: qcom_battmgr: terminate the strings from firmware (git- fixes). * power: supply: rt9455: quiesce delayed work before teardown (git-fixes). * power: supply: sbs-battery: Use a per-device serial number buffer (git- fixes). * power: supply: twl4030_charger: cancel workers via devm (git-fixes). * power: supply: ucs1002: fix use-after-free on remove (git-fixes). * powercap: intel_rapl_tpmi: Handle PMU registration failure during probe (git-fixes). * powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash (bsc#1271256). * powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). * powerpc/pseries: pci - logic bug (bsc#1274749 ltc#221282 bsc#1274755 ltc#221284 bsc#1274756 ltc#221283). * ppdev: prevent overflow when setting port timeout (git-fixes). * qede: fix out-of-bounds check for cqe->len_list (git-fixes). * rapidio: clear mport->net when rio_add_net() fails (git-fixes). * rapidio: mport_cdev: fix use-after-free in dma_req_free() (git-fixes). * RDMA/irdma: Remove redundant legacy_mode checks (git-fixes). * RDMA/mana_ib: drain QP references after partial table insertion (git-fixes). * RDMA/mana_ib: unify QP lookup table (git-fixes). * RDMA/mlx5: Fix integer overflow of user QP buffer size (git-fixes). * regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (git-fixes). * regulator: core: use system_freezable_wq for init complete work (git-fixes). * regulator: devres: add API for reference voltage supplies (stable-fixes). * regulator: devres: fix devm_regulator_get_enable_read_voltage() return (git- fixes). * regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata (git-fixes). * regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling (git-fixes). * remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev (git-fixes). * remoteproc: qcom_q6v5_adsp: Fix reference leak for device node (git-fixes). * remoteproc: scp: Fix device reference leak on failed lookup (git-fixes). * Revert "drm/amdgpu: fix aperture mapping leak" (git-fixes). * Revert "media: v4l2-dev: fix error handling in __video_register_device()" (git-fixes). * Revert "thermal/drivers/hwmon: Cleanup coding style a bit" (stable-fixes). * rpmsg: core: Fix incorrect return value documentation (git-fixes). * rpmsg: glink: smem: order FIFO read after availability check (git-fixes). * rtc: gamecube: check return value of devm_rtc_register_device() (git-fixes). * rtc: pcf8563: fix clock provider leak on unbind (git-fixes). * rtc: pcf85363: Add error checking to regmap calls in probe() (git-fixes). * rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers (git-fixes). * rtc: rzn1: Fix weekday underflow when alarm crosses month boundary (git- fixes). * rtc: zynqmp: Return optional clock lookup errors (git-fixes). * scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes). * sctp: avoid auth_enable sysctl UAF during netns teardown (git-fixes). * serial: 8250_dma: Clear stale RX state on shutdown (git-fixes). * serial: amba-pl011: unprepare console clock on unregister (git-fixes). * serial: core: clear freed pointers on uart_register_driver() failure (git- fixes). * serial: qcom-geni: fix TX DMA buffer flush (git-fixes). * serial: sc16is7xx: fix copy-paste errors in EFR_SWFLOWx_BIT constants (stable-fixes). * smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). * smb: client: reject overlapping data areas in SMB2 responses (git-fixes). * smb: client: require net admin for CIFS SWN netlink (bsc#1273966). * smb: client: resolve SWN tcon from live registrations (bsc#1273872). * soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() (git- fixes). * soc: qcom: rpmh-rsc: manage PM notifiers with devres (git-fixes). * soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() (git-fixes). * software node: Fix software_node_get_reference_args() with index -1 (git- fixes). * soundwire: qcom: Fix port exhaustion check in stream_alloc_ports (git- fixes). * speakup: keyhelp: guard letter_offsets possible out-of-range indexing (git- fixes). * spi: img-spfi: don't disable runtime PM on DMA deferred probe (git-fixes). * spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (stable-fixes). * spi: sprd-adi: Fix probe succeeding without registering the controller (git- fixes). * staging: fbtft: Use sysfs_emit_at() to print to sysfs file (git-fixes). * staging: media: tegra-video: vi: fix probe failure on skipped last port (git-fixes). * staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown (git- fixes). * staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() (git-fixes). * staging: rtl8723bs: fix missing shared-key auth challenge length check (git- fixes). * staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (git-fixes). * staging: rtl8723bs: fix OOB read in WMM_param_handler() (git-fixes). * staging: rtl8723bs: use kfree_sensitive() for key material (git-fixes). * staging: rtl8723bs: validate monitor transmit frame lengths (git-fixes). * staging: sm750fb: gate dualview dataflow using g_dualview (git-fixes). * thermal/drivers/imx: Disable clock on runtime resume failure (git-fixes). * thermal/drivers/qoriq: Disable clock on resume failure (git-fixes). * thermal: intel: int3400: clean up ODVP on probe failures (git-fixes). * thunderbolt: Bound the DROM dual link port number before indexing sw->ports (git-fixes). * thunderbolt: icm: Preserve USB4 proxy data-valid bit (git-fixes). * tlclk: if sscanf() fails, fall back to 0, not random value (git-fixes). * tpm: st33zp24: Return zero on status read failure (git-fixes). * tpm: st33zp24: Validate locality read result (git-fixes). * tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (git-fixes). * tty: clear cdev pointer after cdev_add() failure (git-fixes). * tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 (git-fixes). * tty: skip cdev_del() when no cdev is registered (git-fixes). * uio: Fix stale info pointer in failed registration path (git-fixes). * usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (git-fixes). * usb: atm: usbatm: fix invalid ci_range initialization (git-fixes). * USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (git-fixes). * usb: cdnsp: fix incorrect endian conversions for APB timeout register (git- fixes). * usb: dwc2: add missing @remotewakeup kernel-doc parameter (git-fixes). * usb: dwc2: gadget: Exit partial power down state when changing USB pull-up (git-fixes). * usb: gadget: configfs: fix out-of-bounds read of qw_sign (git-fixes). * usb: gadget: f_fs: Prevent deadlock during ep0 read loop (git-fixes). * usb: gadget: f_ncm: Use unsigned int for ndp_index (git-fixes). * usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() (git-fixes). * usb: gadget: f_uac1_legacy: remove broken string configfs attributes (git- fixes). * usb: gadget: pch_udc: remove excess kernel-doc member for registered (git- fixes). * usb: gadget: r8a66597: avoid double free of ep0_req in probe error path (git-fixes). * usb: gadget: snps_udc_plat: clean up PHY on probe deferral (git-fixes). * usb: gadget: u_audio: Fix use-after-free on sound card disconnect (git- fixes). * usb: gadget: uac: validate rate list length before storing (git-fixes). * usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() (git-fixes). * usb: mtu3: allow system suspend during active gadget connection (git-fixes). * usb: musb: omap2430: clean up probe error handling (stable-fixes). * USB: phy: fsl-usb: fix missing static keywords (git-fixes). * usb: renesas_usbhs: Fix power-off ordering on unbind (git-fixes). * USB: serial: digi_acceleport: fix port registration order (git-fixes). * USB: serial: ftdi_sio: add support for E+H FXA291 (stable-fixes). * USB: serial: option: add TDTECH MT5710-CN (stable-fixes). * USB: serial: option: fix slab OOB read in interrupt URB callback (git- fixes). * USB: serial: spcp8x5: drop broken carrier detect support (git-fixes). * USB: storage: add NO_ATA_1X quirk for Longmai USB Key (stable-fixes). * usb: typec: ucsi: unregister debugfs entries on teardown (git-fixes). * usb: usbfs: fix use-after-free of usb_device in usbdev_release() (git- fixes). * usb: xhci: Handle USB3 port events when there is one roothub (git-fixes). * vt: add permission check for KDSKBMETA ioctl (stable-fixes). * vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (stable- fixes). * w1: ds28e17: reject an oversize length on an I2C block read (git-fixes). * w1: ds2482: Fix signedness bug in ds2482_w1_triplet() (git-fixes). * wifi: ath6kl: avoid buffer overreads in WMI event handlers (git-fixes). * wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (git-fixes). * wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump (git-fixes). * wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() (git-fixes). * wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate (git- fixes). * wifi: ath11k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() (git-fixes). * wifi: ath12k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (git-fixes). * wifi: brcmfmac: fix P2P action frame handling without device vif (git- fixes). * wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs (git-fixes). * wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments (git-fixes). * wifi: iwlwifi: mei: pass correct argument to function (git-fixes). * wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser (git-fixes). * wifi: mac80211: send TWT teardown to peer after setup TX failure (git- fixes). * wifi: mac80211: skip default WMM setup for AP_VLAN links (git-fixes). * wifi: mac80211: skip unused probe response countdown offsets (git-fixes). * wifi: mt76: fix 4th chain ACK RSSI bitmask in sta_poll (git-fixes). * wifi: mt76: fix ER-SU 106-tone RU check in RX rate decode (git-fixes). * wifi: mt76: fix HE DCM max-RU capability encoding (git-fixes). * wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length (git- fixes). * wifi: mt76: mt792x: Fix memory leak in SDIO TX path (git-fixes). * wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (git- fixes). * wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss (git- fixes). * wifi: mt76: mt7915: fix double hif2 init on the non-WED path (git-fixes). * wifi: mt76: mt7915: fix ext PHY use-after-free on register error path (git- fixes). * wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 (git- fixes). * wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie (git-fixes). * wifi: mt76: mt7915: release hif2 reference on probe IRQ failure (git-fixes). * wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement (git- fixes). * wifi: mt76: mt7915: unwind state on add_interface failure (git-fixes). * wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields (git- fixes). * wifi: mt76: mt7915: write RX header translation bit to the correct register (git-fixes). * wifi: mt76: mt7921: validate CLC firmware records (git-fixes). * wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (git- fixes). * wifi: mt76: mt7925: fix msg len mismatch between driver and firmware (git- fixes). * wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config (git- fixes). * wifi: mt76: mt7996: don't report a zero TX bitrate (git-fixes). * wifi: mt76: mt7996: fix reg addr remap when addr is 0 (git-fixes). * wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV (git- fixes). * wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset (git-fixes). * wifi: mt76: mt7996: validate RX band_idx before dereferencing phys (git- fixes). * wifi: mt76: report data NSS for STBC frames in RX rate decode (git-fixes). * wifi: mwifiex: Detach sync cmd buffer on interrupted wait (git-fixes). * wifi: rtlwifi: pci: fix error path in rtl_pci_probe() (git-fixes). * wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (git-fixes). * wifi: rtw89: fix HE extended capability length check (git-fixes). * wifi: zd1211rw: reject secondary interfaces to prevent conflicts (git- fixes). * x86/bugs: Clarify that syscall hardening isn't a BHI mitigation (git-fixes). * xhci: dbgtty: Fix unregister on tty_alloc_driver() failure (git-fixes). * xhci: dbgtty: Fix unregister on tty_register_driver() failure (git-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-601=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 nosrc s390x x86_64) * kernel-default-6.4.0-52.1 * SUSE Linux Micro 6.0 (x86_64) * kernel-kvmsmall-debuginfo-6.4.0-52.1 * kernel-default-base-6.4.0-52.1.21.35 * kernel-kvmsmall-debugsource-6.4.0-52.1 * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * kernel-default-debuginfo-6.4.0-52.1 * kernel-default-debugsource-6.4.0-52.1 * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-default-livepatch-6.4.0-52.1 * SUSE Linux Micro 6.0 (noarch) * kernel-source-6.4.0-52.1 * kernel-macros-6.4.0-52.1 * kernel-devel-6.4.0-52.1 * SUSE Linux Micro 6.0 (nosrc x86_64) * kernel-kvmsmall-6.4.0-52.1 * SUSE Linux Micro 6.0 (aarch64) * kernel-default-base-6.4.0-52.1.21.36 ## References: * https://www.suse.com/security/cve/CVE-2024-44981.html * https://www.suse.com/security/cve/CVE-2024-57841.html * https://www.suse.com/security/cve/CVE-2025-38469.html * https://www.suse.com/security/cve/CVE-2025-39964.html * https://www.suse.com/security/cve/CVE-2025-40022.html * https://www.suse.com/security/cve/CVE-2025-68179.html * https://www.suse.com/security/cve/CVE-2025-68214.html * https://www.suse.com/security/cve/CVE-2025-71075.html * https://www.suse.com/security/cve/CVE-2025-71104.html * https://www.suse.com/security/cve/CVE-2026-23210.html * https://www.suse.com/security/cve/CVE-2026-23230.html * https://www.suse.com/security/cve/CVE-2026-23454.html * https://www.suse.com/security/cve/CVE-2026-31392.html * https://www.suse.com/security/cve/CVE-2026-31418.html * https://www.suse.com/security/cve/CVE-2026-31531.html * https://www.suse.com/security/cve/CVE-2026-31557.html * https://www.suse.com/security/cve/CVE-2026-31663.html * https://www.suse.com/security/cve/CVE-2026-43116.html * https://www.suse.com/security/cve/CVE-2026-43125.html * https://www.suse.com/security/cve/CVE-2026-43163.html * https://www.suse.com/security/cve/CVE-2026-43271.html * https://www.suse.com/security/cve/CVE-2026-43273.html * https://www.suse.com/security/cve/CVE-2026-43278.html * https://www.suse.com/security/cve/CVE-2026-43319.html * https://www.suse.com/security/cve/CVE-2026-43363.html * https://www.suse.com/security/cve/CVE-2026-43416.html * https://www.suse.com/security/cve/CVE-2026-45897.html * https://www.suse.com/security/cve/CVE-2026-45968.html * https://www.suse.com/security/cve/CVE-2026-46070.html * https://www.suse.com/security/cve/CVE-2026-46091.html * https://www.suse.com/security/cve/CVE-2026-46107.html * https://www.suse.com/security/cve/CVE-2026-46115.html * https://www.suse.com/security/cve/CVE-2026-46195.html * https://www.suse.com/security/cve/CVE-2026-52920.html * https://www.suse.com/security/cve/CVE-2026-52925.html * https://www.suse.com/security/cve/CVE-2026-52929.html * https://www.suse.com/security/cve/CVE-2026-52935.html * https://www.suse.com/security/cve/CVE-2026-52939.html * https://www.suse.com/security/cve/CVE-2026-52946.html * https://www.suse.com/security/cve/CVE-2026-52975.html * https://www.suse.com/security/cve/CVE-2026-52977.html * https://www.suse.com/security/cve/CVE-2026-52990.html * https://www.suse.com/security/cve/CVE-2026-52994.html * https://www.suse.com/security/cve/CVE-2026-53001.html * https://www.suse.com/security/cve/CVE-2026-53033.html * https://www.suse.com/security/cve/CVE-2026-53059.html * https://www.suse.com/security/cve/CVE-2026-53076.html * https://www.suse.com/security/cve/CVE-2026-53077.html * https://www.suse.com/security/cve/CVE-2026-53089.html * https://www.suse.com/security/cve/CVE-2026-53091.html * https://www.suse.com/security/cve/CVE-2026-53094.html * https://www.suse.com/security/cve/CVE-2026-53096.html * https://www.suse.com/security/cve/CVE-2026-53110.html * https://www.suse.com/security/cve/CVE-2026-53111.html * https://www.suse.com/security/cve/CVE-2026-53126.html * https://www.suse.com/security/cve/CVE-2026-53154.html * https://www.suse.com/security/cve/CVE-2026-53163.html * https://www.suse.com/security/cve/CVE-2026-53207.html * https://www.suse.com/security/cve/CVE-2026-53219.html * https://www.suse.com/security/cve/CVE-2026-53220.html * https://www.suse.com/security/cve/CVE-2026-53223.html * https://www.suse.com/security/cve/CVE-2026-53228.html * https://www.suse.com/security/cve/CVE-2026-53238.html * https://www.suse.com/security/cve/CVE-2026-53260.html * https://www.suse.com/security/cve/CVE-2026-53264.html * https://www.suse.com/security/cve/CVE-2026-53269.html * https://www.suse.com/security/cve/CVE-2026-53273.html * https://www.suse.com/security/cve/CVE-2026-53309.html * https://www.suse.com/security/cve/CVE-2026-53330.html * https://www.suse.com/security/cve/CVE-2026-53336.html * https://www.suse.com/security/cve/CVE-2026-53337.html * https://www.suse.com/security/cve/CVE-2026-53353.html * https://www.suse.com/security/cve/CVE-2026-53365.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://www.suse.com/security/cve/CVE-2026-53381.html * https://www.suse.com/security/cve/CVE-2026-53388.html * https://www.suse.com/security/cve/CVE-2026-63801.html * https://www.suse.com/security/cve/CVE-2026-63808.html * https://www.suse.com/security/cve/CVE-2026-63810.html * https://www.suse.com/security/cve/CVE-2026-63823.html * https://www.suse.com/security/cve/CVE-2026-63827.html * https://www.suse.com/security/cve/CVE-2026-63828.html * https://www.suse.com/security/cve/CVE-2026-63860.html * https://www.suse.com/security/cve/CVE-2026-63865.html * https://www.suse.com/security/cve/CVE-2026-63868.html * https://www.suse.com/security/cve/CVE-2026-63879.html * https://www.suse.com/security/cve/CVE-2026-63881.html * https://www.suse.com/security/cve/CVE-2026-63886.html * https://www.suse.com/security/cve/CVE-2026-63887.html * https://www.suse.com/security/cve/CVE-2026-63888.html * https://www.suse.com/security/cve/CVE-2026-63889.html * https://www.suse.com/security/cve/CVE-2026-63891.html * https://www.suse.com/security/cve/CVE-2026-63898.html * https://www.suse.com/security/cve/CVE-2026-63920.html * https://www.suse.com/security/cve/CVE-2026-63925.html * https://www.suse.com/security/cve/CVE-2026-63926.html * https://www.suse.com/security/cve/CVE-2026-63928.html * https://www.suse.com/security/cve/CVE-2026-63944.html * https://www.suse.com/security/cve/CVE-2026-63969.html * https://www.suse.com/security/cve/CVE-2026-63970.html * https://www.suse.com/security/cve/CVE-2026-63972.html * https://www.suse.com/security/cve/CVE-2026-63973.html * https://www.suse.com/security/cve/CVE-2026-63980.html * https://www.suse.com/security/cve/CVE-2026-63985.html * https://www.suse.com/security/cve/CVE-2026-63990.html * https://www.suse.com/security/cve/CVE-2026-63992.html * https://www.suse.com/security/cve/CVE-2026-63999.html * https://www.suse.com/security/cve/CVE-2026-64000.html * https://www.suse.com/security/cve/CVE-2026-64001.html * https://www.suse.com/security/cve/CVE-2026-64002.html * https://www.suse.com/security/cve/CVE-2026-64004.html * https://www.suse.com/security/cve/CVE-2026-64005.html * https://www.suse.com/security/cve/CVE-2026-64006.html * https://www.suse.com/security/cve/CVE-2026-64007.html * https://www.suse.com/security/cve/CVE-2026-64010.html * https://www.suse.com/security/cve/CVE-2026-64011.html * https://www.suse.com/security/cve/CVE-2026-64014.html * https://www.suse.com/security/cve/CVE-2026-64015.html * https://www.suse.com/security/cve/CVE-2026-64018.html * https://www.suse.com/security/cve/CVE-2026-64029.html * https://www.suse.com/security/cve/CVE-2026-64034.html * https://www.suse.com/security/cve/CVE-2026-64039.html * https://www.suse.com/security/cve/CVE-2026-64047.html * https://www.suse.com/security/cve/CVE-2026-64048.html * https://www.suse.com/security/cve/CVE-2026-64051.html * https://www.suse.com/security/cve/CVE-2026-64052.html * https://www.suse.com/security/cve/CVE-2026-64073.html * https://www.suse.com/security/cve/CVE-2026-64083.html * https://www.suse.com/security/cve/CVE-2026-64084.html * https://www.suse.com/security/cve/CVE-2026-64085.html * https://www.suse.com/security/cve/CVE-2026-64086.html * https://www.suse.com/security/cve/CVE-2026-64087.html * https://www.suse.com/security/cve/CVE-2026-64088.html * https://www.suse.com/security/cve/CVE-2026-64097.html * https://www.suse.com/security/cve/CVE-2026-64098.html * https://www.suse.com/security/cve/CVE-2026-64102.html * https://www.suse.com/security/cve/CVE-2026-64109.html * https://www.suse.com/security/cve/CVE-2026-64112.html * https://www.suse.com/security/cve/CVE-2026-64113.html * https://www.suse.com/security/cve/CVE-2026-64114.html * https://www.suse.com/security/cve/CVE-2026-64115.html * https://www.suse.com/security/cve/CVE-2026-64118.html * https://www.suse.com/security/cve/CVE-2026-64121.html * https://www.suse.com/security/cve/CVE-2026-64125.html * https://www.suse.com/security/cve/CVE-2026-64126.html * https://www.suse.com/security/cve/CVE-2026-64128.html * https://www.suse.com/security/cve/CVE-2026-64131.html * https://www.suse.com/security/cve/CVE-2026-64133.html * https://www.suse.com/security/cve/CVE-2026-64135.html * https://www.suse.com/security/cve/CVE-2026-64137.html * https://www.suse.com/security/cve/CVE-2026-64148.html * https://www.suse.com/security/cve/CVE-2026-64155.html * https://www.suse.com/security/cve/CVE-2026-64164.html * https://www.suse.com/security/cve/CVE-2026-64166.html * https://www.suse.com/security/cve/CVE-2026-64168.html * https://www.suse.com/security/cve/CVE-2026-64178.html * https://www.suse.com/security/cve/CVE-2026-64185.html * https://www.suse.com/security/cve/CVE-2026-64188.html * https://www.suse.com/security/cve/CVE-2026-64190.html * https://www.suse.com/security/cve/CVE-2026-64192.html * https://www.suse.com/security/cve/CVE-2026-64214.html * https://www.suse.com/security/cve/CVE-2026-64217.html * https://www.suse.com/security/cve/CVE-2026-64218.html * https://www.suse.com/security/cve/CVE-2026-64219.html * https://www.suse.com/security/cve/CVE-2026-64222.html * https://www.suse.com/security/cve/CVE-2026-64225.html * https://www.suse.com/security/cve/CVE-2026-64237.html * https://www.suse.com/security/cve/CVE-2026-64243.html * https://www.suse.com/security/cve/CVE-2026-64245.html * https://www.suse.com/security/cve/CVE-2026-64246.html * https://www.suse.com/security/cve/CVE-2026-64247.html * https://www.suse.com/security/cve/CVE-2026-64249.html * https://www.suse.com/security/cve/CVE-2026-64257.html * https://www.suse.com/security/cve/CVE-2026-64266.html * https://www.suse.com/security/cve/CVE-2026-64268.html * https://www.suse.com/security/cve/CVE-2026-64271.html * https://www.suse.com/security/cve/CVE-2026-64273.html * https://www.suse.com/security/cve/CVE-2026-64274.html * https://www.suse.com/security/cve/CVE-2026-64275.html * https://www.suse.com/security/cve/CVE-2026-64276.html * https://www.suse.com/security/cve/CVE-2026-64277.html * https://www.suse.com/security/cve/CVE-2026-64286.html * https://www.suse.com/security/cve/CVE-2026-64287.html * https://www.suse.com/security/cve/CVE-2026-64294.html * https://www.suse.com/security/cve/CVE-2026-64296.html * https://www.suse.com/security/cve/CVE-2026-64303.html * https://www.suse.com/security/cve/CVE-2026-64304.html * https://www.suse.com/security/cve/CVE-2026-64305.html * https://www.suse.com/security/cve/CVE-2026-64306.html * https://www.suse.com/security/cve/CVE-2026-64312.html * https://www.suse.com/security/cve/CVE-2026-64313.html * https://www.suse.com/security/cve/CVE-2026-64315.html * https://www.suse.com/security/cve/CVE-2026-64316.html * https://www.suse.com/security/cve/CVE-2026-64317.html * https://www.suse.com/security/cve/CVE-2026-64322.html * https://www.suse.com/security/cve/CVE-2026-64323.html * https://www.suse.com/security/cve/CVE-2026-64329.html * https://www.suse.com/security/cve/CVE-2026-64331.html * https://www.suse.com/security/cve/CVE-2026-64332.html * https://www.suse.com/security/cve/CVE-2026-64333.html * https://www.suse.com/security/cve/CVE-2026-64334.html * https://www.suse.com/security/cve/CVE-2026-64335.html * https://www.suse.com/security/cve/CVE-2026-64337.html * https://www.suse.com/security/cve/CVE-2026-64338.html * https://www.suse.com/security/cve/CVE-2026-64340.html * https://www.suse.com/security/cve/CVE-2026-64341.html * https://www.suse.com/security/cve/CVE-2026-64342.html * https://www.suse.com/security/cve/CVE-2026-64343.html * https://www.suse.com/security/cve/CVE-2026-64344.html * https://www.suse.com/security/cve/CVE-2026-64346.html * https://www.suse.com/security/cve/CVE-2026-64348.html * https://www.suse.com/security/cve/CVE-2026-64350.html * https://www.suse.com/security/cve/CVE-2026-64351.html * https://www.suse.com/security/cve/CVE-2026-64355.html * https://www.suse.com/security/cve/CVE-2026-64358.html * https://www.suse.com/security/cve/CVE-2026-64362.html * https://www.suse.com/security/cve/CVE-2026-64365.html * https://www.suse.com/security/cve/CVE-2026-64375.html * https://www.suse.com/security/cve/CVE-2026-64376.html * https://www.suse.com/security/cve/CVE-2026-64378.html * https://www.suse.com/security/cve/CVE-2026-64381.html * https://www.suse.com/security/cve/CVE-2026-64382.html * https://www.suse.com/security/cve/CVE-2026-64383.html * https://www.suse.com/security/cve/CVE-2026-64384.html * https://www.suse.com/security/cve/CVE-2026-64385.html * https://www.suse.com/security/cve/CVE-2026-64386.html * https://www.suse.com/security/cve/CVE-2026-64387.html * https://www.suse.com/security/cve/CVE-2026-64388.html * https://www.suse.com/security/cve/CVE-2026-64401.html * https://www.suse.com/security/cve/CVE-2026-64403.html * https://www.suse.com/security/cve/CVE-2026-64406.html * https://www.suse.com/security/cve/CVE-2026-64408.html * https://www.suse.com/security/cve/CVE-2026-64409.html * https://www.suse.com/security/cve/CVE-2026-64411.html * https://www.suse.com/security/cve/CVE-2026-64412.html * https://www.suse.com/security/cve/CVE-2026-64420.html * https://www.suse.com/security/cve/CVE-2026-64421.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64427.html * https://www.suse.com/security/cve/CVE-2026-64429.html * https://www.suse.com/security/cve/CVE-2026-64433.html * https://www.suse.com/security/cve/CVE-2026-64434.html * https://www.suse.com/security/cve/CVE-2026-64436.html * https://www.suse.com/security/cve/CVE-2026-64440.html * https://www.suse.com/security/cve/CVE-2026-64442.html * https://www.suse.com/security/cve/CVE-2026-64443.html * https://www.suse.com/security/cve/CVE-2026-64444.html * https://www.suse.com/security/cve/CVE-2026-64445.html * https://www.suse.com/security/cve/CVE-2026-64448.html * https://www.suse.com/security/cve/CVE-2026-64450.html * https://www.suse.com/security/cve/CVE-2026-64454.html * https://www.suse.com/security/cve/CVE-2026-64455.html * https://www.suse.com/security/cve/CVE-2026-64463.html * https://www.suse.com/security/cve/CVE-2026-64470.html * https://www.suse.com/security/cve/CVE-2026-64471.html * https://www.suse.com/security/cve/CVE-2026-64472.html * https://www.suse.com/security/cve/CVE-2026-64478.html * https://www.suse.com/security/cve/CVE-2026-64479.html * https://www.suse.com/security/cve/CVE-2026-64480.html * https://www.suse.com/security/cve/CVE-2026-64481.html * https://www.suse.com/security/cve/CVE-2026-64482.html * https://www.suse.com/security/cve/CVE-2026-64483.html * https://www.suse.com/security/cve/CVE-2026-64484.html * https://www.suse.com/security/cve/CVE-2026-64486.html * https://www.suse.com/security/cve/CVE-2026-64487.html * https://www.suse.com/security/cve/CVE-2026-64489.html * https://www.suse.com/security/cve/CVE-2026-64494.html * https://www.suse.com/security/cve/CVE-2026-64495.html * https://www.suse.com/security/cve/CVE-2026-64496.html * https://www.suse.com/security/cve/CVE-2026-64497.html * https://www.suse.com/security/cve/CVE-2026-64500.html * https://www.suse.com/security/cve/CVE-2026-64503.html * https://www.suse.com/security/cve/CVE-2026-64504.html * https://www.suse.com/security/cve/CVE-2026-64505.html * https://www.suse.com/security/cve/CVE-2026-64511.html * https://www.suse.com/security/cve/CVE-2026-64512.html * https://www.suse.com/security/cve/CVE-2026-64513.html * https://www.suse.com/security/cve/CVE-2026-64524.html * https://www.suse.com/security/cve/CVE-2026-64527.html * https://www.suse.com/security/cve/CVE-2026-64536.html * https://www.suse.com/security/cve/CVE-2026-64537.html * https://www.suse.com/security/cve/CVE-2026-64538.html * https://www.suse.com/security/cve/CVE-2026-64539.html * https://www.suse.com/security/cve/CVE-2026-64540.html * https://www.suse.com/security/cve/CVE-2026-64541.html * https://www.suse.com/security/cve/CVE-2026-64543.html * https://www.suse.com/security/cve/CVE-2026-64544.html * https://www.suse.com/security/cve/CVE-2026-64545.html * https://www.suse.com/security/cve/CVE-2026-64546.html * https://www.suse.com/security/cve/CVE-2026-64547.html * https://www.suse.com/security/cve/CVE-2026-64548.html * https://www.suse.com/security/cve/CVE-2026-64549.html * https://www.suse.com/security/cve/CVE-2026-64551.html * https://www.suse.com/security/cve/CVE-2026-64552.html * https://www.suse.com/security/cve/CVE-2026-64553.html * https://www.suse.com/security/cve/CVE-2026-64554.html * https://www.suse.com/security/cve/CVE-2026-64562.html * https://www.suse.com/security/cve/CVE-2026-64563.html * https://www.suse.com/security/cve/CVE-2026-64565.html * https://www.suse.com/security/cve/CVE-2026-64567.html * https://www.suse.com/security/cve/CVE-2026-64571.html * https://www.suse.com/security/cve/CVE-2026-64572.html * https://www.suse.com/security/cve/CVE-2026-64573.html * https://www.suse.com/security/cve/CVE-2026-64574.html * https://www.suse.com/security/cve/CVE-2026-64576.html * https://www.suse.com/security/cve/CVE-2026-64577.html * https://www.suse.com/security/cve/CVE-2026-64581.html * https://www.suse.com/security/cve/CVE-2026-64582.html * https://www.suse.com/security/cve/CVE-2026-64583.html * https://www.suse.com/security/cve/CVE-2026-64584.html * https://www.suse.com/security/cve/CVE-2026-64585.html * https://www.suse.com/security/cve/CVE-2026-64593.html * https://www.suse.com/security/cve/CVE-2026-64597.html * https://www.suse.com/security/cve/CVE-2026-64598.html * https://www.suse.com/security/cve/CVE-2026-64599.html * https://www.suse.com/security/cve/CVE-2026-64602.html * https://www.suse.com/security/cve/CVE-2026-64604.html * https://www.suse.com/security/cve/CVE-2026-68081.html * https://www.suse.com/security/cve/CVE-2026-68082.html * https://www.suse.com/security/cve/CVE-2026-68085.html * https://www.suse.com/security/cve/CVE-2026-68086.html * https://www.suse.com/security/cve/CVE-2026-68088.html * https://www.suse.com/security/cve/CVE-2026-68091.html * https://www.suse.com/security/cve/CVE-2026-68093.html * https://www.suse.com/security/cve/CVE-2026-68102.html * https://www.suse.com/security/cve/CVE-2026-68104.html * https://www.suse.com/security/cve/CVE-2026-68106.html * https://www.suse.com/security/cve/CVE-2026-68107.html * https://www.suse.com/security/cve/CVE-2026-68108.html * https://www.suse.com/security/cve/CVE-2026-68110.html * https://www.suse.com/security/cve/CVE-2026-68111.html * https://www.suse.com/security/cve/CVE-2026-68112.html * https://www.suse.com/security/cve/CVE-2026-68115.html * https://www.suse.com/security/cve/CVE-2026-68116.html * https://www.suse.com/security/cve/CVE-2026-68117.html * https://www.suse.com/security/cve/CVE-2026-68121.html * https://www.suse.com/security/cve/CVE-2026-68123.html * https://www.suse.com/security/cve/CVE-2026-68125.html * https://www.suse.com/security/cve/CVE-2026-68126.html * https://www.suse.com/security/cve/CVE-2026-68127.html * https://www.suse.com/security/cve/CVE-2026-68129.html * https://www.suse.com/security/cve/CVE-2026-68132.html * https://www.suse.com/security/cve/CVE-2026-68133.html * https://www.suse.com/security/cve/CVE-2026-68136.html * https://www.suse.com/security/cve/CVE-2026-68137.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://www.suse.com/security/cve/CVE-2026-68139.html * https://www.suse.com/security/cve/CVE-2026-68142.html * https://www.suse.com/security/cve/CVE-2026-68143.html * https://www.suse.com/security/cve/CVE-2026-68145.html * https://www.suse.com/security/cve/CVE-2026-68149.html * https://www.suse.com/security/cve/CVE-2026-68153.html * https://www.suse.com/security/cve/CVE-2026-68154.html * https://www.suse.com/security/cve/CVE-2026-68155.html * https://www.suse.com/security/cve/CVE-2026-68156.html * https://www.suse.com/security/cve/CVE-2026-68157.html * https://www.suse.com/security/cve/CVE-2026-68158.html * https://www.suse.com/security/cve/CVE-2026-68159.html * https://www.suse.com/security/cve/CVE-2026-68160.html * https://www.suse.com/security/cve/CVE-2026-68161.html * https://www.suse.com/security/cve/CVE-2026-68162.html * https://www.suse.com/security/cve/CVE-2026-68166.html * https://www.suse.com/security/cve/CVE-2026-68180.html * https://www.suse.com/security/cve/CVE-2026-68181.html * https://www.suse.com/security/cve/CVE-2026-68182.html * https://www.suse.com/security/cve/CVE-2026-68184.html * https://www.suse.com/security/cve/CVE-2026-68188.html * https://www.suse.com/security/cve/CVE-2026-68189.html * https://www.suse.com/security/cve/CVE-2026-68192.html * https://www.suse.com/security/cve/CVE-2026-68193.html * https://www.suse.com/security/cve/CVE-2026-68194.html * https://www.suse.com/security/cve/CVE-2026-68195.html * https://www.suse.com/security/cve/CVE-2026-68196.html * https://www.suse.com/security/cve/CVE-2026-68197.html * https://www.suse.com/security/cve/CVE-2026-68199.html * https://www.suse.com/security/cve/CVE-2026-68202.html * https://www.suse.com/security/cve/CVE-2026-68204.html * https://www.suse.com/security/cve/CVE-2026-68205.html * https://www.suse.com/security/cve/CVE-2026-68206.html * https://www.suse.com/security/cve/CVE-2026-68207.html * https://www.suse.com/security/cve/CVE-2026-68209.html * https://www.suse.com/security/cve/CVE-2026-68210.html * https://www.suse.com/security/cve/CVE-2026-68212.html * https://www.suse.com/security/cve/CVE-2026-68213.html * https://www.suse.com/security/cve/CVE-2026-68214.html * https://www.suse.com/security/cve/CVE-2026-68215.html * https://www.suse.com/security/cve/CVE-2026-68216.html * https://www.suse.com/security/cve/CVE-2026-68217.html * https://www.suse.com/security/cve/CVE-2026-68218.html * https://www.suse.com/security/cve/CVE-2026-68219.html * https://www.suse.com/security/cve/CVE-2026-68220.html * https://www.suse.com/security/cve/CVE-2026-68222.html * https://www.suse.com/security/cve/CVE-2026-68223.html * https://www.suse.com/security/cve/CVE-2026-68226.html * https://www.suse.com/security/cve/CVE-2026-68227.html * https://www.suse.com/security/cve/CVE-2026-68229.html * https://www.suse.com/security/cve/CVE-2026-68231.html * https://www.suse.com/security/cve/CVE-2026-68234.html * https://www.suse.com/security/cve/CVE-2026-68236.html * https://www.suse.com/security/cve/CVE-2026-68238.html * https://www.suse.com/security/cve/CVE-2026-68243.html * https://www.suse.com/security/cve/CVE-2026-68244.html * https://www.suse.com/security/cve/CVE-2026-68246.html * https://www.suse.com/security/cve/CVE-2026-68247.html * https://www.suse.com/security/cve/CVE-2026-68248.html * https://www.suse.com/security/cve/CVE-2026-68249.html * https://www.suse.com/security/cve/CVE-2026-68250.html * https://www.suse.com/security/cve/CVE-2026-68251.html * https://www.suse.com/security/cve/CVE-2026-68254.html * https://www.suse.com/security/cve/CVE-2026-68255.html * https://www.suse.com/security/cve/CVE-2026-68256.html * https://www.suse.com/security/cve/CVE-2026-68259.html * https://www.suse.com/security/cve/CVE-2026-68269.html * https://www.suse.com/security/cve/CVE-2026-68271.html * https://www.suse.com/security/cve/CVE-2026-68272.html * https://www.suse.com/security/cve/CVE-2026-68277.html * https://www.suse.com/security/cve/CVE-2026-68278.html * https://www.suse.com/security/cve/CVE-2026-68279.html * https://www.suse.com/security/cve/CVE-2026-68280.html * https://www.suse.com/security/cve/CVE-2026-68284.html * https://www.suse.com/security/cve/CVE-2026-68286.html * https://www.suse.com/security/cve/CVE-2026-68288.html * https://www.suse.com/security/cve/CVE-2026-68289.html * https://www.suse.com/security/cve/CVE-2026-68293.html * https://www.suse.com/security/cve/CVE-2026-68297.html * https://www.suse.com/security/cve/CVE-2026-68299.html * https://www.suse.com/security/cve/CVE-2026-68300.html * https://www.suse.com/security/cve/CVE-2026-68303.html * https://www.suse.com/security/cve/CVE-2026-68304.html * https://www.suse.com/security/cve/CVE-2026-68306.html * https://www.suse.com/security/cve/CVE-2026-68308.html * https://www.suse.com/security/cve/CVE-2026-68309.html * https://www.suse.com/security/cve/CVE-2026-68310.html * https://www.suse.com/security/cve/CVE-2026-68312.html * https://www.suse.com/security/cve/CVE-2026-68313.html * https://www.suse.com/security/cve/CVE-2026-68315.html * https://www.suse.com/security/cve/CVE-2026-68320.html * https://www.suse.com/security/cve/CVE-2026-68322.html * https://www.suse.com/security/cve/CVE-2026-68324.html * https://www.suse.com/security/cve/CVE-2026-68325.html * https://www.suse.com/security/cve/CVE-2026-68326.html * https://www.suse.com/security/cve/CVE-2026-68327.html * https://www.suse.com/security/cve/CVE-2026-68328.html * https://www.suse.com/security/cve/CVE-2026-68329.html * https://www.suse.com/security/cve/CVE-2026-68331.html * https://www.suse.com/security/cve/CVE-2026-68333.html * https://www.suse.com/security/cve/CVE-2026-68335.html * https://www.suse.com/security/cve/CVE-2026-68336.html * https://www.suse.com/security/cve/CVE-2026-68339.html * https://www.suse.com/security/cve/CVE-2026-68340.html * https://www.suse.com/security/cve/CVE-2026-68343.html * https://www.suse.com/security/cve/CVE-2026-68346.html * https://www.suse.com/security/cve/CVE-2026-68348.html * https://www.suse.com/security/cve/CVE-2026-68349.html * https://www.suse.com/security/cve/CVE-2026-68350.html * https://www.suse.com/security/cve/CVE-2026-68351.html * https://www.suse.com/security/cve/CVE-2026-68352.html * https://www.suse.com/security/cve/CVE-2026-68353.html * https://www.suse.com/security/cve/CVE-2026-68354.html * https://www.suse.com/security/cve/CVE-2026-68355.html * https://www.suse.com/security/cve/CVE-2026-68357.html * https://www.suse.com/security/cve/CVE-2026-68359.html * https://www.suse.com/security/cve/CVE-2026-68360.html * https://www.suse.com/security/cve/CVE-2026-68361.html * https://www.suse.com/security/cve/CVE-2026-68362.html * https://www.suse.com/security/cve/CVE-2026-68363.html * https://www.suse.com/security/cve/CVE-2026-68365.html * https://www.suse.com/security/cve/CVE-2026-68366.html * https://www.suse.com/security/cve/CVE-2026-68368.html * https://www.suse.com/security/cve/CVE-2026-68369.html * https://www.suse.com/security/cve/CVE-2026-68370.html * https://www.suse.com/security/cve/CVE-2026-68372.html * https://www.suse.com/security/cve/CVE-2026-68373.html * https://www.suse.com/security/cve/CVE-2026-68377.html * https://www.suse.com/security/cve/CVE-2026-68386.html * https://www.suse.com/security/cve/CVE-2026-68391.html * https://www.suse.com/security/cve/CVE-2026-68392.html * https://www.suse.com/security/cve/CVE-2026-68397.html * https://www.suse.com/security/cve/CVE-2026-68398.html * https://www.suse.com/security/cve/CVE-2026-68399.html * https://www.suse.com/security/cve/CVE-2026-68402.html * https://www.suse.com/security/cve/CVE-2026-68403.html * https://www.suse.com/security/cve/CVE-2026-68405.html * https://www.suse.com/security/cve/CVE-2026-68406.html * https://www.suse.com/security/cve/CVE-2026-68407.html * https://www.suse.com/security/cve/CVE-2026-68408.html * https://www.suse.com/security/cve/CVE-2026-68410.html * https://www.suse.com/security/cve/CVE-2026-68413.html * https://www.suse.com/security/cve/CVE-2026-68414.html * https://www.suse.com/security/cve/CVE-2026-68417.html * https://www.suse.com/security/cve/CVE-2026-68418.html * https://www.suse.com/security/cve/CVE-2026-68419.html * https://www.suse.com/security/cve/CVE-2026-68422.html * https://www.suse.com/security/cve/CVE-2026-68425.html * https://www.suse.com/security/cve/CVE-2026-68426.html * https://www.suse.com/security/cve/CVE-2026-68427.html * https://www.suse.com/security/cve/CVE-2026-68428.html * https://www.suse.com/security/cve/CVE-2026-68429.html * https://www.suse.com/security/cve/CVE-2026-68430.html * https://www.suse.com/security/cve/CVE-2026-68432.html * https://www.suse.com/security/cve/CVE-2026-68433.html * https://www.suse.com/security/cve/CVE-2026-68434.html * https://www.suse.com/security/cve/CVE-2026-68444.html * https://www.suse.com/security/cve/CVE-2026-68445.html * https://www.suse.com/security/cve/CVE-2026-68446.html * https://www.suse.com/security/cve/CVE-2026-68450.html * https://www.suse.com/security/cve/CVE-2026-68470.html * https://www.suse.com/security/cve/CVE-2026-68480.html * https://www.suse.com/security/cve/CVE-2026-72020.html * https://www.suse.com/security/cve/CVE-2026-72035.html * https://www.suse.com/security/cve/CVE-2026-72036.html * https://www.suse.com/security/cve/CVE-2026-72069.html * https://www.suse.com/security/cve/CVE-2026-72072.html * https://www.suse.com/security/cve/CVE-2026-72083.html * https://www.suse.com/security/cve/CVE-2026-72084.html * https://www.suse.com/security/cve/CVE-2026-72123.html * https://www.suse.com/security/cve/CVE-2026-72132.html * https://www.suse.com/security/cve/CVE-2026-72221.html * https://www.suse.com/security/cve/CVE-2026-72222.html * https://www.suse.com/security/cve/CVE-2026-72251.html * https://www.suse.com/security/cve/CVE-2026-72254.html * https://www.suse.com/security/cve/CVE-2026-72262.html * https://www.suse.com/security/cve/CVE-2026-72288.html * https://www.suse.com/security/cve/CVE-2026-72289.html * https://www.suse.com/security/cve/CVE-2026-72296.html * https://www.suse.com/security/cve/CVE-2026-72307.html * https://www.suse.com/security/cve/CVE-2026-72308.html * https://www.suse.com/security/cve/CVE-2026-72317.html * https://www.suse.com/security/cve/CVE-2026-72341.html * https://www.suse.com/security/cve/CVE-2026-72342.html * https://www.suse.com/security/cve/CVE-2026-72343.html * https://www.suse.com/security/cve/CVE-2026-72389.html * https://www.suse.com/security/cve/CVE-2026-72463.html * https://www.suse.com/security/cve/CVE-2026-72464.html * https://www.suse.com/security/cve/CVE-2026-72466.html * https://www.suse.com/security/cve/CVE-2026-72467.html * https://www.suse.com/security/cve/CVE-2026-72469.html * https://www.suse.com/security/cve/CVE-2026-72473.html * https://www.suse.com/security/cve/CVE-2026-72494.html * https://www.suse.com/security/cve/CVE-2026-72495.html * https://www.suse.com/security/cve/CVE-2026-72496.html * https://www.suse.com/security/cve/CVE-2026-72499.html * https://www.suse.com/security/cve/CVE-2026-72501.html * https://www.suse.com/security/cve/CVE-2026-72502.html * https://www.suse.com/security/cve/CVE-2026-74269.html * https://www.suse.com/security/cve/CVE-2026-74296.html * https://www.suse.com/security/cve/CVE-2026-74297.html * https://www.suse.com/security/cve/CVE-2026-74318.html * https://www.suse.com/security/cve/CVE-2026-74321.html * https://www.suse.com/security/cve/CVE-2026-74334.html * https://www.suse.com/security/cve/CVE-2026-74345.html * https://www.suse.com/security/cve/CVE-2026-74394.html * https://www.suse.com/security/cve/CVE-2026-74395.html * https://www.suse.com/security/cve/CVE-2026-74454.html * https://www.suse.com/security/cve/CVE-2026-74474.html * https://www.suse.com/security/cve/CVE-2026-74481.html * https://www.suse.com/security/cve/CVE-2026-74482.html * https://www.suse.com/security/cve/CVE-2026-74488.html * https://www.suse.com/security/cve/CVE-2026-74495.html * https://www.suse.com/security/cve/CVE-2026-74496.html * https://www.suse.com/security/cve/CVE-2026-74509.html * https://www.suse.com/security/cve/CVE-2026-74510.html * https://www.suse.com/security/cve/CVE-2026-74512.html * https://www.suse.com/security/cve/CVE-2026-74516.html * https://www.suse.com/security/cve/CVE-2026-74518.html * https://www.suse.com/security/cve/CVE-2026-74527.html * https://www.suse.com/security/cve/CVE-2026-74537.html * https://www.suse.com/security/cve/CVE-2026-74548.html * https://www.suse.com/security/cve/CVE-2026-74550.html * https://www.suse.com/security/cve/CVE-2026-74556.html * https://www.suse.com/security/cve/CVE-2026-74563.html * https://www.suse.com/security/cve/CVE-2026-74566.html * https://www.suse.com/security/cve/CVE-2026-74567.html * https://www.suse.com/security/cve/CVE-2026-74571.html * https://www.suse.com/security/cve/CVE-2026-74581.html * https://www.suse.com/security/cve/CVE-2026-74582.html * https://www.suse.com/security/cve/CVE-2026-74584.html * https://www.suse.com/security/cve/CVE-2026-74610.html * https://www.suse.com/security/cve/CVE-2026-74669.html * https://www.suse.com/security/cve/CVE-2026-74692.html * https://www.suse.com/security/cve/CVE-2026-74694.html * https://www.suse.com/security/cve/CVE-2026-74695.html * https://www.suse.com/security/cve/CVE-2026-74717.html * https://www.suse.com/security/cve/CVE-2026-74722.html * https://www.suse.com/security/cve/CVE-2026-80529.html * https://www.suse.com/security/cve/CVE-2026-80534.html * https://www.suse.com/security/cve/CVE-2026-80590.html * https://www.suse.com/security/cve/CVE-2026-80654.html * https://bugzilla.suse.com/show_bug.cgi?id=1230238 * https://bugzilla.suse.com/show_bug.cgi?id=1235944 * https://bugzilla.suse.com/show_bug.cgi?id=1247455 * https://bugzilla.suse.com/show_bug.cgi?id=1250748 * https://bugzilla.suse.com/show_bug.cgi?id=1251966 * https://bugzilla.suse.com/show_bug.cgi?id=1252682 * https://bugzilla.suse.com/show_bug.cgi?id=1254306 * https://bugzilla.suse.com/show_bug.cgi?id=1255225 * https://bugzilla.suse.com/show_bug.cgi?id=1255250 * https://bugzilla.suse.com/show_bug.cgi?id=1256629 * https://bugzilla.suse.com/show_bug.cgi?id=1256708 * https://bugzilla.suse.com/show_bug.cgi?id=1257154 * https://bugzilla.suse.com/show_bug.cgi?id=1258430 * https://bugzilla.suse.com/show_bug.cgi?id=1258517 * https://bugzilla.suse.com/show_bug.cgi?id=1260522 * https://bugzilla.suse.com/show_bug.cgi?id=1261780 * https://bugzilla.suse.com/show_bug.cgi?id=1261788 * https://bugzilla.suse.com/show_bug.cgi?id=1262073 * https://bugzilla.suse.com/show_bug.cgi?id=1263004 * https://bugzilla.suse.com/show_bug.cgi?id=1263061 * https://bugzilla.suse.com/show_bug.cgi?id=1263133 * https://bugzilla.suse.com/show_bug.cgi?id=1264335 * https://bugzilla.suse.com/show_bug.cgi?id=1264446 * https://bugzilla.suse.com/show_bug.cgi?id=1264541 * https://bugzilla.suse.com/show_bug.cgi?id=1264584 * https://bugzilla.suse.com/show_bug.cgi?id=1264587 * https://bugzilla.suse.com/show_bug.cgi?id=1264619 * https://bugzilla.suse.com/show_bug.cgi?id=1264788 * https://bugzilla.suse.com/show_bug.cgi?id=1265068 * https://bugzilla.suse.com/show_bug.cgi?id=1265121 * https://bugzilla.suse.com/show_bug.cgi?id=1265449 * https://bugzilla.suse.com/show_bug.cgi?id=1265928 * https://bugzilla.suse.com/show_bug.cgi?id=1266402 * https://bugzilla.suse.com/show_bug.cgi?id=1266860 * https://bugzilla.suse.com/show_bug.cgi?id=1266874 * https://bugzilla.suse.com/show_bug.cgi?id=1266897 * https://bugzilla.suse.com/show_bug.cgi?id=1267023 * https://bugzilla.suse.com/show_bug.cgi?id=1267238 * https://bugzilla.suse.com/show_bug.cgi?id=1267501 * https://bugzilla.suse.com/show_bug.cgi?id=1267612 * https://bugzilla.suse.com/show_bug.cgi?id=1268276 * https://bugzilla.suse.com/show_bug.cgi?id=1268972 * https://bugzilla.suse.com/show_bug.cgi?id=1268979 * https://bugzilla.suse.com/show_bug.cgi?id=1268987 * https://bugzilla.suse.com/show_bug.cgi?id=1269004 * https://bugzilla.suse.com/show_bug.cgi?id=1269013 * https://bugzilla.suse.com/show_bug.cgi?id=1269108 * https://bugzilla.suse.com/show_bug.cgi?id=1269113 * https://bugzilla.suse.com/show_bug.cgi?id=1269114 * https://bugzilla.suse.com/show_bug.cgi?id=1269126 * https://bugzilla.suse.com/show_bug.cgi?id=1269167 * https://bugzilla.suse.com/show_bug.cgi?id=1269234 * https://bugzilla.suse.com/show_bug.cgi?id=1269238 * https://bugzilla.suse.com/show_bug.cgi?id=1269242 * https://bugzilla.suse.com/show_bug.cgi?id=1269256 * https://bugzilla.suse.com/show_bug.cgi?id=1269301 * https://bugzilla.suse.com/show_bug.cgi?id=1269306 * https://bugzilla.suse.com/show_bug.cgi?id=1269381 * https://bugzilla.suse.com/show_bug.cgi?id=1269388 * https://bugzilla.suse.com/show_bug.cgi?id=1269412 * https://bugzilla.suse.com/show_bug.cgi?id=1269530 * https://bugzilla.suse.com/show_bug.cgi?id=1269579 * https://bugzilla.suse.com/show_bug.cgi?id=1269590 * https://bugzilla.suse.com/show_bug.cgi?id=1269635 * https://bugzilla.suse.com/show_bug.cgi?id=1269655 * https://bugzilla.suse.com/show_bug.cgi?id=1269665 * https://bugzilla.suse.com/show_bug.cgi?id=1269686 * https://bugzilla.suse.com/show_bug.cgi?id=1269695 * https://bugzilla.suse.com/show_bug.cgi?id=1269713 * https://bugzilla.suse.com/show_bug.cgi?id=1269731 * https://bugzilla.suse.com/show_bug.cgi?id=1269774 * https://bugzilla.suse.com/show_bug.cgi?id=1269783 * https://bugzilla.suse.com/show_bug.cgi?id=1269792 * https://bugzilla.suse.com/show_bug.cgi?id=1269815 * https://bugzilla.suse.com/show_bug.cgi?id=1269965 * https://bugzilla.suse.com/show_bug.cgi?id=1269969 * https://bugzilla.suse.com/show_bug.cgi?id=1269981 * https://bugzilla.suse.com/show_bug.cgi?id=1269985 * https://bugzilla.suse.com/show_bug.cgi?id=1270090 * https://bugzilla.suse.com/show_bug.cgi?id=1270108 * https://bugzilla.suse.com/show_bug.cgi?id=1270111 * https://bugzilla.suse.com/show_bug.cgi?id=1270251 * https://bugzilla.suse.com/show_bug.cgi?id=1271256 * https://bugzilla.suse.com/show_bug.cgi?id=1271365 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 * https://bugzilla.suse.com/show_bug.cgi?id=1271825 * https://bugzilla.suse.com/show_bug.cgi?id=1271830 * https://bugzilla.suse.com/show_bug.cgi?id=1272150 * https://bugzilla.suse.com/show_bug.cgi?id=1272175 * https://bugzilla.suse.com/show_bug.cgi?id=1272179 * https://bugzilla.suse.com/show_bug.cgi?id=1272182 * https://bugzilla.suse.com/show_bug.cgi?id=1272200 * https://bugzilla.suse.com/show_bug.cgi?id=1272210 * https://bugzilla.suse.com/show_bug.cgi?id=1272213 * https://bugzilla.suse.com/show_bug.cgi?id=1272230 * https://bugzilla.suse.com/show_bug.cgi?id=1272260 * https://bugzilla.suse.com/show_bug.cgi?id=1272261 * https://bugzilla.suse.com/show_bug.cgi?id=1272262 * https://bugzilla.suse.com/show_bug.cgi?id=1272297 * https://bugzilla.suse.com/show_bug.cgi?id=1272346 * https://bugzilla.suse.com/show_bug.cgi?id=1272381 * https://bugzilla.suse.com/show_bug.cgi?id=1272385 * https://bugzilla.suse.com/show_bug.cgi?id=1272390 * https://bugzilla.suse.com/show_bug.cgi?id=1272423 * https://bugzilla.suse.com/show_bug.cgi?id=1272429 * https://bugzilla.suse.com/show_bug.cgi?id=1272484 * https://bugzilla.suse.com/show_bug.cgi?id=1272486 * https://bugzilla.suse.com/show_bug.cgi?id=1272497 * https://bugzilla.suse.com/show_bug.cgi?id=1272516 * https://bugzilla.suse.com/show_bug.cgi?id=1272569 * https://bugzilla.suse.com/show_bug.cgi?id=1272571 * https://bugzilla.suse.com/show_bug.cgi?id=1272641 * https://bugzilla.suse.com/show_bug.cgi?id=1272643 * https://bugzilla.suse.com/show_bug.cgi?id=1272662 * https://bugzilla.suse.com/show_bug.cgi?id=1272673 * https://bugzilla.suse.com/show_bug.cgi?id=1272680 * https://bugzilla.suse.com/show_bug.cgi?id=1272682 * https://bugzilla.suse.com/show_bug.cgi?id=1272756 * https://bugzilla.suse.com/show_bug.cgi?id=1272786 * https://bugzilla.suse.com/show_bug.cgi?id=1272788 * https://bugzilla.suse.com/show_bug.cgi?id=1272798 * https://bugzilla.suse.com/show_bug.cgi?id=1272799 * https://bugzilla.suse.com/show_bug.cgi?id=1272868 * https://bugzilla.suse.com/show_bug.cgi?id=1272877 * https://bugzilla.suse.com/show_bug.cgi?id=1272891 * https://bugzilla.suse.com/show_bug.cgi?id=1272963 * https://bugzilla.suse.com/show_bug.cgi?id=1272983 * https://bugzilla.suse.com/show_bug.cgi?id=1273008 * https://bugzilla.suse.com/show_bug.cgi?id=1273019 * https://bugzilla.suse.com/show_bug.cgi?id=1273027 * https://bugzilla.suse.com/show_bug.cgi?id=1273028 * https://bugzilla.suse.com/show_bug.cgi?id=1273030 * https://bugzilla.suse.com/show_bug.cgi?id=1273038 * https://bugzilla.suse.com/show_bug.cgi?id=1273053 * https://bugzilla.suse.com/show_bug.cgi?id=1273054 * https://bugzilla.suse.com/show_bug.cgi?id=1273060 * https://bugzilla.suse.com/show_bug.cgi?id=1273105 * https://bugzilla.suse.com/show_bug.cgi?id=1273249 * https://bugzilla.suse.com/show_bug.cgi?id=1273250 * https://bugzilla.suse.com/show_bug.cgi?id=1273260 * https://bugzilla.suse.com/show_bug.cgi?id=1273273 * https://bugzilla.suse.com/show_bug.cgi?id=1273274 * https://bugzilla.suse.com/show_bug.cgi?id=1273276 * https://bugzilla.suse.com/show_bug.cgi?id=1273281 * https://bugzilla.suse.com/show_bug.cgi?id=1273284 * https://bugzilla.suse.com/show_bug.cgi?id=1273285 * https://bugzilla.suse.com/show_bug.cgi?id=1273289 * https://bugzilla.suse.com/show_bug.cgi?id=1273291 * https://bugzilla.suse.com/show_bug.cgi?id=1273294 * https://bugzilla.suse.com/show_bug.cgi?id=1273302 * https://bugzilla.suse.com/show_bug.cgi?id=1273303 * https://bugzilla.suse.com/show_bug.cgi?id=1273305 * https://bugzilla.suse.com/show_bug.cgi?id=1273310 * https://bugzilla.suse.com/show_bug.cgi?id=1273311 * https://bugzilla.suse.com/show_bug.cgi?id=1273316 * https://bugzilla.suse.com/show_bug.cgi?id=1273318 * https://bugzilla.suse.com/show_bug.cgi?id=1273319 * https://bugzilla.suse.com/show_bug.cgi?id=1273323 * https://bugzilla.suse.com/show_bug.cgi?id=1273325 * https://bugzilla.suse.com/show_bug.cgi?id=1273327 * https://bugzilla.suse.com/show_bug.cgi?id=1273334 * https://bugzilla.suse.com/show_bug.cgi?id=1273335 * https://bugzilla.suse.com/show_bug.cgi?id=1273336 * https://bugzilla.suse.com/show_bug.cgi?id=1273337 * https://bugzilla.suse.com/show_bug.cgi?id=1273338 * https://bugzilla.suse.com/show_bug.cgi?id=1273340 * https://bugzilla.suse.com/show_bug.cgi?id=1273341 * https://bugzilla.suse.com/show_bug.cgi?id=1273346 * https://bugzilla.suse.com/show_bug.cgi?id=1273422 * https://bugzilla.suse.com/show_bug.cgi?id=1273426 * https://bugzilla.suse.com/show_bug.cgi?id=1273443 * https://bugzilla.suse.com/show_bug.cgi?id=1273463 * https://bugzilla.suse.com/show_bug.cgi?id=1273468 * https://bugzilla.suse.com/show_bug.cgi?id=1273469 * https://bugzilla.suse.com/show_bug.cgi?id=1273471 * https://bugzilla.suse.com/show_bug.cgi?id=1273479 * https://bugzilla.suse.com/show_bug.cgi?id=1273480 * https://bugzilla.suse.com/show_bug.cgi?id=1273482 * https://bugzilla.suse.com/show_bug.cgi?id=1273484 * https://bugzilla.suse.com/show_bug.cgi?id=1273488 * https://bugzilla.suse.com/show_bug.cgi?id=1273490 * https://bugzilla.suse.com/show_bug.cgi?id=1273501 * https://bugzilla.suse.com/show_bug.cgi?id=1273503 * https://bugzilla.suse.com/show_bug.cgi?id=1273504 * https://bugzilla.suse.com/show_bug.cgi?id=1273506 * https://bugzilla.suse.com/show_bug.cgi?id=1273523 * https://bugzilla.suse.com/show_bug.cgi?id=1273525 * https://bugzilla.suse.com/show_bug.cgi?id=1273533 * https://bugzilla.suse.com/show_bug.cgi?id=1273536 * https://bugzilla.suse.com/show_bug.cgi?id=1273542 * https://bugzilla.suse.com/show_bug.cgi?id=1273555 * https://bugzilla.suse.com/show_bug.cgi?id=1273578 * https://bugzilla.suse.com/show_bug.cgi?id=1273579 * https://bugzilla.suse.com/show_bug.cgi?id=1273582 * https://bugzilla.suse.com/show_bug.cgi?id=1273596 * https://bugzilla.suse.com/show_bug.cgi?id=1273597 * https://bugzilla.suse.com/show_bug.cgi?id=1273598 * https://bugzilla.suse.com/show_bug.cgi?id=1273600 * https://bugzilla.suse.com/show_bug.cgi?id=1273601 * https://bugzilla.suse.com/show_bug.cgi?id=1273602 * https://bugzilla.suse.com/show_bug.cgi?id=1273603 * https://bugzilla.suse.com/show_bug.cgi?id=1273682 * https://bugzilla.suse.com/show_bug.cgi?id=1273734 * https://bugzilla.suse.com/show_bug.cgi?id=1273738 * https://bugzilla.suse.com/show_bug.cgi?id=1273739 * https://bugzilla.suse.com/show_bug.cgi?id=1273741 * https://bugzilla.suse.com/show_bug.cgi?id=1273742 * https://bugzilla.suse.com/show_bug.cgi?id=1273743 * https://bugzilla.suse.com/show_bug.cgi?id=1273745 * https://bugzilla.suse.com/show_bug.cgi?id=1273748 * https://bugzilla.suse.com/show_bug.cgi?id=1273749 * https://bugzilla.suse.com/show_bug.cgi?id=1273755 * https://bugzilla.suse.com/show_bug.cgi?id=1273762 * https://bugzilla.suse.com/show_bug.cgi?id=1273765 * https://bugzilla.suse.com/show_bug.cgi?id=1273766 * https://bugzilla.suse.com/show_bug.cgi?id=1273769 * https://bugzilla.suse.com/show_bug.cgi?id=1273774 * https://bugzilla.suse.com/show_bug.cgi?id=1273778 * https://bugzilla.suse.com/show_bug.cgi?id=1273780 * https://bugzilla.suse.com/show_bug.cgi?id=1273790 * https://bugzilla.suse.com/show_bug.cgi?id=1273796 * https://bugzilla.suse.com/show_bug.cgi?id=1273804 * https://bugzilla.suse.com/show_bug.cgi?id=1273810 * https://bugzilla.suse.com/show_bug.cgi?id=1273811 * https://bugzilla.suse.com/show_bug.cgi?id=1273813 * https://bugzilla.suse.com/show_bug.cgi?id=1273817 * https://bugzilla.suse.com/show_bug.cgi?id=1273822 * https://bugzilla.suse.com/show_bug.cgi?id=1273824 * https://bugzilla.suse.com/show_bug.cgi?id=1273831 * https://bugzilla.suse.com/show_bug.cgi?id=1273832 * https://bugzilla.suse.com/show_bug.cgi?id=1273834 * https://bugzilla.suse.com/show_bug.cgi?id=1273838 * https://bugzilla.suse.com/show_bug.cgi?id=1273844 * https://bugzilla.suse.com/show_bug.cgi?id=1273849 * https://bugzilla.suse.com/show_bug.cgi?id=1273860 * https://bugzilla.suse.com/show_bug.cgi?id=1273862 * https://bugzilla.suse.com/show_bug.cgi?id=1273867 * https://bugzilla.suse.com/show_bug.cgi?id=1273868 * https://bugzilla.suse.com/show_bug.cgi?id=1273869 * https://bugzilla.suse.com/show_bug.cgi?id=1273872 * https://bugzilla.suse.com/show_bug.cgi?id=1273876 * https://bugzilla.suse.com/show_bug.cgi?id=1273877 * https://bugzilla.suse.com/show_bug.cgi?id=1273880 * https://bugzilla.suse.com/show_bug.cgi?id=1273882 * https://bugzilla.suse.com/show_bug.cgi?id=1273890 * https://bugzilla.suse.com/show_bug.cgi?id=1273891 * https://bugzilla.suse.com/show_bug.cgi?id=1273892 * https://bugzilla.suse.com/show_bug.cgi?id=1273895 * https://bugzilla.suse.com/show_bug.cgi?id=1273896 * https://bugzilla.suse.com/show_bug.cgi?id=1273903 * https://bugzilla.suse.com/show_bug.cgi?id=1273905 * https://bugzilla.suse.com/show_bug.cgi?id=1273930 * https://bugzilla.suse.com/show_bug.cgi?id=1273933 * https://bugzilla.suse.com/show_bug.cgi?id=1273934 * https://bugzilla.suse.com/show_bug.cgi?id=1273935 * https://bugzilla.suse.com/show_bug.cgi?id=1273936 * https://bugzilla.suse.com/show_bug.cgi?id=1273939 * https://bugzilla.suse.com/show_bug.cgi?id=1273940 * https://bugzilla.suse.com/show_bug.cgi?id=1273941 * https://bugzilla.suse.com/show_bug.cgi?id=1273942 * https://bugzilla.suse.com/show_bug.cgi?id=1273944 * https://bugzilla.suse.com/show_bug.cgi?id=1273945 * https://bugzilla.suse.com/show_bug.cgi?id=1273946 * https://bugzilla.suse.com/show_bug.cgi?id=1273956 * https://bugzilla.suse.com/show_bug.cgi?id=1273957 * https://bugzilla.suse.com/show_bug.cgi?id=1273958 * https://bugzilla.suse.com/show_bug.cgi?id=1273966 * https://bugzilla.suse.com/show_bug.cgi?id=1273967 * https://bugzilla.suse.com/show_bug.cgi?id=1273968 * https://bugzilla.suse.com/show_bug.cgi?id=1273972 * https://bugzilla.suse.com/show_bug.cgi?id=1273974 * https://bugzilla.suse.com/show_bug.cgi?id=1273975 * https://bugzilla.suse.com/show_bug.cgi?id=1273977 * https://bugzilla.suse.com/show_bug.cgi?id=1273982 * https://bugzilla.suse.com/show_bug.cgi?id=1273988 * https://bugzilla.suse.com/show_bug.cgi?id=1273990 * https://bugzilla.suse.com/show_bug.cgi?id=1273991 * https://bugzilla.suse.com/show_bug.cgi?id=1273995 * https://bugzilla.suse.com/show_bug.cgi?id=1274001 * https://bugzilla.suse.com/show_bug.cgi?id=1274003 * https://bugzilla.suse.com/show_bug.cgi?id=1274006 * https://bugzilla.suse.com/show_bug.cgi?id=1274011 * https://bugzilla.suse.com/show_bug.cgi?id=1274012 * https://bugzilla.suse.com/show_bug.cgi?id=1274014 * https://bugzilla.suse.com/show_bug.cgi?id=1274017 * https://bugzilla.suse.com/show_bug.cgi?id=1274019 * https://bugzilla.suse.com/show_bug.cgi?id=1274020 * https://bugzilla.suse.com/show_bug.cgi?id=1274026 * https://bugzilla.suse.com/show_bug.cgi?id=1274028 * https://bugzilla.suse.com/show_bug.cgi?id=1274030 * https://bugzilla.suse.com/show_bug.cgi?id=1274031 * https://bugzilla.suse.com/show_bug.cgi?id=1274035 * https://bugzilla.suse.com/show_bug.cgi?id=1274040 * https://bugzilla.suse.com/show_bug.cgi?id=1274041 * https://bugzilla.suse.com/show_bug.cgi?id=1274057 * https://bugzilla.suse.com/show_bug.cgi?id=1274058 * https://bugzilla.suse.com/show_bug.cgi?id=1274061 * https://bugzilla.suse.com/show_bug.cgi?id=1274063 * https://bugzilla.suse.com/show_bug.cgi?id=1274065 * https://bugzilla.suse.com/show_bug.cgi?id=1274067 * https://bugzilla.suse.com/show_bug.cgi?id=1274075 * https://bugzilla.suse.com/show_bug.cgi?id=1274076 * https://bugzilla.suse.com/show_bug.cgi?id=1274077 * https://bugzilla.suse.com/show_bug.cgi?id=1274078 * https://bugzilla.suse.com/show_bug.cgi?id=1274208 * https://bugzilla.suse.com/show_bug.cgi?id=1274226 * https://bugzilla.suse.com/show_bug.cgi?id=1274239 * https://bugzilla.suse.com/show_bug.cgi?id=1274243 * https://bugzilla.suse.com/show_bug.cgi?id=1274258 * https://bugzilla.suse.com/show_bug.cgi?id=1274265 * https://bugzilla.suse.com/show_bug.cgi?id=1274274 * https://bugzilla.suse.com/show_bug.cgi?id=1274277 * https://bugzilla.suse.com/show_bug.cgi?id=1274278 * https://bugzilla.suse.com/show_bug.cgi?id=1274281 * https://bugzilla.suse.com/show_bug.cgi?id=1274283 * https://bugzilla.suse.com/show_bug.cgi?id=1274286 * https://bugzilla.suse.com/show_bug.cgi?id=1274290 * https://bugzilla.suse.com/show_bug.cgi?id=1274294 * https://bugzilla.suse.com/show_bug.cgi?id=1274296 * https://bugzilla.suse.com/show_bug.cgi?id=1274297 * https://bugzilla.suse.com/show_bug.cgi?id=1274298 * https://bugzilla.suse.com/show_bug.cgi?id=1274314 * https://bugzilla.suse.com/show_bug.cgi?id=1274321 * https://bugzilla.suse.com/show_bug.cgi?id=1274491 * https://bugzilla.suse.com/show_bug.cgi?id=1274497 * https://bugzilla.suse.com/show_bug.cgi?id=1274539 * https://bugzilla.suse.com/show_bug.cgi?id=1274541 * https://bugzilla.suse.com/show_bug.cgi?id=1274543 * https://bugzilla.suse.com/show_bug.cgi?id=1274545 * https://bugzilla.suse.com/show_bug.cgi?id=1274547 * https://bugzilla.suse.com/show_bug.cgi?id=1274550 * https://bugzilla.suse.com/show_bug.cgi?id=1274573 * https://bugzilla.suse.com/show_bug.cgi?id=1274578 * https://bugzilla.suse.com/show_bug.cgi?id=1274580 * https://bugzilla.suse.com/show_bug.cgi?id=1274581 * https://bugzilla.suse.com/show_bug.cgi?id=1274620 * https://bugzilla.suse.com/show_bug.cgi?id=1274622 * https://bugzilla.suse.com/show_bug.cgi?id=1274624 * https://bugzilla.suse.com/show_bug.cgi?id=1274629 * https://bugzilla.suse.com/show_bug.cgi?id=1274632 * https://bugzilla.suse.com/show_bug.cgi?id=1274636 * https://bugzilla.suse.com/show_bug.cgi?id=1274639 * https://bugzilla.suse.com/show_bug.cgi?id=1274640 * https://bugzilla.suse.com/show_bug.cgi?id=1274642 * https://bugzilla.suse.com/show_bug.cgi?id=1274644 * https://bugzilla.suse.com/show_bug.cgi?id=1274645 * https://bugzilla.suse.com/show_bug.cgi?id=1274646 * https://bugzilla.suse.com/show_bug.cgi?id=1274649 * https://bugzilla.suse.com/show_bug.cgi?id=1274650 * https://bugzilla.suse.com/show_bug.cgi?id=1274651 * https://bugzilla.suse.com/show_bug.cgi?id=1274656 * https://bugzilla.suse.com/show_bug.cgi?id=1274659 * https://bugzilla.suse.com/show_bug.cgi?id=1274662 * https://bugzilla.suse.com/show_bug.cgi?id=1274663 * https://bugzilla.suse.com/show_bug.cgi?id=1274665 * https://bugzilla.suse.com/show_bug.cgi?id=1274667 * https://bugzilla.suse.com/show_bug.cgi?id=1274670 * https://bugzilla.suse.com/show_bug.cgi?id=1274675 * https://bugzilla.suse.com/show_bug.cgi?id=1274677 * https://bugzilla.suse.com/show_bug.cgi?id=1274678 * https://bugzilla.suse.com/show_bug.cgi?id=1274679 * https://bugzilla.suse.com/show_bug.cgi?id=1274681 * https://bugzilla.suse.com/show_bug.cgi?id=1274682 * https://bugzilla.suse.com/show_bug.cgi?id=1274690 * https://bugzilla.suse.com/show_bug.cgi?id=1274694 * https://bugzilla.suse.com/show_bug.cgi?id=1274696 * https://bugzilla.suse.com/show_bug.cgi?id=1274698 * https://bugzilla.suse.com/show_bug.cgi?id=1274699 * https://bugzilla.suse.com/show_bug.cgi?id=1274700 * https://bugzilla.suse.com/show_bug.cgi?id=1274702 * https://bugzilla.suse.com/show_bug.cgi?id=1274703 * https://bugzilla.suse.com/show_bug.cgi?id=1274705 * https://bugzilla.suse.com/show_bug.cgi?id=1274706 * https://bugzilla.suse.com/show_bug.cgi?id=1274709 * https://bugzilla.suse.com/show_bug.cgi?id=1274710 * https://bugzilla.suse.com/show_bug.cgi?id=1274713 * https://bugzilla.suse.com/show_bug.cgi?id=1274716 * https://bugzilla.suse.com/show_bug.cgi?id=1274721 * https://bugzilla.suse.com/show_bug.cgi?id=1274725 * https://bugzilla.suse.com/show_bug.cgi?id=1274737 * https://bugzilla.suse.com/show_bug.cgi?id=1274738 * https://bugzilla.suse.com/show_bug.cgi?id=1274749 * https://bugzilla.suse.com/show_bug.cgi?id=1274752 * https://bugzilla.suse.com/show_bug.cgi?id=1274753 * https://bugzilla.suse.com/show_bug.cgi?id=1274754 * https://bugzilla.suse.com/show_bug.cgi?id=1274755 * https://bugzilla.suse.com/show_bug.cgi?id=1274756 * https://bugzilla.suse.com/show_bug.cgi?id=1274764 * https://bugzilla.suse.com/show_bug.cgi?id=1274768 * https://bugzilla.suse.com/show_bug.cgi?id=1274770 * https://bugzilla.suse.com/show_bug.cgi?id=1274787 * https://bugzilla.suse.com/show_bug.cgi?id=1274800 * https://bugzilla.suse.com/show_bug.cgi?id=1274801 * https://bugzilla.suse.com/show_bug.cgi?id=1274802 * https://bugzilla.suse.com/show_bug.cgi?id=1274804 * https://bugzilla.suse.com/show_bug.cgi?id=1274805 * https://bugzilla.suse.com/show_bug.cgi?id=1274807 * https://bugzilla.suse.com/show_bug.cgi?id=1274808 * https://bugzilla.suse.com/show_bug.cgi?id=1274811 * https://bugzilla.suse.com/show_bug.cgi?id=1274813 * https://bugzilla.suse.com/show_bug.cgi?id=1274814 * https://bugzilla.suse.com/show_bug.cgi?id=1274831 * https://bugzilla.suse.com/show_bug.cgi?id=1274834 * https://bugzilla.suse.com/show_bug.cgi?id=1274847 * https://bugzilla.suse.com/show_bug.cgi?id=1274853 * https://bugzilla.suse.com/show_bug.cgi?id=1274868 * https://bugzilla.suse.com/show_bug.cgi?id=1274869 * https://bugzilla.suse.com/show_bug.cgi?id=1274872 * https://bugzilla.suse.com/show_bug.cgi?id=1274873 * https://bugzilla.suse.com/show_bug.cgi?id=1274874 * https://bugzilla.suse.com/show_bug.cgi?id=1274876 * https://bugzilla.suse.com/show_bug.cgi?id=1274879 * https://bugzilla.suse.com/show_bug.cgi?id=1274881 * https://bugzilla.suse.com/show_bug.cgi?id=1274883 * https://bugzilla.suse.com/show_bug.cgi?id=1274886 * https://bugzilla.suse.com/show_bug.cgi?id=1274888 * https://bugzilla.suse.com/show_bug.cgi?id=1274891 * https://bugzilla.suse.com/show_bug.cgi?id=1274892 * https://bugzilla.suse.com/show_bug.cgi?id=1274893 * https://bugzilla.suse.com/show_bug.cgi?id=1274894 * https://bugzilla.suse.com/show_bug.cgi?id=1274896 * https://bugzilla.suse.com/show_bug.cgi?id=1274897 * https://bugzilla.suse.com/show_bug.cgi?id=1274898 * https://bugzilla.suse.com/show_bug.cgi?id=1274899 * https://bugzilla.suse.com/show_bug.cgi?id=1274901 * https://bugzilla.suse.com/show_bug.cgi?id=1274902 * https://bugzilla.suse.com/show_bug.cgi?id=1274905 * https://bugzilla.suse.com/show_bug.cgi?id=1274907 * https://bugzilla.suse.com/show_bug.cgi?id=1274908 * https://bugzilla.suse.com/show_bug.cgi?id=1274913 * https://bugzilla.suse.com/show_bug.cgi?id=1274914 * https://bugzilla.suse.com/show_bug.cgi?id=1274920 * https://bugzilla.suse.com/show_bug.cgi?id=1274921 * https://bugzilla.suse.com/show_bug.cgi?id=1274924 * https://bugzilla.suse.com/show_bug.cgi?id=1274925 * https://bugzilla.suse.com/show_bug.cgi?id=1274929 * https://bugzilla.suse.com/show_bug.cgi?id=1274930 * https://bugzilla.suse.com/show_bug.cgi?id=1274933 * https://bugzilla.suse.com/show_bug.cgi?id=1274934 * https://bugzilla.suse.com/show_bug.cgi?id=1274935 * https://bugzilla.suse.com/show_bug.cgi?id=1274941 * https://bugzilla.suse.com/show_bug.cgi?id=1274945 * https://bugzilla.suse.com/show_bug.cgi?id=1274947 * https://bugzilla.suse.com/show_bug.cgi?id=1274951 * https://bugzilla.suse.com/show_bug.cgi?id=1274953 * https://bugzilla.suse.com/show_bug.cgi?id=1274958 * https://bugzilla.suse.com/show_bug.cgi?id=1274968 * https://bugzilla.suse.com/show_bug.cgi?id=1274981 * https://bugzilla.suse.com/show_bug.cgi?id=1275040 * https://bugzilla.suse.com/show_bug.cgi?id=1275069 * https://bugzilla.suse.com/show_bug.cgi?id=1275071 * https://bugzilla.suse.com/show_bug.cgi?id=1275073 * https://bugzilla.suse.com/show_bug.cgi?id=1275076 * https://bugzilla.suse.com/show_bug.cgi?id=1275080 * https://bugzilla.suse.com/show_bug.cgi?id=1275083 * https://bugzilla.suse.com/show_bug.cgi?id=1275088 * https://bugzilla.suse.com/show_bug.cgi?id=1275091 * https://bugzilla.suse.com/show_bug.cgi?id=1275125 * https://bugzilla.suse.com/show_bug.cgi?id=1275126 * https://bugzilla.suse.com/show_bug.cgi?id=1275131 * https://bugzilla.suse.com/show_bug.cgi?id=1275132 * https://bugzilla.suse.com/show_bug.cgi?id=1275150 * https://bugzilla.suse.com/show_bug.cgi?id=1275152 * https://bugzilla.suse.com/show_bug.cgi?id=1275154 * https://bugzilla.suse.com/show_bug.cgi?id=1275155 * https://bugzilla.suse.com/show_bug.cgi?id=1275157 * https://bugzilla.suse.com/show_bug.cgi?id=1275158 * https://bugzilla.suse.com/show_bug.cgi?id=1275161 * https://bugzilla.suse.com/show_bug.cgi?id=1275163 * https://bugzilla.suse.com/show_bug.cgi?id=1275164 * https://bugzilla.suse.com/show_bug.cgi?id=1275169 * https://bugzilla.suse.com/show_bug.cgi?id=1275173 * https://bugzilla.suse.com/show_bug.cgi?id=1275176 * https://bugzilla.suse.com/show_bug.cgi?id=1275185 * https://bugzilla.suse.com/show_bug.cgi?id=1275190 * https://bugzilla.suse.com/show_bug.cgi?id=1275236 * https://bugzilla.suse.com/show_bug.cgi?id=1275237 * https://bugzilla.suse.com/show_bug.cgi?id=1275239 * https://bugzilla.suse.com/show_bug.cgi?id=1275294 * https://bugzilla.suse.com/show_bug.cgi?id=1275301 * https://bugzilla.suse.com/show_bug.cgi?id=1275303 * https://bugzilla.suse.com/show_bug.cgi?id=1275304 * https://bugzilla.suse.com/show_bug.cgi?id=1275305 * https://bugzilla.suse.com/show_bug.cgi?id=1275306 * https://bugzilla.suse.com/show_bug.cgi?id=1275307 * https://bugzilla.suse.com/show_bug.cgi?id=1275470 * https://bugzilla.suse.com/show_bug.cgi?id=1275472 * https://bugzilla.suse.com/show_bug.cgi?id=1275474 * https://bugzilla.suse.com/show_bug.cgi?id=1275479 * https://bugzilla.suse.com/show_bug.cgi?id=1275483 * https://bugzilla.suse.com/show_bug.cgi?id=1275486 * https://bugzilla.suse.com/show_bug.cgi?id=1275487 * https://bugzilla.suse.com/show_bug.cgi?id=1275506 * https://bugzilla.suse.com/show_bug.cgi?id=1275509 * https://bugzilla.suse.com/show_bug.cgi?id=1275511 * https://bugzilla.suse.com/show_bug.cgi?id=1275517 * https://bugzilla.suse.com/show_bug.cgi?id=1275528 * https://bugzilla.suse.com/show_bug.cgi?id=1275535 * https://bugzilla.suse.com/show_bug.cgi?id=1275540 * https://bugzilla.suse.com/show_bug.cgi?id=1275553 * https://bugzilla.suse.com/show_bug.cgi?id=1275555 * https://bugzilla.suse.com/show_bug.cgi?id=1275561 * https://bugzilla.suse.com/show_bug.cgi?id=1275566 * https://bugzilla.suse.com/show_bug.cgi?id=1275569 * https://bugzilla.suse.com/show_bug.cgi?id=1275574 * https://bugzilla.suse.com/show_bug.cgi?id=1275578 * https://bugzilla.suse.com/show_bug.cgi?id=1275582 * https://bugzilla.suse.com/show_bug.cgi?id=1275583 * https://bugzilla.suse.com/show_bug.cgi?id=1275584 * https://bugzilla.suse.com/show_bug.cgi?id=1275591 * https://bugzilla.suse.com/show_bug.cgi?id=1275595 * https://bugzilla.suse.com/show_bug.cgi?id=1275633 * https://bugzilla.suse.com/show_bug.cgi?id=1275636 * https://bugzilla.suse.com/show_bug.cgi?id=1275650 * https://bugzilla.suse.com/show_bug.cgi?id=1275659 * https://bugzilla.suse.com/show_bug.cgi?id=1275665 * https://bugzilla.suse.com/show_bug.cgi?id=1275669 * https://bugzilla.suse.com/show_bug.cgi?id=1275687 * https://bugzilla.suse.com/show_bug.cgi?id=1275688 * https://bugzilla.suse.com/show_bug.cgi?id=1275695 * https://bugzilla.suse.com/show_bug.cgi?id=1275696 * https://bugzilla.suse.com/show_bug.cgi?id=1275704 * https://bugzilla.suse.com/show_bug.cgi?id=1275782 * https://bugzilla.suse.com/show_bug.cgi?id=1275784 * https://bugzilla.suse.com/show_bug.cgi?id=1275787 * https://bugzilla.suse.com/show_bug.cgi?id=1275788 * https://bugzilla.suse.com/show_bug.cgi?id=1275790 * https://bugzilla.suse.com/show_bug.cgi?id=1275797 * https://bugzilla.suse.com/show_bug.cgi?id=1275798 * https://bugzilla.suse.com/show_bug.cgi?id=1275805 * https://bugzilla.suse.com/show_bug.cgi?id=1275817 * https://bugzilla.suse.com/show_bug.cgi?id=1275818 * https://bugzilla.suse.com/show_bug.cgi?id=1275819 * https://bugzilla.suse.com/show_bug.cgi?id=1275820 * https://bugzilla.suse.com/show_bug.cgi?id=1275821 * https://bugzilla.suse.com/show_bug.cgi?id=1275827 * https://bugzilla.suse.com/show_bug.cgi?id=1275864 * https://bugzilla.suse.com/show_bug.cgi?id=1275867 * https://bugzilla.suse.com/show_bug.cgi?id=1275869 * https://bugzilla.suse.com/show_bug.cgi?id=1275870 * https://bugzilla.suse.com/show_bug.cgi?id=1275871 * https://bugzilla.suse.com/show_bug.cgi?id=1275872 * https://bugzilla.suse.com/show_bug.cgi?id=1275886 * https://bugzilla.suse.com/show_bug.cgi?id=1275905 * https://bugzilla.suse.com/show_bug.cgi?id=1275923 * https://bugzilla.suse.com/show_bug.cgi?id=1275925 * https://bugzilla.suse.com/show_bug.cgi?id=1275946 * https://bugzilla.suse.com/show_bug.cgi?id=1275950 * https://bugzilla.suse.com/show_bug.cgi?id=1275954 * https://bugzilla.suse.com/show_bug.cgi?id=1275970 * https://bugzilla.suse.com/show_bug.cgi?id=1275973 * https://bugzilla.suse.com/show_bug.cgi?id=1275975 * https://bugzilla.suse.com/show_bug.cgi?id=1275976 * https://bugzilla.suse.com/show_bug.cgi?id=1276029 * https://bugzilla.suse.com/show_bug.cgi?id=1276257 * https://bugzilla.suse.com/show_bug.cgi?id=1276263 * https://bugzilla.suse.com/show_bug.cgi?id=1276270 * https://bugzilla.suse.com/show_bug.cgi?id=1276273 * https://bugzilla.suse.com/show_bug.cgi?id=1276277 * https://bugzilla.suse.com/show_bug.cgi?id=1276335 * https://bugzilla.suse.com/show_bug.cgi?id=1276346 * https://bugzilla.suse.com/show_bug.cgi?id=1276350 * https://bugzilla.suse.com/show_bug.cgi?id=1276355 * https://bugzilla.suse.com/show_bug.cgi?id=1276446 * https://bugzilla.suse.com/show_bug.cgi?id=1276452 * https://bugzilla.suse.com/show_bug.cgi?id=1276500 * https://bugzilla.suse.com/show_bug.cgi?id=1276507 * https://bugzilla.suse.com/show_bug.cgi?id=1276542 * https://bugzilla.suse.com/show_bug.cgi?id=1276546 * https://bugzilla.suse.com/show_bug.cgi?id=1276551 * https://bugzilla.suse.com/show_bug.cgi?id=1276561 * https://bugzilla.suse.com/show_bug.cgi?id=1276569 * https://bugzilla.suse.com/show_bug.cgi?id=1276665 * https://bugzilla.suse.com/show_bug.cgi?id=1276864 * https://bugzilla.suse.com/show_bug.cgi?id=1276927 * https://bugzilla.suse.com/show_bug.cgi?id=1276931 * https://bugzilla.suse.com/show_bug.cgi?id=1276937 * https://bugzilla.suse.com/show_bug.cgi?id=1276941 * https://bugzilla.suse.com/show_bug.cgi?id=1276943 * https://bugzilla.suse.com/show_bug.cgi?id=1276961 * https://bugzilla.suse.com/show_bug.cgi?id=1277022 * https://bugzilla.suse.com/show_bug.cgi?id=1277034 * https://bugzilla.suse.com/show_bug.cgi?id=1277037 * https://bugzilla.suse.com/show_bug.cgi?id=1277047 * https://bugzilla.suse.com/show_bug.cgi?id=1277054 * https://bugzilla.suse.com/show_bug.cgi?id=1277057 * https://bugzilla.suse.com/show_bug.cgi?id=1277059 * https://bugzilla.suse.com/show_bug.cgi?id=1277064 * https://bugzilla.suse.com/show_bug.cgi?id=1277066 * https://bugzilla.suse.com/show_bug.cgi?id=1277069 * https://bugzilla.suse.com/show_bug.cgi?id=1277073 * https://bugzilla.suse.com/show_bug.cgi?id=1277077 * https://bugzilla.suse.com/show_bug.cgi?id=1277095 * https://bugzilla.suse.com/show_bug.cgi?id=1277155 * https://bugzilla.suse.com/show_bug.cgi?id=1277159 * https://bugzilla.suse.com/show_bug.cgi?id=1277160 * https://bugzilla.suse.com/show_bug.cgi?id=1277202 * https://bugzilla.suse.com/show_bug.cgi?id=1277204 * https://bugzilla.suse.com/show_bug.cgi?id=1277275 * https://bugzilla.suse.com/show_bug.cgi?id=1277285 * https://bugzilla.suse.com/show_bug.cgi?id=1277391 * https://bugzilla.suse.com/show_bug.cgi?id=1277408 * https://bugzilla.suse.com/show_bug.cgi?id=1277516 * https://bugzilla.suse.com/show_bug.cgi?id=1277523 * https://bugzilla.suse.com/show_bug.cgi?id=1277551 * https://bugzilla.suse.com/show_bug.cgi?id=1277625 * https://bugzilla.suse.com/show_bug.cgi?id=1277660 * https://bugzilla.suse.com/show_bug.cgi?id=1277678 * https://bugzilla.suse.com/show_bug.cgi?id=1277688 * https://bugzilla.suse.com/show_bug.cgi?id=1277775 * https://bugzilla.suse.com/show_bug.cgi?id=1277776 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:21:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:21:29 -0000 Subject: SUSE-SU-2026:23480-1: important: Security update for kernel-livepatch-MICRO-6-0-RT_Update_29 Message-ID: <178896008929.1855.8243856982550901339@aaf27ed6f0fb> # Security update for kernel-livepatch-MICRO-6-0-RT_Update_29 Announcement ID: SUSE-SU-2026:23480-1 Release Date: 2026-09-08T11:34:19Z Rating: important References: Affected Products: * SUSE Linux Micro 6.0 An update that can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_29 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 29 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-604=1 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_29-debugsource-1-1.1 * kernel-livepatch-6_4_0-52-rt-debuginfo-1-1.1 * kernel-livepatch-6_4_0-52-rt-1-1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:22:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:22:03 -0000 Subject: SUSE-SU-2026:23479-1: important: Security update for kernel-livepatch-MICRO-6-0_Update_29 Message-ID: <178896012358.1855.2120645739644917055@aaf27ed6f0fb> # Security update for kernel-livepatch-MICRO-6-0_Update_29 Announcement ID: SUSE-SU-2026:23479-1 Release Date: 2026-09-08T11:34:19Z Rating: important References: Affected Products: * SUSE Linux Micro 6.0 An update that can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_29 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 29 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-602=1 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-52-default-1-1.1 * kernel-livepatch-6_4_0-52-default-debuginfo-1-1.1 * kernel-livepatch-MICRO-6-0_Update_29-debugsource-1-1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:22:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:22:42 -0000 Subject: SUSE-SU-2026:23478-1: moderate: Security update for opensc Message-ID: <178896016271.1855.6758105527648439190@aaf27ed6f0fb> # Security update for opensc Announcement ID: SUSE-SU-2026:23478-1 Release Date: 2026-09-08T11:09:46Z Rating: moderate References: * bsc#1266964 Cross-References: * CVE-2026-40510 CVSS scores: * CVE-2026-40510 ( SUSE ): 4.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-40510 ( SUSE ): 5.7 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-40510 ( NVD ): 1.0 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40510 ( NVD ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-40510 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for opensc fixes the following issue: * CVE-2026-40510: stack buffer overflow in `piv_process_history()` allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device (bsc#1266964). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-887=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * opensc-debuginfo-0.24.0-7.1 * opensc-debugsource-0.24.0-7.1 * opensc-0.24.0-7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40510.html * https://bugzilla.suse.com/show_bug.cgi?id=1266964 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:37:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:37:14 -0000 Subject: SUSE-SU-2026:23477-1: important: Security update for the Linux Kernel Message-ID: <178896103452.1855.12318320808001746764@aaf27ed6f0fb> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:23477-1 Release Date: 2026-09-08T11:04:19Z Rating: important References: * bsc#1230238 * bsc#1235944 * bsc#1247455 * bsc#1250748 * bsc#1251966 * bsc#1252682 * bsc#1254306 * bsc#1255225 * bsc#1255250 * bsc#1256629 * bsc#1256708 * bsc#1257154 * bsc#1258430 * bsc#1258517 * bsc#1260522 * bsc#1261780 * bsc#1261788 * bsc#1262073 * bsc#1263004 * bsc#1263061 * bsc#1263133 * bsc#1264335 * bsc#1264446 * bsc#1264541 * bsc#1264584 * bsc#1264587 * bsc#1264619 * bsc#1264788 * bsc#1265068 * bsc#1265121 * bsc#1265449 * bsc#1265928 * bsc#1266402 * bsc#1266860 * bsc#1266874 * bsc#1266897 * bsc#1267023 * bsc#1267238 * bsc#1267501 * bsc#1267612 * bsc#1268276 * bsc#1268972 * bsc#1268979 * bsc#1268987 * bsc#1269004 * bsc#1269013 * bsc#1269108 * bsc#1269113 * bsc#1269114 * bsc#1269126 * bsc#1269167 * bsc#1269234 * bsc#1269238 * bsc#1269242 * bsc#1269256 * bsc#1269301 * bsc#1269306 * bsc#1269381 * bsc#1269388 * bsc#1269412 * bsc#1269530 * bsc#1269579 * bsc#1269590 * bsc#1269635 * bsc#1269655 * bsc#1269665 * bsc#1269686 * bsc#1269695 * bsc#1269713 * bsc#1269731 * bsc#1269774 * bsc#1269783 * bsc#1269792 * bsc#1269815 * bsc#1269965 * bsc#1269969 * bsc#1269981 * bsc#1269985 * bsc#1270090 * bsc#1270108 * bsc#1270111 * bsc#1270251 * bsc#1271256 * bsc#1271365 * bsc#1271366 * bsc#1271825 * bsc#1271830 * bsc#1272150 * bsc#1272175 * bsc#1272179 * bsc#1272182 * bsc#1272200 * bsc#1272210 * bsc#1272213 * bsc#1272230 * bsc#1272260 * bsc#1272261 * bsc#1272262 * bsc#1272297 * bsc#1272346 * bsc#1272381 * bsc#1272385 * bsc#1272390 * bsc#1272423 * bsc#1272429 * bsc#1272484 * bsc#1272486 * bsc#1272497 * bsc#1272516 * bsc#1272569 * bsc#1272571 * bsc#1272641 * bsc#1272643 * bsc#1272662 * bsc#1272673 * bsc#1272680 * bsc#1272682 * bsc#1272756 * bsc#1272786 * bsc#1272788 * bsc#1272798 * bsc#1272799 * bsc#1272868 * bsc#1272877 * bsc#1272891 * bsc#1272963 * bsc#1272983 * bsc#1273008 * bsc#1273019 * bsc#1273027 * bsc#1273028 * bsc#1273030 * bsc#1273038 * bsc#1273053 * bsc#1273054 * bsc#1273060 * bsc#1273105 * bsc#1273249 * bsc#1273250 * bsc#1273260 * bsc#1273273 * bsc#1273274 * bsc#1273276 * bsc#1273281 * bsc#1273284 * bsc#1273285 * bsc#1273289 * bsc#1273291 * bsc#1273294 * bsc#1273302 * bsc#1273303 * bsc#1273305 * bsc#1273310 * bsc#1273311 * bsc#1273316 * bsc#1273318 * bsc#1273319 * bsc#1273323 * bsc#1273325 * bsc#1273327 * bsc#1273334 * bsc#1273335 * bsc#1273336 * bsc#1273337 * bsc#1273338 * bsc#1273340 * bsc#1273341 * bsc#1273346 * bsc#1273422 * bsc#1273426 * bsc#1273443 * bsc#1273463 * bsc#1273468 * bsc#1273469 * bsc#1273471 * bsc#1273479 * bsc#1273480 * bsc#1273482 * bsc#1273484 * bsc#1273488 * bsc#1273490 * bsc#1273501 * bsc#1273503 * bsc#1273504 * bsc#1273506 * bsc#1273523 * bsc#1273525 * bsc#1273533 * bsc#1273536 * bsc#1273542 * bsc#1273555 * bsc#1273578 * bsc#1273579 * bsc#1273582 * bsc#1273596 * bsc#1273597 * bsc#1273598 * bsc#1273600 * bsc#1273601 * bsc#1273602 * bsc#1273603 * bsc#1273682 * bsc#1273734 * bsc#1273738 * bsc#1273739 * bsc#1273741 * bsc#1273742 * bsc#1273743 * bsc#1273745 * bsc#1273748 * bsc#1273749 * bsc#1273755 * bsc#1273762 * bsc#1273765 * bsc#1273766 * bsc#1273769 * bsc#1273774 * bsc#1273778 * bsc#1273780 * bsc#1273790 * bsc#1273796 * bsc#1273804 * bsc#1273810 * bsc#1273811 * bsc#1273813 * bsc#1273817 * bsc#1273822 * bsc#1273824 * bsc#1273831 * bsc#1273832 * bsc#1273834 * bsc#1273838 * bsc#1273844 * bsc#1273849 * bsc#1273860 * bsc#1273862 * bsc#1273867 * bsc#1273868 * bsc#1273869 * bsc#1273872 * bsc#1273876 * bsc#1273877 * bsc#1273880 * bsc#1273882 * bsc#1273890 * bsc#1273891 * bsc#1273892 * bsc#1273895 * bsc#1273896 * bsc#1273903 * bsc#1273905 * bsc#1273930 * bsc#1273933 * bsc#1273934 * bsc#1273935 * bsc#1273936 * bsc#1273939 * bsc#1273940 * bsc#1273941 * bsc#1273942 * bsc#1273944 * bsc#1273945 * bsc#1273946 * bsc#1273956 * bsc#1273957 * bsc#1273958 * bsc#1273966 * bsc#1273967 * bsc#1273968 * bsc#1273972 * bsc#1273974 * bsc#1273975 * bsc#1273977 * bsc#1273982 * bsc#1273988 * bsc#1273990 * bsc#1273991 * bsc#1273995 * bsc#1274001 * bsc#1274003 * bsc#1274006 * bsc#1274011 * bsc#1274012 * bsc#1274014 * bsc#1274017 * bsc#1274019 * bsc#1274020 * bsc#1274026 * bsc#1274028 * bsc#1274030 * bsc#1274031 * bsc#1274035 * bsc#1274040 * bsc#1274041 * bsc#1274057 * bsc#1274058 * bsc#1274061 * bsc#1274063 * bsc#1274065 * bsc#1274067 * bsc#1274075 * bsc#1274076 * bsc#1274077 * bsc#1274078 * bsc#1274208 * bsc#1274226 * bsc#1274239 * bsc#1274243 * bsc#1274258 * bsc#1274265 * bsc#1274274 * bsc#1274277 * bsc#1274278 * bsc#1274281 * bsc#1274283 * bsc#1274286 * bsc#1274290 * bsc#1274294 * bsc#1274296 * bsc#1274297 * bsc#1274298 * bsc#1274314 * bsc#1274321 * bsc#1274491 * bsc#1274497 * bsc#1274539 * bsc#1274541 * bsc#1274543 * bsc#1274545 * bsc#1274547 * bsc#1274550 * bsc#1274573 * bsc#1274578 * bsc#1274580 * bsc#1274581 * bsc#1274620 * bsc#1274622 * bsc#1274624 * bsc#1274629 * bsc#1274632 * bsc#1274636 * bsc#1274639 * bsc#1274640 * bsc#1274642 * bsc#1274644 * bsc#1274645 * bsc#1274646 * bsc#1274649 * bsc#1274650 * bsc#1274651 * bsc#1274656 * bsc#1274659 * bsc#1274662 * bsc#1274663 * bsc#1274665 * bsc#1274667 * bsc#1274670 * bsc#1274675 * bsc#1274677 * bsc#1274678 * bsc#1274679 * bsc#1274681 * bsc#1274682 * bsc#1274690 * bsc#1274694 * bsc#1274696 * bsc#1274698 * bsc#1274699 * bsc#1274700 * bsc#1274702 * bsc#1274703 * bsc#1274705 * bsc#1274706 * bsc#1274709 * bsc#1274710 * bsc#1274713 * bsc#1274716 * bsc#1274721 * bsc#1274725 * bsc#1274737 * bsc#1274738 * bsc#1274749 * bsc#1274752 * bsc#1274753 * bsc#1274754 * bsc#1274755 * bsc#1274756 * bsc#1274764 * bsc#1274768 * bsc#1274770 * bsc#1274787 * bsc#1274800 * bsc#1274801 * bsc#1274802 * bsc#1274804 * bsc#1274805 * bsc#1274807 * bsc#1274808 * bsc#1274811 * bsc#1274813 * bsc#1274814 * bsc#1274831 * bsc#1274834 * bsc#1274847 * bsc#1274853 * bsc#1274868 * bsc#1274869 * bsc#1274872 * bsc#1274873 * bsc#1274874 * bsc#1274876 * bsc#1274879 * bsc#1274881 * bsc#1274883 * bsc#1274886 * bsc#1274888 * bsc#1274891 * bsc#1274892 * bsc#1274893 * bsc#1274894 * bsc#1274896 * bsc#1274897 * bsc#1274898 * bsc#1274899 * bsc#1274901 * bsc#1274902 * bsc#1274905 * bsc#1274907 * bsc#1274908 * bsc#1274913 * bsc#1274914 * bsc#1274920 * bsc#1274921 * bsc#1274924 * bsc#1274925 * bsc#1274929 * bsc#1274930 * bsc#1274933 * bsc#1274934 * bsc#1274935 * bsc#1274941 * bsc#1274945 * bsc#1274947 * bsc#1274951 * bsc#1274953 * bsc#1274958 * bsc#1274968 * bsc#1274981 * bsc#1275040 * bsc#1275069 * bsc#1275071 * bsc#1275073 * bsc#1275076 * bsc#1275080 * bsc#1275083 * bsc#1275088 * bsc#1275091 * bsc#1275125 * bsc#1275126 * bsc#1275131 * bsc#1275132 * bsc#1275150 * bsc#1275152 * bsc#1275154 * bsc#1275155 * bsc#1275157 * bsc#1275158 * bsc#1275161 * bsc#1275163 * bsc#1275164 * bsc#1275169 * bsc#1275173 * bsc#1275176 * bsc#1275185 * bsc#1275190 * bsc#1275236 * bsc#1275237 * bsc#1275239 * bsc#1275294 * bsc#1275301 * bsc#1275303 * bsc#1275304 * bsc#1275305 * bsc#1275306 * bsc#1275307 * bsc#1275470 * bsc#1275472 * bsc#1275474 * bsc#1275479 * bsc#1275483 * bsc#1275486 * bsc#1275487 * bsc#1275506 * bsc#1275509 * bsc#1275511 * bsc#1275517 * bsc#1275528 * bsc#1275535 * bsc#1275540 * bsc#1275553 * bsc#1275555 * bsc#1275561 * bsc#1275566 * bsc#1275569 * bsc#1275574 * bsc#1275578 * bsc#1275582 * bsc#1275583 * bsc#1275584 * bsc#1275591 * bsc#1275595 * bsc#1275633 * bsc#1275636 * bsc#1275650 * bsc#1275659 * bsc#1275665 * bsc#1275669 * bsc#1275687 * bsc#1275688 * bsc#1275695 * bsc#1275696 * bsc#1275704 * bsc#1275782 * bsc#1275784 * bsc#1275787 * bsc#1275788 * bsc#1275790 * bsc#1275797 * bsc#1275798 * bsc#1275805 * bsc#1275817 * bsc#1275818 * bsc#1275819 * bsc#1275820 * bsc#1275821 * bsc#1275827 * bsc#1275864 * bsc#1275867 * bsc#1275869 * bsc#1275870 * bsc#1275871 * bsc#1275872 * bsc#1275886 * bsc#1275905 * bsc#1275923 * bsc#1275925 * bsc#1275946 * bsc#1275950 * bsc#1275954 * bsc#1275970 * bsc#1275973 * bsc#1275975 * bsc#1275976 * bsc#1276029 * bsc#1276257 * bsc#1276263 * bsc#1276270 * bsc#1276273 * bsc#1276277 * bsc#1276335 * bsc#1276346 * bsc#1276350 * bsc#1276355 * bsc#1276446 * bsc#1276452 * bsc#1276500 * bsc#1276507 * bsc#1276542 * bsc#1276546 * bsc#1276551 * bsc#1276561 * bsc#1276569 * bsc#1276665 * bsc#1276864 * bsc#1276927 * bsc#1276931 * bsc#1276937 * bsc#1276941 * bsc#1276943 * bsc#1276961 * bsc#1277022 * bsc#1277034 * bsc#1277037 * bsc#1277047 * bsc#1277054 * bsc#1277057 * bsc#1277059 * bsc#1277064 * bsc#1277066 * bsc#1277069 * bsc#1277073 * bsc#1277077 * bsc#1277095 * bsc#1277155 * bsc#1277159 * bsc#1277160 * bsc#1277202 * bsc#1277204 * bsc#1277275 * bsc#1277285 * bsc#1277391 * bsc#1277408 * bsc#1277516 * bsc#1277523 * bsc#1277551 * bsc#1277625 * bsc#1277660 * bsc#1277678 * bsc#1277688 * bsc#1277775 * bsc#1277776 Cross-References: * CVE-2024-44981 * CVE-2024-57841 * CVE-2025-38469 * CVE-2025-39964 * CVE-2025-40022 * CVE-2025-68179 * CVE-2025-68214 * CVE-2025-71075 * CVE-2025-71104 * CVE-2026-23210 * CVE-2026-23230 * CVE-2026-23454 * CVE-2026-31392 * CVE-2026-31418 * CVE-2026-31531 * CVE-2026-31557 * CVE-2026-31663 * CVE-2026-43116 * CVE-2026-43125 * CVE-2026-43163 * CVE-2026-43271 * CVE-2026-43273 * CVE-2026-43278 * CVE-2026-43319 * CVE-2026-43363 * CVE-2026-43416 * CVE-2026-45897 * CVE-2026-45968 * CVE-2026-46070 * CVE-2026-46091 * CVE-2026-46107 * CVE-2026-46115 * CVE-2026-46195 * CVE-2026-52920 * CVE-2026-52925 * CVE-2026-52929 * CVE-2026-52935 * CVE-2026-52939 * CVE-2026-52946 * CVE-2026-52975 * CVE-2026-52977 * CVE-2026-52990 * CVE-2026-52994 * CVE-2026-53001 * CVE-2026-53033 * CVE-2026-53059 * CVE-2026-53076 * CVE-2026-53077 * CVE-2026-53089 * CVE-2026-53091 * CVE-2026-53094 * CVE-2026-53096 * CVE-2026-53110 * CVE-2026-53111 * CVE-2026-53126 * CVE-2026-53154 * CVE-2026-53163 * CVE-2026-53207 * CVE-2026-53219 * CVE-2026-53220 * CVE-2026-53223 * CVE-2026-53228 * CVE-2026-53238 * CVE-2026-53260 * CVE-2026-53264 * CVE-2026-53269 * CVE-2026-53273 * CVE-2026-53309 * CVE-2026-53330 * CVE-2026-53336 * CVE-2026-53337 * CVE-2026-53353 * CVE-2026-53365 * CVE-2026-53366 * CVE-2026-53381 * CVE-2026-53388 * CVE-2026-63801 * CVE-2026-63808 * CVE-2026-63810 * CVE-2026-63823 * CVE-2026-63827 * CVE-2026-63828 * CVE-2026-63860 * CVE-2026-63865 * CVE-2026-63868 * CVE-2026-63879 * CVE-2026-63881 * CVE-2026-63886 * CVE-2026-63887 * CVE-2026-63888 * CVE-2026-63889 * CVE-2026-63891 * CVE-2026-63898 * CVE-2026-63920 * CVE-2026-63925 * CVE-2026-63926 * CVE-2026-63928 * CVE-2026-63944 * CVE-2026-63969 * CVE-2026-63970 * CVE-2026-63972 * CVE-2026-63973 * CVE-2026-63980 * CVE-2026-63985 * CVE-2026-63990 * CVE-2026-63992 * CVE-2026-63999 * CVE-2026-64000 * CVE-2026-64001 * CVE-2026-64002 * CVE-2026-64004 * CVE-2026-64005 * CVE-2026-64006 * CVE-2026-64007 * CVE-2026-64010 * CVE-2026-64011 * CVE-2026-64014 * CVE-2026-64015 * CVE-2026-64018 * CVE-2026-64029 * CVE-2026-64034 * CVE-2026-64039 * CVE-2026-64047 * CVE-2026-64048 * CVE-2026-64051 * CVE-2026-64052 * CVE-2026-64073 * CVE-2026-64083 * CVE-2026-64084 * CVE-2026-64085 * CVE-2026-64086 * CVE-2026-64087 * CVE-2026-64088 * CVE-2026-64097 * CVE-2026-64098 * CVE-2026-64102 * CVE-2026-64109 * CVE-2026-64112 * CVE-2026-64113 * CVE-2026-64114 * CVE-2026-64115 * CVE-2026-64118 * CVE-2026-64121 * CVE-2026-64125 * CVE-2026-64126 * CVE-2026-64128 * CVE-2026-64131 * CVE-2026-64133 * CVE-2026-64135 * CVE-2026-64137 * CVE-2026-64148 * CVE-2026-64155 * CVE-2026-64164 * CVE-2026-64166 * CVE-2026-64168 * CVE-2026-64178 * CVE-2026-64185 * CVE-2026-64188 * CVE-2026-64190 * CVE-2026-64192 * CVE-2026-64214 * CVE-2026-64217 * CVE-2026-64218 * CVE-2026-64219 * CVE-2026-64222 * CVE-2026-64225 * CVE-2026-64237 * CVE-2026-64243 * CVE-2026-64245 * CVE-2026-64246 * CVE-2026-64247 * CVE-2026-64249 * CVE-2026-64257 * CVE-2026-64266 * CVE-2026-64268 * CVE-2026-64271 * CVE-2026-64273 * CVE-2026-64274 * CVE-2026-64275 * CVE-2026-64276 * CVE-2026-64277 * CVE-2026-64286 * CVE-2026-64287 * CVE-2026-64294 * CVE-2026-64296 * CVE-2026-64303 * CVE-2026-64304 * CVE-2026-64305 * CVE-2026-64306 * CVE-2026-64312 * CVE-2026-64313 * CVE-2026-64315 * CVE-2026-64316 * CVE-2026-64317 * CVE-2026-64322 * CVE-2026-64323 * CVE-2026-64329 * CVE-2026-64331 * CVE-2026-64332 * CVE-2026-64333 * CVE-2026-64334 * CVE-2026-64335 * CVE-2026-64337 * CVE-2026-64338 * CVE-2026-64340 * CVE-2026-64341 * CVE-2026-64342 * CVE-2026-64343 * CVE-2026-64344 * CVE-2026-64346 * CVE-2026-64348 * CVE-2026-64350 * CVE-2026-64351 * CVE-2026-64355 * CVE-2026-64358 * CVE-2026-64362 * CVE-2026-64365 * CVE-2026-64375 * CVE-2026-64376 * CVE-2026-64378 * CVE-2026-64381 * CVE-2026-64382 * CVE-2026-64383 * CVE-2026-64384 * CVE-2026-64385 * CVE-2026-64386 * CVE-2026-64387 * CVE-2026-64388 * CVE-2026-64401 * CVE-2026-64403 * CVE-2026-64406 * CVE-2026-64408 * CVE-2026-64409 * CVE-2026-64411 * CVE-2026-64412 * CVE-2026-64420 * CVE-2026-64421 * CVE-2026-64423 * CVE-2026-64427 * CVE-2026-64429 * CVE-2026-64433 * CVE-2026-64434 * CVE-2026-64436 * CVE-2026-64440 * CVE-2026-64442 * CVE-2026-64443 * CVE-2026-64444 * CVE-2026-64445 * CVE-2026-64448 * CVE-2026-64450 * CVE-2026-64454 * CVE-2026-64455 * CVE-2026-64463 * CVE-2026-64470 * CVE-2026-64471 * CVE-2026-64472 * CVE-2026-64478 * CVE-2026-64479 * CVE-2026-64480 * CVE-2026-64481 * CVE-2026-64482 * CVE-2026-64483 * CVE-2026-64484 * CVE-2026-64486 * CVE-2026-64487 * CVE-2026-64489 * CVE-2026-64494 * CVE-2026-64495 * CVE-2026-64496 * CVE-2026-64497 * CVE-2026-64500 * CVE-2026-64503 * CVE-2026-64504 * CVE-2026-64505 * CVE-2026-64511 * CVE-2026-64512 * CVE-2026-64513 * CVE-2026-64524 * CVE-2026-64527 * CVE-2026-64536 * CVE-2026-64537 * CVE-2026-64538 * CVE-2026-64539 * CVE-2026-64540 * CVE-2026-64541 * CVE-2026-64543 * CVE-2026-64544 * CVE-2026-64545 * CVE-2026-64546 * CVE-2026-64547 * CVE-2026-64548 * CVE-2026-64549 * CVE-2026-64551 * CVE-2026-64552 * CVE-2026-64553 * CVE-2026-64554 * CVE-2026-64562 * CVE-2026-64563 * CVE-2026-64565 * CVE-2026-64567 * CVE-2026-64571 * CVE-2026-64572 * CVE-2026-64573 * CVE-2026-64574 * CVE-2026-64576 * CVE-2026-64577 * CVE-2026-64581 * CVE-2026-64582 * CVE-2026-64583 * CVE-2026-64584 * CVE-2026-64585 * CVE-2026-64593 * CVE-2026-64597 * CVE-2026-64598 * CVE-2026-64599 * CVE-2026-64602 * CVE-2026-64604 * CVE-2026-68081 * CVE-2026-68082 * CVE-2026-68085 * CVE-2026-68086 * CVE-2026-68088 * CVE-2026-68091 * CVE-2026-68093 * CVE-2026-68102 * CVE-2026-68104 * CVE-2026-68106 * CVE-2026-68107 * CVE-2026-68108 * CVE-2026-68110 * CVE-2026-68111 * CVE-2026-68112 * CVE-2026-68115 * CVE-2026-68116 * CVE-2026-68117 * CVE-2026-68121 * CVE-2026-68123 * CVE-2026-68125 * CVE-2026-68126 * CVE-2026-68127 * CVE-2026-68129 * CVE-2026-68132 * CVE-2026-68133 * CVE-2026-68136 * CVE-2026-68137 * CVE-2026-68138 * CVE-2026-68139 * CVE-2026-68142 * CVE-2026-68143 * CVE-2026-68145 * CVE-2026-68149 * CVE-2026-68153 * CVE-2026-68154 * CVE-2026-68155 * CVE-2026-68156 * CVE-2026-68157 * CVE-2026-68158 * CVE-2026-68159 * CVE-2026-68160 * CVE-2026-68161 * CVE-2026-68162 * CVE-2026-68166 * CVE-2026-68180 * CVE-2026-68181 * CVE-2026-68182 * CVE-2026-68184 * CVE-2026-68188 * CVE-2026-68189 * CVE-2026-68192 * CVE-2026-68193 * CVE-2026-68194 * CVE-2026-68195 * CVE-2026-68196 * CVE-2026-68197 * CVE-2026-68199 * CVE-2026-68202 * CVE-2026-68204 * CVE-2026-68205 * CVE-2026-68206 * CVE-2026-68207 * CVE-2026-68209 * CVE-2026-68210 * CVE-2026-68212 * CVE-2026-68213 * CVE-2026-68214 * CVE-2026-68215 * CVE-2026-68216 * CVE-2026-68217 * CVE-2026-68218 * CVE-2026-68219 * CVE-2026-68220 * CVE-2026-68222 * CVE-2026-68223 * CVE-2026-68226 * CVE-2026-68227 * CVE-2026-68229 * CVE-2026-68231 * CVE-2026-68234 * CVE-2026-68236 * CVE-2026-68238 * CVE-2026-68243 * CVE-2026-68244 * CVE-2026-68246 * CVE-2026-68247 * CVE-2026-68248 * CVE-2026-68249 * CVE-2026-68250 * CVE-2026-68251 * CVE-2026-68254 * CVE-2026-68255 * CVE-2026-68256 * CVE-2026-68259 * CVE-2026-68269 * CVE-2026-68271 * CVE-2026-68272 * CVE-2026-68277 * CVE-2026-68278 * CVE-2026-68279 * CVE-2026-68280 * CVE-2026-68284 * CVE-2026-68286 * CVE-2026-68288 * CVE-2026-68289 * CVE-2026-68293 * CVE-2026-68297 * CVE-2026-68299 * CVE-2026-68300 * CVE-2026-68303 * CVE-2026-68304 * CVE-2026-68306 * CVE-2026-68308 * CVE-2026-68309 * CVE-2026-68310 * CVE-2026-68312 * CVE-2026-68313 * CVE-2026-68315 * CVE-2026-68320 * CVE-2026-68322 * CVE-2026-68324 * CVE-2026-68325 * CVE-2026-68326 * CVE-2026-68327 * CVE-2026-68328 * CVE-2026-68329 * CVE-2026-68331 * CVE-2026-68333 * CVE-2026-68335 * CVE-2026-68336 * CVE-2026-68339 * CVE-2026-68340 * CVE-2026-68343 * CVE-2026-68346 * CVE-2026-68348 * CVE-2026-68349 * CVE-2026-68350 * CVE-2026-68351 * CVE-2026-68352 * CVE-2026-68353 * CVE-2026-68354 * CVE-2026-68355 * CVE-2026-68357 * CVE-2026-68359 * CVE-2026-68360 * CVE-2026-68361 * CVE-2026-68362 * CVE-2026-68363 * CVE-2026-68365 * CVE-2026-68366 * CVE-2026-68368 * CVE-2026-68369 * CVE-2026-68370 * CVE-2026-68372 * CVE-2026-68373 * CVE-2026-68377 * CVE-2026-68386 * CVE-2026-68391 * CVE-2026-68392 * CVE-2026-68397 * CVE-2026-68398 * CVE-2026-68399 * CVE-2026-68402 * CVE-2026-68403 * CVE-2026-68405 * CVE-2026-68406 * CVE-2026-68407 * CVE-2026-68408 * CVE-2026-68410 * CVE-2026-68413 * CVE-2026-68414 * CVE-2026-68417 * CVE-2026-68418 * CVE-2026-68419 * CVE-2026-68422 * CVE-2026-68425 * CVE-2026-68426 * CVE-2026-68427 * CVE-2026-68428 * CVE-2026-68429 * CVE-2026-68430 * CVE-2026-68432 * CVE-2026-68433 * CVE-2026-68434 * CVE-2026-68444 * CVE-2026-68445 * CVE-2026-68446 * CVE-2026-68450 * CVE-2026-68470 * CVE-2026-68480 * CVE-2026-72020 * CVE-2026-72035 * CVE-2026-72036 * CVE-2026-72069 * CVE-2026-72072 * CVE-2026-72083 * CVE-2026-72084 * CVE-2026-72123 * CVE-2026-72132 * CVE-2026-72221 * CVE-2026-72222 * CVE-2026-72251 * CVE-2026-72254 * CVE-2026-72262 * CVE-2026-72288 * CVE-2026-72289 * CVE-2026-72296 * CVE-2026-72307 * CVE-2026-72308 * CVE-2026-72317 * CVE-2026-72341 * CVE-2026-72342 * CVE-2026-72343 * CVE-2026-72389 * CVE-2026-72463 * CVE-2026-72464 * CVE-2026-72466 * CVE-2026-72467 * CVE-2026-72469 * CVE-2026-72473 * CVE-2026-72494 * CVE-2026-72495 * CVE-2026-72496 * CVE-2026-72499 * CVE-2026-72501 * CVE-2026-72502 * CVE-2026-74269 * CVE-2026-74296 * CVE-2026-74297 * CVE-2026-74318 * CVE-2026-74321 * CVE-2026-74334 * CVE-2026-74345 * CVE-2026-74394 * CVE-2026-74395 * CVE-2026-74454 * CVE-2026-74474 * CVE-2026-74481 * CVE-2026-74482 * CVE-2026-74488 * CVE-2026-74495 * CVE-2026-74496 * CVE-2026-74509 * CVE-2026-74510 * CVE-2026-74512 * CVE-2026-74516 * CVE-2026-74518 * CVE-2026-74527 * CVE-2026-74537 * CVE-2026-74548 * CVE-2026-74550 * CVE-2026-74556 * CVE-2026-74563 * CVE-2026-74566 * CVE-2026-74567 * CVE-2026-74571 * CVE-2026-74581 * CVE-2026-74582 * CVE-2026-74584 * CVE-2026-74610 * CVE-2026-74669 * CVE-2026-74692 * CVE-2026-74694 * CVE-2026-74695 * CVE-2026-74717 * CVE-2026-74722 * CVE-2026-80529 * CVE-2026-80534 * CVE-2026-80590 * CVE-2026-80654 CVSS scores: * CVE-2024-44981 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L * CVE-2024-44981 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2024-44981 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-57841 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-38469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39964 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-39964 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-39964 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-39964 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-40022 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-40022 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-68179 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68179 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68214 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71104 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2025-71104 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-71104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23210 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23230 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23230 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23230 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23230 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-23454 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23454 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23454 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31392 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-31392 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-31392 ( NVD ): 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L * CVE-2026-31418 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31418 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31531 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31557 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31663 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31663 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43116 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43125 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43163 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43271 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43271 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43271 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43319 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43319 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45897 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45897 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45897 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46070 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46070 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46091 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46091 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46091 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46107 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46107 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46107 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46115 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46115 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46195 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46195 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52920 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-52920 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-52925 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52925 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52925 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52939 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52939 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52977 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52977 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52990 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53033 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53059 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53059 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53059 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53076 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53076 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53077 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53077 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53077 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53089 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53089 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53091 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53091 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53091 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53091 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-53094 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53094 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53096 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53096 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53110 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53111 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53111 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53111 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53207 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53228 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53228 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53238 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53238 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53269 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53269 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53269 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53309 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53309 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53309 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53330 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53330 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53336 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53336 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53353 ( SUSE ): 0.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53353 ( SUSE ): 0.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N * CVE-2026-53353 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53365 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53365 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53365 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53381 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63801 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63801 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63801 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63808 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63808 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-63808 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63810 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63810 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63823 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63823 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63823 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63827 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63828 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63828 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63828 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-63860 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63860 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63860 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63865 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63865 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63865 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-63868 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63868 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63879 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63879 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63879 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63881 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63886 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63886 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63886 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63887 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63887 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63887 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63888 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63888 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63888 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63889 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63889 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63889 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63891 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63891 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63898 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63898 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63920 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63920 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63920 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63925 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63925 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63925 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-63926 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63926 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63926 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63928 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63928 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63944 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63944 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63969 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63969 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63970 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63970 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63972 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63972 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63972 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63973 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63973 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63980 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63985 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63985 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63985 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63990 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63990 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63992 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63992 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63992 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63999 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63999 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64000 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64000 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64000 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64001 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64001 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64002 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64002 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64002 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64004 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64004 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64005 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64005 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64005 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64006 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-64006 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-64007 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64007 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64007 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64010 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64011 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64014 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64014 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64015 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64015 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64018 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-64018 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-64018 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64029 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64029 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64029 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64034 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64039 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64039 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64039 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64047 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64047 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64048 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64048 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64048 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64051 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64051 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64051 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64052 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64052 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64052 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64073 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64073 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64073 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64083 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64083 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64083 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64084 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64084 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64084 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64085 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64085 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64085 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64086 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64086 ( SUSE ): 5.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64086 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64087 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64087 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64087 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64088 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64088 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64088 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64097 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64097 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64097 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64098 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64102 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-64102 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-64102 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64113 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64113 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64114 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64115 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64118 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64118 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64118 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64121 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64121 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64121 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64125 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64126 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64126 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L * CVE-2026-64126 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-64128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64128 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64135 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64137 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64137 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64137 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64148 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64148 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64148 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64155 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64164 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64166 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64178 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64178 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64185 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64185 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64188 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64188 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64188 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64190 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64190 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64190 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64217 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64217 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64217 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64218 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64219 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64222 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64222 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64222 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64225 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64225 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64225 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64237 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64237 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64245 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64246 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64246 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64246 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64247 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64247 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-64249 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64249 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64257 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64257 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-64257 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64266 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64266 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64268 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64271 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64271 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64271 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64273 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64275 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64275 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64277 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64286 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64286 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64287 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64303 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64303 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64303 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64304 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64305 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64305 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64306 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64313 ( SUSE ): 7.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-64313 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64313 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64315 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64316 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64316 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64317 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64317 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64317 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64322 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64322 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64322 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64323 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64323 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64329 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64329 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64329 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64331 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64331 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64333 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64333 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64334 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64334 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64334 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64335 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64335 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64335 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64337 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64337 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64338 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64340 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64340 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64340 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64341 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64342 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64343 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64344 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64346 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64348 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64348 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64348 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64350 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64350 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64350 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64351 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64351 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64351 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64355 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64355 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64358 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64358 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64365 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64375 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64375 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64376 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64376 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64376 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64381 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64381 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64382 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64382 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64383 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64383 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64384 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64385 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64386 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64387 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64388 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64388 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-64388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64401 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64401 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64403 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64403 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64403 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64406 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64408 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64409 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64409 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64411 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64411 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64411 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64412 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64412 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64412 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64420 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64421 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64421 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64427 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64427 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64434 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64436 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64436 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64440 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64440 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64440 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64442 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64442 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64443 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64443 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64444 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64444 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64444 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64445 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64448 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64448 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64450 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64454 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64471 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64478 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64478 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64479 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64480 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64481 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64481 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64482 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64482 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64483 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64484 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64484 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64486 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64487 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64489 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64497 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64500 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64503 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64504 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64505 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64511 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64511 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64512 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64513 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64527 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64537 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64537 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64538 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64540 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64540 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64540 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64541 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64541 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64541 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64544 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64544 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64545 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64547 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64547 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64547 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64548 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64548 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64549 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64551 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64551 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64552 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64552 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64552 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64553 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64562 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64562 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64563 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64563 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64565 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64565 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64567 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64567 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64567 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64571 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64571 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64572 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64572 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64573 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64573 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64574 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64576 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64576 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64576 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64577 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64577 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64577 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64581 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64581 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64581 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64582 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64583 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64583 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64584 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64585 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64593 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64593 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64598 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64598 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64599 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64599 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64602 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64604 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68081 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68081 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68082 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68082 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68082 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68085 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68085 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68085 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68086 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-68086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-68088 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68088 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68091 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68091 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68091 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68093 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-68093 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68102 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68102 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68104 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68106 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68106 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68106 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68107 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68107 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68107 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68108 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68108 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68108 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68110 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68110 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68111 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68111 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68115 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68115 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68116 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68116 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-68116 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68117 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68117 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68121 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68121 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68123 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68123 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68123 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68125 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68125 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68125 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68126 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68126 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68127 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68127 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68127 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68129 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68129 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68129 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68132 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68132 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68133 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68133 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68136 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68136 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68137 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68139 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68139 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68142 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68142 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-68142 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68143 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68143 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68143 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68145 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68145 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68145 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68149 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68149 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68149 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-68153 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68153 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68153 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68154 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68154 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68154 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68155 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68155 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68155 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68156 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68156 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68156 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68157 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68157 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68157 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68158 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68158 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68158 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68159 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68159 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68159 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68160 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68160 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68160 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68161 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68161 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68161 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68162 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68166 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68166 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68180 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68182 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68184 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68184 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68188 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68192 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68192 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68197 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68202 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68204 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68207 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68210 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68210 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68212 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68217 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68218 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68218 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68219 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68219 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68220 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68220 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68222 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68223 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68223 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68226 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68226 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68227 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68227 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68229 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68229 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-68229 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68231 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68231 ( SUSE ): 2.1 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68234 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68236 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68236 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68236 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68238 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68238 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68243 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68244 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68246 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68246 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68247 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68247 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68248 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68249 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68250 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68250 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68251 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68251 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68256 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68259 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68259 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68269 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68271 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68272 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68278 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68278 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68279 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68279 ( SUSE ): 2.4 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68280 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68280 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68284 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68284 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68286 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68286 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68288 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68288 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68289 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68293 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68293 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68299 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68308 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68309 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68310 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68312 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68313 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-68322 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68324 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68325 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68327 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68327 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68328 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68333 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68343 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68349 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68350 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68351 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68353 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68353 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68354 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68355 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68357 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68359 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68360 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68361 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68365 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68365 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-68366 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68368 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68369 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68370 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68372 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68377 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68377 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68386 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68391 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68391 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68392 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68392 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68402 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68402 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68403 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68405 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68406 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68407 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68408 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68410 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68413 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68414 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68414 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68422 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68425 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68425 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68426 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68426 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68427 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68427 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68427 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68428 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68430 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68430 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68433 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-68434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68444 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68445 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68445 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68445 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68446 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68446 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68470 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68470 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68470 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68480 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-72020 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72020 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72020 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72035 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72036 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72069 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72083 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72084 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72123 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72132 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72132 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72221 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72221 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72221 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72222 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72251 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72251 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72251 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72254 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72262 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72262 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72288 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72289 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72289 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72289 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72296 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72296 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72296 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-72307 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72307 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72308 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72308 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72317 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72317 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72317 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72341 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72342 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72342 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72343 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72343 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72389 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72463 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72463 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72464 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72464 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72467 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72473 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-72473 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72494 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72495 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72496 ( NVD ): 9.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H * CVE-2026-72499 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72499 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72501 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74269 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74269 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74318 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74345 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74345 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74345 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74394 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74395 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74395 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74454 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74454 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-74454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74474 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74474 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74481 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74482 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74482 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74488 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74488 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74495 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74495 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74509 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74509 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74516 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-74516 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74518 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74518 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74527 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-74527 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74537 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74537 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74550 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74550 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74556 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-74556 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74563 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74566 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-74567 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74567 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74571 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74581 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74581 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74582 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74584 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-74584 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-74584 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-74610 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-74610 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74610 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74692 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74694 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74694 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74695 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74695 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74717 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74717 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74722 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80534 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80534 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80590 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-80654 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80654 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves 588 vulnerabilities and has 23 fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 RT kernel was updated to fix various security issues: The following security issues were fixed: * CVE-2024-57841: net: fix memory leak in tcp_conn_request() (bsc#1235944) * CVE-2025-68214: timers: Fix NULL function pointer race in timer_shutdown_sync() (bsc#1255225). * CVE-2025-71075: scsi: aic94xx: fix use-after-free in device removal path (bsc#1256629). * CVE-2026-31392: smb: client: fix krb5 mount with username option (bsc#1261788). * CVE-2026-31418: netfilter: ipset: drop logically empty buckets in mtype_del (bsc#1262073). * CVE-2026-31531: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() (bsc#1263004). * CVE-2026-31557: nvmet: move async event work off nvmet-wq (bsc#1263061). * CVE-2026-31663: xfrm: hold device only for the asynchronous decryption (bsc#1263133). * CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack (bsc#1264619). * CVE-2026-43125: dlm: validate length in dlm_search_rsb_tree (bsc#1264541). * CVE-2026-43163: md/bitmap: fix GPF in write_page caused by resize race (bsc#1264335). * CVE-2026-43271: md-cluster: fix NULL pointer dereference in process_metadata_update (bsc#1264587). * CVE-2026-43273: ceph: supply snapshot context in ceph_zero_partial_object() (bsc#1264446). * CVE-2026-43278: dm: clear cloned request bio pointer when last clone bio completes (bsc#1264584). * CVE-2026-43319: spi: spidev: fix lock inversion between spi_lock and buf_lock (bsc#1264788). * CVE-2026-43363: x86/apic: Disable x2apic on resume if the kernel expects so (bsc#1265068). * CVE-2026-43416: powerpc, perf: Check that current->mm is alive before getting user callchain (bsc#1265121). * CVE-2026-45897: bpf: Fix UAF in sock clone early bailouts (bsc#1266897). * CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). * CVE-2026-46070: md/raid5: validate payload size before accessing journal metadata (bsc#1267501). * CVE-2026-46091: media: rc: igorplugusb: heed coherency rules (bsc#1267238). * CVE-2026-46107: dm-thin: fix metadata refcount underflow (bsc#1267612). * CVE-2026-46115: block: add pgmap check to biovec_phys_mergeable (bsc#1266874). * CVE-2026-46195: smb: client: validate dacloffset before building DACL pointers (bsc#1266860). * CVE-2026-52920: netfilter: xt_policy: fix strict mode inbound policy matching (bsc#1269013). * CVE-2026-52925: vrf: Fix a potential NPD when removing a port from a VRF (bsc#1268987). * CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). * CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send (bsc#1268979). * CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion (bsc#1268972). * CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (bsc#1269113). * CVE-2026-52975: bonding: 802.3ad replace MAC_ADDRESS_EQUAL with __agg_has_partner (bsc#1269234). * CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). * CVE-2026-52990: fsnotify: fix inode reference leak in fsnotify_recalc_mask() (bsc#1269108). * CVE-2026-52994: vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting (bsc#1269126). * CVE-2026-53001: netfilter: xtables: restrict several matches to inet family (bsc#1269114). * CVE-2026-53033: bpf, sockmap: Take state lock for af_unix iter (bsc#1269388). * CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). * CVE-2026-53076: bpf: Fix OOB in pcpu_init_value (bsc#1269695). * CVE-2026-53077: net/rds: Restrict use of RDS/IB to the initial network namespace (bsc#1269412). * CVE-2026-53089: bpf: Fix use-after-free in offloaded map/prog info fill (bsc#1269783). * CVE-2026-53091: net: account for encap headers in qdisc pkt len (bsc#1269530). * CVE-2026-53094: bpf: Fix stale offload->prog pointer after constant blinding (bsc#1269965). * CVE-2026-53096: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (bsc#1269969). * CVE-2026-53110: selftests/bpf: Add ASSERT_OK_FD macro (bsc#1269985). * CVE-2026-53111: bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap (bsc#1269167). * CVE-2026-53126: blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() (bsc#1269635). * CVE-2026-53154: mm/hugetlb: restore reservation on error in hugetlb folio copy paths (bsc#1269665). * CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). * CVE-2026-53207: mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison (bsc#1269590). * CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers (bsc#1269686). * CVE-2026-53220: netfilter: revalidate bridge ports (bsc#1269381). * CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs (bsc#1269301). * CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads (bsc#1269256). * CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths (bsc#1269774). * CVE-2026-53260: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req() (bsc#1269731). * CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). * CVE-2026-53269: netfilter: synproxy: add mutex to guard hook reference counting (bsc#1269579). * CVE-2026-53273: tee: optee: prevent use-after-free when the client exits before the supplicant (bsc#1269713). * CVE-2026-53309: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (bsc#1269815). * CVE-2026-53330: drm/amd/display: Fix out-of-bounds read in (bsc#1270090). * CVE-2026-53336: nvmem: layouts: onie-tlv: fix hang on unknown types (bsc#1270108). * CVE-2026-53337: net: bonding: fix NULL pointer dereference in bond_do_ioctl() (bsc#1270251). * CVE-2026-53353: hsr: Remove WARN_ONCE() in hsr_addr_is_self() (bsc#1270111). * CVE-2026-53365: vsock/virtio: fix zerocopy completion for multi-skb sends (bsc#1271365). * CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). * CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). * CVE-2026-63808: exfat: fix potential use-after-free in exfat_find_dir_entry() (bsc#1272260). * CVE-2026-63810: block: Avoid mounting the bdev pseudo-filesystem in userspace (bsc#1272297). * CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). * CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179). * CVE-2026-63828: apparmor: mediate the implicit connect of TCP fast open sendmsg (bsc#1272175). * CVE-2026-63860: RDMA/core: Prefer NLA_NUL_STRING (bsc#1272429). * CVE-2026-63865: bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (bsc#1272486). * CVE-2026-63868: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (bsc#1272497). * CVE-2026-63879: drm/amdgpu: fix amdgpu_hmm_range_get_pages (bsc#1272569). * CVE-2026-63881: drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger (bsc#1272571). * CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). * CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). * CVE-2026-63889: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (bsc#1272423). * CVE-2026-63891: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (bsc#1272641). * CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). * CVE-2026-63925: macsec: fix replay protection at XPN lower-PN wrap (bsc#1273008). * CVE-2026-63926: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (bsc#1273019). * CVE-2026-63944: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (bsc#1272662). * CVE-2026-63969: ipv6: fix possible infinite loop in rt6_fill_node() (bsc#1272484). * CVE-2026-63970: vsock/virtio: bind uarg before filling zerocopy skb (bsc#1272673). * CVE-2026-63980: net/handshake: Use spin_lock_bh for hn_lock (bsc#1273028). * CVE-2026-63985: ethtool: eeprom: add more safeties to EEPROM Netlink fallback (bsc#1272963). * CVE-2026-63990: bonding: refuse to enslave CAN devices (bsc#1273027). * CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). * CVE-2026-63999: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure (bsc#1273038). * CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273030). * CVE-2026-64001: ALSA: pcm: oss: Fix setup list UAF on proc write error (bsc#1273734). * CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). * CVE-2026-64004: net/iucv: fix locking in .getsockopt (bsc#1273804). * CVE-2026-64005: net/smc: Do not re-initialize smc hashtables (bsc#1273831). * CVE-2026-64006: netfilter: nf_tables: fix dst corruption in same register operation (bsc#1273834). * CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). * CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882). * CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891). * CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762). * CVE-2026-64029: ALSA: seq: Serialize UMP output teardown with event_input (bsc#1273766). * CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). * CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). * CVE-2026-64052: block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() (bsc#1272983). * CVE-2026-64073: irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT (bsc#1273490). * CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488). * CVE-2026-64102: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (bsc#1272516). * CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748). * CVE-2026-64112: rbd: eliminate a race in lock_dwork draining on unmap (bsc#1273741). * CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning (bsc#1272262). * CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). * CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). * CVE-2026-64118: qed: fix double free in qed_cxt_tables_alloc() (bsc#1273749). * CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273743). * CVE-2026-64125: net: bcmgenet: keep RBUF EEE/PM disabled (bsc#1272346). * CVE-2026-64131: mm/memory: fix spurious warning when unmapping device- private/exclusive pages (bsc#1274063). * CVE-2026-64148: pds_core: check health in devcmd wait (bsc#1273956). * CVE-2026-64164: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (bsc#1273957). * CVE-2026-64185: sysfs: don't remove existing directory on update failure (bsc#1272200). * CVE-2026-64188: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (bsc#1272150). * CVE-2026-64190: net: team: fix NULL pointer dereference in team_xmit during mode change (bsc#1272210). * CVE-2026-64192: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (bsc#1272213). * CVE-2026-64214: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() (bsc#1272799). * CVE-2026-64217: netfs: Fix overrun check in netfs_extract_user_iter() (bsc#1272798). * CVE-2026-64222: octeontx2-pf: avoid double free of pool->stack on AQ init failure (bsc#1272788). * CVE-2026-64225: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (bsc#1272786). * CVE-2026-64245: fbdev: modedb: fix a possible UAF in fb_find_mode() (bsc#1273905). * CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). * CVE-2026-64286: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (bsc#1274058). * CVE-2026-64287: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (bsc#1273325). * CVE-2026-64294: mm: do file ownership checks with the proper mount idmap (bsc#1273525). * CVE-2026-64296: exfat: bound uniname advance in exfat_find_dir_entry() (bsc#1273975). * CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944). * CVE-2026-64312: crypto: pcrypt - restore callback for non-parallel fallback (bsc#1273968). * CVE-2026-64315: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1274028). * CVE-2026-64316: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1273598). * CVE-2026-64317: isofs: bound Rock Ridge symlink components to the SL record (bsc#1273936). * CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count (bsc#1273958). * CVE-2026-64323: udf: validate VAT header length against the VAT inode size (bsc#1273305). * CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). * CVE-2026-64375: proc: protect ptrace_may_access() with exec_update_lock (FD links) (bsc#1273868). * CVE-2026-64378: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() (bsc#1273603). * CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard() (bsc#1273860). * CVE-2026-64382: smb: client: fix double-free in SMB2_open() replay (bsc#1273291). * CVE-2026-64383: smb: client: fix double-free in SMB2_flush() replay (bsc#1273426). * CVE-2026-64384: smb: client: fix change notify replay double-free (bsc#1274541). * CVE-2026-64385: smb: client: fix double-free in SMB2_ioctl() replay (bsc#1274539). * CVE-2026-64386: smb: client: fix query_info() replay double-free (bsc#1274543). * CVE-2026-64387: smb: client: fix query directory replay double-free (bsc#1274545). * CVE-2026-64388: smb/client: fix chown/chgrp with SMB3 POSIX Extensions (bsc#1274061). * CVE-2026-64411: netfilter: ebtables: terminate table name before find_table_lock() (bsc#1274077). * CVE-2026-64412: netfilter: ebtables: module names must be null-terminated (bsc#1273780). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). * CVE-2026-64434: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (bsc#1273880). * CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states (bsc#1274277). * CVE-2026-64448: smb: client: restrict implied bcc[0] exemption to responses without data area (bsc#1273982). * CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). * CVE-2026-64463: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres (bsc#1273273). * CVE-2026-64472: vfio/mlx5: Fix racy bitfields and tighten struct layout (bsc#1274075). * CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547). * CVE-2026-64537: bridge: cfm: reject invalid CCM interval at configuration time (bsc#1273289). * CVE-2026-64538: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change() (bsc#1273335). * CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). * CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). * CVE-2026-64545: net, bpf: check master for NULL in xdp_master_redirect() (bsc#1273318). * CVE-2026-64548: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (bsc#1273337). * CVE-2026-64551: sctp: validate STALE_COOKIE cause length before reading staleness (bsc#1273813). * CVE-2026-64552: virtio-net: fix len check in receive_big() (bsc#1273323). * CVE-2026-64553: net: psample: fix info leak in PSAMPLE_ATTR_DATA (bsc#1273336). * CVE-2026-64554: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (bsc#1273340). * CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930). * CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). * CVE-2026-64567: btrfs: reject free space cache with more entries than pages (bsc#1274006). * CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). * CVE-2026-64576: nexthop: initialize extack in nh_res_bucket_migrate() (bsc#1274030). * CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031). * CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). * CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (bsc#1274040). * CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497). * CVE-2026-64597: smb: client: fix double-free in SMB2_close() replay (bsc#1274297). * CVE-2026-64598: smb/client: Fix error code in smb2_aead_req_alloc() (bsc#1274298). * CVE-2026-68081: KVM: nVMX: Add helper to put (unmap) vmcs12 pages (bsc#1274580). * CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers() (bsc#1274581). * CVE-2026-68086: mm/khugepaged: write all dirty file folios when collapsing (bsc#1274713). * CVE-2026-68116: vxlan: mdb: Fix source list corruption on a failed replace (bsc#1274876). * CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (bsc#1274881). * CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). * CVE-2026-68123: openvswitch: fix GSO userspace truncation underflow (bsc#1275169). * CVE-2026-68127: ila: reload IPv6 header after pskb_may_pull in checksum adjust (bsc#1275237). * CVE-2026-68129: gve: fix Rx queue stall on alloc failure (bsc#1275517). * CVE-2026-68132: super: fix emergency thaw deadlock on frozen block devices (bsc#1275553). * CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). * CVE-2026-68139: net/mlx5e: Use sender devcom for MPV master-up (bsc#1275578). * CVE-2026-68142: geneve: require CAP_NET_ADMIN in the device netns for changelink (bsc#1275582). * CVE-2026-68143: net: slip: serialize receive against buffer reallocation (bsc#1275583). * CVE-2026-68145: iomap: fix out-of-bounds bitmap_set() with zero-length range (bsc#1275584). * CVE-2026-68149: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (bsc#1275294). * CVE-2026-68153: libceph: remove debugfs files before client teardown (bsc#1275301). * CVE-2026-68154: libceph: reject zero bucket types in crush_decode (bsc#1275303). * CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). * CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after authorizer update (bsc#1275305). * CVE-2026-68157: libceph: guard missing CRUSH type name lookup (bsc#1275306). * CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). * CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). * CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472). * CVE-2026-68161: sctp: close UDP tunnel sockets during netns teardown (bsc#1274892). * CVE-2026-68166: userfaultfd: prevent registration of special VMAs (bsc#1274930). * CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). * CVE-2026-68205: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (bsc#1274934). * CVE-2026-68238: drm/amdgpu: Release VFCT ACPI table reference (bsc#1275704). * CVE-2026-68247: drm/i915/bios: range check LFP Data Block panel_type2 (bsc#1275817). * CVE-2026-68254: drm/i915/vrr: require valid min/max vfreq for VRR (bsc#1275150). * CVE-2026-68284: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (bsc#1275970). * CVE-2026-68286: drop_monitor: perform u64_stats updates under IRQ-disabled section (bsc#1275973). * CVE-2026-68288: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (bsc#1275975). * CVE-2026-68289: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (bsc#1275976). * CVE-2026-68293: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (bsc#1275091). * CVE-2026-68297: tipc: fix u16 MTU truncation in media and bearer MTU validation (bsc#1275040). * CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (bsc#1275088). * CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL (bsc#1275083). * CVE-2026-68312: cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths (bsc#1274663). * CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit (bsc#1274665). * CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq() (bsc#1274662). * CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (bsc#1274659). * CVE-2026-68322: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (bsc#1274656). * CVE-2026-68324: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (bsc#1274649). * CVE-2026-68325: iommu/amd: Bound the early ACPI HID map (bsc#1274651). * CVE-2026-68328: nfp: Check resource mutex allocation (bsc#1274646). * CVE-2026-68329: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (bsc#1274645). * CVE-2026-68331: dpaa2-eth: put MAC endpoint device on disconnect (bsc#1274642). * CVE-2026-68333: dpaa2-switch: put MAC endpoint device on disconnect (bsc#1274644). * CVE-2026-68335: rds: drop incoming messages that cross network namespace boundaries (bsc#1274640). * CVE-2026-68336: bonding: fix devconf_all NULL dereference when IPv6 is disabled (bsc#1274639). * CVE-2026-68343: smb: client: validate DFS referral PathConsumed (bsc#1274629). * CVE-2026-68377: net/sched: act_tunnel_key: Defer dst_release to RCU callback (bsc#1274831). * CVE-2026-68386: bpf, sockmap: Reject unhashed UDP sockets on sockmap update (bsc#1274814). * CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). * CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). * CVE-2026-68408: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (bsc#1274709). * CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). * CVE-2026-68418: RDMA/irdma: Prevent user-triggered null deref on QP create (bsc#1274690). * CVE-2026-68419: RDMA/irdma: Prevent rereg_mr for non-mem regions (bsc#1274698). * CVE-2026-68422: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (bsc#1274706). * CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1274700). * CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). * CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink (bsc#1274800). * CVE-2026-68433: libceph: bound get_version reply decode to front len (bsc#1274801). * CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert (bsc#1274834). * CVE-2026-68470: wifi: cfg80211/mac80211: correctly parse S1G beacon optional elements (bsc#1276500). * CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). * CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). * CVE-2026-72035: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1276961). * CVE-2026-72036: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1277034). * CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). * CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155). * CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). * CVE-2026-72084: scsi: target: Bound PR-OUT TransportID parsing to the received buffer (bsc#1275540). * CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523). * CVE-2026-72132: NFS: Charge unstable writes by request size, not folio size (bsc#1277551). * CVE-2026-72221: sunrpc: wait for in-flight TLS handshake callback when cancel loses race (bsc#1275665). * CVE-2026-72222: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback (bsc#1275669). * CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). * CVE-2026-72254: netfilter: nft_fib: reject fib expression on the netdev egress hook (bsc#1277204). * CVE-2026-72262: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (bsc#1277678). * CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). * CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). * CVE-2026-72296: net: ife: require ETH_HLEN to be pullable in ife_decode() (bsc#1275923). * CVE-2026-72307: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (bsc#1277160). * CVE-2026-72308: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (bsc#1277159). * CVE-2026-72317: SUNRPC: pin upper rpc_clnt across the TLS connect_worker (bsc#1275925). * CVE-2026-72341: net/mlx5e: Fix publication race for priv->channel_stats[] (bsc#1277660). * CVE-2026-72342: net/mlx5e: Fix HV VHCA stats agent registration race (bsc#1277775). * CVE-2026-72343: net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation (bsc#1277776). * CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). * CVE-2026-72463: xfrm: Fix dev use-after-free in xfrm async resumption (bsc#1268276 bsc#1277064). * CVE-2026-72464: xprtrdma: Remove temp allocation of rpcrdma_rep objects (bsc#1277069). * CVE-2026-72466: xprtrdma: Fix bcall rep leak and unbounded peek (bsc#1277057). * CVE-2026-72467: xprtrdma: Check frwr_wp_create() during connect (bsc#1277059). * CVE-2026-72469: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE (bsc#1277047). * CVE-2026-72473: xprtrdma: Avoid 250 ms delay on backlog wakeup (bsc#1277037). * CVE-2026-72494: RDMA/irdma: Replace waitqueue and flag with completion (bsc#1276941). * CVE-2026-72495: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages (bsc#1276937). * CVE-2026-72496: RDMA/bnxt_re: Proper rollback if the ioremap fails (bsc#1276943). * CVE-2026-72499: RDMA/bnxt_re: Free CQ toggle page after firmware teardown (bsc#1276551). * CVE-2026-72501: RDMA/bnxt_re: Initialize dpi variable to zero (bsc#1276546). * CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (bsc#1276542). * CVE-2026-74269: bnxt: fix head underflow on XDP head-grow (bsc#1276507). * CVE-2026-74296: RDMA/mlx5: Release the HW-provided UAR index rather than the SW one (bsc#1276452). * CVE-2026-74297: RDMA/mlx5: Fix undefined shift of user RQ WQE size (bsc#1276446). * CVE-2026-74318: btrfs: fix deadlock cloning inline extent when using flushoncommit (bsc#1276864). * CVE-2026-74321: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (bsc#1277202). * CVE-2026-74334: RDMA/nldev: Fix locking when accessing mr->pd (bsc#1277095). * CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). * CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). * CVE-2026-74395: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (bsc#1277077). * CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073). * CVE-2026-74474: vxlan: use pskb_network_may_pull() for transmit path header pulls (bsc#1276335). * CVE-2026-74481: mm/page_reporting: use system_freezable_wq to fix UAF during suspend (bsc#1276355). * CVE-2026-74482: mm/huge_memory: unlock i_mmap_rwsem before releasing after- split folios (bsc#1276346). * CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350). * CVE-2026-74495: igbvf: Fix leak in TX DMA error cleanup (bsc#1275864). * CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). * CVE-2026-74509: Bluetooth: hci_sync: Fix advertising data UAFs (bsc#1275946). * CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation (bsc#1275950). * CVE-2026-74512: audit: fix potential use-after-free in audit_del_rule() (bsc#1275954). * CVE-2026-74516: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (bsc#1275797). * CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). * CVE-2026-74527: octeontx2-af: Block VFs from clobbering special CGX PKIND state (bsc#1275805). * CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). * CVE-2026-74548: forcedeth: fix UAF of txrx_stats in nv_remove (bsc#1275695). * CVE-2026-74550: net: do not send ICMP/NDISC Redirects when peer allocation fails (bsc#1275688). * CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). * CVE-2026-74563: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() (bsc#1275574). * CVE-2026-74566: keys: make keyring key-chunk byte order agree with keyring_diff_objects() (bsc#1275566). * CVE-2026-74567: keys: fix out-of-bounds read in keyring_get_key_chunk() (bsc#1275569). * CVE-2026-74571: btrfs: skip global block reserve accounting for rescue mounts (bsc#1275561). * CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782). * CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). * CVE-2026-74584: RDMA/bnxt_re: zero shared page before exposing to userspace (bsc#1277066). * CVE-2026-74610: tls: don't leave a full plaintext sk_msg ring unpushed (bsc#1277054). * CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). * CVE-2026-74692: net/smc: fix TOCTOU race between smc_listen_out() and listener close (bsc#1276927). * CVE-2026-74694: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (bsc#1277625). * CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). * CVE-2026-74717: net/mlx5: fw_tracer, return NULL on create error (bsc#1276569). * CVE-2026-74722: btrfs: fix memory leak in btrfs_do_encoded_write() (bsc#1276561). * CVE-2026-80529: xfs: don't swallow dquot recovery verification errors (bsc#1277688). * CVE-2026-80534: xfs: fix ilock leak on error in xfs_dq_get_next_id (bsc#1277022). * CVE-2026-80590: inet: frags: strip GSO state from fragments before reassembly (bsc#1277275). * CVE-2026-80654: soc: xilinx: Shutdown and free rx mailbox channel (bsc#1277516). The following non security issues were fixed: * accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() (git-fixes). * accessibility: speakup: unregister tty ldisc on later init failures (git- fixes). * ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer (git-fixes). * ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root (git- fixes). * ACPI: pfr_update: fix stack buffer overflow in query_capability() (git- fixes). * ACPI: processor: idle: Expand _LPI package sanity checks (git-fixes). * ACPI: processor: validate MADT IOAPIC entry bounds (git-fixes). * ACPI: scan: fix bus ID cleanup on device_add() failures (git-fixes). * ACPI: video: Release PCI device reference after lookup (git-fixes). * add my missing Reviewed-by: tag. * ALSA: 6fire: bound the MIDI event length from the device (git-fixes). * ALSA: 6fire: Fix UAF at error handling during probe (stable-fixes). * ALSA: bcd2000: clear the URB pointers on disconnect (git-fixes). * ALSA: core: Fix use-after-free in snd_card_do_free() (git-fixes). * ALSA: dummy: Check card index validity at probe (stable-fixes). * ALSA: hda/ext: preserve PPLCCTL bits when clearing reset (git-fixes). * ALSA: hda: Fix connection list comparison in proc output (git-fixes). * ALSA: hpi: Check transport errors during HPI6000 adapter initialization (git-fixes). * ALSA: pcxhr: initialize mutexes before requesting threaded IRQ (git-fixes). * ALSA: seq: midi: Optimize event_input locking with RCU (git-fixes). * ALSA: seq: midi: Serialize input teardown with event_input (git-fixes). * ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion (git-fixes). * ALSA: usb-audio: Complete cleanup after system-resume errors (git-fixes). * ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (git-fixes). * ALSA: usb-audio: fix OOB write on Type II inbound URBs (git-fixes). * ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (git-fixes). * ALSA: usx2y: bound the hwdep mmap fault offset (git-fixes). * ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() (git- fixes). * apparmor: advertise the tcp fast open fix is applied (git-fixes). * ASoC: adau1761: sort the register default table (git-fixes). * ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC (git-fixes). * ASoC: apple: mca: increase SERDES reset delay (git-fixes). * ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (git-fixes). * ASoC: cs35l33: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l34: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l41: sort the register default table (git-fixes). * ASoC: cs35l45: sort the register default table (git-fixes). * ASoC: cs4265: sort the register default table (git-fixes). * ASoC: cx2072x: sort the register default table (git-fixes). * ASoC: dapm: Fix off-by-one check on the second enum channel (git-fixes). * ASoC: fix unmet dependencies on PPC_BESTCOMM and SND_SOC_AC97_BUS (git- fixes). * ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready (git- fixes). * ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure (git-fixes). * ASoC: fsl_audmix: rework runtime PM handling in probe (git-fixes). * ASoC: fsl_easrc: sort the register default table (git-fixes). * AsoC: intel: sst: fix PCI device reference leak on probe failure (git- fixes). * ASoC: max9860: sort the register default table (git-fixes). * ASoC: meson: Keep link pointers valid on realloc failure (git-fixes). * ASoC: ml26124: sort the register default table (git-fixes). * ASoC: pcm512x: sort the register default table (git-fixes). * ASoC: pxa: Use devm_clk_get_optional() for extclk clock (git-fixes). * ASoC: qcom: q6apm: keep the graph start count in sync with the DSP (git- fixes). * ASoC: rt274: sort the register default table (git-fixes). * ASoC: rt286: sort the register default table (git-fixes). * ASoC: rt298: sort the register default table (git-fixes). * ASoC: rt700-sdw: always drain jack work on remove (git-fixes). * ASoC: rt700: drop duplicate reg_default entry (git-fixes). * ASoC: rt700: sort the register default table (git-fixes). * ASoC: rt711-sdca: sort the register default tables (git-fixes). * ASoC: rt711: sort the register default table (git-fixes). * ASoC: rt712-sdca-dmic: sort the register default table (git-fixes). * ASoC: rt715-sdca: drop duplicate reg_default entries (git-fixes). * ASoC: rt715-sdca: sort the register default tables (git-fixes). * ASoC: rt715: sort the register default table (git-fixes). * ASoC: rt1316-sdw: sort the register default table (git-fixes). * ASoC: rt1318-sdw: sort the register default table (git-fixes). * ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get (git-fixes). * ASoC: sgtl5000: sort the register default table (git-fixes). * ASoC: SOF: pcm: Move period/buffer configuration print after platform open (stable-fixes). * ASoC: sof: pcm: use snd_pcm_direction_name() (stable-fixes). * ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() (git- fixes). * ASoC: SOF: validate topology volume range before allocation (git-fixes). * ASoC: sti-sas: sort the register default table (git-fixes). * ASoC: tas2552: sort the register default table (git-fixes). * ASoC: tas2764: sort the register default table (git-fixes). * ASoC: tas2780: sort the register default table (git-fixes). * ASoC: tegra210_i2s: sort the register default table (git-fixes). * ASoC: tegra210_mixer: sort the register default table (git-fixes). * ASoC: tegra: Fix the MIXER enable default value (git-fixes). * ASoC: tegra: Sort MBDRC register defaults (git-fixes). * ASoC: xilinx: formatter_pcm: fix stream_data leak on open error (git-fixes). * ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (git-fixes). * batman-adv: bla: fix freeing of claims on meshif deletion (git-fixes). * batman-adv: bla: prevent CRC corruptions after claim flush (git-fixes). * batman-adv: dat: avoid unaligned fault in IP extraction (git-fixes). * batman-adv: fix stale receive device on merged fragments (git-fixes). * Bluetooth: btintel: Fix diagnostics event detection (git-fixes). * Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path (git-fixes). * Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX (git- fixes). * Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event (git- fixes). * Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() (git- fixes). * Bluetooth: do not leak an hci_conn when a second LE connect is rejected (git-fixes). * Bluetooth: eir: Fix OOB read in eir_get_service_data() (git-fixes). * Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (git-fixes). * Bluetooth: hci_conn: re-enable advertising only for peripheral role (git- fixes). * Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection (git- fixes). * Bluetooth: hci_event: fix LE list UAF on reset (git-fixes). * Bluetooth: hci_event: validate LE Set CIG Parameters response (git-fixes). * Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths (git-fixes). * Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (stable-fixes). * Bluetooth: hci_uart: Fix false success return in hci_uart_setup() (git- fixes). * Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready (git-fixes). * Bluetooth: MGMT: free the mesh send cancel command when it is cancelled (git-fixes). * Bluetooth: MSFT: validate evt_prefix_len against the response length (git- fixes). * Bluetooth: RFCOMM: serialize security confirmation handling (git-fixes). * Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (git- fixes). * Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop (git-fixes). * Bluetooth: virtio_bt: avoid OOB read of build info string (git-fixes). * bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation (git-fixes). * bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET (git-fixes). * bus: ti-sysc: Fix /chosen node reference leak (git-fixes). * cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64) (git-fixes). * can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (stable-fixes). * crypto: aspeed - Propagate platform_get_irq() errors (git-fixes). * crypto: atmel-sha204a - fix heap info leak on I2C transfer failure (git- fixes). * crypto: atmel-tdes - use scatterlist length before DMA mapping (git-fixes). * crypto: ccm - Set rfc4309 maxauthsize from child (git-fixes). * crypto: ccp - Fix memory leak in SEV INIT_EX path (git-fixes). * crypto: ccp - Fix possible deadlock in SEV init failure path (git-fixes). * crypto: doc - Remove extra parenthesis (git-fixes). * crypto: hisilicon/sec2 - fix CCM algorithm long packet failure (git-fixes). * crypto: keembay - Initialize completion before requesting IRQ (git-fixes). * crypto: keembay - publish OF module alias for OCS AES/SM4 (git-fixes). * crypto: mxs-dcp - fix source scatterlist length access (git-fixes). * crypto: qat - cancel work on re-enable SR-IOV timeout (git-fixes). * crypto: qat - clear AES key schedule from stack (git-fixes). * crypto: qce - fix CCM AAD buffer underallocation (git-fixes). * crypto: qce - fix error path in devm_qce_register_algs (git-fixes). * crypto: rk3288 - fail ahash requests on HASH idle timeout (git-fixes). * crypto: sa2ul - stop probe if context pool creation fails (git-fixes). * crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping (git- fixes). * device property: fix infinite loop in fwnode_for_each_child_node() (git- fixes). * dmaengine: dw-edma: Clear stale requests on termination (git-fixes). * dmaengine: dw-edma: Complete descriptors before pausing (git-fixes). * dmaengine: dw-edma: Initialize IRQ data before requesting IRQs (git-fixes). * dmaengine: dw-edma: Serialize abort state updates (git-fixes). * dmaengine: dw-edma: Serialize channel state checks (git-fixes). * dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe (git-fixes). * dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure (git-fixes). * dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal (git-fixes). * dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers (git-fixes). * dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout (git-fixes). * driver core: soc: Unregister bus on early device registration failure (git- fixes). * drm/amd/display: avoid divide-by-zero in __is_lut_linear() (git-fixes). * drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read (git- fixes). * drm/amdgpu/gfx6: Fixup emit_cntxcntl() (git-fixes). * drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets (git-fixes). * drm/amdgpu/gfx6: Use PFP on the compute queues too (git-fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup (git- fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup (git- fixes). * drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check (git- fixes). * drm/amdgpu: cap GTT size to physical RAM on APUs (stable-fixes). * drm/amdgpu: check ASPM on the dGPU host link (git-fixes). * drm/amdgpu: disallow multiple FENCE chunks in one submit (git-fixes). * drm/amdgpu: fix aperture iounmap skipped on device removal (git-fixes). * drm/amdgpu: fix autosuspend cleanup during removal (git-fixes). * drm/amdgpu: Fix UVD decode image min size calculation (stable-fixes). * drm/amdgpu: Fix UVD dpb min size calculation for H264 (stable-fixes). * drm/amdgpu: Fix UVD min buffer sizes (stable-fixes). * drm/amdgpu: Fix VCE 3 ring align_mask (git-fixes). * drm/amdgpu: Implement insert_end for VCE 3 (git-fixes). * drm/amdgpu: Reject UVD message with dimensions above 4096 (stable-fixes). * drm/amdgpu: Reject UVD message with invalid number of h265 refs (stable- fixes). * drm/amdgpu: restore UMD profile pstate after runtime resume (stable-fixes). * drm/amdgpu: validate GEM_CREATE domain combinations (stable-fixes). * drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (stable-fixes). * drm/amdkfd: fix QID bit leak in pqm_create_queue() (stable-fixes). * drm/amdkfd: Handle invalid event type in CRIU event restore (stable-fixes). * drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure (git-fixes). * drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure (git-fixes). * drm/bridge: ps8640: propagate AUX transfer register errors (git-fixes). * drm/bridge: tc358767: clamp the reported AUX read size to the request (git- fixes). * drm/connector: Fix epoch_counter docs to reflect reality (git-fixes). * drm/hibmc: Fix list of formats on the primary plane (git-fixes). * drm/hibmc: Use drm_atomic_helper_check_plane_state() (git-fixes). * drm/i915/fbc: Extract intel_fbc_has_fences() (stable-fixes). * drm/lima: call drm_mm_init() with a valid allocation range (git-fixes). * drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: Drop dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value (git- fixes). * drm/panel-edp: fix i2c adapter leak on probe failure (git-fixes). * drm/panel: samsung-s6d16d0: Power off on prepare failure (git-fixes). * drm/radeon: fix autosuspend cleanup during teardown (git-fixes). * drm/radeon: restore hardware polling in fence_is_signaled to fix performance regression (git-fixes). * drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format (git-fixes). * drm/ssd130x: fix column and row end address in partial updates for ssd132x (git-fixes). * drm/sun4i: crtc: Propagate layer initialization error (git-fixes). * drm/sun4i: Drop node references while building component list (git-fixes). * drm/sun4i: dw-hdmi: Drop TCON TOP port reference (git-fixes). * drm/sun4i: fix refcount leak in sun4i_backend_init_sat() (git-fixes). * drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz (git-fixes). * drm/sun4i: tcon: Drop remote endpoint reference (git-fixes). * drm/sun4i: tcon: Drop TCON TOP device reference (git-fixes). * drm/sun4i: tcon: Set output mux for DSI and LVDS (git-fixes). * drm/sun4i: vi scaler: Fix coefficient selection (git-fixes). * drm/tegra: dsi: Re-add clear enable register if DSI was powered by bootloader (git-fixes). * drm/tve200: add OF module alias for autoloading (git-fixes). * drm: fix race between partial drm_dev_register() failure and ioctl (git- fixes). * drm: lcdif: Wait for vblank before disabling DMA (git-fixes). * drm: Remove unused header in drm_dumb_buffers.c (git-fixes). * ethtool: rss: fix hkey leak when indir_size is 0 (git-fixes). * fbdev: bitblit: bound-check glyph index in bit_cursor() (git-fixes). * fbdev: core: Fix pointer desynchronization in fb_io_read() (git-fixes). * fbdev: kyro: Validate overlay viewport coordinates (git-fixes). * fbdev: omapfb: panel-dsi-cm: initialize lock before registering display (git-fixes). * fbdev: ssd1307fb: defer I2C transfers from damage callbacks (git-fixes). * fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() (git-fixes). * fbdev: uvesafb: unregister connector callback on init failure (git-fixes). * firmware: arm_scmi: Avoid IDR updates while cleaning channels (git-fixes). * firmware: arm_scmi: Drop handle on protocol bind failures (git-fixes). * firmware: arm_scmi: Fix requested device removal race (git-fixes). * firmware: arm_scmi: Free transport channel on IDR failure (git-fixes). * firmware: arm_scmi: Protect device request lookup with RCU (git-fixes). * firmware: arm_scmi: Reject out of range DT protocol IDs (git-fixes). * firmware: arm_scmi: Unregister device notifier before IDR teardown (git- fixes). * firmware: arm_scmi: Use channel ID for transport teardown (git-fixes). * firmware_loader: do not queue completed sysfs fallback requests (git-fixes). * fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write (git- fixes). * fpga: dfl: fme: add error handling (git-fixes). * fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration (git- fixes). * gpu: host1x: Avoid stack over-read in debug output helpers (git-fixes). * gpu: host1x: Fix offset calculation in trace_write_gather (git-fixes). * HID: core: fix number/pointer type confusion on long items (git-fixes). * HID: core: fix OOB read of field->usage in hid_set_field() (git-fixes). * HID: hyperv: validate initial device info bounds (git-fixes). * HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure (git-fixes). * HID: lg4ff: validate report length before fixed offsets (git-fixes). * HID: logitech-dj: Fix maxfield check in DJ short report validation (git- fixes). * HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (git- fixes). * HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (stable-fixes). * HID: logitech-dj: Standardise hid_report_enum variable nomenclature (stable- fixes). * HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID (stable-fixes). * HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (git- fixes). * HID: mcp2221: validate report size in mcp2221_raw_event() (git-fixes). * HID: nintendo: Fix imu_timestamp_us double increment per report (git-fixes). * HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() (git- fixes). * HID: picolcd: clamp eeprom debugfs read to bytes actually received (git- fixes). * HID: roccat: bound device-supplied profile index (git-fixes). * HID: roccat: free buffered reports when destroying device (git-fixes). * HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature (git- fixes). * HID: sensor: custom: Fix field sysfs group cleanup on failure (git-fixes). * HID: sensor: custom: Fix use-after-free in enable_sensor (git-fixes). * HID: tmff: Use 64-bit arithmetic for force feedback scaling (git-fixes). * hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (git-fixes). * hwmon: (lm25066) Use i2c_get_match_data() (stable-fixes). * hwmon: (max6621) fix negative temperature offset and crit readings (git- fixes). * hwmon: (max6621) fix temperature clamp range (git-fixes). * hwmon: (nzxt-smart2) Check return value of init_device() in probe (git- fixes). * hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (git-fixes). * hwrng: ks-sa - Fix runtime PM cleanup on registration failure (git-fixes). * hwrng: omap - Fix probe error path cleanup (git-fixes). * hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() (git- fixes). * i2c: bcm-iproc: remove printout on handled timeouts (stable-fixes). * i2c: iproc: reset bus after timeout if START_BUSY is stuck (git-fixes). * i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure (git-fixes). * i2c: mux: Fix channel node leak on adapter add failure (git-fixes). * i2c: ocores: Disable clock on failed resume (git-fixes). * i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices (git-fixes). * i3c: master: Fix device_register() error path (git-fixes). * i3c: master: Fix info leak and UAF in device unregister path (git-fixes). * i3c: master: svc: bound IBI payload to the requested max_payload_len (git- fixes). * ibmvnic: Only record tx completed bytes once per handler (bsc#1274620). * iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE (git-fixes). * iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable (git-fixes). * iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF (git-fixes). * iio: chemical: sgp30: Handle IAQ thread creation failure (git-fixes). * iio: dac: m62332: Fix regulator reference count imbalance (git-fixes). * iio: gyro: mpu3050: fix sign of raw angular velocity readings (git-fixes). * iio: light: cm32181: return zero after writing calibscale (git-fixes). * iio: light: gp2ap002: Disable regulators on resume failure (git-fixes). * iio: light: gp2ap002: re-enable irq if runtime suspend fails (git-fixes). * iio: light: isl29028: return zero in write_raw() on success (git-fixes). * iio: light: tsl2583: return zero in write_raw() on success (git-fixes). * iio: light: tsl2772: fix ALS calibscale readback (git-fixes). * iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure (git-fixes). * iio: pressure: dps310: fix NULL pointer dereference on ACPI probe (git- fixes). * iio: pressure: mpl115: Fix runtime PM cleanup (git-fixes). * iio: srf04: fix pm_runtime handling on probe error path (git-fixes). * iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() (git-fixes). * Input: atkbd - skip deactivate for HONOR ZQC-P (git-fixes). * Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (stable-fixes). * Input: evdev - fix information leak in evdev_pass_values() (stable-fixes). * Input: evdev - sanitize event type index when fetching event masks (stable- fixes). * Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (git-fixes). * Input: focaltech - use signed coordinates to prevent underflow (git-fixes). * Input: hynitron_cstxxx - validate touch count and finger IDs (git-fixes). * Input: iforce - validate input packet lengths (stable-fixes). * Input: iqs5xx - validate firmware record destination span (git-fixes). * Input: mms114 - fix Y-resolution configuration (git-fixes). * Input: psxpad-spi - set driver data before use (git-fixes). * Input: sur40 - fix input device registration ordering (stable-fixes). * Input: sur40 - fix V4L error path cleanup (stable-fixes). * Input: synaptics-rmi4 - block s_input when F54 queue is busy (git-fixes). * Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (git-fixes). * Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (git- fixes). * Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (git- fixes). * Input: synaptics-rmi4 - zero report size on F54 work error (git-fixes). * Input: xpad - add support for ZENAIM LEVERLESS (stable-fixes). * interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (git-fixes). * ipmi: ipmb: validate write message length (git-fixes). * ipmi: si: Fix NULL pointer dereference after failed registration (git- fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (git-fixes). * leds: pca9532: Fix inverted GPIO output polarity (git-fixes). * leds: pca9532: Fix phantom device registration on missing hardware (git- fixes). * lib/string: fix memchr_inv() for large ranges (git-fixes). * lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() (git-fixes). * mailbox: qcom-ipcc: fix duplicate channel allocation across holes (git- fixes). * mailbox: rockchip: disable pclk on probe failure and unbind (git-fixes). * maple_tree: fix argument name in header (git-fixes). * md/raid1: create serial pool adding rdev to array with serialize_policy=1 (bsc#1272261). * media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref (git-fixes). * media: cec-pin: Fix event FIFO ordering (git-fixes). * media: cec: disable delayed work before freeing an interrupted transmit (git-fixes). * media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash (git-fixes). * media: cec: Serialize exclusive follower delivery (git-fixes). * media: cec: stm32: prevent out-of-bounds write on RX overflow (git-fixes). * media: cedrus: fix memory leak in cedrus_init_ctrls() (git-fixes). * media: cobalt: Avoid freeing ALSA private data twice (git-fixes). * media: cx231xx: reject geometry changes while the VBI queue is busy (git- fixes). * media: cx23885: cancel NetUP CI work before teardown (git-fixes). * media: em28xx: defer audio-only extension registration (git-fixes). * media: em28xx: fix use-after-free of dev_next->devlist on disconnect (git- fixes). * media: go7007: defer the ALSA v4l2 put until card release (git-fixes). * media: i2c: ov02a10: fix endpoint parsing use-after-free (git-fixes). * media: i2c: ov7740: fix use-after-destroy in remove (git-fixes). * media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define (git- fixes). * media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define (git-fixes). * media: mc-entity: Add missing kerneldoc (git-fixes). * media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common (git- fixes). * media: nxp: imx8-isi: Correct color map between V4L2 and ISI (git-fixes). * media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing (git-fixes). * media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks (git-fixes). * media: rc: sunxi-cir: Unregister rc device on probe failure (git-fixes). * media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure (git-fixes). * media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak (git-fixes). * media: s2255: bound JPEG frame size before copying into the buffer (git- fixes). * media: s2255: check firmware size before reading trailing marker (git- fixes). * media: saa7164: fix cleanup on resource allocation failure (git-fixes). * media: tda18250: fix possible integer overflow (git-fixes). * media: usbtv: keep device alive while ALSA card exists (git-fixes). * media: v4l2-ctrls: Allow unknown HDR10 white point and luminance (git- fixes). * media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link (git-fixes). * media: venus: fix payload size calculation in parse_raw_formats() (git- fixes). * media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() (git-fixes). * media: vicodec: fix out-of-bounds write in FWHT encoder (git-fixes). * media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure (git-fixes). * media: vimc: fix pixel format lookup in enum_framesizes (git-fixes). * media: zoran: Avoid freeing a registered video_device twice (git-fixes). * mei: pull kvfree out of spinlock (git-fixes). * mfd: iqs62x: Reject zero-length firmware records (git-fixes). * mfd: rave-sp: validate received frame payload lengths (git-fixes). * misc: bcm-vk: Use acquire/release for msgq_inited (git-fixes). * misc: fastrpc: fix channel ctx ref leak when session alloc fails (git- fixes). * misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (git-fixes). * misc: fastrpc: Remove buffer from list prior to unmap operation (git-fixes). * misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke (git- fixes). * misc: rtsx: add missing write register handling (git-fixes). * misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() (git- fixes). * mkspec-dtb: Move DTS prefix into package list. * mkspec-dtb: Move provides-obsoletes to package list. * mkspec-dtb: Put per-architecture package lists into a hash. * mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (git- fixes). * mmc: sdhci: unmap the bounce buffer before device release (git-fixes). * mmc: via-sdmmc: stop card-detect handling on probe failure (git-fixes). * mtd: afs: validate v2 image info bounds (git-fixes). * mtd: mtdoops: free page bitmap when the backing MTD is removed (git-fixes). * mtd: mtdswap: Avoid freeing registered blktrans device twice (git-fixes). * mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() (git-fixes). * mtd: rawnand: validate ONFI extended parameter page sections (git-fixes). * net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes). * net: mana: Add handler for sriov configure (bsc#1272756). * net: mana: Cap MSI-X vectors to the device MSI-X table size (git-fixes). * net: mana: Extend RX CQE coalescing up to 8 packets (git-fixes). * net: mana: Fall back to scattered pages for GDMA queues (git-fixes). * net: mana: force full-page RX buffers via ethtool private flag (bsc#1269792). * net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792). * net: mana: Route ring-buffer access through offset-based helpers (git- fixes). * net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). * net: thunderbolt: Count delivered packets in rx_packets and rx_bytes (git- fixes). * net: thunderbolt: Mark the connection down when bringing it up fails (git- fixes). * net: thunderbolt: Release the Rx HopID that was handed out on mismatch (git- fixes). * net: thunderbolt: Tear down DMA paths before stopping the rings (git-fixes). * net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (git-fixes). * net: usb: ipheth: fix carrier_work UAF on disconnect (git-fixes). * nfc: digital: clamp SENSF_RES length to the destination buffer (git-fixes). * nfc: digital: Do not dump a NULL response in command completion (git-fixes). * nfc: fdp: bound the device-reported read length and fix an skb leak (git- fixes). * nfc: llcp: avoid userspace overflow on invalid optlen (git-fixes). * nfc: llcp: bound SNL TLV parsing to the skb and add length checks (git- fixes). * nfc: llcp: bound the connect_sn TLV walk to the skb (git-fixes). * nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (git-fixes). * nfc: llcp: read llcp_sock->local under the socket lock in getsockopt (git- fixes). * nfc: llcp: reject PDUs shorter than the LLCP header (git-fixes). * nfc: microread: validate target discovery payload lengths (git-fixes). * nfc: nci: fix double completion race in nci_data_exchange_complete (git- fixes). * nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (git- fixes). * nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (git- fixes). * nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing (git- fixes). * nfc: nci: free destination parameters when closing a connection (git-fixes). * nfc: pn533: hold a reference to the request skb during send_frame (git- fixes). * nfc: pn533: purge fragmented skbs during cleanup (git-fixes). * nfc: st21nfca: validate ATR_REQ length against the received frame (git- fixes). * nouveau/gem: reserve the bo in the info ioctl around the vma lookup (git- fixes). * PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] (git-fixes). * PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk (git- fixes). * PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git- fixes). * PCI: j721e: Fix incorrect max_lanes for J7200 (git-fixes). * PCI: meson: Fix GPIO state while requesting PERST# (git-fixes). * phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs (git- fixes). * phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend (git-fixes). * phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table (git- fixes). * phy: sunplus: fix error handling in sp_uphy_init() (git-fixes). * pinctrl: bcm2835: Don't remove an unregistered GPIO chip (git-fixes). * pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip (git-fixes). * pinctrl: rockchip: Reset the pin count when recalculating SoC data (git- fixes). * platform/chrome: cros_ec_debugfs: Clean up console log on probe failure (git-fixes). * platform/chrome: cros_ec_debugfs: Unregister panic notifier (git-fixes). * platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count (git- fixes). * platform/chrome: sensorhub: Bound the EC-reported sensor number (git-fixes). * platform/chrome: sensorhub: Fix dropped timestamp events and log spam (git- fixes). * platform/chrome: sensorhub: Fix memory overread in ring handler (git-fixes). * platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL (git- fixes). * platform/surface: acpi-notify: Check ACPI companion before use (git-fixes). * platform/x86: dell-privacy: Fix race condition (git-fixes). * platform/x86: dell-wmi-base: Fix resource leak on module load failure (git- fixes). * platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (git-fixes). * platform/x86: dell-wmi-sysman: Fix instance ID bounds (git-fixes). * platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path (git-fixes). * platform/x86: ISST: Just allow 2 bits for SST feature enable (git-fixes). * platform/x86: ISST: Validate level in perf mask ioctls (git-fixes). * platform/x86: ISST: Validate logical CPU id and clos id (git-fixes). * platform/x86: ISST: Validate socket ID in clos_assoc ioctl (git-fixes). * PM: sleep: Fix off-by-one in wakelocks number limit check (git-fixes). * power: supply: bd99954: Drop bad register fields (git-fixes). * power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq27520g4: fix REG_TTES address (git-fixes). * power: supply: bq256xx: drain usb_work before freeing the charger (git- fixes). * power: supply: bq24257: fix use-after-free on remove (git-fixes). * power: supply: bq25890: Fix power_supply reference leak (git-fixes). * power: supply: cros_usbpd-charger: bound the EC-reported port count (git- fixes). * power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS (git- fixes). * power: supply: isp1704_charger: cancel work on remove (git-fixes). * power: supply: lp8727: fix use-after-free in lp8727_release_irq() (git- fixes). * power: supply: max17040: drop incorrect I2C functionality check (git-fixes). * power: supply: max17040: synchronize work cancellation on suspend (git- fixes). * power: supply: qcom_battmgr: terminate the strings from firmware (git- fixes). * power: supply: rt9455: quiesce delayed work before teardown (git-fixes). * power: supply: sbs-battery: Use a per-device serial number buffer (git- fixes). * power: supply: twl4030_charger: cancel workers via devm (git-fixes). * power: supply: ucs1002: fix use-after-free on remove (git-fixes). * powercap: intel_rapl_tpmi: Handle PMU registration failure during probe (git-fixes). * powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash (bsc#1271256). * powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). * powerpc/pseries: pci - logic bug (bsc#1274749 ltc#221282 bsc#1274755 ltc#221284 bsc#1274756 ltc#221283). * ppdev: prevent overflow when setting port timeout (git-fixes). * qede: fix out-of-bounds check for cqe->len_list (git-fixes). * rapidio: clear mport->net when rio_add_net() fails (git-fixes). * rapidio: mport_cdev: fix use-after-free in dma_req_free() (git-fixes). * RDMA/irdma: Remove redundant legacy_mode checks (git-fixes). * RDMA/mana_ib: drain QP references after partial table insertion (git-fixes). * RDMA/mana_ib: unify QP lookup table (git-fixes). * RDMA/mlx5: Fix integer overflow of user QP buffer size (git-fixes). * regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (git-fixes). * regulator: core: use system_freezable_wq for init complete work (git-fixes). * regulator: devres: add API for reference voltage supplies (stable-fixes). * regulator: devres: fix devm_regulator_get_enable_read_voltage() return (git- fixes). * regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata (git-fixes). * regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling (git-fixes). * remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev (git-fixes). * remoteproc: qcom_q6v5_adsp: Fix reference leak for device node (git-fixes). * remoteproc: scp: Fix device reference leak on failed lookup (git-fixes). * Revert "drm/amdgpu: fix aperture mapping leak" (git-fixes). * Revert "media: v4l2-dev: fix error handling in __video_register_device()" (git-fixes). * Revert "thermal/drivers/hwmon: Cleanup coding style a bit" (stable-fixes). * rpmsg: core: Fix incorrect return value documentation (git-fixes). * rpmsg: glink: smem: order FIFO read after availability check (git-fixes). * rtc: gamecube: check return value of devm_rtc_register_device() (git-fixes). * rtc: pcf8563: fix clock provider leak on unbind (git-fixes). * rtc: pcf85363: Add error checking to regmap calls in probe() (git-fixes). * rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers (git-fixes). * rtc: rzn1: Fix weekday underflow when alarm crosses month boundary (git- fixes). * rtc: zynqmp: Return optional clock lookup errors (git-fixes). * scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes). * sctp: avoid auth_enable sysctl UAF during netns teardown (git-fixes). * serial: 8250_dma: Clear stale RX state on shutdown (git-fixes). * serial: amba-pl011: unprepare console clock on unregister (git-fixes). * serial: core: clear freed pointers on uart_register_driver() failure (git- fixes). * serial: qcom-geni: fix TX DMA buffer flush (git-fixes). * serial: sc16is7xx: fix copy-paste errors in EFR_SWFLOWx_BIT constants (stable-fixes). * smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). * smb: client: reject overlapping data areas in SMB2 responses (git-fixes). * smb: client: require net admin for CIFS SWN netlink (bsc#1273966). * smb: client: resolve SWN tcon from live registrations (bsc#1273872). * soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() (git- fixes). * soc: qcom: rpmh-rsc: manage PM notifiers with devres (git-fixes). * soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() (git-fixes). * software node: Fix software_node_get_reference_args() with index -1 (git- fixes). * soundwire: qcom: Fix port exhaustion check in stream_alloc_ports (git- fixes). * speakup: keyhelp: guard letter_offsets possible out-of-range indexing (git- fixes). * spi: img-spfi: don't disable runtime PM on DMA deferred probe (git-fixes). * spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (stable-fixes). * spi: sprd-adi: Fix probe succeeding without registering the controller (git- fixes). * staging: fbtft: Use sysfs_emit_at() to print to sysfs file (git-fixes). * staging: media: tegra-video: vi: fix probe failure on skipped last port (git-fixes). * staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown (git- fixes). * staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() (git-fixes). * staging: rtl8723bs: fix missing shared-key auth challenge length check (git- fixes). * staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (git-fixes). * staging: rtl8723bs: fix OOB read in WMM_param_handler() (git-fixes). * staging: rtl8723bs: use kfree_sensitive() for key material (git-fixes). * staging: rtl8723bs: validate monitor transmit frame lengths (git-fixes). * staging: sm750fb: gate dualview dataflow using g_dualview (git-fixes). * thermal/drivers/imx: Disable clock on runtime resume failure (git-fixes). * thermal/drivers/qoriq: Disable clock on resume failure (git-fixes). * thermal: intel: int3400: clean up ODVP on probe failures (git-fixes). * thunderbolt: Bound the DROM dual link port number before indexing sw->ports (git-fixes). * thunderbolt: icm: Preserve USB4 proxy data-valid bit (git-fixes). * tlclk: if sscanf() fails, fall back to 0, not random value (git-fixes). * tpm: st33zp24: Return zero on status read failure (git-fixes). * tpm: st33zp24: Validate locality read result (git-fixes). * tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (git-fixes). * tty: clear cdev pointer after cdev_add() failure (git-fixes). * tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 (git-fixes). * tty: skip cdev_del() when no cdev is registered (git-fixes). * uio: Fix stale info pointer in failed registration path (git-fixes). * usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (git-fixes). * usb: atm: usbatm: fix invalid ci_range initialization (git-fixes). * USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (git-fixes). * usb: cdnsp: fix incorrect endian conversions for APB timeout register (git- fixes). * usb: dwc2: add missing @remotewakeup kernel-doc parameter (git-fixes). * usb: dwc2: gadget: Exit partial power down state when changing USB pull-up (git-fixes). * usb: gadget: configfs: fix out-of-bounds read of qw_sign (git-fixes). * usb: gadget: f_fs: Prevent deadlock during ep0 read loop (git-fixes). * usb: gadget: f_ncm: Use unsigned int for ndp_index (git-fixes). * usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() (git-fixes). * usb: gadget: f_uac1_legacy: remove broken string configfs attributes (git- fixes). * usb: gadget: pch_udc: remove excess kernel-doc member for registered (git- fixes). * usb: gadget: r8a66597: avoid double free of ep0_req in probe error path (git-fixes). * usb: gadget: snps_udc_plat: clean up PHY on probe deferral (git-fixes). * usb: gadget: u_audio: Fix use-after-free on sound card disconnect (git- fixes). * usb: gadget: uac: validate rate list length before storing (git-fixes). * usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() (git-fixes). * usb: mtu3: allow system suspend during active gadget connection (git-fixes). * usb: musb: omap2430: clean up probe error handling (stable-fixes). * USB: phy: fsl-usb: fix missing static keywords (git-fixes). * usb: renesas_usbhs: Fix power-off ordering on unbind (git-fixes). * USB: serial: digi_acceleport: fix port registration order (git-fixes). * USB: serial: ftdi_sio: add support for E+H FXA291 (stable-fixes). * USB: serial: option: add TDTECH MT5710-CN (stable-fixes). * USB: serial: option: fix slab OOB read in interrupt URB callback (git- fixes). * USB: serial: spcp8x5: drop broken carrier detect support (git-fixes). * USB: storage: add NO_ATA_1X quirk for Longmai USB Key (stable-fixes). * usb: typec: ucsi: unregister debugfs entries on teardown (git-fixes). * usb: usbfs: fix use-after-free of usb_device in usbdev_release() (git- fixes). * usb: xhci: Handle USB3 port events when there is one roothub (git-fixes). * vt: add permission check for KDSKBMETA ioctl (stable-fixes). * vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (stable- fixes). * w1: ds28e17: reject an oversize length on an I2C block read (git-fixes). * w1: ds2482: Fix signedness bug in ds2482_w1_triplet() (git-fixes). * wifi: ath6kl: avoid buffer overreads in WMI event handlers (git-fixes). * wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (git-fixes). * wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump (git-fixes). * wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() (git-fixes). * wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate (git- fixes). * wifi: ath11k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() (git-fixes). * wifi: ath12k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (git-fixes). * wifi: brcmfmac: fix P2P action frame handling without device vif (git- fixes). * wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs (git-fixes). * wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments (git-fixes). * wifi: iwlwifi: mei: pass correct argument to function (git-fixes). * wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser (git-fixes). * wifi: mac80211: send TWT teardown to peer after setup TX failure (git- fixes). * wifi: mac80211: skip default WMM setup for AP_VLAN links (git-fixes). * wifi: mac80211: skip unused probe response countdown offsets (git-fixes). * wifi: mt76: fix 4th chain ACK RSSI bitmask in sta_poll (git-fixes). * wifi: mt76: fix ER-SU 106-tone RU check in RX rate decode (git-fixes). * wifi: mt76: fix HE DCM max-RU capability encoding (git-fixes). * wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length (git- fixes). * wifi: mt76: mt792x: Fix memory leak in SDIO TX path (git-fixes). * wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (git- fixes). * wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss (git- fixes). * wifi: mt76: mt7915: fix double hif2 init on the non-WED path (git-fixes). * wifi: mt76: mt7915: fix ext PHY use-after-free on register error path (git- fixes). * wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 (git- fixes). * wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie (git-fixes). * wifi: mt76: mt7915: release hif2 reference on probe IRQ failure (git-fixes). * wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement (git- fixes). * wifi: mt76: mt7915: unwind state on add_interface failure (git-fixes). * wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields (git- fixes). * wifi: mt76: mt7915: write RX header translation bit to the correct register (git-fixes). * wifi: mt76: mt7921: validate CLC firmware records (git-fixes). * wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (git- fixes). * wifi: mt76: mt7925: fix msg len mismatch between driver and firmware (git- fixes). * wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config (git- fixes). * wifi: mt76: mt7996: don't report a zero TX bitrate (git-fixes). * wifi: mt76: mt7996: fix reg addr remap when addr is 0 (git-fixes). * wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV (git- fixes). * wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset (git-fixes). * wifi: mt76: mt7996: validate RX band_idx before dereferencing phys (git- fixes). * wifi: mt76: report data NSS for STBC frames in RX rate decode (git-fixes). * wifi: mwifiex: Detach sync cmd buffer on interrupted wait (git-fixes). * wifi: rtlwifi: pci: fix error path in rtl_pci_probe() (git-fixes). * wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (git-fixes). * wifi: rtw89: fix HE extended capability length check (git-fixes). * wifi: zd1211rw: reject secondary interfaces to prevent conflicts (git- fixes). * x86/bugs: Clarify that syscall hardening isn't a BHI mitigation (git-fixes). * xhci: dbgtty: Fix unregister on tty_alloc_driver() failure (git-fixes). * xhci: dbgtty: Fix unregister on tty_register_driver() failure (git-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-603=1 ## Package List: * SUSE Linux Micro 6.0 (noarch) * kernel-source-rt-6.4.0-52.1 * kernel-devel-rt-6.4.0-52.1 * SUSE Linux Micro 6.0 (nosrc x86_64) * kernel-rt-6.4.0-52.1 * SUSE Linux Micro 6.0 (x86_64) * kernel-rt-debuginfo-6.4.0-52.1 * kernel-rt-debugsource-6.4.0-52.1 * kernel-rt-livepatch-6.4.0-52.1 ## References: * https://www.suse.com/security/cve/CVE-2024-44981.html * https://www.suse.com/security/cve/CVE-2024-57841.html * https://www.suse.com/security/cve/CVE-2025-38469.html * https://www.suse.com/security/cve/CVE-2025-39964.html * https://www.suse.com/security/cve/CVE-2025-40022.html * https://www.suse.com/security/cve/CVE-2025-68179.html * https://www.suse.com/security/cve/CVE-2025-68214.html * https://www.suse.com/security/cve/CVE-2025-71075.html * https://www.suse.com/security/cve/CVE-2025-71104.html * https://www.suse.com/security/cve/CVE-2026-23210.html * https://www.suse.com/security/cve/CVE-2026-23230.html * https://www.suse.com/security/cve/CVE-2026-23454.html * https://www.suse.com/security/cve/CVE-2026-31392.html * https://www.suse.com/security/cve/CVE-2026-31418.html * https://www.suse.com/security/cve/CVE-2026-31531.html * https://www.suse.com/security/cve/CVE-2026-31557.html * https://www.suse.com/security/cve/CVE-2026-31663.html * https://www.suse.com/security/cve/CVE-2026-43116.html * https://www.suse.com/security/cve/CVE-2026-43125.html * https://www.suse.com/security/cve/CVE-2026-43163.html * https://www.suse.com/security/cve/CVE-2026-43271.html * https://www.suse.com/security/cve/CVE-2026-43273.html * https://www.suse.com/security/cve/CVE-2026-43278.html * https://www.suse.com/security/cve/CVE-2026-43319.html * https://www.suse.com/security/cve/CVE-2026-43363.html * https://www.suse.com/security/cve/CVE-2026-43416.html * https://www.suse.com/security/cve/CVE-2026-45897.html * https://www.suse.com/security/cve/CVE-2026-45968.html * https://www.suse.com/security/cve/CVE-2026-46070.html * https://www.suse.com/security/cve/CVE-2026-46091.html * https://www.suse.com/security/cve/CVE-2026-46107.html * https://www.suse.com/security/cve/CVE-2026-46115.html * https://www.suse.com/security/cve/CVE-2026-46195.html * https://www.suse.com/security/cve/CVE-2026-52920.html * https://www.suse.com/security/cve/CVE-2026-52925.html * https://www.suse.com/security/cve/CVE-2026-52929.html * https://www.suse.com/security/cve/CVE-2026-52935.html * https://www.suse.com/security/cve/CVE-2026-52939.html * https://www.suse.com/security/cve/CVE-2026-52946.html * https://www.suse.com/security/cve/CVE-2026-52975.html * https://www.suse.com/security/cve/CVE-2026-52977.html * https://www.suse.com/security/cve/CVE-2026-52990.html * https://www.suse.com/security/cve/CVE-2026-52994.html * https://www.suse.com/security/cve/CVE-2026-53001.html * https://www.suse.com/security/cve/CVE-2026-53033.html * https://www.suse.com/security/cve/CVE-2026-53059.html * https://www.suse.com/security/cve/CVE-2026-53076.html * https://www.suse.com/security/cve/CVE-2026-53077.html * https://www.suse.com/security/cve/CVE-2026-53089.html * https://www.suse.com/security/cve/CVE-2026-53091.html * https://www.suse.com/security/cve/CVE-2026-53094.html * https://www.suse.com/security/cve/CVE-2026-53096.html * https://www.suse.com/security/cve/CVE-2026-53110.html * https://www.suse.com/security/cve/CVE-2026-53111.html * https://www.suse.com/security/cve/CVE-2026-53126.html * https://www.suse.com/security/cve/CVE-2026-53154.html * https://www.suse.com/security/cve/CVE-2026-53163.html * https://www.suse.com/security/cve/CVE-2026-53207.html * https://www.suse.com/security/cve/CVE-2026-53219.html * https://www.suse.com/security/cve/CVE-2026-53220.html * https://www.suse.com/security/cve/CVE-2026-53223.html * https://www.suse.com/security/cve/CVE-2026-53228.html * https://www.suse.com/security/cve/CVE-2026-53238.html * https://www.suse.com/security/cve/CVE-2026-53260.html * https://www.suse.com/security/cve/CVE-2026-53264.html * https://www.suse.com/security/cve/CVE-2026-53269.html * https://www.suse.com/security/cve/CVE-2026-53273.html * https://www.suse.com/security/cve/CVE-2026-53309.html * https://www.suse.com/security/cve/CVE-2026-53330.html * https://www.suse.com/security/cve/CVE-2026-53336.html * https://www.suse.com/security/cve/CVE-2026-53337.html * https://www.suse.com/security/cve/CVE-2026-53353.html * https://www.suse.com/security/cve/CVE-2026-53365.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://www.suse.com/security/cve/CVE-2026-53381.html * https://www.suse.com/security/cve/CVE-2026-53388.html * https://www.suse.com/security/cve/CVE-2026-63801.html * https://www.suse.com/security/cve/CVE-2026-63808.html * https://www.suse.com/security/cve/CVE-2026-63810.html * https://www.suse.com/security/cve/CVE-2026-63823.html * https://www.suse.com/security/cve/CVE-2026-63827.html * https://www.suse.com/security/cve/CVE-2026-63828.html * https://www.suse.com/security/cve/CVE-2026-63860.html * https://www.suse.com/security/cve/CVE-2026-63865.html * https://www.suse.com/security/cve/CVE-2026-63868.html * https://www.suse.com/security/cve/CVE-2026-63879.html * https://www.suse.com/security/cve/CVE-2026-63881.html * https://www.suse.com/security/cve/CVE-2026-63886.html * https://www.suse.com/security/cve/CVE-2026-63887.html * https://www.suse.com/security/cve/CVE-2026-63888.html * https://www.suse.com/security/cve/CVE-2026-63889.html * https://www.suse.com/security/cve/CVE-2026-63891.html * https://www.suse.com/security/cve/CVE-2026-63898.html * https://www.suse.com/security/cve/CVE-2026-63920.html * https://www.suse.com/security/cve/CVE-2026-63925.html * https://www.suse.com/security/cve/CVE-2026-63926.html * https://www.suse.com/security/cve/CVE-2026-63928.html * https://www.suse.com/security/cve/CVE-2026-63944.html * https://www.suse.com/security/cve/CVE-2026-63969.html * https://www.suse.com/security/cve/CVE-2026-63970.html * https://www.suse.com/security/cve/CVE-2026-63972.html * https://www.suse.com/security/cve/CVE-2026-63973.html * https://www.suse.com/security/cve/CVE-2026-63980.html * https://www.suse.com/security/cve/CVE-2026-63985.html * https://www.suse.com/security/cve/CVE-2026-63990.html * https://www.suse.com/security/cve/CVE-2026-63992.html * https://www.suse.com/security/cve/CVE-2026-63999.html * https://www.suse.com/security/cve/CVE-2026-64000.html * https://www.suse.com/security/cve/CVE-2026-64001.html * https://www.suse.com/security/cve/CVE-2026-64002.html * https://www.suse.com/security/cve/CVE-2026-64004.html * https://www.suse.com/security/cve/CVE-2026-64005.html * https://www.suse.com/security/cve/CVE-2026-64006.html * https://www.suse.com/security/cve/CVE-2026-64007.html * https://www.suse.com/security/cve/CVE-2026-64010.html * https://www.suse.com/security/cve/CVE-2026-64011.html * https://www.suse.com/security/cve/CVE-2026-64014.html * https://www.suse.com/security/cve/CVE-2026-64015.html * https://www.suse.com/security/cve/CVE-2026-64018.html * https://www.suse.com/security/cve/CVE-2026-64029.html * https://www.suse.com/security/cve/CVE-2026-64034.html * https://www.suse.com/security/cve/CVE-2026-64039.html * https://www.suse.com/security/cve/CVE-2026-64047.html * https://www.suse.com/security/cve/CVE-2026-64048.html * https://www.suse.com/security/cve/CVE-2026-64051.html * https://www.suse.com/security/cve/CVE-2026-64052.html * https://www.suse.com/security/cve/CVE-2026-64073.html * https://www.suse.com/security/cve/CVE-2026-64083.html * https://www.suse.com/security/cve/CVE-2026-64084.html * https://www.suse.com/security/cve/CVE-2026-64085.html * https://www.suse.com/security/cve/CVE-2026-64086.html * https://www.suse.com/security/cve/CVE-2026-64087.html * https://www.suse.com/security/cve/CVE-2026-64088.html * https://www.suse.com/security/cve/CVE-2026-64097.html * https://www.suse.com/security/cve/CVE-2026-64098.html * https://www.suse.com/security/cve/CVE-2026-64102.html * https://www.suse.com/security/cve/CVE-2026-64109.html * https://www.suse.com/security/cve/CVE-2026-64112.html * https://www.suse.com/security/cve/CVE-2026-64113.html * https://www.suse.com/security/cve/CVE-2026-64114.html * https://www.suse.com/security/cve/CVE-2026-64115.html * https://www.suse.com/security/cve/CVE-2026-64118.html * https://www.suse.com/security/cve/CVE-2026-64121.html * https://www.suse.com/security/cve/CVE-2026-64125.html * https://www.suse.com/security/cve/CVE-2026-64126.html * https://www.suse.com/security/cve/CVE-2026-64128.html * https://www.suse.com/security/cve/CVE-2026-64131.html * https://www.suse.com/security/cve/CVE-2026-64133.html * https://www.suse.com/security/cve/CVE-2026-64135.html * https://www.suse.com/security/cve/CVE-2026-64137.html * https://www.suse.com/security/cve/CVE-2026-64148.html * https://www.suse.com/security/cve/CVE-2026-64155.html * https://www.suse.com/security/cve/CVE-2026-64164.html * https://www.suse.com/security/cve/CVE-2026-64166.html * https://www.suse.com/security/cve/CVE-2026-64168.html * https://www.suse.com/security/cve/CVE-2026-64178.html * https://www.suse.com/security/cve/CVE-2026-64185.html * https://www.suse.com/security/cve/CVE-2026-64188.html * https://www.suse.com/security/cve/CVE-2026-64190.html * https://www.suse.com/security/cve/CVE-2026-64192.html * https://www.suse.com/security/cve/CVE-2026-64214.html * https://www.suse.com/security/cve/CVE-2026-64217.html * https://www.suse.com/security/cve/CVE-2026-64218.html * https://www.suse.com/security/cve/CVE-2026-64219.html * https://www.suse.com/security/cve/CVE-2026-64222.html * https://www.suse.com/security/cve/CVE-2026-64225.html * https://www.suse.com/security/cve/CVE-2026-64237.html * https://www.suse.com/security/cve/CVE-2026-64243.html * https://www.suse.com/security/cve/CVE-2026-64245.html * https://www.suse.com/security/cve/CVE-2026-64246.html * https://www.suse.com/security/cve/CVE-2026-64247.html * https://www.suse.com/security/cve/CVE-2026-64249.html * https://www.suse.com/security/cve/CVE-2026-64257.html * https://www.suse.com/security/cve/CVE-2026-64266.html * https://www.suse.com/security/cve/CVE-2026-64268.html * https://www.suse.com/security/cve/CVE-2026-64271.html * https://www.suse.com/security/cve/CVE-2026-64273.html * https://www.suse.com/security/cve/CVE-2026-64274.html * https://www.suse.com/security/cve/CVE-2026-64275.html * https://www.suse.com/security/cve/CVE-2026-64276.html * https://www.suse.com/security/cve/CVE-2026-64277.html * https://www.suse.com/security/cve/CVE-2026-64286.html * https://www.suse.com/security/cve/CVE-2026-64287.html * https://www.suse.com/security/cve/CVE-2026-64294.html * https://www.suse.com/security/cve/CVE-2026-64296.html * https://www.suse.com/security/cve/CVE-2026-64303.html * https://www.suse.com/security/cve/CVE-2026-64304.html * https://www.suse.com/security/cve/CVE-2026-64305.html * https://www.suse.com/security/cve/CVE-2026-64306.html * https://www.suse.com/security/cve/CVE-2026-64312.html * https://www.suse.com/security/cve/CVE-2026-64313.html * https://www.suse.com/security/cve/CVE-2026-64315.html * https://www.suse.com/security/cve/CVE-2026-64316.html * https://www.suse.com/security/cve/CVE-2026-64317.html * https://www.suse.com/security/cve/CVE-2026-64322.html * https://www.suse.com/security/cve/CVE-2026-64323.html * https://www.suse.com/security/cve/CVE-2026-64329.html * https://www.suse.com/security/cve/CVE-2026-64331.html * https://www.suse.com/security/cve/CVE-2026-64332.html * https://www.suse.com/security/cve/CVE-2026-64333.html * https://www.suse.com/security/cve/CVE-2026-64334.html * https://www.suse.com/security/cve/CVE-2026-64335.html * https://www.suse.com/security/cve/CVE-2026-64337.html * https://www.suse.com/security/cve/CVE-2026-64338.html * https://www.suse.com/security/cve/CVE-2026-64340.html * https://www.suse.com/security/cve/CVE-2026-64341.html * https://www.suse.com/security/cve/CVE-2026-64342.html * https://www.suse.com/security/cve/CVE-2026-64343.html * https://www.suse.com/security/cve/CVE-2026-64344.html * https://www.suse.com/security/cve/CVE-2026-64346.html * https://www.suse.com/security/cve/CVE-2026-64348.html * https://www.suse.com/security/cve/CVE-2026-64350.html * https://www.suse.com/security/cve/CVE-2026-64351.html * https://www.suse.com/security/cve/CVE-2026-64355.html * https://www.suse.com/security/cve/CVE-2026-64358.html * https://www.suse.com/security/cve/CVE-2026-64362.html * https://www.suse.com/security/cve/CVE-2026-64365.html * https://www.suse.com/security/cve/CVE-2026-64375.html * https://www.suse.com/security/cve/CVE-2026-64376.html * https://www.suse.com/security/cve/CVE-2026-64378.html * https://www.suse.com/security/cve/CVE-2026-64381.html * https://www.suse.com/security/cve/CVE-2026-64382.html * https://www.suse.com/security/cve/CVE-2026-64383.html * https://www.suse.com/security/cve/CVE-2026-64384.html * https://www.suse.com/security/cve/CVE-2026-64385.html * https://www.suse.com/security/cve/CVE-2026-64386.html * https://www.suse.com/security/cve/CVE-2026-64387.html * https://www.suse.com/security/cve/CVE-2026-64388.html * https://www.suse.com/security/cve/CVE-2026-64401.html * https://www.suse.com/security/cve/CVE-2026-64403.html * https://www.suse.com/security/cve/CVE-2026-64406.html * https://www.suse.com/security/cve/CVE-2026-64408.html * https://www.suse.com/security/cve/CVE-2026-64409.html * https://www.suse.com/security/cve/CVE-2026-64411.html * https://www.suse.com/security/cve/CVE-2026-64412.html * https://www.suse.com/security/cve/CVE-2026-64420.html * https://www.suse.com/security/cve/CVE-2026-64421.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64427.html * https://www.suse.com/security/cve/CVE-2026-64429.html * https://www.suse.com/security/cve/CVE-2026-64433.html * https://www.suse.com/security/cve/CVE-2026-64434.html * https://www.suse.com/security/cve/CVE-2026-64436.html * https://www.suse.com/security/cve/CVE-2026-64440.html * https://www.suse.com/security/cve/CVE-2026-64442.html * https://www.suse.com/security/cve/CVE-2026-64443.html * https://www.suse.com/security/cve/CVE-2026-64444.html * https://www.suse.com/security/cve/CVE-2026-64445.html * https://www.suse.com/security/cve/CVE-2026-64448.html * https://www.suse.com/security/cve/CVE-2026-64450.html * https://www.suse.com/security/cve/CVE-2026-64454.html * https://www.suse.com/security/cve/CVE-2026-64455.html * https://www.suse.com/security/cve/CVE-2026-64463.html * https://www.suse.com/security/cve/CVE-2026-64470.html * https://www.suse.com/security/cve/CVE-2026-64471.html * https://www.suse.com/security/cve/CVE-2026-64472.html * https://www.suse.com/security/cve/CVE-2026-64478.html * https://www.suse.com/security/cve/CVE-2026-64479.html * https://www.suse.com/security/cve/CVE-2026-64480.html * https://www.suse.com/security/cve/CVE-2026-64481.html * https://www.suse.com/security/cve/CVE-2026-64482.html * https://www.suse.com/security/cve/CVE-2026-64483.html * https://www.suse.com/security/cve/CVE-2026-64484.html * https://www.suse.com/security/cve/CVE-2026-64486.html * https://www.suse.com/security/cve/CVE-2026-64487.html * https://www.suse.com/security/cve/CVE-2026-64489.html * https://www.suse.com/security/cve/CVE-2026-64494.html * https://www.suse.com/security/cve/CVE-2026-64495.html * https://www.suse.com/security/cve/CVE-2026-64496.html * https://www.suse.com/security/cve/CVE-2026-64497.html * https://www.suse.com/security/cve/CVE-2026-64500.html * https://www.suse.com/security/cve/CVE-2026-64503.html * https://www.suse.com/security/cve/CVE-2026-64504.html * https://www.suse.com/security/cve/CVE-2026-64505.html * https://www.suse.com/security/cve/CVE-2026-64511.html * https://www.suse.com/security/cve/CVE-2026-64512.html * https://www.suse.com/security/cve/CVE-2026-64513.html * https://www.suse.com/security/cve/CVE-2026-64524.html * https://www.suse.com/security/cve/CVE-2026-64527.html * https://www.suse.com/security/cve/CVE-2026-64536.html * https://www.suse.com/security/cve/CVE-2026-64537.html * https://www.suse.com/security/cve/CVE-2026-64538.html * https://www.suse.com/security/cve/CVE-2026-64539.html * https://www.suse.com/security/cve/CVE-2026-64540.html * https://www.suse.com/security/cve/CVE-2026-64541.html * https://www.suse.com/security/cve/CVE-2026-64543.html * https://www.suse.com/security/cve/CVE-2026-64544.html * https://www.suse.com/security/cve/CVE-2026-64545.html * https://www.suse.com/security/cve/CVE-2026-64546.html * https://www.suse.com/security/cve/CVE-2026-64547.html * https://www.suse.com/security/cve/CVE-2026-64548.html * https://www.suse.com/security/cve/CVE-2026-64549.html * https://www.suse.com/security/cve/CVE-2026-64551.html * https://www.suse.com/security/cve/CVE-2026-64552.html * https://www.suse.com/security/cve/CVE-2026-64553.html * https://www.suse.com/security/cve/CVE-2026-64554.html * https://www.suse.com/security/cve/CVE-2026-64562.html * https://www.suse.com/security/cve/CVE-2026-64563.html * https://www.suse.com/security/cve/CVE-2026-64565.html * https://www.suse.com/security/cve/CVE-2026-64567.html * https://www.suse.com/security/cve/CVE-2026-64571.html * https://www.suse.com/security/cve/CVE-2026-64572.html * https://www.suse.com/security/cve/CVE-2026-64573.html * https://www.suse.com/security/cve/CVE-2026-64574.html * https://www.suse.com/security/cve/CVE-2026-64576.html * https://www.suse.com/security/cve/CVE-2026-64577.html * https://www.suse.com/security/cve/CVE-2026-64581.html * https://www.suse.com/security/cve/CVE-2026-64582.html * https://www.suse.com/security/cve/CVE-2026-64583.html * https://www.suse.com/security/cve/CVE-2026-64584.html * https://www.suse.com/security/cve/CVE-2026-64585.html * https://www.suse.com/security/cve/CVE-2026-64593.html * https://www.suse.com/security/cve/CVE-2026-64597.html * https://www.suse.com/security/cve/CVE-2026-64598.html * https://www.suse.com/security/cve/CVE-2026-64599.html * https://www.suse.com/security/cve/CVE-2026-64602.html * https://www.suse.com/security/cve/CVE-2026-64604.html * https://www.suse.com/security/cve/CVE-2026-68081.html * https://www.suse.com/security/cve/CVE-2026-68082.html * https://www.suse.com/security/cve/CVE-2026-68085.html * https://www.suse.com/security/cve/CVE-2026-68086.html * https://www.suse.com/security/cve/CVE-2026-68088.html * https://www.suse.com/security/cve/CVE-2026-68091.html * https://www.suse.com/security/cve/CVE-2026-68093.html * https://www.suse.com/security/cve/CVE-2026-68102.html * https://www.suse.com/security/cve/CVE-2026-68104.html * https://www.suse.com/security/cve/CVE-2026-68106.html * https://www.suse.com/security/cve/CVE-2026-68107.html * https://www.suse.com/security/cve/CVE-2026-68108.html * https://www.suse.com/security/cve/CVE-2026-68110.html * https://www.suse.com/security/cve/CVE-2026-68111.html * https://www.suse.com/security/cve/CVE-2026-68112.html * https://www.suse.com/security/cve/CVE-2026-68115.html * https://www.suse.com/security/cve/CVE-2026-68116.html * https://www.suse.com/security/cve/CVE-2026-68117.html * https://www.suse.com/security/cve/CVE-2026-68121.html * https://www.suse.com/security/cve/CVE-2026-68123.html * https://www.suse.com/security/cve/CVE-2026-68125.html * https://www.suse.com/security/cve/CVE-2026-68126.html * https://www.suse.com/security/cve/CVE-2026-68127.html * https://www.suse.com/security/cve/CVE-2026-68129.html * https://www.suse.com/security/cve/CVE-2026-68132.html * https://www.suse.com/security/cve/CVE-2026-68133.html * https://www.suse.com/security/cve/CVE-2026-68136.html * https://www.suse.com/security/cve/CVE-2026-68137.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://www.suse.com/security/cve/CVE-2026-68139.html * https://www.suse.com/security/cve/CVE-2026-68142.html * https://www.suse.com/security/cve/CVE-2026-68143.html * https://www.suse.com/security/cve/CVE-2026-68145.html * https://www.suse.com/security/cve/CVE-2026-68149.html * https://www.suse.com/security/cve/CVE-2026-68153.html * https://www.suse.com/security/cve/CVE-2026-68154.html * https://www.suse.com/security/cve/CVE-2026-68155.html * https://www.suse.com/security/cve/CVE-2026-68156.html * https://www.suse.com/security/cve/CVE-2026-68157.html * https://www.suse.com/security/cve/CVE-2026-68158.html * https://www.suse.com/security/cve/CVE-2026-68159.html * https://www.suse.com/security/cve/CVE-2026-68160.html * https://www.suse.com/security/cve/CVE-2026-68161.html * https://www.suse.com/security/cve/CVE-2026-68162.html * https://www.suse.com/security/cve/CVE-2026-68166.html * https://www.suse.com/security/cve/CVE-2026-68180.html * https://www.suse.com/security/cve/CVE-2026-68181.html * https://www.suse.com/security/cve/CVE-2026-68182.html * https://www.suse.com/security/cve/CVE-2026-68184.html * https://www.suse.com/security/cve/CVE-2026-68188.html * https://www.suse.com/security/cve/CVE-2026-68189.html * https://www.suse.com/security/cve/CVE-2026-68192.html * https://www.suse.com/security/cve/CVE-2026-68193.html * https://www.suse.com/security/cve/CVE-2026-68194.html * https://www.suse.com/security/cve/CVE-2026-68195.html * https://www.suse.com/security/cve/CVE-2026-68196.html * https://www.suse.com/security/cve/CVE-2026-68197.html * https://www.suse.com/security/cve/CVE-2026-68199.html * https://www.suse.com/security/cve/CVE-2026-68202.html * https://www.suse.com/security/cve/CVE-2026-68204.html * https://www.suse.com/security/cve/CVE-2026-68205.html * https://www.suse.com/security/cve/CVE-2026-68206.html * https://www.suse.com/security/cve/CVE-2026-68207.html * https://www.suse.com/security/cve/CVE-2026-68209.html * https://www.suse.com/security/cve/CVE-2026-68210.html * https://www.suse.com/security/cve/CVE-2026-68212.html * https://www.suse.com/security/cve/CVE-2026-68213.html * https://www.suse.com/security/cve/CVE-2026-68214.html * https://www.suse.com/security/cve/CVE-2026-68215.html * https://www.suse.com/security/cve/CVE-2026-68216.html * https://www.suse.com/security/cve/CVE-2026-68217.html * https://www.suse.com/security/cve/CVE-2026-68218.html * https://www.suse.com/security/cve/CVE-2026-68219.html * https://www.suse.com/security/cve/CVE-2026-68220.html * https://www.suse.com/security/cve/CVE-2026-68222.html * https://www.suse.com/security/cve/CVE-2026-68223.html * https://www.suse.com/security/cve/CVE-2026-68226.html * https://www.suse.com/security/cve/CVE-2026-68227.html * https://www.suse.com/security/cve/CVE-2026-68229.html * https://www.suse.com/security/cve/CVE-2026-68231.html * https://www.suse.com/security/cve/CVE-2026-68234.html * https://www.suse.com/security/cve/CVE-2026-68236.html * https://www.suse.com/security/cve/CVE-2026-68238.html * https://www.suse.com/security/cve/CVE-2026-68243.html * https://www.suse.com/security/cve/CVE-2026-68244.html * https://www.suse.com/security/cve/CVE-2026-68246.html * https://www.suse.com/security/cve/CVE-2026-68247.html * https://www.suse.com/security/cve/CVE-2026-68248.html * https://www.suse.com/security/cve/CVE-2026-68249.html * https://www.suse.com/security/cve/CVE-2026-68250.html * https://www.suse.com/security/cve/CVE-2026-68251.html * https://www.suse.com/security/cve/CVE-2026-68254.html * https://www.suse.com/security/cve/CVE-2026-68255.html * https://www.suse.com/security/cve/CVE-2026-68256.html * https://www.suse.com/security/cve/CVE-2026-68259.html * https://www.suse.com/security/cve/CVE-2026-68269.html * https://www.suse.com/security/cve/CVE-2026-68271.html * https://www.suse.com/security/cve/CVE-2026-68272.html * https://www.suse.com/security/cve/CVE-2026-68277.html * https://www.suse.com/security/cve/CVE-2026-68278.html * https://www.suse.com/security/cve/CVE-2026-68279.html * https://www.suse.com/security/cve/CVE-2026-68280.html * https://www.suse.com/security/cve/CVE-2026-68284.html * https://www.suse.com/security/cve/CVE-2026-68286.html * https://www.suse.com/security/cve/CVE-2026-68288.html * https://www.suse.com/security/cve/CVE-2026-68289.html * https://www.suse.com/security/cve/CVE-2026-68293.html * https://www.suse.com/security/cve/CVE-2026-68297.html * https://www.suse.com/security/cve/CVE-2026-68299.html * https://www.suse.com/security/cve/CVE-2026-68300.html * https://www.suse.com/security/cve/CVE-2026-68303.html * https://www.suse.com/security/cve/CVE-2026-68304.html * https://www.suse.com/security/cve/CVE-2026-68306.html * https://www.suse.com/security/cve/CVE-2026-68308.html * https://www.suse.com/security/cve/CVE-2026-68309.html * https://www.suse.com/security/cve/CVE-2026-68310.html * https://www.suse.com/security/cve/CVE-2026-68312.html * https://www.suse.com/security/cve/CVE-2026-68313.html * https://www.suse.com/security/cve/CVE-2026-68315.html * https://www.suse.com/security/cve/CVE-2026-68320.html * https://www.suse.com/security/cve/CVE-2026-68322.html * https://www.suse.com/security/cve/CVE-2026-68324.html * https://www.suse.com/security/cve/CVE-2026-68325.html * https://www.suse.com/security/cve/CVE-2026-68326.html * https://www.suse.com/security/cve/CVE-2026-68327.html * https://www.suse.com/security/cve/CVE-2026-68328.html * https://www.suse.com/security/cve/CVE-2026-68329.html * https://www.suse.com/security/cve/CVE-2026-68331.html * https://www.suse.com/security/cve/CVE-2026-68333.html * https://www.suse.com/security/cve/CVE-2026-68335.html * https://www.suse.com/security/cve/CVE-2026-68336.html * https://www.suse.com/security/cve/CVE-2026-68339.html * https://www.suse.com/security/cve/CVE-2026-68340.html * https://www.suse.com/security/cve/CVE-2026-68343.html * https://www.suse.com/security/cve/CVE-2026-68346.html * https://www.suse.com/security/cve/CVE-2026-68348.html * https://www.suse.com/security/cve/CVE-2026-68349.html * https://www.suse.com/security/cve/CVE-2026-68350.html * https://www.suse.com/security/cve/CVE-2026-68351.html * https://www.suse.com/security/cve/CVE-2026-68352.html * https://www.suse.com/security/cve/CVE-2026-68353.html * https://www.suse.com/security/cve/CVE-2026-68354.html * https://www.suse.com/security/cve/CVE-2026-68355.html * https://www.suse.com/security/cve/CVE-2026-68357.html * https://www.suse.com/security/cve/CVE-2026-68359.html * https://www.suse.com/security/cve/CVE-2026-68360.html * https://www.suse.com/security/cve/CVE-2026-68361.html * https://www.suse.com/security/cve/CVE-2026-68362.html * https://www.suse.com/security/cve/CVE-2026-68363.html * https://www.suse.com/security/cve/CVE-2026-68365.html * https://www.suse.com/security/cve/CVE-2026-68366.html * https://www.suse.com/security/cve/CVE-2026-68368.html * https://www.suse.com/security/cve/CVE-2026-68369.html * https://www.suse.com/security/cve/CVE-2026-68370.html * https://www.suse.com/security/cve/CVE-2026-68372.html * https://www.suse.com/security/cve/CVE-2026-68373.html * https://www.suse.com/security/cve/CVE-2026-68377.html * https://www.suse.com/security/cve/CVE-2026-68386.html * https://www.suse.com/security/cve/CVE-2026-68391.html * https://www.suse.com/security/cve/CVE-2026-68392.html * https://www.suse.com/security/cve/CVE-2026-68397.html * https://www.suse.com/security/cve/CVE-2026-68398.html * https://www.suse.com/security/cve/CVE-2026-68399.html * https://www.suse.com/security/cve/CVE-2026-68402.html * https://www.suse.com/security/cve/CVE-2026-68403.html * https://www.suse.com/security/cve/CVE-2026-68405.html * https://www.suse.com/security/cve/CVE-2026-68406.html * https://www.suse.com/security/cve/CVE-2026-68407.html * https://www.suse.com/security/cve/CVE-2026-68408.html * https://www.suse.com/security/cve/CVE-2026-68410.html * https://www.suse.com/security/cve/CVE-2026-68413.html * https://www.suse.com/security/cve/CVE-2026-68414.html * https://www.suse.com/security/cve/CVE-2026-68417.html * https://www.suse.com/security/cve/CVE-2026-68418.html * https://www.suse.com/security/cve/CVE-2026-68419.html * https://www.suse.com/security/cve/CVE-2026-68422.html * https://www.suse.com/security/cve/CVE-2026-68425.html * https://www.suse.com/security/cve/CVE-2026-68426.html * https://www.suse.com/security/cve/CVE-2026-68427.html * https://www.suse.com/security/cve/CVE-2026-68428.html * https://www.suse.com/security/cve/CVE-2026-68429.html * https://www.suse.com/security/cve/CVE-2026-68430.html * https://www.suse.com/security/cve/CVE-2026-68432.html * https://www.suse.com/security/cve/CVE-2026-68433.html * https://www.suse.com/security/cve/CVE-2026-68434.html * https://www.suse.com/security/cve/CVE-2026-68444.html * https://www.suse.com/security/cve/CVE-2026-68445.html * https://www.suse.com/security/cve/CVE-2026-68446.html * https://www.suse.com/security/cve/CVE-2026-68450.html * https://www.suse.com/security/cve/CVE-2026-68470.html * https://www.suse.com/security/cve/CVE-2026-68480.html * https://www.suse.com/security/cve/CVE-2026-72020.html * https://www.suse.com/security/cve/CVE-2026-72035.html * https://www.suse.com/security/cve/CVE-2026-72036.html * https://www.suse.com/security/cve/CVE-2026-72069.html * https://www.suse.com/security/cve/CVE-2026-72072.html * https://www.suse.com/security/cve/CVE-2026-72083.html * https://www.suse.com/security/cve/CVE-2026-72084.html * https://www.suse.com/security/cve/CVE-2026-72123.html * https://www.suse.com/security/cve/CVE-2026-72132.html * https://www.suse.com/security/cve/CVE-2026-72221.html * https://www.suse.com/security/cve/CVE-2026-72222.html * https://www.suse.com/security/cve/CVE-2026-72251.html * https://www.suse.com/security/cve/CVE-2026-72254.html * https://www.suse.com/security/cve/CVE-2026-72262.html * https://www.suse.com/security/cve/CVE-2026-72288.html * https://www.suse.com/security/cve/CVE-2026-72289.html * https://www.suse.com/security/cve/CVE-2026-72296.html * https://www.suse.com/security/cve/CVE-2026-72307.html * https://www.suse.com/security/cve/CVE-2026-72308.html * https://www.suse.com/security/cve/CVE-2026-72317.html * https://www.suse.com/security/cve/CVE-2026-72341.html * https://www.suse.com/security/cve/CVE-2026-72342.html * https://www.suse.com/security/cve/CVE-2026-72343.html * https://www.suse.com/security/cve/CVE-2026-72389.html * https://www.suse.com/security/cve/CVE-2026-72463.html * https://www.suse.com/security/cve/CVE-2026-72464.html * https://www.suse.com/security/cve/CVE-2026-72466.html * https://www.suse.com/security/cve/CVE-2026-72467.html * https://www.suse.com/security/cve/CVE-2026-72469.html * https://www.suse.com/security/cve/CVE-2026-72473.html * https://www.suse.com/security/cve/CVE-2026-72494.html * https://www.suse.com/security/cve/CVE-2026-72495.html * https://www.suse.com/security/cve/CVE-2026-72496.html * https://www.suse.com/security/cve/CVE-2026-72499.html * https://www.suse.com/security/cve/CVE-2026-72501.html * https://www.suse.com/security/cve/CVE-2026-72502.html * https://www.suse.com/security/cve/CVE-2026-74269.html * https://www.suse.com/security/cve/CVE-2026-74296.html * https://www.suse.com/security/cve/CVE-2026-74297.html * https://www.suse.com/security/cve/CVE-2026-74318.html * https://www.suse.com/security/cve/CVE-2026-74321.html * https://www.suse.com/security/cve/CVE-2026-74334.html * https://www.suse.com/security/cve/CVE-2026-74345.html * https://www.suse.com/security/cve/CVE-2026-74394.html * https://www.suse.com/security/cve/CVE-2026-74395.html * https://www.suse.com/security/cve/CVE-2026-74454.html * https://www.suse.com/security/cve/CVE-2026-74474.html * https://www.suse.com/security/cve/CVE-2026-74481.html * https://www.suse.com/security/cve/CVE-2026-74482.html * https://www.suse.com/security/cve/CVE-2026-74488.html * https://www.suse.com/security/cve/CVE-2026-74495.html * https://www.suse.com/security/cve/CVE-2026-74496.html * https://www.suse.com/security/cve/CVE-2026-74509.html * https://www.suse.com/security/cve/CVE-2026-74510.html * https://www.suse.com/security/cve/CVE-2026-74512.html * https://www.suse.com/security/cve/CVE-2026-74516.html * https://www.suse.com/security/cve/CVE-2026-74518.html * https://www.suse.com/security/cve/CVE-2026-74527.html * https://www.suse.com/security/cve/CVE-2026-74537.html * https://www.suse.com/security/cve/CVE-2026-74548.html * https://www.suse.com/security/cve/CVE-2026-74550.html * https://www.suse.com/security/cve/CVE-2026-74556.html * https://www.suse.com/security/cve/CVE-2026-74563.html * https://www.suse.com/security/cve/CVE-2026-74566.html * https://www.suse.com/security/cve/CVE-2026-74567.html * https://www.suse.com/security/cve/CVE-2026-74571.html * https://www.suse.com/security/cve/CVE-2026-74581.html * https://www.suse.com/security/cve/CVE-2026-74582.html * https://www.suse.com/security/cve/CVE-2026-74584.html * https://www.suse.com/security/cve/CVE-2026-74610.html * https://www.suse.com/security/cve/CVE-2026-74669.html * https://www.suse.com/security/cve/CVE-2026-74692.html * https://www.suse.com/security/cve/CVE-2026-74694.html * https://www.suse.com/security/cve/CVE-2026-74695.html * https://www.suse.com/security/cve/CVE-2026-74717.html * https://www.suse.com/security/cve/CVE-2026-74722.html * https://www.suse.com/security/cve/CVE-2026-80529.html * https://www.suse.com/security/cve/CVE-2026-80534.html * https://www.suse.com/security/cve/CVE-2026-80590.html * https://www.suse.com/security/cve/CVE-2026-80654.html * https://bugzilla.suse.com/show_bug.cgi?id=1230238 * https://bugzilla.suse.com/show_bug.cgi?id=1235944 * https://bugzilla.suse.com/show_bug.cgi?id=1247455 * https://bugzilla.suse.com/show_bug.cgi?id=1250748 * https://bugzilla.suse.com/show_bug.cgi?id=1251966 * https://bugzilla.suse.com/show_bug.cgi?id=1252682 * https://bugzilla.suse.com/show_bug.cgi?id=1254306 * https://bugzilla.suse.com/show_bug.cgi?id=1255225 * https://bugzilla.suse.com/show_bug.cgi?id=1255250 * https://bugzilla.suse.com/show_bug.cgi?id=1256629 * https://bugzilla.suse.com/show_bug.cgi?id=1256708 * https://bugzilla.suse.com/show_bug.cgi?id=1257154 * https://bugzilla.suse.com/show_bug.cgi?id=1258430 * https://bugzilla.suse.com/show_bug.cgi?id=1258517 * https://bugzilla.suse.com/show_bug.cgi?id=1260522 * https://bugzilla.suse.com/show_bug.cgi?id=1261780 * https://bugzilla.suse.com/show_bug.cgi?id=1261788 * https://bugzilla.suse.com/show_bug.cgi?id=1262073 * https://bugzilla.suse.com/show_bug.cgi?id=1263004 * https://bugzilla.suse.com/show_bug.cgi?id=1263061 * https://bugzilla.suse.com/show_bug.cgi?id=1263133 * https://bugzilla.suse.com/show_bug.cgi?id=1264335 * https://bugzilla.suse.com/show_bug.cgi?id=1264446 * https://bugzilla.suse.com/show_bug.cgi?id=1264541 * https://bugzilla.suse.com/show_bug.cgi?id=1264584 * https://bugzilla.suse.com/show_bug.cgi?id=1264587 * https://bugzilla.suse.com/show_bug.cgi?id=1264619 * https://bugzilla.suse.com/show_bug.cgi?id=1264788 * https://bugzilla.suse.com/show_bug.cgi?id=1265068 * https://bugzilla.suse.com/show_bug.cgi?id=1265121 * https://bugzilla.suse.com/show_bug.cgi?id=1265449 * https://bugzilla.suse.com/show_bug.cgi?id=1265928 * https://bugzilla.suse.com/show_bug.cgi?id=1266402 * https://bugzilla.suse.com/show_bug.cgi?id=1266860 * https://bugzilla.suse.com/show_bug.cgi?id=1266874 * https://bugzilla.suse.com/show_bug.cgi?id=1266897 * https://bugzilla.suse.com/show_bug.cgi?id=1267023 * https://bugzilla.suse.com/show_bug.cgi?id=1267238 * https://bugzilla.suse.com/show_bug.cgi?id=1267501 * https://bugzilla.suse.com/show_bug.cgi?id=1267612 * https://bugzilla.suse.com/show_bug.cgi?id=1268276 * https://bugzilla.suse.com/show_bug.cgi?id=1268972 * https://bugzilla.suse.com/show_bug.cgi?id=1268979 * https://bugzilla.suse.com/show_bug.cgi?id=1268987 * https://bugzilla.suse.com/show_bug.cgi?id=1269004 * https://bugzilla.suse.com/show_bug.cgi?id=1269013 * https://bugzilla.suse.com/show_bug.cgi?id=1269108 * https://bugzilla.suse.com/show_bug.cgi?id=1269113 * https://bugzilla.suse.com/show_bug.cgi?id=1269114 * https://bugzilla.suse.com/show_bug.cgi?id=1269126 * https://bugzilla.suse.com/show_bug.cgi?id=1269167 * https://bugzilla.suse.com/show_bug.cgi?id=1269234 * https://bugzilla.suse.com/show_bug.cgi?id=1269238 * https://bugzilla.suse.com/show_bug.cgi?id=1269242 * https://bugzilla.suse.com/show_bug.cgi?id=1269256 * https://bugzilla.suse.com/show_bug.cgi?id=1269301 * https://bugzilla.suse.com/show_bug.cgi?id=1269306 * https://bugzilla.suse.com/show_bug.cgi?id=1269381 * https://bugzilla.suse.com/show_bug.cgi?id=1269388 * https://bugzilla.suse.com/show_bug.cgi?id=1269412 * https://bugzilla.suse.com/show_bug.cgi?id=1269530 * https://bugzilla.suse.com/show_bug.cgi?id=1269579 * https://bugzilla.suse.com/show_bug.cgi?id=1269590 * https://bugzilla.suse.com/show_bug.cgi?id=1269635 * https://bugzilla.suse.com/show_bug.cgi?id=1269655 * https://bugzilla.suse.com/show_bug.cgi?id=1269665 * https://bugzilla.suse.com/show_bug.cgi?id=1269686 * https://bugzilla.suse.com/show_bug.cgi?id=1269695 * https://bugzilla.suse.com/show_bug.cgi?id=1269713 * https://bugzilla.suse.com/show_bug.cgi?id=1269731 * https://bugzilla.suse.com/show_bug.cgi?id=1269774 * https://bugzilla.suse.com/show_bug.cgi?id=1269783 * https://bugzilla.suse.com/show_bug.cgi?id=1269792 * https://bugzilla.suse.com/show_bug.cgi?id=1269815 * https://bugzilla.suse.com/show_bug.cgi?id=1269965 * https://bugzilla.suse.com/show_bug.cgi?id=1269969 * https://bugzilla.suse.com/show_bug.cgi?id=1269981 * https://bugzilla.suse.com/show_bug.cgi?id=1269985 * https://bugzilla.suse.com/show_bug.cgi?id=1270090 * https://bugzilla.suse.com/show_bug.cgi?id=1270108 * https://bugzilla.suse.com/show_bug.cgi?id=1270111 * https://bugzilla.suse.com/show_bug.cgi?id=1270251 * https://bugzilla.suse.com/show_bug.cgi?id=1271256 * https://bugzilla.suse.com/show_bug.cgi?id=1271365 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 * https://bugzilla.suse.com/show_bug.cgi?id=1271825 * https://bugzilla.suse.com/show_bug.cgi?id=1271830 * https://bugzilla.suse.com/show_bug.cgi?id=1272150 * https://bugzilla.suse.com/show_bug.cgi?id=1272175 * https://bugzilla.suse.com/show_bug.cgi?id=1272179 * https://bugzilla.suse.com/show_bug.cgi?id=1272182 * https://bugzilla.suse.com/show_bug.cgi?id=1272200 * https://bugzilla.suse.com/show_bug.cgi?id=1272210 * https://bugzilla.suse.com/show_bug.cgi?id=1272213 * https://bugzilla.suse.com/show_bug.cgi?id=1272230 * https://bugzilla.suse.com/show_bug.cgi?id=1272260 * https://bugzilla.suse.com/show_bug.cgi?id=1272261 * https://bugzilla.suse.com/show_bug.cgi?id=1272262 * https://bugzilla.suse.com/show_bug.cgi?id=1272297 * https://bugzilla.suse.com/show_bug.cgi?id=1272346 * https://bugzilla.suse.com/show_bug.cgi?id=1272381 * https://bugzilla.suse.com/show_bug.cgi?id=1272385 * https://bugzilla.suse.com/show_bug.cgi?id=1272390 * https://bugzilla.suse.com/show_bug.cgi?id=1272423 * https://bugzilla.suse.com/show_bug.cgi?id=1272429 * https://bugzilla.suse.com/show_bug.cgi?id=1272484 * https://bugzilla.suse.com/show_bug.cgi?id=1272486 * https://bugzilla.suse.com/show_bug.cgi?id=1272497 * https://bugzilla.suse.com/show_bug.cgi?id=1272516 * https://bugzilla.suse.com/show_bug.cgi?id=1272569 * https://bugzilla.suse.com/show_bug.cgi?id=1272571 * https://bugzilla.suse.com/show_bug.cgi?id=1272641 * https://bugzilla.suse.com/show_bug.cgi?id=1272643 * https://bugzilla.suse.com/show_bug.cgi?id=1272662 * https://bugzilla.suse.com/show_bug.cgi?id=1272673 * https://bugzilla.suse.com/show_bug.cgi?id=1272680 * https://bugzilla.suse.com/show_bug.cgi?id=1272682 * https://bugzilla.suse.com/show_bug.cgi?id=1272756 * https://bugzilla.suse.com/show_bug.cgi?id=1272786 * https://bugzilla.suse.com/show_bug.cgi?id=1272788 * https://bugzilla.suse.com/show_bug.cgi?id=1272798 * https://bugzilla.suse.com/show_bug.cgi?id=1272799 * https://bugzilla.suse.com/show_bug.cgi?id=1272868 * https://bugzilla.suse.com/show_bug.cgi?id=1272877 * https://bugzilla.suse.com/show_bug.cgi?id=1272891 * https://bugzilla.suse.com/show_bug.cgi?id=1272963 * https://bugzilla.suse.com/show_bug.cgi?id=1272983 * https://bugzilla.suse.com/show_bug.cgi?id=1273008 * https://bugzilla.suse.com/show_bug.cgi?id=1273019 * https://bugzilla.suse.com/show_bug.cgi?id=1273027 * https://bugzilla.suse.com/show_bug.cgi?id=1273028 * https://bugzilla.suse.com/show_bug.cgi?id=1273030 * https://bugzilla.suse.com/show_bug.cgi?id=1273038 * https://bugzilla.suse.com/show_bug.cgi?id=1273053 * https://bugzilla.suse.com/show_bug.cgi?id=1273054 * https://bugzilla.suse.com/show_bug.cgi?id=1273060 * https://bugzilla.suse.com/show_bug.cgi?id=1273105 * https://bugzilla.suse.com/show_bug.cgi?id=1273249 * https://bugzilla.suse.com/show_bug.cgi?id=1273250 * https://bugzilla.suse.com/show_bug.cgi?id=1273260 * https://bugzilla.suse.com/show_bug.cgi?id=1273273 * https://bugzilla.suse.com/show_bug.cgi?id=1273274 * https://bugzilla.suse.com/show_bug.cgi?id=1273276 * https://bugzilla.suse.com/show_bug.cgi?id=1273281 * https://bugzilla.suse.com/show_bug.cgi?id=1273284 * https://bugzilla.suse.com/show_bug.cgi?id=1273285 * https://bugzilla.suse.com/show_bug.cgi?id=1273289 * https://bugzilla.suse.com/show_bug.cgi?id=1273291 * https://bugzilla.suse.com/show_bug.cgi?id=1273294 * https://bugzilla.suse.com/show_bug.cgi?id=1273302 * https://bugzilla.suse.com/show_bug.cgi?id=1273303 * https://bugzilla.suse.com/show_bug.cgi?id=1273305 * https://bugzilla.suse.com/show_bug.cgi?id=1273310 * https://bugzilla.suse.com/show_bug.cgi?id=1273311 * https://bugzilla.suse.com/show_bug.cgi?id=1273316 * https://bugzilla.suse.com/show_bug.cgi?id=1273318 * https://bugzilla.suse.com/show_bug.cgi?id=1273319 * https://bugzilla.suse.com/show_bug.cgi?id=1273323 * https://bugzilla.suse.com/show_bug.cgi?id=1273325 * https://bugzilla.suse.com/show_bug.cgi?id=1273327 * https://bugzilla.suse.com/show_bug.cgi?id=1273334 * https://bugzilla.suse.com/show_bug.cgi?id=1273335 * https://bugzilla.suse.com/show_bug.cgi?id=1273336 * https://bugzilla.suse.com/show_bug.cgi?id=1273337 * https://bugzilla.suse.com/show_bug.cgi?id=1273338 * https://bugzilla.suse.com/show_bug.cgi?id=1273340 * https://bugzilla.suse.com/show_bug.cgi?id=1273341 * https://bugzilla.suse.com/show_bug.cgi?id=1273346 * https://bugzilla.suse.com/show_bug.cgi?id=1273422 * https://bugzilla.suse.com/show_bug.cgi?id=1273426 * https://bugzilla.suse.com/show_bug.cgi?id=1273443 * https://bugzilla.suse.com/show_bug.cgi?id=1273463 * https://bugzilla.suse.com/show_bug.cgi?id=1273468 * https://bugzilla.suse.com/show_bug.cgi?id=1273469 * https://bugzilla.suse.com/show_bug.cgi?id=1273471 * https://bugzilla.suse.com/show_bug.cgi?id=1273479 * https://bugzilla.suse.com/show_bug.cgi?id=1273480 * https://bugzilla.suse.com/show_bug.cgi?id=1273482 * https://bugzilla.suse.com/show_bug.cgi?id=1273484 * https://bugzilla.suse.com/show_bug.cgi?id=1273488 * https://bugzilla.suse.com/show_bug.cgi?id=1273490 * https://bugzilla.suse.com/show_bug.cgi?id=1273501 * https://bugzilla.suse.com/show_bug.cgi?id=1273503 * https://bugzilla.suse.com/show_bug.cgi?id=1273504 * https://bugzilla.suse.com/show_bug.cgi?id=1273506 * https://bugzilla.suse.com/show_bug.cgi?id=1273523 * https://bugzilla.suse.com/show_bug.cgi?id=1273525 * https://bugzilla.suse.com/show_bug.cgi?id=1273533 * https://bugzilla.suse.com/show_bug.cgi?id=1273536 * https://bugzilla.suse.com/show_bug.cgi?id=1273542 * https://bugzilla.suse.com/show_bug.cgi?id=1273555 * https://bugzilla.suse.com/show_bug.cgi?id=1273578 * https://bugzilla.suse.com/show_bug.cgi?id=1273579 * https://bugzilla.suse.com/show_bug.cgi?id=1273582 * https://bugzilla.suse.com/show_bug.cgi?id=1273596 * https://bugzilla.suse.com/show_bug.cgi?id=1273597 * https://bugzilla.suse.com/show_bug.cgi?id=1273598 * https://bugzilla.suse.com/show_bug.cgi?id=1273600 * https://bugzilla.suse.com/show_bug.cgi?id=1273601 * https://bugzilla.suse.com/show_bug.cgi?id=1273602 * https://bugzilla.suse.com/show_bug.cgi?id=1273603 * https://bugzilla.suse.com/show_bug.cgi?id=1273682 * https://bugzilla.suse.com/show_bug.cgi?id=1273734 * https://bugzilla.suse.com/show_bug.cgi?id=1273738 * https://bugzilla.suse.com/show_bug.cgi?id=1273739 * https://bugzilla.suse.com/show_bug.cgi?id=1273741 * https://bugzilla.suse.com/show_bug.cgi?id=1273742 * https://bugzilla.suse.com/show_bug.cgi?id=1273743 * https://bugzilla.suse.com/show_bug.cgi?id=1273745 * https://bugzilla.suse.com/show_bug.cgi?id=1273748 * https://bugzilla.suse.com/show_bug.cgi?id=1273749 * https://bugzilla.suse.com/show_bug.cgi?id=1273755 * https://bugzilla.suse.com/show_bug.cgi?id=1273762 * https://bugzilla.suse.com/show_bug.cgi?id=1273765 * https://bugzilla.suse.com/show_bug.cgi?id=1273766 * https://bugzilla.suse.com/show_bug.cgi?id=1273769 * https://bugzilla.suse.com/show_bug.cgi?id=1273774 * https://bugzilla.suse.com/show_bug.cgi?id=1273778 * https://bugzilla.suse.com/show_bug.cgi?id=1273780 * https://bugzilla.suse.com/show_bug.cgi?id=1273790 * https://bugzilla.suse.com/show_bug.cgi?id=1273796 * https://bugzilla.suse.com/show_bug.cgi?id=1273804 * https://bugzilla.suse.com/show_bug.cgi?id=1273810 * https://bugzilla.suse.com/show_bug.cgi?id=1273811 * https://bugzilla.suse.com/show_bug.cgi?id=1273813 * https://bugzilla.suse.com/show_bug.cgi?id=1273817 * https://bugzilla.suse.com/show_bug.cgi?id=1273822 * https://bugzilla.suse.com/show_bug.cgi?id=1273824 * https://bugzilla.suse.com/show_bug.cgi?id=1273831 * https://bugzilla.suse.com/show_bug.cgi?id=1273832 * https://bugzilla.suse.com/show_bug.cgi?id=1273834 * https://bugzilla.suse.com/show_bug.cgi?id=1273838 * https://bugzilla.suse.com/show_bug.cgi?id=1273844 * https://bugzilla.suse.com/show_bug.cgi?id=1273849 * https://bugzilla.suse.com/show_bug.cgi?id=1273860 * https://bugzilla.suse.com/show_bug.cgi?id=1273862 * https://bugzilla.suse.com/show_bug.cgi?id=1273867 * https://bugzilla.suse.com/show_bug.cgi?id=1273868 * https://bugzilla.suse.com/show_bug.cgi?id=1273869 * https://bugzilla.suse.com/show_bug.cgi?id=1273872 * https://bugzilla.suse.com/show_bug.cgi?id=1273876 * https://bugzilla.suse.com/show_bug.cgi?id=1273877 * https://bugzilla.suse.com/show_bug.cgi?id=1273880 * https://bugzilla.suse.com/show_bug.cgi?id=1273882 * https://bugzilla.suse.com/show_bug.cgi?id=1273890 * https://bugzilla.suse.com/show_bug.cgi?id=1273891 * https://bugzilla.suse.com/show_bug.cgi?id=1273892 * https://bugzilla.suse.com/show_bug.cgi?id=1273895 * https://bugzilla.suse.com/show_bug.cgi?id=1273896 * https://bugzilla.suse.com/show_bug.cgi?id=1273903 * https://bugzilla.suse.com/show_bug.cgi?id=1273905 * https://bugzilla.suse.com/show_bug.cgi?id=1273930 * https://bugzilla.suse.com/show_bug.cgi?id=1273933 * https://bugzilla.suse.com/show_bug.cgi?id=1273934 * https://bugzilla.suse.com/show_bug.cgi?id=1273935 * https://bugzilla.suse.com/show_bug.cgi?id=1273936 * https://bugzilla.suse.com/show_bug.cgi?id=1273939 * https://bugzilla.suse.com/show_bug.cgi?id=1273940 * https://bugzilla.suse.com/show_bug.cgi?id=1273941 * https://bugzilla.suse.com/show_bug.cgi?id=1273942 * https://bugzilla.suse.com/show_bug.cgi?id=1273944 * https://bugzilla.suse.com/show_bug.cgi?id=1273945 * https://bugzilla.suse.com/show_bug.cgi?id=1273946 * https://bugzilla.suse.com/show_bug.cgi?id=1273956 * https://bugzilla.suse.com/show_bug.cgi?id=1273957 * https://bugzilla.suse.com/show_bug.cgi?id=1273958 * https://bugzilla.suse.com/show_bug.cgi?id=1273966 * https://bugzilla.suse.com/show_bug.cgi?id=1273967 * https://bugzilla.suse.com/show_bug.cgi?id=1273968 * https://bugzilla.suse.com/show_bug.cgi?id=1273972 * https://bugzilla.suse.com/show_bug.cgi?id=1273974 * https://bugzilla.suse.com/show_bug.cgi?id=1273975 * https://bugzilla.suse.com/show_bug.cgi?id=1273977 * https://bugzilla.suse.com/show_bug.cgi?id=1273982 * https://bugzilla.suse.com/show_bug.cgi?id=1273988 * https://bugzilla.suse.com/show_bug.cgi?id=1273990 * https://bugzilla.suse.com/show_bug.cgi?id=1273991 * https://bugzilla.suse.com/show_bug.cgi?id=1273995 * https://bugzilla.suse.com/show_bug.cgi?id=1274001 * https://bugzilla.suse.com/show_bug.cgi?id=1274003 * https://bugzilla.suse.com/show_bug.cgi?id=1274006 * https://bugzilla.suse.com/show_bug.cgi?id=1274011 * https://bugzilla.suse.com/show_bug.cgi?id=1274012 * https://bugzilla.suse.com/show_bug.cgi?id=1274014 * https://bugzilla.suse.com/show_bug.cgi?id=1274017 * https://bugzilla.suse.com/show_bug.cgi?id=1274019 * https://bugzilla.suse.com/show_bug.cgi?id=1274020 * https://bugzilla.suse.com/show_bug.cgi?id=1274026 * https://bugzilla.suse.com/show_bug.cgi?id=1274028 * https://bugzilla.suse.com/show_bug.cgi?id=1274030 * https://bugzilla.suse.com/show_bug.cgi?id=1274031 * https://bugzilla.suse.com/show_bug.cgi?id=1274035 * https://bugzilla.suse.com/show_bug.cgi?id=1274040 * https://bugzilla.suse.com/show_bug.cgi?id=1274041 * https://bugzilla.suse.com/show_bug.cgi?id=1274057 * https://bugzilla.suse.com/show_bug.cgi?id=1274058 * https://bugzilla.suse.com/show_bug.cgi?id=1274061 * https://bugzilla.suse.com/show_bug.cgi?id=1274063 * https://bugzilla.suse.com/show_bug.cgi?id=1274065 * https://bugzilla.suse.com/show_bug.cgi?id=1274067 * https://bugzilla.suse.com/show_bug.cgi?id=1274075 * https://bugzilla.suse.com/show_bug.cgi?id=1274076 * https://bugzilla.suse.com/show_bug.cgi?id=1274077 * https://bugzilla.suse.com/show_bug.cgi?id=1274078 * https://bugzilla.suse.com/show_bug.cgi?id=1274208 * https://bugzilla.suse.com/show_bug.cgi?id=1274226 * https://bugzilla.suse.com/show_bug.cgi?id=1274239 * https://bugzilla.suse.com/show_bug.cgi?id=1274243 * https://bugzilla.suse.com/show_bug.cgi?id=1274258 * https://bugzilla.suse.com/show_bug.cgi?id=1274265 * https://bugzilla.suse.com/show_bug.cgi?id=1274274 * https://bugzilla.suse.com/show_bug.cgi?id=1274277 * https://bugzilla.suse.com/show_bug.cgi?id=1274278 * https://bugzilla.suse.com/show_bug.cgi?id=1274281 * https://bugzilla.suse.com/show_bug.cgi?id=1274283 * https://bugzilla.suse.com/show_bug.cgi?id=1274286 * https://bugzilla.suse.com/show_bug.cgi?id=1274290 * https://bugzilla.suse.com/show_bug.cgi?id=1274294 * https://bugzilla.suse.com/show_bug.cgi?id=1274296 * https://bugzilla.suse.com/show_bug.cgi?id=1274297 * https://bugzilla.suse.com/show_bug.cgi?id=1274298 * https://bugzilla.suse.com/show_bug.cgi?id=1274314 * https://bugzilla.suse.com/show_bug.cgi?id=1274321 * https://bugzilla.suse.com/show_bug.cgi?id=1274491 * https://bugzilla.suse.com/show_bug.cgi?id=1274497 * https://bugzilla.suse.com/show_bug.cgi?id=1274539 * https://bugzilla.suse.com/show_bug.cgi?id=1274541 * https://bugzilla.suse.com/show_bug.cgi?id=1274543 * https://bugzilla.suse.com/show_bug.cgi?id=1274545 * https://bugzilla.suse.com/show_bug.cgi?id=1274547 * https://bugzilla.suse.com/show_bug.cgi?id=1274550 * https://bugzilla.suse.com/show_bug.cgi?id=1274573 * https://bugzilla.suse.com/show_bug.cgi?id=1274578 * https://bugzilla.suse.com/show_bug.cgi?id=1274580 * https://bugzilla.suse.com/show_bug.cgi?id=1274581 * https://bugzilla.suse.com/show_bug.cgi?id=1274620 * https://bugzilla.suse.com/show_bug.cgi?id=1274622 * https://bugzilla.suse.com/show_bug.cgi?id=1274624 * https://bugzilla.suse.com/show_bug.cgi?id=1274629 * https://bugzilla.suse.com/show_bug.cgi?id=1274632 * https://bugzilla.suse.com/show_bug.cgi?id=1274636 * https://bugzilla.suse.com/show_bug.cgi?id=1274639 * https://bugzilla.suse.com/show_bug.cgi?id=1274640 * https://bugzilla.suse.com/show_bug.cgi?id=1274642 * https://bugzilla.suse.com/show_bug.cgi?id=1274644 * https://bugzilla.suse.com/show_bug.cgi?id=1274645 * https://bugzilla.suse.com/show_bug.cgi?id=1274646 * https://bugzilla.suse.com/show_bug.cgi?id=1274649 * https://bugzilla.suse.com/show_bug.cgi?id=1274650 * https://bugzilla.suse.com/show_bug.cgi?id=1274651 * https://bugzilla.suse.com/show_bug.cgi?id=1274656 * https://bugzilla.suse.com/show_bug.cgi?id=1274659 * https://bugzilla.suse.com/show_bug.cgi?id=1274662 * https://bugzilla.suse.com/show_bug.cgi?id=1274663 * https://bugzilla.suse.com/show_bug.cgi?id=1274665 * https://bugzilla.suse.com/show_bug.cgi?id=1274667 * https://bugzilla.suse.com/show_bug.cgi?id=1274670 * https://bugzilla.suse.com/show_bug.cgi?id=1274675 * https://bugzilla.suse.com/show_bug.cgi?id=1274677 * https://bugzilla.suse.com/show_bug.cgi?id=1274678 * https://bugzilla.suse.com/show_bug.cgi?id=1274679 * https://bugzilla.suse.com/show_bug.cgi?id=1274681 * https://bugzilla.suse.com/show_bug.cgi?id=1274682 * https://bugzilla.suse.com/show_bug.cgi?id=1274690 * https://bugzilla.suse.com/show_bug.cgi?id=1274694 * https://bugzilla.suse.com/show_bug.cgi?id=1274696 * https://bugzilla.suse.com/show_bug.cgi?id=1274698 * https://bugzilla.suse.com/show_bug.cgi?id=1274699 * https://bugzilla.suse.com/show_bug.cgi?id=1274700 * https://bugzilla.suse.com/show_bug.cgi?id=1274702 * https://bugzilla.suse.com/show_bug.cgi?id=1274703 * https://bugzilla.suse.com/show_bug.cgi?id=1274705 * https://bugzilla.suse.com/show_bug.cgi?id=1274706 * https://bugzilla.suse.com/show_bug.cgi?id=1274709 * https://bugzilla.suse.com/show_bug.cgi?id=1274710 * https://bugzilla.suse.com/show_bug.cgi?id=1274713 * https://bugzilla.suse.com/show_bug.cgi?id=1274716 * https://bugzilla.suse.com/show_bug.cgi?id=1274721 * https://bugzilla.suse.com/show_bug.cgi?id=1274725 * https://bugzilla.suse.com/show_bug.cgi?id=1274737 * https://bugzilla.suse.com/show_bug.cgi?id=1274738 * https://bugzilla.suse.com/show_bug.cgi?id=1274749 * https://bugzilla.suse.com/show_bug.cgi?id=1274752 * https://bugzilla.suse.com/show_bug.cgi?id=1274753 * https://bugzilla.suse.com/show_bug.cgi?id=1274754 * https://bugzilla.suse.com/show_bug.cgi?id=1274755 * https://bugzilla.suse.com/show_bug.cgi?id=1274756 * https://bugzilla.suse.com/show_bug.cgi?id=1274764 * https://bugzilla.suse.com/show_bug.cgi?id=1274768 * https://bugzilla.suse.com/show_bug.cgi?id=1274770 * https://bugzilla.suse.com/show_bug.cgi?id=1274787 * https://bugzilla.suse.com/show_bug.cgi?id=1274800 * https://bugzilla.suse.com/show_bug.cgi?id=1274801 * https://bugzilla.suse.com/show_bug.cgi?id=1274802 * https://bugzilla.suse.com/show_bug.cgi?id=1274804 * https://bugzilla.suse.com/show_bug.cgi?id=1274805 * https://bugzilla.suse.com/show_bug.cgi?id=1274807 * https://bugzilla.suse.com/show_bug.cgi?id=1274808 * https://bugzilla.suse.com/show_bug.cgi?id=1274811 * https://bugzilla.suse.com/show_bug.cgi?id=1274813 * https://bugzilla.suse.com/show_bug.cgi?id=1274814 * https://bugzilla.suse.com/show_bug.cgi?id=1274831 * https://bugzilla.suse.com/show_bug.cgi?id=1274834 * https://bugzilla.suse.com/show_bug.cgi?id=1274847 * https://bugzilla.suse.com/show_bug.cgi?id=1274853 * https://bugzilla.suse.com/show_bug.cgi?id=1274868 * https://bugzilla.suse.com/show_bug.cgi?id=1274869 * https://bugzilla.suse.com/show_bug.cgi?id=1274872 * https://bugzilla.suse.com/show_bug.cgi?id=1274873 * https://bugzilla.suse.com/show_bug.cgi?id=1274874 * https://bugzilla.suse.com/show_bug.cgi?id=1274876 * https://bugzilla.suse.com/show_bug.cgi?id=1274879 * https://bugzilla.suse.com/show_bug.cgi?id=1274881 * https://bugzilla.suse.com/show_bug.cgi?id=1274883 * https://bugzilla.suse.com/show_bug.cgi?id=1274886 * https://bugzilla.suse.com/show_bug.cgi?id=1274888 * https://bugzilla.suse.com/show_bug.cgi?id=1274891 * https://bugzilla.suse.com/show_bug.cgi?id=1274892 * https://bugzilla.suse.com/show_bug.cgi?id=1274893 * https://bugzilla.suse.com/show_bug.cgi?id=1274894 * https://bugzilla.suse.com/show_bug.cgi?id=1274896 * https://bugzilla.suse.com/show_bug.cgi?id=1274897 * https://bugzilla.suse.com/show_bug.cgi?id=1274898 * https://bugzilla.suse.com/show_bug.cgi?id=1274899 * https://bugzilla.suse.com/show_bug.cgi?id=1274901 * https://bugzilla.suse.com/show_bug.cgi?id=1274902 * https://bugzilla.suse.com/show_bug.cgi?id=1274905 * https://bugzilla.suse.com/show_bug.cgi?id=1274907 * https://bugzilla.suse.com/show_bug.cgi?id=1274908 * https://bugzilla.suse.com/show_bug.cgi?id=1274913 * https://bugzilla.suse.com/show_bug.cgi?id=1274914 * https://bugzilla.suse.com/show_bug.cgi?id=1274920 * https://bugzilla.suse.com/show_bug.cgi?id=1274921 * https://bugzilla.suse.com/show_bug.cgi?id=1274924 * https://bugzilla.suse.com/show_bug.cgi?id=1274925 * https://bugzilla.suse.com/show_bug.cgi?id=1274929 * https://bugzilla.suse.com/show_bug.cgi?id=1274930 * https://bugzilla.suse.com/show_bug.cgi?id=1274933 * https://bugzilla.suse.com/show_bug.cgi?id=1274934 * https://bugzilla.suse.com/show_bug.cgi?id=1274935 * https://bugzilla.suse.com/show_bug.cgi?id=1274941 * https://bugzilla.suse.com/show_bug.cgi?id=1274945 * https://bugzilla.suse.com/show_bug.cgi?id=1274947 * https://bugzilla.suse.com/show_bug.cgi?id=1274951 * https://bugzilla.suse.com/show_bug.cgi?id=1274953 * https://bugzilla.suse.com/show_bug.cgi?id=1274958 * https://bugzilla.suse.com/show_bug.cgi?id=1274968 * https://bugzilla.suse.com/show_bug.cgi?id=1274981 * https://bugzilla.suse.com/show_bug.cgi?id=1275040 * https://bugzilla.suse.com/show_bug.cgi?id=1275069 * https://bugzilla.suse.com/show_bug.cgi?id=1275071 * https://bugzilla.suse.com/show_bug.cgi?id=1275073 * https://bugzilla.suse.com/show_bug.cgi?id=1275076 * https://bugzilla.suse.com/show_bug.cgi?id=1275080 * https://bugzilla.suse.com/show_bug.cgi?id=1275083 * https://bugzilla.suse.com/show_bug.cgi?id=1275088 * https://bugzilla.suse.com/show_bug.cgi?id=1275091 * https://bugzilla.suse.com/show_bug.cgi?id=1275125 * https://bugzilla.suse.com/show_bug.cgi?id=1275126 * https://bugzilla.suse.com/show_bug.cgi?id=1275131 * https://bugzilla.suse.com/show_bug.cgi?id=1275132 * https://bugzilla.suse.com/show_bug.cgi?id=1275150 * https://bugzilla.suse.com/show_bug.cgi?id=1275152 * https://bugzilla.suse.com/show_bug.cgi?id=1275154 * https://bugzilla.suse.com/show_bug.cgi?id=1275155 * https://bugzilla.suse.com/show_bug.cgi?id=1275157 * https://bugzilla.suse.com/show_bug.cgi?id=1275158 * https://bugzilla.suse.com/show_bug.cgi?id=1275161 * https://bugzilla.suse.com/show_bug.cgi?id=1275163 * https://bugzilla.suse.com/show_bug.cgi?id=1275164 * https://bugzilla.suse.com/show_bug.cgi?id=1275169 * https://bugzilla.suse.com/show_bug.cgi?id=1275173 * https://bugzilla.suse.com/show_bug.cgi?id=1275176 * https://bugzilla.suse.com/show_bug.cgi?id=1275185 * https://bugzilla.suse.com/show_bug.cgi?id=1275190 * https://bugzilla.suse.com/show_bug.cgi?id=1275236 * https://bugzilla.suse.com/show_bug.cgi?id=1275237 * https://bugzilla.suse.com/show_bug.cgi?id=1275239 * https://bugzilla.suse.com/show_bug.cgi?id=1275294 * https://bugzilla.suse.com/show_bug.cgi?id=1275301 * https://bugzilla.suse.com/show_bug.cgi?id=1275303 * https://bugzilla.suse.com/show_bug.cgi?id=1275304 * https://bugzilla.suse.com/show_bug.cgi?id=1275305 * https://bugzilla.suse.com/show_bug.cgi?id=1275306 * https://bugzilla.suse.com/show_bug.cgi?id=1275307 * https://bugzilla.suse.com/show_bug.cgi?id=1275470 * https://bugzilla.suse.com/show_bug.cgi?id=1275472 * https://bugzilla.suse.com/show_bug.cgi?id=1275474 * https://bugzilla.suse.com/show_bug.cgi?id=1275479 * https://bugzilla.suse.com/show_bug.cgi?id=1275483 * https://bugzilla.suse.com/show_bug.cgi?id=1275486 * https://bugzilla.suse.com/show_bug.cgi?id=1275487 * https://bugzilla.suse.com/show_bug.cgi?id=1275506 * https://bugzilla.suse.com/show_bug.cgi?id=1275509 * https://bugzilla.suse.com/show_bug.cgi?id=1275511 * https://bugzilla.suse.com/show_bug.cgi?id=1275517 * https://bugzilla.suse.com/show_bug.cgi?id=1275528 * https://bugzilla.suse.com/show_bug.cgi?id=1275535 * https://bugzilla.suse.com/show_bug.cgi?id=1275540 * https://bugzilla.suse.com/show_bug.cgi?id=1275553 * https://bugzilla.suse.com/show_bug.cgi?id=1275555 * https://bugzilla.suse.com/show_bug.cgi?id=1275561 * https://bugzilla.suse.com/show_bug.cgi?id=1275566 * https://bugzilla.suse.com/show_bug.cgi?id=1275569 * https://bugzilla.suse.com/show_bug.cgi?id=1275574 * https://bugzilla.suse.com/show_bug.cgi?id=1275578 * https://bugzilla.suse.com/show_bug.cgi?id=1275582 * https://bugzilla.suse.com/show_bug.cgi?id=1275583 * https://bugzilla.suse.com/show_bug.cgi?id=1275584 * https://bugzilla.suse.com/show_bug.cgi?id=1275591 * https://bugzilla.suse.com/show_bug.cgi?id=1275595 * https://bugzilla.suse.com/show_bug.cgi?id=1275633 * https://bugzilla.suse.com/show_bug.cgi?id=1275636 * https://bugzilla.suse.com/show_bug.cgi?id=1275650 * https://bugzilla.suse.com/show_bug.cgi?id=1275659 * https://bugzilla.suse.com/show_bug.cgi?id=1275665 * https://bugzilla.suse.com/show_bug.cgi?id=1275669 * https://bugzilla.suse.com/show_bug.cgi?id=1275687 * https://bugzilla.suse.com/show_bug.cgi?id=1275688 * https://bugzilla.suse.com/show_bug.cgi?id=1275695 * https://bugzilla.suse.com/show_bug.cgi?id=1275696 * https://bugzilla.suse.com/show_bug.cgi?id=1275704 * https://bugzilla.suse.com/show_bug.cgi?id=1275782 * https://bugzilla.suse.com/show_bug.cgi?id=1275784 * https://bugzilla.suse.com/show_bug.cgi?id=1275787 * https://bugzilla.suse.com/show_bug.cgi?id=1275788 * https://bugzilla.suse.com/show_bug.cgi?id=1275790 * https://bugzilla.suse.com/show_bug.cgi?id=1275797 * https://bugzilla.suse.com/show_bug.cgi?id=1275798 * https://bugzilla.suse.com/show_bug.cgi?id=1275805 * https://bugzilla.suse.com/show_bug.cgi?id=1275817 * https://bugzilla.suse.com/show_bug.cgi?id=1275818 * https://bugzilla.suse.com/show_bug.cgi?id=1275819 * https://bugzilla.suse.com/show_bug.cgi?id=1275820 * https://bugzilla.suse.com/show_bug.cgi?id=1275821 * https://bugzilla.suse.com/show_bug.cgi?id=1275827 * https://bugzilla.suse.com/show_bug.cgi?id=1275864 * https://bugzilla.suse.com/show_bug.cgi?id=1275867 * https://bugzilla.suse.com/show_bug.cgi?id=1275869 * https://bugzilla.suse.com/show_bug.cgi?id=1275870 * https://bugzilla.suse.com/show_bug.cgi?id=1275871 * https://bugzilla.suse.com/show_bug.cgi?id=1275872 * https://bugzilla.suse.com/show_bug.cgi?id=1275886 * https://bugzilla.suse.com/show_bug.cgi?id=1275905 * https://bugzilla.suse.com/show_bug.cgi?id=1275923 * https://bugzilla.suse.com/show_bug.cgi?id=1275925 * https://bugzilla.suse.com/show_bug.cgi?id=1275946 * https://bugzilla.suse.com/show_bug.cgi?id=1275950 * https://bugzilla.suse.com/show_bug.cgi?id=1275954 * https://bugzilla.suse.com/show_bug.cgi?id=1275970 * https://bugzilla.suse.com/show_bug.cgi?id=1275973 * https://bugzilla.suse.com/show_bug.cgi?id=1275975 * https://bugzilla.suse.com/show_bug.cgi?id=1275976 * https://bugzilla.suse.com/show_bug.cgi?id=1276029 * https://bugzilla.suse.com/show_bug.cgi?id=1276257 * https://bugzilla.suse.com/show_bug.cgi?id=1276263 * https://bugzilla.suse.com/show_bug.cgi?id=1276270 * https://bugzilla.suse.com/show_bug.cgi?id=1276273 * https://bugzilla.suse.com/show_bug.cgi?id=1276277 * https://bugzilla.suse.com/show_bug.cgi?id=1276335 * https://bugzilla.suse.com/show_bug.cgi?id=1276346 * https://bugzilla.suse.com/show_bug.cgi?id=1276350 * https://bugzilla.suse.com/show_bug.cgi?id=1276355 * https://bugzilla.suse.com/show_bug.cgi?id=1276446 * https://bugzilla.suse.com/show_bug.cgi?id=1276452 * https://bugzilla.suse.com/show_bug.cgi?id=1276500 * https://bugzilla.suse.com/show_bug.cgi?id=1276507 * https://bugzilla.suse.com/show_bug.cgi?id=1276542 * https://bugzilla.suse.com/show_bug.cgi?id=1276546 * https://bugzilla.suse.com/show_bug.cgi?id=1276551 * https://bugzilla.suse.com/show_bug.cgi?id=1276561 * https://bugzilla.suse.com/show_bug.cgi?id=1276569 * https://bugzilla.suse.com/show_bug.cgi?id=1276665 * https://bugzilla.suse.com/show_bug.cgi?id=1276864 * https://bugzilla.suse.com/show_bug.cgi?id=1276927 * https://bugzilla.suse.com/show_bug.cgi?id=1276931 * https://bugzilla.suse.com/show_bug.cgi?id=1276937 * https://bugzilla.suse.com/show_bug.cgi?id=1276941 * https://bugzilla.suse.com/show_bug.cgi?id=1276943 * https://bugzilla.suse.com/show_bug.cgi?id=1276961 * https://bugzilla.suse.com/show_bug.cgi?id=1277022 * https://bugzilla.suse.com/show_bug.cgi?id=1277034 * https://bugzilla.suse.com/show_bug.cgi?id=1277037 * https://bugzilla.suse.com/show_bug.cgi?id=1277047 * https://bugzilla.suse.com/show_bug.cgi?id=1277054 * https://bugzilla.suse.com/show_bug.cgi?id=1277057 * https://bugzilla.suse.com/show_bug.cgi?id=1277059 * https://bugzilla.suse.com/show_bug.cgi?id=1277064 * https://bugzilla.suse.com/show_bug.cgi?id=1277066 * https://bugzilla.suse.com/show_bug.cgi?id=1277069 * https://bugzilla.suse.com/show_bug.cgi?id=1277073 * https://bugzilla.suse.com/show_bug.cgi?id=1277077 * https://bugzilla.suse.com/show_bug.cgi?id=1277095 * https://bugzilla.suse.com/show_bug.cgi?id=1277155 * https://bugzilla.suse.com/show_bug.cgi?id=1277159 * https://bugzilla.suse.com/show_bug.cgi?id=1277160 * https://bugzilla.suse.com/show_bug.cgi?id=1277202 * https://bugzilla.suse.com/show_bug.cgi?id=1277204 * https://bugzilla.suse.com/show_bug.cgi?id=1277275 * https://bugzilla.suse.com/show_bug.cgi?id=1277285 * https://bugzilla.suse.com/show_bug.cgi?id=1277391 * https://bugzilla.suse.com/show_bug.cgi?id=1277408 * https://bugzilla.suse.com/show_bug.cgi?id=1277516 * https://bugzilla.suse.com/show_bug.cgi?id=1277523 * https://bugzilla.suse.com/show_bug.cgi?id=1277551 * https://bugzilla.suse.com/show_bug.cgi?id=1277625 * https://bugzilla.suse.com/show_bug.cgi?id=1277660 * https://bugzilla.suse.com/show_bug.cgi?id=1277678 * https://bugzilla.suse.com/show_bug.cgi?id=1277688 * https://bugzilla.suse.com/show_bug.cgi?id=1277775 * https://bugzilla.suse.com/show_bug.cgi?id=1277776 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:38:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:38:01 -0000 Subject: SUSE-SU-2026:23476-1: moderate: Security update for multipath-tools Message-ID: <178896108162.1855.14258905777599353693@aaf27ed6f0fb> # Security update for multipath-tools Announcement ID: SUSE-SU-2026:23476-1 Release Date: 2026-09-08T09:53:36Z Rating: moderate References: * bsc#1277199 * bsc#1277203 * bsc#1277205 * bsc#1277208 * bsc#1277209 * bsc#1277210 * bsc#1277212 Affected Products: * SUSE Linux Micro 6.0 An update that has seven fixes can now be installed. ## Description: This update for multipath-tools fixes the following issues: * Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205). * Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210). * SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212). * Local Denial of Service via Blocking IPC Send Operations (bsc#1277199). * Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209). * DoS on multipathd socket by exhausting connections (bsc#1277203). * Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208). Changes for multipath-tools: * Update to version 0.9.8+312+suse.c6cbd08. * Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-886=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * multipath-tools-debuginfo-0.9.8+312+suse.c6cbd08-1.1 * multipath-tools-0.9.8+312+suse.c6cbd08-1.1 * kpartx-debuginfo-0.9.8+312+suse.c6cbd08-1.1 * libmpath0-debuginfo-0.9.8+312+suse.c6cbd08-1.1 * kpartx-0.9.8+312+suse.c6cbd08-1.1 * libmpath0-0.9.8+312+suse.c6cbd08-1.1 * multipath-tools-debugsource-0.9.8+312+suse.c6cbd08-1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1277199 * https://bugzilla.suse.com/show_bug.cgi?id=1277203 * https://bugzilla.suse.com/show_bug.cgi?id=1277205 * https://bugzilla.suse.com/show_bug.cgi?id=1277208 * https://bugzilla.suse.com/show_bug.cgi?id=1277209 * https://bugzilla.suse.com/show_bug.cgi?id=1277210 * https://bugzilla.suse.com/show_bug.cgi?id=1277212 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:38:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:38:41 -0000 Subject: SUSE-SU-2026:23475-1: important: Security update for NetworkManager Message-ID: <178896112182.1855.9676402194019509652@aaf27ed6f0fb> # Security update for NetworkManager Announcement ID: SUSE-SU-2026:23475-1 Release Date: 2026-09-08T09:53:36Z Rating: important References: * bsc#1267696 * bsc#1276764 Cross-References: * CVE-2026-10805 * CVE-2026-19685 CVSS scores: * CVE-2026-10805 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-10805 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19685 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-19685 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-19685 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19685 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for NetworkManager fixes the following issues: * CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). * CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-885=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libnm0-1.42.6-9.1 * NetworkManager-debugsource-1.42.6-9.1 * NetworkManager-bluetooth-debuginfo-1.42.6-9.1 * libnm0-debuginfo-1.42.6-9.1 * NetworkManager-pppoe-1.42.6-9.1 * NetworkManager-tui-debuginfo-1.42.6-9.1 * typelib-1_0-NM-1_0-1.42.6-9.1 * NetworkManager-1.42.6-9.1 * NetworkManager-bluetooth-1.42.6-9.1 * NetworkManager-cloud-setup-1.42.6-9.1 * NetworkManager-cloud-setup-debuginfo-1.42.6-9.1 * NetworkManager-debuginfo-1.42.6-9.1 * NetworkManager-tui-1.42.6-9.1 * NetworkManager-wwan-1.42.6-9.1 * NetworkManager-pppoe-debuginfo-1.42.6-9.1 * NetworkManager-wwan-debuginfo-1.42.6-9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10805.html * https://www.suse.com/security/cve/CVE-2026-19685.html * https://bugzilla.suse.com/show_bug.cgi?id=1267696 * https://bugzilla.suse.com/show_bug.cgi?id=1276764 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:39:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:39:49 -0000 Subject: SUSE-SU-2026:23473-1: important: Security update for openssl-3 Message-ID: <178896118987.1855.17221185260904191407@aaf27ed6f0fb> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:23473-1 Release Date: 2026-09-04T09:14:01Z Rating: important References: * bsc#1274774 * bsc#1274788 * bsc#1274790 * bsc#1274795 * bsc#1274797 * bsc#1275837 Cross-References: * CVE-2026-54874 * CVE-2026-63072 * CVE-2026-63074 * CVE-2026-63076 * CVE-2026-75803 CVSS scores: * CVE-2026-54874 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-54874 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63074 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63074 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-75803 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-75803 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for openssl-3 fixes the following issues: August 2026 release. * CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). * CVE-2026-54874: excessive memory use when buffering DTLS records for a future epoch (bsc#1274795). * CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). * CVE-2026-63074: unbounded growth of `extraCerts` cache in the CMP server (bsc#1274797). * CVE-2026-63076: invalid pointer dereference in the CMP server via crafted `protectionAlg` (bsc#1274790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-882=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libopenssl3-debuginfo-3.1.4-17.1 * libopenssl-3-devel-3.1.4-17.1 * openssl-3-debuginfo-3.1.4-17.1 * openssl-3-debugsource-3.1.4-17.1 * libopenssl-3-fips-provider-debuginfo-3.1.4-17.1 * openssl-3-3.1.4-17.1 * libopenssl-3-fips-provider-3.1.4-17.1 * libopenssl3-3.1.4-17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54874.html * https://www.suse.com/security/cve/CVE-2026-63072.html * https://www.suse.com/security/cve/CVE-2026-63074.html * https://www.suse.com/security/cve/CVE-2026-63076.html * https://www.suse.com/security/cve/CVE-2026-75803.html * https://bugzilla.suse.com/show_bug.cgi?id=1274774 * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1274790 * https://bugzilla.suse.com/show_bug.cgi?id=1274795 * https://bugzilla.suse.com/show_bug.cgi?id=1274797 * https://bugzilla.suse.com/show_bug.cgi?id=1275837 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:40:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:40:53 -0000 Subject: SUSE-SU-2026:23455-1: moderate: Security update for wget Message-ID: <178896125317.1855.10211336426207488415@aaf27ed6f0fb> # Security update for wget Announcement ID: SUSE-SU-2026:23455-1 Release Date: 2026-09-04T08:19:02Z Rating: moderate References: * bsc#1276962 Cross-References: * CVE-2026-16599 CVSS scores: * CVE-2026-16599 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-16599 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-16599 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for wget fixes the following issue: * CVE-2026-16599: server-controlled unbounded MD5 loop in FTP OPIE (bsc#1276962). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-880=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * wget-debugsource-1.24.5-5.1 * wget-1.24.5-5.1 * wget-debuginfo-1.24.5-5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16599.html * https://bugzilla.suse.com/show_bug.cgi?id=1276962 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:41:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:41:40 -0000 Subject: SUSE-SU-2026:23470-1: moderate: Security update for systemd Message-ID: <178896130054.1855.3100532495905313301@aaf27ed6f0fb> # Security update for systemd Announcement ID: SUSE-SU-2026:23470-1 Release Date: 2026-09-03T20:25:16Z Rating: moderate References: * bsc#1237515 * bsc#1254924 * bsc#1259418 * bsc#1259650 * bsc#1261400 * bsc#1271444 Cross-References: * CVE-2026-16742 * CVE-2026-29111 * CVE-2026-40226 * CVE-2026-4105 CVSS scores: * CVE-2026-16742 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16742 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-29111 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-29111 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-29111 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40226 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-40226 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40226 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4105 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-4105 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4105 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves four vulnerabilities and has two fixes can now be installed. ## Description: This update for systemd fixes the following issue: Security issue fixed: * CVE-2026-16742: `systemd-homed`: local privilege escalation due to missing home record signature verification on the authentication path (bsc#1271444). Non security issue fixed: * `systemd-resolved` fails to start due to write access to `tmpfs` denied (bsc#1237515). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1602=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libudev1-257.13-160000.4.1 * systemd-experimental-debuginfo-257.13-160000.4.1 * libsystemd0-257.13-160000.4.1 * libudev1-debuginfo-257.13-160000.4.1 * systemd-experimental-257.13-160000.4.1 * udev-debuginfo-257.13-160000.4.1 * systemd-portable-debuginfo-257.13-160000.4.1 * systemd-container-257.13-160000.4.1 * systemd-container-debuginfo-257.13-160000.4.1 * systemd-debuginfo-257.13-160000.4.1 * systemd-debugsource-257.13-160000.4.1 * udev-257.13-160000.4.1 * systemd-portable-257.13-160000.4.1 * systemd-journal-remote-debuginfo-257.13-160000.4.1 * systemd-257.13-160000.4.1 * systemd-journal-remote-257.13-160000.4.1 * libsystemd0-debuginfo-257.13-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16742.html * https://www.suse.com/security/cve/CVE-2026-29111.html * https://www.suse.com/security/cve/CVE-2026-40226.html * https://www.suse.com/security/cve/CVE-2026-4105.html * https://bugzilla.suse.com/show_bug.cgi?id=1237515 * https://bugzilla.suse.com/show_bug.cgi?id=1254924 * https://bugzilla.suse.com/show_bug.cgi?id=1259418 * https://bugzilla.suse.com/show_bug.cgi?id=1259650 * https://bugzilla.suse.com/show_bug.cgi?id=1261400 * https://bugzilla.suse.com/show_bug.cgi?id=1271444 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:42:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:42:19 -0000 Subject: SUSE-SU-2026:23469-1: moderate: Security update for fuse-overlayfs Message-ID: <178896133943.1855.10824183826318116531@aaf27ed6f0fb> # Security update for fuse-overlayfs Announcement ID: SUSE-SU-2026:23469-1 Release Date: 2026-09-03T20:11:38Z Rating: moderate References: * bsc#1273100 Cross-References: * CVE-2026-52791 CVSS scores: * CVE-2026-52791 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-52791 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-52791 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for fuse-overlayfs fixes the following issue: * CVE-2026-52791: privilege escalation due to SUID/SGID bit preservation after truncate operation (bsc#1273100). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1601=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * fuse-overlayfs-debuginfo-1.15-160000.3.1 * fuse-overlayfs-debugsource-1.15-160000.3.1 * fuse-overlayfs-1.15-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-52791.html * https://bugzilla.suse.com/show_bug.cgi?id=1273100 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:43:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:43:43 -0000 Subject: SUSE-SU-2026:23466-1: important: Security update for dracut Message-ID: <178896142328.1855.4223633290378769144@aaf27ed6f0fb> # Security update for dracut Announcement ID: SUSE-SU-2026:23466-1 Release Date: 2026-09-03T16:43:28Z Rating: important References: * bsc#1268322 * bsc#1273580 Cross-References: * CVE-2026-16445 * CVE-2026-6893 CVSS scores: * CVE-2026-16445 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16445 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for dracut fixes the following issues: Update to version 059+suse.730.g73d3411aa. * CVE-2026-6893: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` (bsc#1268322). * CVE-2026-16445: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` during system boot (bsc#1273580). Changes for dracut: * Update to version 059+suse.730.g73d3411aa: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1597=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * dracut-fips-059+suse.730.g73d3411aa-160000.1.1 * dracut-debuginfo-059+suse.730.g73d3411aa-160000.1.1 * dracut-debugsource-059+suse.730.g73d3411aa-160000.1.1 * dracut-059+suse.730.g73d3411aa-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16445.html * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 * https://bugzilla.suse.com/show_bug.cgi?id=1273580 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:44:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:44:28 -0000 Subject: SUSE-SU-2026:23465-1: moderate: Security update for sssd Message-ID: <178896146805.1855.7078551783906159546@aaf27ed6f0fb> # Security update for sssd Announcement ID: SUSE-SU-2026:23465-1 Release Date: 2026-09-03T16:43:28Z Rating: moderate References: * bsc#1273009 * bsc#1273922 * bsc#1273924 * bsc#1273925 * bsc#1274748 Cross-References: * CVE-2026-68742 * CVE-2026-68743 * CVE-2026-68744 CVSS scores: * CVE-2026-68742 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68742 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68742 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68743 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68743 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68743 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68743 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68744 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68744 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-68744 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities and has two fixes can now be installed. ## Description: This update for sssd fixes the following issues: Security issues fixed: * CVE-2026-68742: insufficient validation in the NSS responder can lead to an out-of-bounds read and a process crash when a crafted GETHOSTBYADDR request is sent to the NSS responder socket (bsc#1273922). * CVE-2026-68743: insufficient validation in the PAM responder can lead to an out-of-bounds read and a process crash when a crafted protocol v1 request is processed (bsc#1273925). * CVE-2026-68744: improper memory management in the NSS responder can lead to uninitialized heap memory disclosure from the `sssd_nss` process (bsc#1273924). Other updates and bugfixes: * Add `systemd-tmpfiles` configuration file to populate `/var/lib/sss` with the correct permissions on transactional servers (bsc#1274748). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1596=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * sssd-debugsource-2.10.2-160000.5.1 * sssd-tools-debuginfo-2.10.2-160000.5.1 * sssd-ad-2.10.2-160000.5.1 * sssd-2.10.2-160000.5.1 * libsss_idmap0-2.10.2-160000.5.1 * sssd-dbus-debuginfo-2.10.2-160000.5.1 * sssd-debuginfo-2.10.2-160000.5.1 * sssd-krb5-debuginfo-2.10.2-160000.5.1 * libsss_certmap0-2.10.2-160000.5.1 * sssd-dbus-2.10.2-160000.5.1 * libsss_certmap0-debuginfo-2.10.2-160000.5.1 * sssd-ldap-2.10.2-160000.5.1 * libsss_idmap0-debuginfo-2.10.2-160000.5.1 * sssd-krb5-common-debuginfo-2.10.2-160000.5.1 * sssd-ad-debuginfo-2.10.2-160000.5.1 * sssd-krb5-2.10.2-160000.5.1 * sssd-tools-2.10.2-160000.5.1 * python3-sssd-config-2.10.2-160000.5.1 * python3-sssd-config-debuginfo-2.10.2-160000.5.1 * sssd-ldap-debuginfo-2.10.2-160000.5.1 * sssd-krb5-common-2.10.2-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-68742.html * https://www.suse.com/security/cve/CVE-2026-68743.html * https://www.suse.com/security/cve/CVE-2026-68744.html * https://bugzilla.suse.com/show_bug.cgi?id=1273009 * https://bugzilla.suse.com/show_bug.cgi?id=1273922 * https://bugzilla.suse.com/show_bug.cgi?id=1273924 * https://bugzilla.suse.com/show_bug.cgi?id=1273925 * https://bugzilla.suse.com/show_bug.cgi?id=1274748 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:45:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:45:10 -0000 Subject: SUSE-SU-2026:23464-1: moderate: Security update for cpio Message-ID: <178896151024.1855.9787202470999256306@aaf27ed6f0fb> # Security update for cpio Announcement ID: SUSE-SU-2026:23464-1 Release Date: 2026-09-03T14:47:37Z Rating: moderate References: * bsc#1274856 * bsc#1274857 * bsc#1274858 Cross-References: * CVE-2026-66484 * CVE-2026-66485 * CVE-2026-66486 CVSS scores: * CVE-2026-66484 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-66484 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66485 ( SUSE ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-66485 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66486 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-66486 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities can now be installed. ## Description: This update for cpio fixes the following issues: * CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). * CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). * CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1595=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * cpio-debugsource-2.15-160000.3.1 * cpio-debuginfo-2.15-160000.3.1 * cpio-2.15-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-66484.html * https://www.suse.com/security/cve/CVE-2026-66485.html * https://www.suse.com/security/cve/CVE-2026-66486.html * https://bugzilla.suse.com/show_bug.cgi?id=1274856 * https://bugzilla.suse.com/show_bug.cgi?id=1274857 * https://bugzilla.suse.com/show_bug.cgi?id=1274858 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:46:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:46:04 -0000 Subject: SUSE-SU-2026:23463-1: important: Security update for openssl-3 Message-ID: <178896156469.1855.14519649104288591752@aaf27ed6f0fb> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:23463-1 Release Date: 2026-09-02T16:08:23Z Rating: important References: * bsc#1266343 * bsc#1274774 * bsc#1274777 * bsc#1274788 * bsc#1274790 * bsc#1274791 * bsc#1274792 * bsc#1274795 * bsc#1274796 * bsc#1274797 * bsc#1274798 * bsc#1275837 Cross-References: * CVE-2026-14456 * CVE-2026-14457 * CVE-2026-18798 * CVE-2026-34181 * CVE-2026-54874 * CVE-2026-63072 * CVE-2026-63073 * CVE-2026-63074 * CVE-2026-63075 * CVE-2026-63076 * CVE-2026-75803 CVSS scores: * CVE-2026-14456 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-14456 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-14457 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-14457 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-18798 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-18798 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34181 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34181 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-34181 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54874 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-54874 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63073 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-63073 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63074 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63074 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63075 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63075 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-75803 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-75803 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves 11 vulnerabilities and has one fix can now be installed. ## Description: This update for openssl-3 fixes the following issues: August 2026 release. * CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). * CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). * CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). * CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). * CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). * CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). * CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). * CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). * CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). * CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). * CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1592=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libopenssl-3-fips-provider-debuginfo-3.5.0-160000.10.1 * openssl-3-3.5.0-160000.10.1 * libopenssl-3-fips-provider-3.5.0-160000.10.1 * openssl-3-debugsource-3.5.0-160000.10.1 * libopenssl3-3.5.0-160000.10.1 * libopenssl3-debuginfo-3.5.0-160000.10.1 * libopenssl-3-devel-3.5.0-160000.10.1 * openssl-3-debuginfo-3.5.0-160000.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14456.html * https://www.suse.com/security/cve/CVE-2026-14457.html * https://www.suse.com/security/cve/CVE-2026-18798.html * https://www.suse.com/security/cve/CVE-2026-34181.html * https://www.suse.com/security/cve/CVE-2026-54874.html * https://www.suse.com/security/cve/CVE-2026-63072.html * https://www.suse.com/security/cve/CVE-2026-63073.html * https://www.suse.com/security/cve/CVE-2026-63074.html * https://www.suse.com/security/cve/CVE-2026-63075.html * https://www.suse.com/security/cve/CVE-2026-63076.html * https://www.suse.com/security/cve/CVE-2026-75803.html * https://bugzilla.suse.com/show_bug.cgi?id=1266343 * https://bugzilla.suse.com/show_bug.cgi?id=1274774 * https://bugzilla.suse.com/show_bug.cgi?id=1274777 * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1274790 * https://bugzilla.suse.com/show_bug.cgi?id=1274791 * https://bugzilla.suse.com/show_bug.cgi?id=1274792 * https://bugzilla.suse.com/show_bug.cgi?id=1274795 * https://bugzilla.suse.com/show_bug.cgi?id=1274796 * https://bugzilla.suse.com/show_bug.cgi?id=1274797 * https://bugzilla.suse.com/show_bug.cgi?id=1274798 * https://bugzilla.suse.com/show_bug.cgi?id=1275837 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:47:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:47:33 -0000 Subject: SUSE-SU-2026:23460-1: important: Security update for libvirt Message-ID: <178896165327.1855.3993594051342031583@aaf27ed6f0fb> # Security update for libvirt Announcement ID: SUSE-SU-2026:23460-1 Release Date: 2026-09-02T09:44:39Z Rating: important References: * bsc#1274576 * bsc#1274946 * bsc#1275264 * bsc#1275265 * bsc#1275863 Cross-References: * CVE-2026-18917 * CVE-2026-61477 * CVE-2026-63622 * CVE-2026-63623 * CVE-2026-77159 CVSS scores: * CVE-2026-18917 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-18917 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-61477 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-61477 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61477 ( NVD ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-63622 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63622 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63622 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63623 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-63623 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-63623 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-77159 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-77159 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves five vulnerabilities can now be installed. ## Description: This update for libvirt fixes the following issues: * CVE-2026-18917: integer overflow in `NodeGetFreePages` RPC handler leads to heap buffer overflow and allows for possible local privilege escalation (bsc#1275863). * CVE-2026-61477: newline injection in network XML DNS TXT/SRV fields allows for `dnsmasq` configuration directive injection and can lead to arbitrary code execution as root (bsc#1274576). * CVE-2026-63622: symlink-following in `virFileChownFiles()` allows `swtpm` user to trick the root-level `libvirt` daemon into changing the ownership of an arbitrary file and can lead to privilege escalation (bsc#1275264). * CVE-2026-63623: newly created volume images are temporarily world-readable during clone/convert operations, which can lead to sensitive information disclosure (bsc#1275265). * CVE-2026-77159: root `chown()` on `swtpm` logfile follows symlinks and allows for root-owned file ownership changes, which can lead to privilege escalation (bsc#1274946). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1586=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libvirt-daemon-driver-storage-logical-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-proxy-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-11.4.0-160000.5.1 * libvirt-daemon-plugin-lockd-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-mpath-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-disk-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-common-11.4.0-160000.5.1 * libvirt-daemon-plugin-lockd-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-logical-11.4.0-160000.5.1 * libvirt-daemon-driver-network-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-core-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-iscsi-11.4.0-160000.5.1 * libvirt-libs-11.4.0-160000.5.1 * libvirt-libs-debuginfo-11.4.0-160000.5.1 * libvirt-client-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-nodedev-11.4.0-160000.5.1 * libvirt-daemon-qemu-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-core-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-nodedev-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-iscsi-direct-11.4.0-160000.5.1 * libvirt-daemon-driver-qemu-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-scsi-11.4.0-160000.5.1 * libvirt-daemon-log-11.4.0-160000.5.1 * libvirt-daemon-lock-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-scsi-debuginfo-11.4.0-160000.5.1 * libvirt-nss-11.4.0-160000.5.1 * libvirt-daemon-lock-11.4.0-160000.5.1 * libvirt-daemon-log-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-nwfilter-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-disk-11.4.0-160000.5.1 * libvirt-daemon-driver-secret-11.4.0-160000.5.1 * libvirt-daemon-config-nwfilter-11.4.0-160000.5.1 * libvirt-daemon-driver-nwfilter-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-qemu-11.4.0-160000.5.1 * libvirt-daemon-hooks-11.4.0-160000.5.1 * libvirt-daemon-proxy-debuginfo-11.4.0-160000.5.1 * libvirt-nss-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-mpath-debuginfo-11.4.0-160000.5.1 * libvirt-client-qemu-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-11.4.0-160000.5.1 * libvirt-debugsource-11.4.0-160000.5.1 * libvirt-daemon-config-network-11.4.0-160000.5.1 * libvirt-daemon-driver-network-debuginfo-11.4.0-160000.5.1 * libvirt-client-11.4.0-160000.5.1 * libvirt-daemon-driver-secret-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-common-debuginfo-11.4.0-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-18917.html * https://www.suse.com/security/cve/CVE-2026-61477.html * https://www.suse.com/security/cve/CVE-2026-63622.html * https://www.suse.com/security/cve/CVE-2026-63623.html * https://www.suse.com/security/cve/CVE-2026-77159.html * https://bugzilla.suse.com/show_bug.cgi?id=1274576 * https://bugzilla.suse.com/show_bug.cgi?id=1274946 * https://bugzilla.suse.com/show_bug.cgi?id=1275264 * https://bugzilla.suse.com/show_bug.cgi?id=1275265 * https://bugzilla.suse.com/show_bug.cgi?id=1275863 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:50:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:50:27 -0000 Subject: SUSE-SU-2026:23459-1: important: Security update for ucode-intel Message-ID: <178896182775.1855.14940250325867593709@aaf27ed6f0fb> # Security update for ucode-intel Announcement ID: SUSE-SU-2026:23459-1 Release Date: 2026-09-02T09:34:17Z Rating: important References: * bsc#1265189 * bsc#1274785 Cross-References: * CVE-2025-31936 * CVE-2025-31938 * CVE-2025-35973 * CVE-2025-35979 * CVE-2026-20707 * CVE-2026-20713 * CVE-2026-20716 * CVE-2026-20760 * CVE-2026-20901 * CVE-2026-20917 CVSS scores: * CVE-2025-31936 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31936 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2025-31936 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31938 ( SUSE ): 4.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31938 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2025-31938 ( NVD ): 4.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35973 ( SUSE ): 4.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35973 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N * CVE-2025-35973 ( NVD ): 4.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35979 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35979 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-35979 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20707 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20707 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-20707 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20713 ( SUSE ): 4.5 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20713 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N * CVE-2026-20713 ( NVD ): 4.5 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( SUSE ): 7.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-20716 ( NVD ): 7.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20760 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20760 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20760 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20901 ( NVD ): 4.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20901 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N * CVE-2026-20917 ( SUSE ): 4.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20917 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2026-20917 ( NVD ): 4.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.2 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for ucode-intel fixes the following issues: * Intel CPU Microcode was updated to the 20260812 release (bsc#1274785) * Removed MTL/06-aa-04/c0 due to functional issues observed when loading the MCU in some platforms. * Intel CPU Microcode was updated to the 20260811 release (bsc#1274785) * Security updates for INTEL-SA-01379 / CVE-2025-31936 * Security updates for INTEL-SA-01404 / CVE-2025-31938 * Security updates for INTEL-SA-01423 / CVE-2026-20917 * Security updates for INTEL-SA-01428 / CVE-2025-35973 * Security updates for INTEL-SA-01435 / CVE-2026-20716 * Security updates for INTEL-SA-01441 / CVE-2026-20760 * Security updates for INTEL-SA-01442 / CVE-2026-20713 / CVE-2026-20901 * Security updates for INTEL-SA-01443 / CVE-2026-20707 * Update for functional issues. * Intel CPU Microcode was updated to the 20260512 release (bsc#1265189) * CVE-2025-35979: Security updates for INTEL-SA-01420 * https://www.intel.com/content/www/us/en/security-center/advisory/intel- sa-01420.html * Update for various functional issues. ##### New Platforms Processor Stepping F-M-S/PI Old Ver New Ver Products PTL 404 A1 06-cc-03/90 0000011b Intel Core Ultra Processor (Series 3) PTL-H 484/12Xe A0/B0 06-cc-02/90 0000011b Intel Core Ultra Processor (Series 3) ##### Updated Platforms Processor Stepping F-M-S/PI Old Ver New Ver Products :--------------- :--------- :------------ :--------- :--------- :--------- ARL-H A1 06-c5-02/82 0000011b 00000121 Core Ultra Processor (Series 2) ARL-S/HX (8P) B0 06-c6-02/82 0000011b 00000121 Core Ultra Processor (Series 2) EMR-SP A1 06-cf-02/87 210002d3 210002e0 Xeon Scalable Gen5 GNR-AP/SP Bx/Hx/Lx 06-ad-01/95 01000405 01000423 Xeon 6900/6700/6500 Series Processors with P-Cores GNR-D B0/B1 06-ae-01/97 01000303 01000307 Xeon 6700P-B/6500P-B Series SoC with P-Cores GNR-SP R1S Bx/Hx/Lx 06-ad-01/20 0a000133 0a000142 Xeon 6700/6500-Series Processors with P-Cores LNL B0 06-bd-01/80 00000125 00000126 Core Ultra 200 V Series Processor SPR-SP E4/S2 06-8f-07/87 2b000661 2b000670 Xeon Scalable Gen4 SPR-SP E5/S3 06-8f-08/87 2b000661 2b000670 Xeon Scalable Gen4 SRF-AP/SP C0 06-af-03/01 03000382 030003a3 Xeon 6900/6700-Series Processors with E-Cores * Update to microcode-20260227: * Update for functional issues. Refer to Intel? Xeon? 6700P-B/6500P-B-Series SoC with P-Cores for details. ##### Updated Platforms Processor Stepping F-M-S/PI Old Ver New Ver Products GNR-D B0/B1 06-ae-01/97 010002f3 01000303 Xeon 6700P-B/6500P-B Series SoC with P-Cores ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1584=1 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * ucode-intel-20260812-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-31936.html * https://www.suse.com/security/cve/CVE-2025-31938.html * https://www.suse.com/security/cve/CVE-2025-35973.html * https://www.suse.com/security/cve/CVE-2025-35979.html * https://www.suse.com/security/cve/CVE-2026-20707.html * https://www.suse.com/security/cve/CVE-2026-20713.html * https://www.suse.com/security/cve/CVE-2026-20716.html * https://www.suse.com/security/cve/CVE-2026-20760.html * https://www.suse.com/security/cve/CVE-2026-20901.html * https://www.suse.com/security/cve/CVE-2026-20917.html * https://bugzilla.suse.com/show_bug.cgi?id=1265189 * https://bugzilla.suse.com/show_bug.cgi?id=1274785 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:53:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:53:13 -0000 Subject: SUSE-SU-2026:23454-1: moderate: Security update for systemd Message-ID: <178896199378.1855.11223897744666327115@aaf27ed6f0fb> # Security update for systemd Announcement ID: SUSE-SU-2026:23454-1 Release Date: 2026-09-03T20:37:44Z Rating: moderate References: * bsc#1237515 * bsc#1254924 * bsc#1259418 * bsc#1259650 * bsc#1261400 * bsc#1271444 Cross-References: * CVE-2026-16742 * CVE-2026-29111 * CVE-2026-40226 * CVE-2026-4105 CVSS scores: * CVE-2026-16742 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16742 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-29111 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-29111 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-29111 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40226 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-40226 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40226 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4105 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-4105 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4105 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that solves four vulnerabilities and has two fixes can now be installed. ## Description: This update for systemd fixes the following issue: Security issue fixed: * CVE-2026-16742: `systemd-homed`: local privilege escalation due to missing home record signature verification on the authentication path (bsc#1271444). Non security issue fixed: * `systemd-resolved` fails to start due to write access to `tmpfs` denied (bsc#1237515). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1602=1 ## Package List: * SUSE Linux Micro Extras 6.2 (aarch64 ppc64le s390x x86_64) * systemd-debuginfo-257.13-160000.4.1 * systemd-debugsource-257.13-160000.4.1 * systemd-devel-257.13-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16742.html * https://www.suse.com/security/cve/CVE-2026-29111.html * https://www.suse.com/security/cve/CVE-2026-40226.html * https://www.suse.com/security/cve/CVE-2026-4105.html * https://bugzilla.suse.com/show_bug.cgi?id=1237515 * https://bugzilla.suse.com/show_bug.cgi?id=1254924 * https://bugzilla.suse.com/show_bug.cgi?id=1259418 * https://bugzilla.suse.com/show_bug.cgi?id=1259650 * https://bugzilla.suse.com/show_bug.cgi?id=1261400 * https://bugzilla.suse.com/show_bug.cgi?id=1271444 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 13:52:05 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 13:52:05 -0000 Subject: SUSE-SU-2026:23456-1: moderate: Security update for helm Message-ID: <178896192581.1855.13270574605077493907@aaf27ed6f0fb> # Security update for helm Announcement ID: SUSE-SU-2026:23456-1 Release Date: 2026-09-04T08:24:13Z Rating: moderate References: * bsc#1270127 * bsc#1270416 * bsc#1271660 * bsc#1272402 * bsc#1276290 * bsc#1276291 * bsc#1276510 * bsc#1276514 * bsc#1277949 Cross-References: * CVE-2026-33630 * CVE-2026-37236 * CVE-2026-41178 * CVE-2026-48978 * CVE-2026-50151 * CVE-2026-63308 * CVE-2026-69184 * CVE-2026-69186 CVSS scores: * CVE-2026-33630 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33630 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33630 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-37236 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-37236 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-37236 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48978 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48978 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48978 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-50151 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-50151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-63308 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-63308 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-63308 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-63308 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-69184 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-69186 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Micro 6.0 * SUSE Linux Micro 6.2 An update that solves eight vulnerabilities and has one fix can now be installed. ## Security update for helm ### Description: This update for helm fixes the following issues: * CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST request through the X-HTTP-Method- Override header and bypass established access control (bsc#1277949). * CVE-2026-41178: go.opentelemetry.io/otel/baggage,go.opentelemetry.io/otel/propagation: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276510). * CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). * CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271660). * CVE-2026-63308: processing zero-length byte slices in template chart files can trigger an index out-of-range panic (bsc#1272402). * gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation (bsc#1276514). ## Security update for c-ares ### Description: This update for c-ares fixes the following issues: Updat to c-ares 1.36.8. * CVE-2026-33630: remotely triggerable use-after-free/double-free in query- completion handling via `ares_getaddrinfo()` over TCP (bsc#1270416). * CVE-2026-69184: CPU exhaustion denial of service via unbounded DNS name compression pointer chains (bsc#1276290). * CVE-2026-69186: memory amplification denial of service via unvalidated DNS header record counts (bsc#1276291). Changes for c-ares: * For details, see https://c-ares.org/changelog.html. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-881=1 * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1579=1 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * helm-debuginfo-3.21.3-2.1 * helm-3.21.3-2.1 * SUSE Linux Micro 6.0 (noarch) * helm-bash-completion-3.21.3-2.1 * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libcares2-1.34.8-160000.1.1 * c-ares-debugsource-1.34.8-160000.1.1 * libcares2-debuginfo-1.34.8-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33630.html * https://www.suse.com/security/cve/CVE-2026-37236.html * https://www.suse.com/security/cve/CVE-2026-41178.html * https://www.suse.com/security/cve/CVE-2026-48978.html * https://www.suse.com/security/cve/CVE-2026-50151.html * https://www.suse.com/security/cve/CVE-2026-63308.html * https://www.suse.com/security/cve/CVE-2026-69184.html * https://www.suse.com/security/cve/CVE-2026-69186.html * https://bugzilla.suse.com/show_bug.cgi?id=1270127 * https://bugzilla.suse.com/show_bug.cgi?id=1270416 * https://bugzilla.suse.com/show_bug.cgi?id=1271660 * https://bugzilla.suse.com/show_bug.cgi?id=1272402 * https://bugzilla.suse.com/show_bug.cgi?id=1276290 * https://bugzilla.suse.com/show_bug.cgi?id=1276291 * https://bugzilla.suse.com/show_bug.cgi?id=1276510 * https://bugzilla.suse.com/show_bug.cgi?id=1276514 * https://bugzilla.suse.com/show_bug.cgi?id=1277949 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 16:33:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 16:33:25 -0000 Subject: SUSE-SU-2026:4096-1: critical: Security update for libzypp, zypper Message-ID: <178897160511.2202.1771130040874999422@bab013902bd8> # Security update for libzypp, zypper Announcement ID: SUSE-SU-2026:4096-1 Release Date: 2026-09-09T08:34:58Z Rating: critical References: * bsc#1257249 * bsc#1261038 * bsc#1268321 * bsc#1271730 * bsc#1272534 * bsc#1273242 * bsc#1274091 * bsc#1274625 * bsc#1277790 Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that has nine security fixes can now be installed. ## Description: This update for libzypp, zypper fixes the following issues: Security issue fixed: * invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY- CACHE-01] (bsc#1274625). * hasCredentials() requires both username AND password to be non-empty (bsc#1273242). * GPG Key hints in repoindex.xml require at least a long id to allow auto- import (bsc#1271730). Non security issues fixed: * Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). * libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). * Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). * zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). * Zypper patch doesn't give enough details about conflicts (bsc#1277790). * dependency issue for package "python3-vsts-cd-manager" after starting the upgrade (bsc#1261038). Changes for libzypp: * Update to version 17.38.15: * Prevent libgpgme from launching gpg-agents; we don't need them. * defaultLoadSystem: Hand out the ZYpp::Ptr as return value. * Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) * zypp: Improve Testcase Loading for MCP Tools. * spec: Remove useless %bcond visibility_hidden (is always ON in cmake) * zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: * Update to version 1.14.101. ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Manager Server 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-4096=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4096=1 SUSE-SLE- INSTALLER-15-SP4-2026-4096=1 * SUSE Linux Enterprise High Performance Computing 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-4096=1 * SUSE Linux Enterprise Desktop 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-4096=1 * SUSE Manager Retail Branch Server 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-4096=1 * SUSE Manager Proxy 4.3 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-4096=1 * SUSE Linux Enterprise Server 15 SP4 zypper in -t patch SUSE-SLE-INSTALLER-15-SP4-2026-4096=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4096=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4096=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4096=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4096=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4096=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4096=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4096=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4096=1 ## Package List: * SUSE Manager Server 4.3 (ppc64le s390x x86_64) * libzypp-17.38.15-150400.3.161.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * zypper-1.14.101-150400.3.107.1 * libzypp-17.38.15-150400.3.161.1 * zypper-debugsource-1.14.101-150400.3.107.1 * libzypp-devel-17.38.15-150400.3.161.1 * libzypp-debuginfo-17.38.15-150400.3.161.1 * libzypp-debugsource-17.38.15-150400.3.161.1 * zypper-debuginfo-1.14.101-150400.3.107.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * zypper-needs-restarting-1.14.101-150400.3.107.1 * zypper-log-1.14.101-150400.3.107.1 * SUSE Linux Enterprise High Performance Computing 15 SP4 (aarch64 x86_64) * libzypp-17.38.15-150400.3.161.1 * SUSE Linux Enterprise Desktop 15 SP4 (x86_64) * libzypp-17.38.15-150400.3.161.1 * SUSE Manager Retail Branch Server 4.3 (x86_64) * libzypp-17.38.15-150400.3.161.1 * SUSE Manager Proxy 4.3 (x86_64) * libzypp-17.38.15-150400.3.161.1 * SUSE Linux Enterprise Server 15 SP4 (aarch64 ppc64le s390x x86_64) * libzypp-17.38.15-150400.3.161.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * zypper-1.14.101-150400.3.107.1 * libzypp-17.38.15-150400.3.161.1 * zypper-debugsource-1.14.101-150400.3.107.1 * libzypp-devel-17.38.15-150400.3.161.1 * libzypp-debuginfo-17.38.15-150400.3.161.1 * libzypp-debugsource-17.38.15-150400.3.161.1 * zypper-debuginfo-1.14.101-150400.3.107.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * zypper-needs-restarting-1.14.101-150400.3.107.1 * zypper-log-1.14.101-150400.3.107.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * zypper-1.14.101-150400.3.107.1 * libzypp-17.38.15-150400.3.161.1 * zypper-debugsource-1.14.101-150400.3.107.1 * libzypp-devel-17.38.15-150400.3.161.1 * libzypp-debuginfo-17.38.15-150400.3.161.1 * libzypp-debugsource-17.38.15-150400.3.161.1 * zypper-debuginfo-1.14.101-150400.3.107.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * zypper-needs-restarting-1.14.101-150400.3.107.1 * zypper-log-1.14.101-150400.3.107.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libzypp-devel-doc-17.38.15-150400.3.161.1 * zypper-1.14.101-150400.3.107.1 * libzypp-17.38.15-150400.3.161.1 * zypper-debugsource-1.14.101-150400.3.107.1 * libzypp-devel-17.38.15-150400.3.161.1 * libzypp-debuginfo-17.38.15-150400.3.161.1 * libzypp-debugsource-17.38.15-150400.3.161.1 * zypper-debuginfo-1.14.101-150400.3.107.1 * openSUSE Leap 15.4 (noarch) * zypper-aptitude-1.14.101-150400.3.107.1 * zypper-needs-restarting-1.14.101-150400.3.107.1 * zypper-log-1.14.101-150400.3.107.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * zypper-1.14.101-150400.3.107.1 * libzypp-17.38.15-150400.3.161.1 * zypper-debugsource-1.14.101-150400.3.107.1 * libzypp-debuginfo-17.38.15-150400.3.161.1 * libzypp-debugsource-17.38.15-150400.3.161.1 * zypper-debuginfo-1.14.101-150400.3.107.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * zypper-needs-restarting-1.14.101-150400.3.107.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * zypper-1.14.101-150400.3.107.1 * libzypp-17.38.15-150400.3.161.1 * zypper-debugsource-1.14.101-150400.3.107.1 * libzypp-debuginfo-17.38.15-150400.3.161.1 * libzypp-debugsource-17.38.15-150400.3.161.1 * zypper-debuginfo-1.14.101-150400.3.107.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * zypper-needs-restarting-1.14.101-150400.3.107.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * zypper-1.14.101-150400.3.107.1 * libzypp-17.38.15-150400.3.161.1 * zypper-debugsource-1.14.101-150400.3.107.1 * libzypp-debuginfo-17.38.15-150400.3.161.1 * libzypp-debugsource-17.38.15-150400.3.161.1 * zypper-debuginfo-1.14.101-150400.3.107.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * zypper-needs-restarting-1.14.101-150400.3.107.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * zypper-1.14.101-150400.3.107.1 * libzypp-17.38.15-150400.3.161.1 * zypper-debugsource-1.14.101-150400.3.107.1 * libzypp-debuginfo-17.38.15-150400.3.161.1 * libzypp-debugsource-17.38.15-150400.3.161.1 * zypper-debuginfo-1.14.101-150400.3.107.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * zypper-needs-restarting-1.14.101-150400.3.107.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * zypper-1.14.101-150400.3.107.1 * libzypp-17.38.15-150400.3.161.1 * zypper-debugsource-1.14.101-150400.3.107.1 * libzypp-devel-17.38.15-150400.3.161.1 * libzypp-debuginfo-17.38.15-150400.3.161.1 * libzypp-debugsource-17.38.15-150400.3.161.1 * zypper-debuginfo-1.14.101-150400.3.107.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * zypper-needs-restarting-1.14.101-150400.3.107.1 * zypper-log-1.14.101-150400.3.107.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1257249 * https://bugzilla.suse.com/show_bug.cgi?id=1261038 * https://bugzilla.suse.com/show_bug.cgi?id=1268321 * https://bugzilla.suse.com/show_bug.cgi?id=1271730 * https://bugzilla.suse.com/show_bug.cgi?id=1272534 * https://bugzilla.suse.com/show_bug.cgi?id=1273242 * https://bugzilla.suse.com/show_bug.cgi?id=1274091 * https://bugzilla.suse.com/show_bug.cgi?id=1274625 * https://bugzilla.suse.com/show_bug.cgi?id=1277790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 16:34:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 16:34:38 -0000 Subject: SUSE-SU-2026:4095-1: important: Security update for libssh2_org Message-ID: <178897167895.2202.6932085757105744485@bab013902bd8> # Security update for libssh2_org Announcement ID: SUSE-SU-2026:4095-1 Release Date: 2026-09-09T08:34:02Z Rating: important References: * bsc#1263890 * bsc#1268546 * bsc#1269567 * bsc#1269568 * bsc#1272734 * bsc#1272735 * bsc#1272736 * bsc#1272737 Cross-References: * CVE-2025-15661 * CVE-2026-58050 * CVE-2026-58051 * CVE-2026-66032 * CVE-2026-66033 * CVE-2026-66034 * CVE-2026-66035 * CVE-2026-7598 CVSS scores: * CVE-2025-15661 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2025-15661 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-15661 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2025-15661 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-58050 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58050 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58050 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58050 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58050 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-58051 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-58051 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-58051 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58051 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-66032 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-66032 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66032 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66032 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66033 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-66033 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66033 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66033 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66034 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-66034 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66034 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66034 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66035 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-66035 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66035 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66035 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-7598 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7598 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-7598 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7598 ( NVD ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-7598 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS An update that solves eight vulnerabilities can now be installed. ## Description: This update for libssh2_org fixes the following issues: * CVE-2025-15661: out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c (bsc#1268546). * CVE-2026-7598: integer overflow in function `userauth_password` of file `src/userauth.c` (bsc#1263890). * CVE-2026-58050: attacker controlled attribute count from a publickey- subsystem response is used without bounds checking and can cause to a heap buffer overflow in a connecting libssh2 client (bsc#1269568). * CVE-2026-58051: public key list is increased and does not zero-initialized new entries, which can cause an uninitialized pointer to be freed when a malformed response is sent by an SSH server (bsc#1269567). * CVE-2026-66032: Arbitrary code execution via double-free in SFTP session (bsc#1272737). * CVE-2026-66033: Denial of Service via integer underflow in AES-GCM cipher negotiation (bsc#1272736). * CVE-2026-66034: Information disclosure and potential arbitrary code execution via heap out-of-bounds read (bsc#1272735). * CVE-2026-66035: Arbitrary code execution via heap buffer overflow during SSH negotiation (bsc#1272734). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4095=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4095=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4095=1 ## Package List: * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libssh2-1-1.11.0-150000.4.35.1 * libssh2-1-debuginfo-1.11.0-150000.4.35.1 * libssh2-1-32bit-1.11.0-150000.4.35.1 * libssh2_org-debugsource-1.11.0-150000.4.35.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libssh2-1-1.11.0-150000.4.35.1 * libssh2-1-debuginfo-1.11.0-150000.4.35.1 * libssh2-1-32bit-1.11.0-150000.4.35.1 * libssh2_org-debugsource-1.11.0-150000.4.35.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libssh2-1-1.11.0-150000.4.35.1 * libssh2-1-debuginfo-1.11.0-150000.4.35.1 * libssh2-1-32bit-1.11.0-150000.4.35.1 * libssh2_org-debugsource-1.11.0-150000.4.35.1 ## References: * https://www.suse.com/security/cve/CVE-2025-15661.html * https://www.suse.com/security/cve/CVE-2026-58050.html * https://www.suse.com/security/cve/CVE-2026-58051.html * https://www.suse.com/security/cve/CVE-2026-66032.html * https://www.suse.com/security/cve/CVE-2026-66033.html * https://www.suse.com/security/cve/CVE-2026-66034.html * https://www.suse.com/security/cve/CVE-2026-66035.html * https://www.suse.com/security/cve/CVE-2026-7598.html * https://bugzilla.suse.com/show_bug.cgi?id=1263890 * https://bugzilla.suse.com/show_bug.cgi?id=1268546 * https://bugzilla.suse.com/show_bug.cgi?id=1269567 * https://bugzilla.suse.com/show_bug.cgi?id=1269568 * https://bugzilla.suse.com/show_bug.cgi?id=1272734 * https://bugzilla.suse.com/show_bug.cgi?id=1272735 * https://bugzilla.suse.com/show_bug.cgi?id=1272736 * https://bugzilla.suse.com/show_bug.cgi?id=1272737 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 20:31:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 20:31:16 -0000 Subject: SUSE-SU-2026:4109-1: moderate: Security update for python-sqlparse Message-ID: <178898587632.2409.9468824935099569121@a0307d149aa3> # Security update for python-sqlparse Announcement ID: SUSE-SU-2026:4109-1 Release Date: 2026-09-09T13:26:03Z Rating: moderate References: * bsc#1278097 Cross-References: * CVE-2026-84305 CVSS scores: * CVE-2026-84305 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84305 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-84305 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves one vulnerability can now be installed. ## Description: This update for python-sqlparse fixes the following issue: * CVE-2026-84305: Reindentation of tuple lists causes near-cap quadratic CPU consumption (bsc#1278097). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-4109=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4109=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-4109=1 ## Package List: * Public Cloud Module 15-SP4 (noarch) * python311-sqlparse-0.4.4-150400.6.19.1 * openSUSE Leap 15.4 (noarch) * python311-sqlparse-0.4.4-150400.6.19.1 * Public Cloud Module 15-SP5 (noarch) * python311-sqlparse-0.4.4-150400.6.19.1 ## References: * https://www.suse.com/security/cve/CVE-2026-84305.html * https://bugzilla.suse.com/show_bug.cgi?id=1278097 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 20:32:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 20:32:11 -0000 Subject: SUSE-SU-2026:4108-1: moderate: Security update for opensc Message-ID: <178898593162.2409.5300659513137197825@a0307d149aa3> # Security update for opensc Announcement ID: SUSE-SU-2026:4108-1 Release Date: 2026-09-09T13:25:18Z Rating: moderate References: * bsc#1266964 Cross-References: * CVE-2026-40510 CVSS scores: * CVE-2026-40510 ( SUSE ): 4.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-40510 ( SUSE ): 5.7 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-40510 ( NVD ): 1.0 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40510 ( NVD ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-40510 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for opensc fixes the following issue: * CVE-2026-40510: stack buffer overflow in `piv_process_history()` allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device (bsc#1266964). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4108=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * opensc-0.13.0-3.39.1 * opensc-debuginfo-0.13.0-3.39.1 * opensc-debugsource-0.13.0-3.39.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40510.html * https://bugzilla.suse.com/show_bug.cgi?id=1266964 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 20:33:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 20:33:00 -0000 Subject: SUSE-SU-2026:4107-1: important: Security update for java-1_8_0-ibm Message-ID: <178898598003.2409.17591121140640571462@a0307d149aa3> # Security update for java-1_8_0-ibm Announcement ID: SUSE-SU-2026:4107-1 Release Date: 2026-09-09T13:25:02Z Rating: important References: * bsc#1274275 * bsc#1274276 * bsc#1275763 * bsc#1275764 * bsc#1275777 * bsc#1275778 * bsc#1275779 * bsc#1277019 * bsc#1277833 Cross-References: * CVE-2026-16243 * CVE-2026-16440 * CVE-2026-60589 * CVE-2026-61308 * CVE-2026-70906 * CVE-2026-70907 * CVE-2026-71054 * CVE-2026-8400 CVSS scores: * CVE-2026-16243 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-16243 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-16243 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-16243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16440 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-60589 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-60589 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61308 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-61308 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-70906 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-70906 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-70907 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-70907 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-71054 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-71054 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-8400 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-8400 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-8400 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-8400 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves eight vulnerabilities and has one security fix can now be installed. ## Description: This update for java-1_8_0-ibm fixes the following issues: Update to Java 8.0 Service Refresh 8 Fix Pack 71 (bsc#1277833): * CVE-2026-8400: flaw in the ORB component may allow a malicious IIOP server to induce loading and instantation of arbitrary classes (bsc#1274276). * CVE-2026-16243: `arraycmp` SIMD implementation for Z and P does not check if the number of bytes to compare is zero (bsc#1274275). * CVE-2026-16440: a crafted .class file with deeply nested annotations causes a segmentation fault (bsc#1275779). * CVE-2026-60589: OpenJDK: Improve Resource Resolving (bsc#1275777). * CVE-2026-61308: OpenJDK: Enhance HTTP Connections (bsc#1275778). * CVE-2026-70906: OpenJDK: Improve font loading (bsc#1275763). * CVE-2026-70907: OpenJDK: Enhance TLS server (bsc#1275764). * CVE-2026-71054: Vulnerability in Oracle Java SE (component: 2D) (bsc#1277019). * Oracle August 18 2026 CSPU and IBM Security Update August 2026 (bsc#1277833). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4107=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4107=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (nosrc ppc64le s390x x86_64) * java-1_8_0-ibm-1.8.0_sr8.71-30.156.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.71-30.156.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.71-30.156.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (ppc64le s390x x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.71-30.156.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (nosrc x86_64) * java-1_8_0-ibm-1.8.0_sr8.71-30.156.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.71-30.156.1 * java-1_8_0-ibm-plugin-1.8.0_sr8.71-30.156.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.71-30.156.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16243.html * https://www.suse.com/security/cve/CVE-2026-16440.html * https://www.suse.com/security/cve/CVE-2026-60589.html * https://www.suse.com/security/cve/CVE-2026-61308.html * https://www.suse.com/security/cve/CVE-2026-70906.html * https://www.suse.com/security/cve/CVE-2026-70907.html * https://www.suse.com/security/cve/CVE-2026-71054.html * https://www.suse.com/security/cve/CVE-2026-8400.html * https://bugzilla.suse.com/show_bug.cgi?id=1274275 * https://bugzilla.suse.com/show_bug.cgi?id=1274276 * https://bugzilla.suse.com/show_bug.cgi?id=1275763 * https://bugzilla.suse.com/show_bug.cgi?id=1275764 * https://bugzilla.suse.com/show_bug.cgi?id=1275777 * https://bugzilla.suse.com/show_bug.cgi?id=1275778 * https://bugzilla.suse.com/show_bug.cgi?id=1275779 * https://bugzilla.suse.com/show_bug.cgi?id=1277019 * https://bugzilla.suse.com/show_bug.cgi?id=1277833 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 20:33:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 20:33:38 -0000 Subject: SUSE-SU-2026:4106-1: important: Security update for golang-github-vpenso-prometheus_slurm_exporter Message-ID: <178898601869.2409.3138242030025085240@a0307d149aa3> # Security update for golang-github-vpenso-prometheus_slurm_exporter Announcement ID: SUSE-SU-2026:4106-1 Release Date: 2026-09-09T13:24:18Z Rating: important References: * bsc#1248703 Cross-References: * CVE-2022-21698 CVSS scores: * CVE-2022-21698 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2022-21698 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * HPC Module 15-SP7 * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for golang-github-vpenso-prometheus_slurm_exporter fixes the following issue: * CVE-2022-21698: github.com/prometheus/client_golang/prometheus/promhttp: Denial of service using InstrumentHandlerCounter (bsc#1248703). Changes for golang-github-vpenso-prometheus_slurm_exporter: * Update to version 1.11.1. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-4106=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4106=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4106=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4106=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4106=1 * HPC Module 15-SP7 zypper in -t patch SUSE-SLE-Module-HPC-15-SP7-2026-4106=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4106=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4106=1 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * golang-github-vpenso-prometheus_slurm_exporter-0.20-150300.3.11.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * golang-github-vpenso-prometheus_slurm_exporter-0.20-150300.3.11.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * golang-github-vpenso-prometheus_slurm_exporter-0.20-150300.3.11.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * golang-github-vpenso-prometheus_slurm_exporter-0.20-150300.3.11.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * golang-github-vpenso-prometheus_slurm_exporter-0.20-150300.3.11.2 * HPC Module 15-SP7 (aarch64 x86_64) * golang-github-vpenso-prometheus_slurm_exporter-0.20-150300.3.11.2 * SUSE Package Hub 15 15-SP7 (ppc64le s390x) * golang-github-vpenso-prometheus_slurm_exporter-0.20-150300.3.11.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * golang-github-vpenso-prometheus_slurm_exporter-0.20-150300.3.11.2 ## References: * https://www.suse.com/security/cve/CVE-2022-21698.html * https://bugzilla.suse.com/show_bug.cgi?id=1248703 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 20:34:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 20:34:34 -0000 Subject: SUSE-SU-2026:4105-1: moderate: Security update for libsoup Message-ID: <178898607437.2409.219080769187353230@a0307d149aa3> # Security update for libsoup Announcement ID: SUSE-SU-2026:4105-1 Release Date: 2026-09-09T13:23:11Z Rating: moderate References: * bsc#1272196 Cross-References: * CVE-2026-12548 CVSS scores: * CVE-2026-12548 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12548 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12548 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for libsoup fixes the following issue: * CVE-2026-12548: out-of-bounds read in multipart body parser due to an integer truncation (bsc#1272196). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4105=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libsoup-2_4-1-debuginfo-32bit-2.62.2-5.46.1 * libsoup-debugsource-2.62.2-5.46.1 * libsoup-2_4-1-2.62.2-5.46.1 * libsoup-2_4-1-32bit-2.62.2-5.46.1 * libsoup-2_4-1-debuginfo-2.62.2-5.46.1 * typelib-1_0-Soup-2_4-2.62.2-5.46.1 * libsoup-devel-2.62.2-5.46.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * libsoup-lang-2.62.2-5.46.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12548.html * https://bugzilla.suse.com/show_bug.cgi?id=1272196 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 9 20:35:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 09 Sep 2026 20:35:13 -0000 Subject: SUSE-SU-2026:4104-1: low: Security update for python-pip Message-ID: <178898611326.2409.4458646733066297156@a0307d149aa3> # Security update for python-pip Announcement ID: SUSE-SU-2026:4104-1 Release Date: 2026-09-09T13:23:00Z Rating: low References: * bsc#1257599 Cross-References: * CVE-2026-1703 CVSS scores: * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for python-pip fixes the following issue: * Fixed patch for CVE-2026-1703 to work with python2 where os.path.commonpath doesn't exists (bsc#1257599) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4104=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * python3-pip-10.0.1-13.23.2 * python-pip-10.0.1-13.23.2 ## References: * https://www.suse.com/security/cve/CVE-2026-1703.html * https://bugzilla.suse.com/show_bug.cgi?id=1257599 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 08:31:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 08:31:34 -0000 Subject: SUSE-SU-2026:23507-1: critical: Security update for libzypp, zypper Message-ID: <178902909410.32187.11720124716076647300@c8813f945ae1> # Security update for libzypp, zypper Announcement ID: SUSE-SU-2026:23507-1 Release Date: 2026-09-08T15:22:38Z Rating: critical References: * bsc#1257249 * bsc#1271730 * bsc#1272534 * bsc#1273242 * bsc#1274091 * bsc#1274625 * bsc#1277790 Affected Products: * SUSE Linux Micro 6.2 An update that has seven fixes can now be installed. ## Description: This update for libzypp, zypper fixes the following issues: Security issue fixed: * invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY- CACHE-01] (bsc#1274625). Non security issues fixed: * Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). * Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). * zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). * Zypper patch doesn't give enough details about conflicts (bsc#1277790). Changes for libzypp: Update to version 17.38.1: * Prevent libgpgme from launching gpg-agents; we don't need them. * defaultLoadSystem: Hand out the ZYpp::Ptr as return value. * Log all solver problem rules (bsc#1277790) The log contains the most relevant problem rule, but sometimes it helps to know all rules associated with this problem. zypper shows them on demand as 'detail'. The log now remembers them as well. * Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) * repoGpgCheck: Strictly follow the repo_gpgcheck setting (bsc#1274625) There's been a legacy exception for unsigned repositories which were explicitly accepted in the past. After switching the repo_gpgcheck from off to on, they were allowed to stay unsigned until a first signed version was retrieved. From there on the handling was strict. Now the handling is strict as soon as the repo_gpgcheck turned on. The next set of metadata retrieved must be signed. * Iniparser: each new file starts in the unnamed section (bsc#1272534) * Fix hasCredentials() to require both username AND password to be non-empty (bsc#1273242) This avoids an unnecessary 2nd 401 response sending just the username in case the username but no password is known. Now it immediately fetches the credentials from disk if no password is known. * GPG Key hints in repoindex.xml require at least a long id to allow auto- import (bsc#1271730) The short Id (32bit/8byte) is not considered to be a safe identifier for a gpg key. A long id (64bit/16byte) or even better the full fingerprint is needed to identify the key. * zypp: Improve Testcase Loading for MCP Tools. Changes for zypper: Update to version 1.14.99: * Show solver problem details per default in not-interactive mode (bsc#1277790) This way they see all details when capturing zypper's output because the (d)etail button can't be pressed in not-interactive mode. * Add --servicesd-dir global option to relocate /etc/zypp/services.d (bsc#1257249) * info: check for missing positional args before systemSetup (bsc#1274091) * Remove deprecated installRecommends option from zypper.conf. The system wide default for all libzypp based applications is defined in zypp.conf(5). It is not recommended to define this in zypper exclusively. ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1639=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libzypp-17.38.15-160000.1.1 * libzypp-debuginfo-17.38.15-160000.1.1 * libzypp-debugsource-17.38.15-160000.1.1 * zypper-debuginfo-1.14.101-160000.1.1 * zypper-debugsource-1.14.101-160000.1.1 * zypper-1.14.101-160000.1.1 * SUSE Linux Micro 6.2 (noarch) * zypper-needs-restarting-1.14.101-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1257249 * https://bugzilla.suse.com/show_bug.cgi?id=1271730 * https://bugzilla.suse.com/show_bug.cgi?id=1272534 * https://bugzilla.suse.com/show_bug.cgi?id=1273242 * https://bugzilla.suse.com/show_bug.cgi?id=1274091 * https://bugzilla.suse.com/show_bug.cgi?id=1274625 * https://bugzilla.suse.com/show_bug.cgi?id=1277790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 08:32:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 08:32:22 -0000 Subject: SUSE-SU-2026:23506-1: important: Security update for helm Message-ID: <178902914252.32187.7659616286472919930@c8813f945ae1> # Security update for helm Announcement ID: SUSE-SU-2026:23506-1 Release Date: 2026-09-08T14:27:43Z Rating: important References: * bsc#1270127 * bsc#1271660 * bsc#1272402 * bsc#1276514 * bsc#1276644 * bsc#1277949 * bsc#1278270 * bsc#1278273 * bsc#1278688 Cross-References: * CVE-2026-37236 * CVE-2026-41178 * CVE-2026-48978 * CVE-2026-50151 * CVE-2026-63308 * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-37236 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-37236 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-37236 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48978 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48978 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48978 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-50151 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-50151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-63308 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-63308 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-63308 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-63308 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves eight vulnerabilities and has one fix can now be installed. ## Description: This update for helm fixes the following issues: Update to version 3.21.1: * CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST request through the X-HTTP-Method- Override header and bypass established access control (bsc#1277949). * CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276644). * CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). * CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271660). * CVE-2026-63308: processing zero-length byte slices in template chart files can trigger an index out-of-range panic (bsc#1272402). * CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1278270). * CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1278273). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing `:authority` and `Host` headers in gRPC-Go xDS servers (bsc#1278688). * gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation (bsc#1276514). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1640=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * helm-3.21.3-160000.2.1 * helm-debuginfo-3.21.3-160000.2.1 * SUSE Linux Micro 6.2 (noarch) * helm-bash-completion-3.21.3-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-37236.html * https://www.suse.com/security/cve/CVE-2026-41178.html * https://www.suse.com/security/cve/CVE-2026-48978.html * https://www.suse.com/security/cve/CVE-2026-50151.html * https://www.suse.com/security/cve/CVE-2026-63308.html * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1270127 * https://bugzilla.suse.com/show_bug.cgi?id=1271660 * https://bugzilla.suse.com/show_bug.cgi?id=1272402 * https://bugzilla.suse.com/show_bug.cgi?id=1276514 * https://bugzilla.suse.com/show_bug.cgi?id=1276644 * https://bugzilla.suse.com/show_bug.cgi?id=1277949 * https://bugzilla.suse.com/show_bug.cgi?id=1278270 * https://bugzilla.suse.com/show_bug.cgi?id=1278273 * https://bugzilla.suse.com/show_bug.cgi?id=1278688 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 08:34:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 08:34:14 -0000 Subject: SUSE-SU-2026:23502-1: moderate: Security update for multipath-tools Message-ID: <178902925455.32187.905284445238214397@c8813f945ae1> # Security update for multipath-tools Announcement ID: SUSE-SU-2026:23502-1 Release Date: 2026-09-07T15:33:05Z Rating: moderate References: * bsc#1277199 * bsc#1277203 * bsc#1277205 * bsc#1277208 * bsc#1277209 * bsc#1277210 * bsc#1277212 Affected Products: * SUSE Linux Micro 6.2 An update that has seven fixes can now be installed. ## Description: This update for multipath-tools fixes the following issues: * Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205). * Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210). * SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212). * Local Denial of Service via Blocking IPC Send Operations (bsc#1277199). * Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209). * DoS on multipathd socket by exhausting connections (bsc#1277203). * Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208). Changes for multipath-tools: * Update to version 0.12.4+278+suse.9cf9c5c. * Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1633=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * multipath-tools-debugsource-0.12.4+278+suse.9cf9c5c-160000.1.1 * multipath-tools-0.12.4+278+suse.9cf9c5c-160000.1.1 * kpartx-0.12.4+278+suse.9cf9c5c-160000.1.1 * libmpath0-debuginfo-0.12.4+278+suse.9cf9c5c-160000.1.1 * libmpath0-0.12.4+278+suse.9cf9c5c-160000.1.1 * multipath-tools-debuginfo-0.12.4+278+suse.9cf9c5c-160000.1.1 * kpartx-debuginfo-0.12.4+278+suse.9cf9c5c-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1277199 * https://bugzilla.suse.com/show_bug.cgi?id=1277203 * https://bugzilla.suse.com/show_bug.cgi?id=1277205 * https://bugzilla.suse.com/show_bug.cgi?id=1277208 * https://bugzilla.suse.com/show_bug.cgi?id=1277209 * https://bugzilla.suse.com/show_bug.cgi?id=1277210 * https://bugzilla.suse.com/show_bug.cgi?id=1277212 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 08:34:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 08:34:54 -0000 Subject: SUSE-SU-2026:23501-1: moderate: Security update for libusb-1_0 Message-ID: <178902929444.32187.548438384004879382@c8813f945ae1> # Security update for libusb-1_0 Announcement ID: SUSE-SU-2026:23501-1 Release Date: 2026-09-07T10:34:06Z Rating: moderate References: * bsc#1266664 * bsc#1266667 Cross-References: * CVE-2026-23679 * CVE-2026-47104 CVSS scores: * CVE-2026-23679 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23679 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23679 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23679 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23679 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-47104 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47104 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47104 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47104 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for libusb-1_0 fixes the following issues: * CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). * CVE-2026-47104: one-byte out-of-bounds read in `parse_iad_array()` allows attackers to trigger a denial of service via a malformed USB descriptor (bsc#1266667). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1631=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libusb-1_0-debugsource-1.0.28-160000.3.1 * libusb-1_0-0-debuginfo-1.0.28-160000.3.1 * libusb-1_0-0-1.0.28-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23679.html * https://www.suse.com/security/cve/CVE-2026-47104.html * https://bugzilla.suse.com/show_bug.cgi?id=1266664 * https://bugzilla.suse.com/show_bug.cgi?id=1266667 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 08:35:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 08:35:57 -0000 Subject: SUSE-SU-2026:23499-1: important: Security update for NetworkManager Message-ID: <178902935776.32187.8214992842272804877@c8813f945ae1> # Security update for NetworkManager Announcement ID: SUSE-SU-2026:23499-1 Release Date: 2026-09-06T17:00:57Z Rating: important References: * bsc#1267696 * bsc#1276764 Cross-References: * CVE-2026-10805 * CVE-2026-19685 CVSS scores: * CVE-2026-10805 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-10805 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19685 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-19685 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-19685 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19685 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for NetworkManager fixes the following issues: * CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). * CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1624=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * NetworkManager-bluetooth-1.52.0-160000.5.1 * NetworkManager-wwan-1.52.0-160000.5.1 * libnm0-1.52.0-160000.5.1 * NetworkManager-1.52.0-160000.5.1 * NetworkManager-cloud-setup-debuginfo-1.52.0-160000.5.1 * NetworkManager-cloud-setup-1.52.0-160000.5.1 * libnm0-debuginfo-1.52.0-160000.5.1 * NetworkManager-debuginfo-1.52.0-160000.5.1 * NetworkManager-tui-debuginfo-1.52.0-160000.5.1 * NetworkManager-debugsource-1.52.0-160000.5.1 * NetworkManager-pppoe-1.52.0-160000.5.1 * NetworkManager-wwan-debuginfo-1.52.0-160000.5.1 * NetworkManager-tui-1.52.0-160000.5.1 * NetworkManager-pppoe-debuginfo-1.52.0-160000.5.1 * NetworkManager-bluetooth-debuginfo-1.52.0-160000.5.1 * typelib-1_0-NM-1_0-1.52.0-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10805.html * https://www.suse.com/security/cve/CVE-2026-19685.html * https://bugzilla.suse.com/show_bug.cgi?id=1267696 * https://bugzilla.suse.com/show_bug.cgi?id=1276764 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 08:36:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 08:36:43 -0000 Subject: SUSE-SU-2026:23498-1: moderate: Security update for curl Message-ID: <178902940392.32187.7301914450347784128@c8813f945ae1> # Security update for curl Announcement ID: SUSE-SU-2026:23498-1 Release Date: 2026-09-06T16:54:54Z Rating: moderate References: * bsc#1262633 * bsc#1263440 * bsc#1268412 * bsc#1277476 * bsc#1277479 * bsc#1277480 Cross-References: * CVE-2026-13608 * CVE-2026-5773 * CVE-2026-7168 * CVE-2026-80229 * CVE-2026-80230 * CVE-2026-8926 CVSS scores: * CVE-2026-13608 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-13608 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-13608 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-5773 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-5773 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-5773 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-5773 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-7168 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-7168 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-7168 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-7168 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-80229 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-80229 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-80229 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80230 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-80230 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-80230 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-8926 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8926 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-8926 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues: * CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). * CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). * CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). * CVE-2026-13608: OpenLDAP SASL authentication bypass (bsc#1277476). * CVE-2026-80229: OpenSSL provider use-after-free (bsc#1277479). * CVE-2026-80230: OpenSSL pinning bypass (bsc#1277480). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1622=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libcurl4-8.14.1-160000.9.1 * curl-debugsource-8.14.1-160000.9.1 * curl-8.14.1-160000.9.1 * libcurl4-debuginfo-8.14.1-160000.9.1 * curl-debuginfo-8.14.1-160000.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13608.html * https://www.suse.com/security/cve/CVE-2026-5773.html * https://www.suse.com/security/cve/CVE-2026-7168.html * https://www.suse.com/security/cve/CVE-2026-80229.html * https://www.suse.com/security/cve/CVE-2026-80230.html * https://www.suse.com/security/cve/CVE-2026-8926.html * https://bugzilla.suse.com/show_bug.cgi?id=1262633 * https://bugzilla.suse.com/show_bug.cgi?id=1263440 * https://bugzilla.suse.com/show_bug.cgi?id=1268412 * https://bugzilla.suse.com/show_bug.cgi?id=1277476 * https://bugzilla.suse.com/show_bug.cgi?id=1277479 * https://bugzilla.suse.com/show_bug.cgi?id=1277480 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 08:37:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 08:37:46 -0000 Subject: SUSE-SU-2026:23496-1: moderate: Security update for mcphost Message-ID: <178902946673.32187.1768471465953370253@c8813f945ae1> # Security update for mcphost Announcement ID: SUSE-SU-2026:23496-1 Release Date: 2026-09-06T16:47:56Z Rating: moderate References: * bsc#1276612 * bsc#1278013 Cross-References: * CVE-2026-41178 * CVE-2026-81092 CVSS scores: * CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-81092 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-81092 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-81092 ( NVD ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-81092 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for mcphost fixes the following issues: * CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276612). * CVE-2026-81092: github.com/mark3labs/mcp-go/server: requests accepted in HTTP transports without Host header checks can lead to tool usage and resource exposure in target server (bsc#1278013). Changes for mcphost: * Update github.com/mark3labs/mcp-go/server to v0.56.0. * Update go.opentelemetry.io/otel to 1.44.0. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1619=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * mcphost-0.34.0-160000.4.1 * mcphost-debuginfo-0.34.0-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41178.html * https://www.suse.com/security/cve/CVE-2026-81092.html * https://bugzilla.suse.com/show_bug.cgi?id=1276612 * https://bugzilla.suse.com/show_bug.cgi?id=1278013 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 08:38:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 08:38:25 -0000 Subject: SUSE-SU-2026:23495-1: moderate: Security update for rpcbind Message-ID: <178902950544.32187.9615368866927731125@c8813f945ae1> # Security update for rpcbind Announcement ID: SUSE-SU-2026:23495-1 Release Date: 2026-09-06T16:46:15Z Rating: moderate References: * bsc#1272340 Cross-References: * CVE-2026-16461 CVSS scores: * CVE-2026-16461 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-16461 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for rpcbind fixes the following issue: * CVE-2026-16461: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting (bsc#1272340). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1613=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * rpcbind-1.2.9-160000.2.1 * rpcbind-debuginfo-1.2.9-160000.2.1 * rpcbind-debugsource-1.2.9-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16461.html * https://bugzilla.suse.com/show_bug.cgi?id=1272340 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 08:39:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 08:39:04 -0000 Subject: SUSE-SU-2026:23494-1: low: Security update for bzip2 Message-ID: <178902954424.32187.4569541697519713094@c8813f945ae1> # Security update for bzip2 Announcement ID: SUSE-SU-2026:23494-1 Release Date: 2026-09-04T13:53:27Z Rating: low References: * bsc#1266786 Cross-References: * CVE-2026-42250 CVSS scores: * CVE-2026-42250 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42250 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-42250 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for bzip2 fixes the following issue: * CVE-2026-42250: off-by-one error in the `bzip2recover` utility when processing a specially crafted file can lead to a crash (bsc#1266786). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1610=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libbz2-1-debuginfo-1.0.8-160000.3.1 * libbz2-1-1.0.8-160000.3.1 * bzip2-1.0.8-160000.3.1 * bzip2-debugsource-1.0.8-160000.3.1 * bzip2-debuginfo-1.0.8-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42250.html * https://bugzilla.suse.com/show_bug.cgi?id=1266786 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 08:41:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 08:41:19 -0000 Subject: SUSE-SU-2026:4115-1: important: Security update for strongswan Message-ID: <178902967967.32187.1778363048303550012@c8813f945ae1> # Security update for strongswan Announcement ID: SUSE-SU-2026:4115-1 Release Date: 2026-09-09T16:21:58Z Rating: important References: * bsc#1266360 * bsc#1276533 * bsc#1276534 * bsc#1276536 * bsc#1276539 * bsc#1276540 * bsc#1276541 * bsc#1276543 * bsc#1276544 * bsc#1276548 * bsc#1276549 Cross-References: * CVE-2026-47895 * CVE-2026-78123 * CVE-2026-78124 * CVE-2026-78126 * CVE-2026-78127 * CVE-2026-78129 * CVE-2026-78130 * CVE-2026-78131 * CVE-2026-78132 * CVE-2026-78134 * CVE-2026-78135 CVSS scores: * CVE-2026-47895 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-47895 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-47895 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-78123 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78123 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78124 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78124 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78126 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78126 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78127 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78127 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78129 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78129 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-78130 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78130 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78131 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78131 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78132 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78132 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78134 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-78134 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-78135 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-78135 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for strongswan fixes the following issues: * CVE-2026-47895: Double-Free When Destroying Certain Cloned Identities (bsc#1266360). * CVE-2026-78123: Undefined Memory Access When Handling PKCS#7 Containers (bsc#1276533). * CVE-2026-78124: Memory Leak When Processing Certificates in PKCS#7 Containers (bsc#1276534). * CVE-2026-78126: NULL-Pointer Dereference When Handling AKA-Synchronization- Failure (bsc#1276536). * CVE-2026-78127: Memory Leak During Message Stringification (bsc#1276539). * CVE-2026-78129: Unbounded Iteration When Decrypting PKCS#7 Containers (bsc#1276540). * CVE-2026-78130: NULL-Pointer Dereference in Attribute Certificate Validation (bsc#1276541). * CVE-2026-78131: Memory Leaks When Parsing Attribute Certificates (bsc#1276543). * CVE-2026-78132: Infinite Loop When Parsing Attribute Certificates (bsc#1276544). * CVE-2026-78134: Missing Inner EAP Method Authentication Details (bsc#1276548). * CVE-2026-78135: Creation of a Child SA Pre-Authentication (bsc#1276549). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4115=1 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-4115=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4115=1 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * strongswan-libs0-5.9.14-150700.3.21.2 * strongswan-hmac-5.9.14-150700.3.21.2 * strongswan-libs0-debuginfo-5.9.14-150700.3.21.2 * strongswan-ipsec-debuginfo-5.9.14-150700.3.21.2 * strongswan-ipsec-5.9.14-150700.3.21.2 * strongswan-debuginfo-5.9.14-150700.3.21.2 * strongswan-5.9.14-150700.3.21.2 * strongswan-debugsource-5.9.14-150700.3.21.2 * Basesystem Module 15-SP7 (noarch) * strongswan-doc-5.9.14-150700.3.21.2 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * strongswan-nm-debuginfo-5.9.14-150700.3.21.2 * strongswan-nm-5.9.14-150700.3.21.2 * strongswan-debugsource-5.9.14-150700.3.21.2 * strongswan-debuginfo-5.9.14-150700.3.21.2 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * strongswan-nm-debuginfo-5.9.14-150700.3.21.2 * strongswan-nm-5.9.14-150700.3.21.2 * strongswan-debugsource-5.9.14-150700.3.21.2 * strongswan-debuginfo-5.9.14-150700.3.21.2 ## References: * https://www.suse.com/security/cve/CVE-2026-47895.html * https://www.suse.com/security/cve/CVE-2026-78123.html * https://www.suse.com/security/cve/CVE-2026-78124.html * https://www.suse.com/security/cve/CVE-2026-78126.html * https://www.suse.com/security/cve/CVE-2026-78127.html * https://www.suse.com/security/cve/CVE-2026-78129.html * https://www.suse.com/security/cve/CVE-2026-78130.html * https://www.suse.com/security/cve/CVE-2026-78131.html * https://www.suse.com/security/cve/CVE-2026-78132.html * https://www.suse.com/security/cve/CVE-2026-78134.html * https://www.suse.com/security/cve/CVE-2026-78135.html * https://bugzilla.suse.com/show_bug.cgi?id=1266360 * https://bugzilla.suse.com/show_bug.cgi?id=1276533 * https://bugzilla.suse.com/show_bug.cgi?id=1276534 * https://bugzilla.suse.com/show_bug.cgi?id=1276536 * https://bugzilla.suse.com/show_bug.cgi?id=1276539 * https://bugzilla.suse.com/show_bug.cgi?id=1276540 * https://bugzilla.suse.com/show_bug.cgi?id=1276541 * https://bugzilla.suse.com/show_bug.cgi?id=1276543 * https://bugzilla.suse.com/show_bug.cgi?id=1276544 * https://bugzilla.suse.com/show_bug.cgi?id=1276548 * https://bugzilla.suse.com/show_bug.cgi?id=1276549 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 08:42:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 08:42:11 -0000 Subject: SUSE-SU-2026:4114-1: important: Security update for tomcat11 Message-ID: <178902973108.32187.12388445116095970251@c8813f945ae1> # Security update for tomcat11 Announcement ID: SUSE-SU-2026:4114-1 Release Date: 2026-09-09T16:20:48Z Rating: important References: * bsc#1273150 * bsc#1276893 * bsc#1276894 * bsc#1276895 * bsc#1276896 * bsc#1276897 * bsc#1276898 * bsc#1276899 * bsc#1276900 * bsc#1276901 * bsc#1276902 Cross-References: * CVE-2026-65182 * CVE-2026-65183 * CVE-2026-65637 * CVE-2026-65905 * CVE-2026-65927 * CVE-2026-66299 * CVE-2026-66422 * CVE-2026-68525 * CVE-2026-68569 * CVE-2026-68763 * CVE-2026-73180 CVSS scores: * CVE-2026-65182 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65182 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-65182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-65183 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65183 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65637 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65637 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65637 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65905 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65905 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-65905 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65927 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65927 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-66299 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-66422 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-66422 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-66422 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-68525 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68525 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68525 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68569 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68569 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68569 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68763 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68763 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68763 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73180 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-73180 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-73180 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for tomcat11 fixes the following issues: * CVE-2026-65182: Apache Tomcat: Bypass longest prefix security constraint (bsc#1276893). * CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets (bsc#1276894). * CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - fix incomplete (bsc#1276895). * CVE-2026-65905: Apache Tomcat: Limited replay attack possible with DIGEST authentication (bsc#1276896). * CVE-2026-65927: Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control (bsc#1276897). * CVE-2026-66299: memory exhaustion via maliciously slow clients due to the WebSocket chat example providing an unbounded buffer for undelivered messages (bsc#1273150). * CVE-2026-66422: Apache Tomcat: Servlet role references can bypass declarative role constraints (bsc#1276898). * CVE-2026-68525: Apache Tomcat: Redirect after FORM auth may bypass method specific constraints (bsc#1276899). * CVE-2026-68569: Apache Tomcat: Principal lookup can fail open in some cases (bsc#1276900). * CVE-2026-68763: Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset (bsc#1276901). * CVE-2026-73180: Apache Tomcat: Authenticated WebSocket session survives end of HTTP session (bsc#1276902). Changes for tomcat11: * Updated to version 11.0.25 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4114=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4114=1 * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-4114=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4114=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * tomcat11-lib-11.0.25-150600.13.33.2 * tomcat11-admin-webapps-11.0.25-150600.13.33.2 * tomcat11-servlet-6_1-api-11.0.25-150600.13.33.2 * tomcat11-el-6_0-api-11.0.25-150600.13.33.2 * tomcat11-webapps-11.0.25-150600.13.33.2 * tomcat11-jsp-4_0-api-11.0.25-150600.13.33.2 * tomcat11-11.0.25-150600.13.33.2 * openSUSE Leap 15.6 (noarch) * tomcat11-lib-11.0.25-150600.13.33.2 * tomcat11-admin-webapps-11.0.25-150600.13.33.2 * tomcat11-embed-11.0.25-150600.13.33.2 * tomcat11-servlet-6_1-api-11.0.25-150600.13.33.2 * tomcat11-el-6_0-api-11.0.25-150600.13.33.2 * tomcat11-jsvc-11.0.25-150600.13.33.2 * tomcat11-docs-webapp-11.0.25-150600.13.33.2 * tomcat11-webapps-11.0.25-150600.13.33.2 * tomcat11-doc-11.0.25-150600.13.33.2 * tomcat11-jsp-4_0-api-11.0.25-150600.13.33.2 * tomcat11-11.0.25-150600.13.33.2 * Web and Scripting Module 15-SP7 (noarch) * tomcat11-lib-11.0.25-150600.13.33.2 * tomcat11-admin-webapps-11.0.25-150600.13.33.2 * tomcat11-servlet-6_1-api-11.0.25-150600.13.33.2 * tomcat11-el-6_0-api-11.0.25-150600.13.33.2 * tomcat11-webapps-11.0.25-150600.13.33.2 * tomcat11-jsp-4_0-api-11.0.25-150600.13.33.2 * tomcat11-11.0.25-150600.13.33.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * tomcat11-lib-11.0.25-150600.13.33.2 * tomcat11-admin-webapps-11.0.25-150600.13.33.2 * tomcat11-servlet-6_1-api-11.0.25-150600.13.33.2 * tomcat11-el-6_0-api-11.0.25-150600.13.33.2 * tomcat11-webapps-11.0.25-150600.13.33.2 * tomcat11-jsp-4_0-api-11.0.25-150600.13.33.2 * tomcat11-11.0.25-150600.13.33.2 ## References: * https://www.suse.com/security/cve/CVE-2026-65182.html * https://www.suse.com/security/cve/CVE-2026-65183.html * https://www.suse.com/security/cve/CVE-2026-65637.html * https://www.suse.com/security/cve/CVE-2026-65905.html * https://www.suse.com/security/cve/CVE-2026-65927.html * https://www.suse.com/security/cve/CVE-2026-66299.html * https://www.suse.com/security/cve/CVE-2026-66422.html * https://www.suse.com/security/cve/CVE-2026-68525.html * https://www.suse.com/security/cve/CVE-2026-68569.html * https://www.suse.com/security/cve/CVE-2026-68763.html * https://www.suse.com/security/cve/CVE-2026-73180.html * https://bugzilla.suse.com/show_bug.cgi?id=1273150 * https://bugzilla.suse.com/show_bug.cgi?id=1276893 * https://bugzilla.suse.com/show_bug.cgi?id=1276894 * https://bugzilla.suse.com/show_bug.cgi?id=1276895 * https://bugzilla.suse.com/show_bug.cgi?id=1276896 * https://bugzilla.suse.com/show_bug.cgi?id=1276897 * https://bugzilla.suse.com/show_bug.cgi?id=1276898 * https://bugzilla.suse.com/show_bug.cgi?id=1276899 * https://bugzilla.suse.com/show_bug.cgi?id=1276900 * https://bugzilla.suse.com/show_bug.cgi?id=1276901 * https://bugzilla.suse.com/show_bug.cgi?id=1276902 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 08:43:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 08:43:07 -0000 Subject: SUSE-SU-2026:4113-1: moderate: Security update for python-aiohttp Message-ID: <178902978790.32187.8037940152448244928@c8813f945ae1> # Security update for python-aiohttp Announcement ID: SUSE-SU-2026:4113-1 Release Date: 2026-09-09T16:19:36Z Rating: moderate References: * bsc#1273125 * bsc#1273553 Cross-References: * CVE-2026-59881 * CVE-2026-69243 CVSS scores: * CVE-2026-59881 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59881 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59881 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-69243 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-69243 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-69243 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-aiohttp fixes the following issues: * CVE-2026-59881: excessive resource consumption due to WebSocket client accepting compressed frames without negotiated permessage-deflate (bsc#1273125). * CVE-2026-69243: HTTP request smuggling via the WebSocket upgrade procedure (bsc#1273553). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-4113=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-4113=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-4113=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-4113=1 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * python-aiohttp-debugsource-3.6.0-150100.3.41.1 * python3-aiohttp-3.6.0-150100.3.41.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.41.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * python-aiohttp-debugsource-3.6.0-150100.3.41.1 * python3-aiohttp-3.6.0-150100.3.41.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.41.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * python-aiohttp-debugsource-3.6.0-150100.3.41.1 * python3-aiohttp-3.6.0-150100.3.41.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.41.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * python-aiohttp-debugsource-3.6.0-150100.3.41.1 * python3-aiohttp-3.6.0-150100.3.41.1 * python3-aiohttp-debuginfo-3.6.0-150100.3.41.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59881.html * https://www.suse.com/security/cve/CVE-2026-69243.html * https://bugzilla.suse.com/show_bug.cgi?id=1273125 * https://bugzilla.suse.com/show_bug.cgi?id=1273553 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 08:43:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 08:43:58 -0000 Subject: SUSE-SU-2026:4112-1: critical: Security update for libzypp, zypper Message-ID: <178902983810.32187.8548145997413072473@c8813f945ae1> # Security update for libzypp, zypper Announcement ID: SUSE-SU-2026:4112-1 Release Date: 2026-09-09T16:17:44Z Rating: critical References: * bsc#1257249 * bsc#1261038 * bsc#1268321 * bsc#1271730 * bsc#1272534 * bsc#1273242 * bsc#1274091 * bsc#1274625 * bsc#1277790 Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that has nine security fixes can now be installed. ## Description: This update for libzypp, zypper fixes the following issues: Security issue fixed: * invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY- CACHE-01] (bsc#1274625). * hasCredentials() requires both username AND password to be non-empty (bsc#1273242). * GPG Key hints in repoindex.xml require at least a long id to allow auto- import (bsc#1271730). Non security issues fixed: * Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). * libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). * Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). * zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). * Zypper patch doesn't give enough details about conflicts (bsc#1277790). * dependency issue for package "python3-vsts-cd-manager" after starting the upgrade (bsc#1261038). Changes for libzypp: * Update to version 17.38.15: * Prevent libgpgme from launching gpg-agents; we don't need them. * defaultLoadSystem: Hand out the ZYpp::Ptr as return value. * Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) * zypp: Improve Testcase Loading for MCP Tools. * spec: Remove useless %bcond visibility_hidden (is always ON in cmake) * zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: * Update to version 1.14.101. ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-4112=1 SUSE-SLE-Product- SLES_SAP-15-SP6-2026-4112=1 * SUSE Linux Enterprise High Performance Computing 15 SP6 zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-4112=1 * SUSE Linux Enterprise Desktop 15 SP6 zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-4112=1 * SUSE Linux Enterprise Server 15 SP6 zypper in -t patch SUSE-SLE-INSTALLER-15-SP6-2026-4112=1 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4112=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4112=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libzypp-debuginfo-17.38.15-150600.3.95.1 * zypper-debugsource-1.14.101-150600.10.58.1 * libzypp-devel-17.38.15-150600.3.95.1 * zypper-debuginfo-1.14.101-150600.10.58.1 * libzypp-debugsource-17.38.15-150600.3.95.1 * libzypp-17.38.15-150600.3.95.1 * zypper-1.14.101-150600.10.58.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * zypper-log-1.14.101-150600.10.58.1 * zypper-needs-restarting-1.14.101-150600.10.58.1 * SUSE Linux Enterprise High Performance Computing 15 SP6 (aarch64 x86_64) * libzypp-17.38.15-150600.3.95.1 * SUSE Linux Enterprise Desktop 15 SP6 (x86_64) * libzypp-17.38.15-150600.3.95.1 * SUSE Linux Enterprise Server 15 SP6 (aarch64 ppc64le s390x x86_64) * libzypp-17.38.15-150600.3.95.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libzypp-debuginfo-17.38.15-150600.3.95.1 * zypper-debugsource-1.14.101-150600.10.58.1 * libzypp-devel-17.38.15-150600.3.95.1 * zypper-debuginfo-1.14.101-150600.10.58.1 * libzypp-debugsource-17.38.15-150600.3.95.1 * libzypp-devel-doc-17.38.15-150600.3.95.1 * libzypp-17.38.15-150600.3.95.1 * zypper-1.14.101-150600.10.58.1 * openSUSE Leap 15.6 (noarch) * zypper-log-1.14.101-150600.10.58.1 * zypper-aptitude-1.14.101-150600.10.58.1 * zypper-needs-restarting-1.14.101-150600.10.58.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libzypp-debuginfo-17.38.15-150600.3.95.1 * zypper-debugsource-1.14.101-150600.10.58.1 * libzypp-devel-17.38.15-150600.3.95.1 * zypper-debuginfo-1.14.101-150600.10.58.1 * libzypp-debugsource-17.38.15-150600.3.95.1 * libzypp-17.38.15-150600.3.95.1 * zypper-1.14.101-150600.10.58.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * zypper-log-1.14.101-150600.10.58.1 * zypper-needs-restarting-1.14.101-150600.10.58.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1257249 * https://bugzilla.suse.com/show_bug.cgi?id=1261038 * https://bugzilla.suse.com/show_bug.cgi?id=1268321 * https://bugzilla.suse.com/show_bug.cgi?id=1271730 * https://bugzilla.suse.com/show_bug.cgi?id=1272534 * https://bugzilla.suse.com/show_bug.cgi?id=1273242 * https://bugzilla.suse.com/show_bug.cgi?id=1274091 * https://bugzilla.suse.com/show_bug.cgi?id=1274625 * https://bugzilla.suse.com/show_bug.cgi?id=1277790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 08:44:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 08:44:53 -0000 Subject: SUSE-SU-2026:4111-1: moderate: Security update for python-Authlib Message-ID: <178902989345.32187.3494210515088645809@c8813f945ae1> # Security update for python-Authlib Announcement ID: SUSE-SU-2026:4111-1 Release Date: 2026-09-09T16:16:39Z Rating: moderate References: * bsc#1275231 Cross-References: * CVE-2026-41479 CVSS scores: * CVE-2026-41479 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-41479 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-Authlib fixes the following issue: * CVE-2026-41479: crafted authorization requests with unsupported response_types can cause unauthenticated open redirects (bsc#1275231). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4111=1 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-4111=1 ## Package List: * openSUSE Leap 15.6 (noarch) * python311-Authlib-1.3.1-150600.3.30.1 * Python 3 Module 15-SP7 (noarch) * python311-Authlib-1.3.1-150600.3.30.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41479.html * https://bugzilla.suse.com/show_bug.cgi?id=1275231 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 16:47:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 16:47:53 -0000 Subject: SUSE-SU-2026:4120-1: important: Security update for the Linux Kernel Message-ID: <178905887355.3779.10433660391269888050@a0307d149aa3> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:4120-1 Release Date: 2026-09-10T09:31:36Z Rating: important References: * bsc#1230238 * bsc#1235944 * bsc#1236344 * bsc#1240957 * bsc#1241363 * bsc#1247180 * bsc#1247455 * bsc#1249104 * bsc#1250748 * bsc#1251130 * bsc#1251966 * bsc#1252682 * bsc#1253454 * bsc#1254306 * bsc#1255225 * bsc#1255250 * bsc#1256629 * bsc#1256708 * bsc#1257154 * bsc#1258430 * bsc#1258472 * bsc#1258517 * bsc#1260522 * bsc#1261562 * bsc#1261780 * bsc#1262073 * bsc#1263004 * bsc#1263052 * bsc#1263061 * bsc#1263133 * bsc#1263864 * bsc#1264010 * bsc#1264012 * bsc#1264335 * bsc#1264446 * bsc#1264541 * bsc#1264587 * bsc#1264619 * bsc#1264643 * bsc#1264740 * bsc#1264807 * bsc#1265068 * bsc#1265121 * bsc#1265220 * bsc#1265449 * bsc#1265928 * bsc#1266402 * bsc#1266860 * bsc#1266874 * bsc#1266897 * bsc#1267023 * bsc#1267236 * bsc#1267238 * bsc#1267501 * bsc#1267505 * bsc#1267612 * bsc#1268276 * bsc#1268972 * bsc#1268979 * bsc#1268987 * bsc#1269004 * bsc#1269013 * bsc#1269108 * bsc#1269113 * bsc#1269114 * bsc#1269126 * bsc#1269140 * bsc#1269167 * bsc#1269234 * bsc#1269238 * bsc#1269242 * bsc#1269256 * bsc#1269301 * bsc#1269306 * bsc#1269313 * bsc#1269381 * bsc#1269388 * bsc#1269402 * bsc#1269412 * bsc#1269530 * bsc#1269579 * bsc#1269590 * bsc#1269635 * bsc#1269647 * bsc#1269655 * bsc#1269665 * bsc#1269686 * bsc#1269695 * bsc#1269713 * bsc#1269731 * bsc#1269774 * bsc#1269783 * bsc#1269792 * bsc#1269815 * bsc#1269888 * bsc#1269965 * bsc#1269969 * bsc#1269981 * bsc#1269985 * bsc#1270090 * bsc#1270108 * bsc#1270111 * bsc#1270251 * bsc#1270263 * bsc#1270268 * bsc#1271256 * bsc#1271365 * bsc#1271366 * bsc#1271825 * bsc#1271830 * bsc#1272150 * bsc#1272175 * bsc#1272179 * bsc#1272182 * bsc#1272200 * bsc#1272210 * bsc#1272213 * bsc#1272230 * bsc#1272260 * bsc#1272261 * bsc#1272262 * bsc#1272297 * bsc#1272346 * bsc#1272351 * bsc#1272359 * bsc#1272381 * bsc#1272383 * bsc#1272385 * bsc#1272390 * bsc#1272423 * bsc#1272429 * bsc#1272484 * bsc#1272486 * bsc#1272497 * bsc#1272502 * bsc#1272516 * bsc#1272569 * bsc#1272571 * bsc#1272618 * bsc#1272641 * bsc#1272643 * bsc#1272662 * bsc#1272673 * bsc#1272680 * bsc#1272682 * bsc#1272756 * bsc#1272786 * bsc#1272788 * bsc#1272798 * bsc#1272799 * bsc#1272804 * bsc#1272868 * bsc#1272877 * bsc#1272891 * bsc#1272893 * bsc#1272963 * bsc#1272983 * bsc#1272993 * bsc#1273005 * bsc#1273008 * bsc#1273019 * bsc#1273027 * bsc#1273028 * bsc#1273030 * bsc#1273032 * bsc#1273033 * bsc#1273036 * bsc#1273037 * bsc#1273038 * bsc#1273053 * bsc#1273054 * bsc#1273060 * bsc#1273105 * bsc#1273134 * bsc#1273249 * bsc#1273250 * bsc#1273260 * bsc#1273273 * bsc#1273274 * bsc#1273276 * bsc#1273277 * bsc#1273280 * bsc#1273281 * bsc#1273284 * bsc#1273285 * bsc#1273289 * bsc#1273291 * bsc#1273294 * bsc#1273302 * bsc#1273303 * bsc#1273305 * bsc#1273310 * bsc#1273311 * bsc#1273316 * bsc#1273318 * bsc#1273319 * bsc#1273323 * bsc#1273325 * bsc#1273327 * bsc#1273334 * bsc#1273335 * bsc#1273336 * bsc#1273337 * bsc#1273338 * bsc#1273340 * bsc#1273341 * bsc#1273346 * bsc#1273422 * bsc#1273426 * bsc#1273443 * bsc#1273460 * bsc#1273463 * bsc#1273465 * bsc#1273468 * bsc#1273469 * bsc#1273471 * bsc#1273479 * bsc#1273480 * bsc#1273482 * bsc#1273484 * bsc#1273488 * bsc#1273490 * bsc#1273501 * bsc#1273503 * bsc#1273504 * bsc#1273506 * bsc#1273523 * bsc#1273525 * bsc#1273533 * bsc#1273536 * bsc#1273542 * bsc#1273555 * bsc#1273578 * bsc#1273579 * bsc#1273581 * bsc#1273582 * bsc#1273596 * bsc#1273597 * bsc#1273598 * bsc#1273600 * bsc#1273601 * bsc#1273602 * bsc#1273603 * bsc#1273679 * bsc#1273681 * bsc#1273682 * bsc#1273734 * bsc#1273738 * bsc#1273739 * bsc#1273741 * bsc#1273742 * bsc#1273743 * bsc#1273745 * bsc#1273748 * bsc#1273749 * bsc#1273755 * bsc#1273762 * bsc#1273765 * bsc#1273766 * bsc#1273769 * bsc#1273774 * bsc#1273778 * bsc#1273780 * bsc#1273790 * bsc#1273796 * bsc#1273797 * bsc#1273801 * bsc#1273804 * bsc#1273810 * bsc#1273811 * bsc#1273812 * bsc#1273813 * bsc#1273817 * bsc#1273822 * bsc#1273824 * bsc#1273831 * bsc#1273832 * bsc#1273834 * bsc#1273838 * bsc#1273844 * bsc#1273849 * bsc#1273859 * bsc#1273860 * bsc#1273862 * bsc#1273867 * bsc#1273868 * bsc#1273869 * bsc#1273872 * bsc#1273876 * bsc#1273877 * bsc#1273880 * bsc#1273882 * bsc#1273890 * bsc#1273891 * bsc#1273892 * bsc#1273895 * bsc#1273896 * bsc#1273903 * bsc#1273905 * bsc#1273930 * bsc#1273933 * bsc#1273934 * bsc#1273935 * bsc#1273936 * bsc#1273939 * bsc#1273940 * bsc#1273941 * bsc#1273942 * bsc#1273944 * bsc#1273945 * bsc#1273946 * bsc#1273956 * bsc#1273957 * bsc#1273958 * bsc#1273966 * bsc#1273967 * bsc#1273968 * bsc#1273972 * bsc#1273974 * bsc#1273975 * bsc#1273977 * bsc#1273982 * bsc#1273988 * bsc#1273990 * bsc#1273991 * bsc#1273995 * bsc#1274001 * bsc#1274003 * bsc#1274006 * bsc#1274008 * bsc#1274009 * bsc#1274010 * bsc#1274011 * bsc#1274012 * bsc#1274014 * bsc#1274017 * bsc#1274019 * bsc#1274020 * bsc#1274026 * bsc#1274028 * bsc#1274030 * bsc#1274031 * bsc#1274035 * bsc#1274040 * bsc#1274041 * bsc#1274055 * bsc#1274057 * bsc#1274058 * bsc#1274061 * bsc#1274063 * bsc#1274065 * bsc#1274067 * bsc#1274071 * bsc#1274075 * bsc#1274076 * bsc#1274077 * bsc#1274078 * bsc#1274208 * bsc#1274226 * bsc#1274239 * bsc#1274243 * bsc#1274258 * bsc#1274264 * bsc#1274265 * bsc#1274267 * bsc#1274274 * bsc#1274277 * bsc#1274278 * bsc#1274281 * bsc#1274283 * bsc#1274286 * bsc#1274290 * bsc#1274294 * bsc#1274295 * bsc#1274296 * bsc#1274297 * bsc#1274298 * bsc#1274314 * bsc#1274321 * bsc#1274491 * bsc#1274497 * bsc#1274539 * bsc#1274541 * bsc#1274543 * bsc#1274545 * bsc#1274547 * bsc#1274550 * bsc#1274573 * bsc#1274578 * bsc#1274580 * bsc#1274581 * bsc#1274620 * bsc#1274622 * bsc#1274624 * bsc#1274629 * bsc#1274632 * bsc#1274636 * bsc#1274639 * bsc#1274640 * bsc#1274642 * bsc#1274644 * bsc#1274645 * bsc#1274646 * bsc#1274649 * bsc#1274650 * bsc#1274651 * bsc#1274656 * bsc#1274659 * bsc#1274662 * bsc#1274663 * bsc#1274665 * bsc#1274667 * bsc#1274670 * bsc#1274675 * bsc#1274677 * bsc#1274678 * bsc#1274679 * bsc#1274681 * bsc#1274682 * bsc#1274690 * bsc#1274694 * bsc#1274696 * bsc#1274698 * bsc#1274699 * bsc#1274700 * bsc#1274702 * bsc#1274703 * bsc#1274705 * bsc#1274706 * bsc#1274709 * bsc#1274710 * bsc#1274713 * bsc#1274716 * bsc#1274721 * bsc#1274725 * bsc#1274737 * bsc#1274738 * bsc#1274749 * bsc#1274752 * bsc#1274753 * bsc#1274754 * bsc#1274755 * bsc#1274756 * bsc#1274764 * bsc#1274768 * bsc#1274770 * bsc#1274783 * bsc#1274787 * bsc#1274800 * bsc#1274801 * bsc#1274802 * bsc#1274804 * bsc#1274805 * bsc#1274807 * bsc#1274808 * bsc#1274811 * bsc#1274813 * bsc#1274814 * bsc#1274831 * bsc#1274834 * bsc#1274835 * bsc#1274847 * bsc#1274849 * bsc#1274853 * bsc#1274868 * bsc#1274869 * bsc#1274872 * bsc#1274873 * bsc#1274874 * bsc#1274876 * bsc#1274877 * bsc#1274879 * bsc#1274881 * bsc#1274883 * bsc#1274886 * bsc#1274888 * bsc#1274891 * bsc#1274892 * bsc#1274893 * bsc#1274894 * bsc#1274895 * bsc#1274896 * bsc#1274897 * bsc#1274898 * bsc#1274899 * bsc#1274901 * bsc#1274902 * bsc#1274905 * bsc#1274906 * bsc#1274907 * bsc#1274908 * bsc#1274913 * bsc#1274914 * bsc#1274920 * bsc#1274921 * bsc#1274924 * bsc#1274925 * bsc#1274929 * bsc#1274930 * bsc#1274933 * bsc#1274934 * bsc#1274935 * bsc#1274941 * bsc#1274945 * bsc#1274947 * bsc#1274951 * bsc#1274953 * bsc#1274958 * bsc#1274968 * bsc#1274981 * bsc#1275040 * bsc#1275069 * bsc#1275071 * bsc#1275073 * bsc#1275076 * bsc#1275080 * bsc#1275081 * bsc#1275083 * bsc#1275088 * bsc#1275091 * bsc#1275125 * bsc#1275126 * bsc#1275131 * bsc#1275132 * bsc#1275139 * bsc#1275141 * bsc#1275146 * bsc#1275148 * bsc#1275149 * bsc#1275150 * bsc#1275152 * bsc#1275154 * bsc#1275155 * bsc#1275156 * bsc#1275157 * bsc#1275158 * bsc#1275161 * bsc#1275163 * bsc#1275164 * bsc#1275169 * bsc#1275173 * bsc#1275176 * bsc#1275185 * bsc#1275190 * bsc#1275192 * bsc#1275236 * bsc#1275237 * bsc#1275239 * bsc#1275294 * bsc#1275300 * bsc#1275301 * bsc#1275303 * bsc#1275304 * bsc#1275305 * bsc#1275306 * bsc#1275307 * bsc#1275470 * bsc#1275472 * bsc#1275474 * bsc#1275479 * bsc#1275483 * bsc#1275486 * bsc#1275487 * bsc#1275506 * bsc#1275509 * bsc#1275511 * bsc#1275517 * bsc#1275519 * bsc#1275528 * bsc#1275535 * bsc#1275540 * bsc#1275553 * bsc#1275555 * bsc#1275557 * bsc#1275561 * bsc#1275566 * bsc#1275569 * bsc#1275572 * bsc#1275574 * bsc#1275578 * bsc#1275582 * bsc#1275583 * bsc#1275584 * bsc#1275591 * bsc#1275595 * bsc#1275633 * bsc#1275636 * bsc#1275650 * bsc#1275656 * bsc#1275659 * bsc#1275665 * bsc#1275669 * bsc#1275687 * bsc#1275688 * bsc#1275695 * bsc#1275696 * bsc#1275704 * bsc#1275737 * bsc#1275782 * bsc#1275784 * bsc#1275787 * bsc#1275788 * bsc#1275789 * bsc#1275790 * bsc#1275797 * bsc#1275798 * bsc#1275805 * bsc#1275817 * bsc#1275818 * bsc#1275819 * bsc#1275820 * bsc#1275821 * bsc#1275822 * bsc#1275823 * bsc#1275827 * bsc#1275864 * bsc#1275867 * bsc#1275869 * bsc#1275870 * bsc#1275871 * bsc#1275872 * bsc#1275886 * bsc#1275905 * bsc#1275923 * bsc#1275925 * bsc#1275928 * bsc#1275946 * bsc#1275950 * bsc#1275954 * bsc#1275970 * bsc#1275973 * bsc#1275975 * bsc#1275976 * bsc#1276029 * bsc#1276257 * bsc#1276263 * bsc#1276270 * bsc#1276273 * bsc#1276277 * bsc#1276335 * bsc#1276346 * bsc#1276350 * bsc#1276355 * bsc#1276446 * bsc#1276452 * bsc#1276500 * bsc#1276507 * bsc#1276542 * bsc#1276546 * bsc#1276551 * bsc#1276552 * bsc#1276561 * bsc#1276569 * bsc#1276577 * bsc#1276665 * bsc#1276864 * bsc#1276912 * bsc#1276913 * bsc#1276927 * bsc#1276931 * bsc#1276937 * bsc#1276941 * bsc#1276943 * bsc#1276944 * bsc#1276955 * bsc#1276961 * bsc#1277022 * bsc#1277034 * bsc#1277037 * bsc#1277047 * bsc#1277054 * bsc#1277057 * bsc#1277059 * bsc#1277064 * bsc#1277066 * bsc#1277069 * bsc#1277073 * bsc#1277077 * bsc#1277095 * bsc#1277155 * bsc#1277159 * bsc#1277160 * bsc#1277202 * bsc#1277204 * bsc#1277275 * bsc#1277285 * bsc#1277391 * bsc#1277408 * bsc#1277516 * bsc#1277523 * bsc#1277551 * bsc#1277625 * bsc#1277660 * bsc#1277678 * bsc#1277688 * bsc#1277775 * bsc#1277776 * jsc#PED-15880 * jsc#PED-16798 Cross-References: * CVE-2024-44981 * CVE-2024-57841 * CVE-2025-23137 * CVE-2025-38469 * CVE-2025-39939 * CVE-2025-39964 * CVE-2025-40022 * CVE-2025-40199 * CVE-2025-68179 * CVE-2025-68214 * CVE-2025-71075 * CVE-2025-71104 * CVE-2026-23210 * CVE-2026-23227 * CVE-2026-23230 * CVE-2026-23454 * CVE-2026-31418 * CVE-2026-31531 * CVE-2026-31557 * CVE-2026-31658 * CVE-2026-31663 * CVE-2026-43014 * CVE-2026-43015 * CVE-2026-43116 * CVE-2026-43125 * CVE-2026-43163 * CVE-2026-43213 * CVE-2026-43271 * CVE-2026-43273 * CVE-2026-43363 * CVE-2026-43386 * CVE-2026-43416 * CVE-2026-43448 * CVE-2026-45897 * CVE-2026-45968 * CVE-2026-46070 * CVE-2026-46078 * CVE-2026-46091 * CVE-2026-46107 * CVE-2026-46115 * CVE-2026-46127 * CVE-2026-46195 * CVE-2026-52920 * CVE-2026-52925 * CVE-2026-52929 * CVE-2026-52935 * CVE-2026-52939 * CVE-2026-52946 * CVE-2026-52975 * CVE-2026-52977 * CVE-2026-52990 * CVE-2026-52994 * CVE-2026-53001 * CVE-2026-53033 * CVE-2026-53034 * CVE-2026-53059 * CVE-2026-53076 * CVE-2026-53077 * CVE-2026-53089 * CVE-2026-53091 * CVE-2026-53094 * CVE-2026-53096 * CVE-2026-53110 * CVE-2026-53111 * CVE-2026-53126 * CVE-2026-53142 * CVE-2026-53154 * CVE-2026-53163 * CVE-2026-53180 * CVE-2026-53207 * CVE-2026-53219 * CVE-2026-53220 * CVE-2026-53223 * CVE-2026-53228 * CVE-2026-53238 * CVE-2026-53260 * CVE-2026-53263 * CVE-2026-53264 * CVE-2026-53269 * CVE-2026-53273 * CVE-2026-53309 * CVE-2026-53330 * CVE-2026-53336 * CVE-2026-53337 * CVE-2026-53353 * CVE-2026-53365 * CVE-2026-53366 * CVE-2026-53381 * CVE-2026-53388 * CVE-2026-63801 * CVE-2026-63808 * CVE-2026-63810 * CVE-2026-63823 * CVE-2026-63827 * CVE-2026-63828 * CVE-2026-63842 * CVE-2026-63850 * CVE-2026-63860 * CVE-2026-63865 * CVE-2026-63868 * CVE-2026-63879 * CVE-2026-63881 * CVE-2026-63886 * CVE-2026-63887 * CVE-2026-63888 * CVE-2026-63889 * CVE-2026-63891 * CVE-2026-63898 * CVE-2026-63920 * CVE-2026-63923 * CVE-2026-63925 * CVE-2026-63926 * CVE-2026-63928 * CVE-2026-63937 * CVE-2026-63944 * CVE-2026-63969 * CVE-2026-63970 * CVE-2026-63972 * CVE-2026-63973 * CVE-2026-63980 * CVE-2026-63985 * CVE-2026-63990 * CVE-2026-63992 * CVE-2026-63995 * CVE-2026-63996 * CVE-2026-63997 * CVE-2026-63998 * CVE-2026-63999 * CVE-2026-64000 * CVE-2026-64001 * CVE-2026-64002 * CVE-2026-64004 * CVE-2026-64005 * CVE-2026-64006 * CVE-2026-64007 * CVE-2026-64010 * CVE-2026-64011 * CVE-2026-64014 * CVE-2026-64015 * CVE-2026-64018 * CVE-2026-64021 * CVE-2026-64029 * CVE-2026-64033 * CVE-2026-64034 * CVE-2026-64039 * CVE-2026-64047 * CVE-2026-64048 * CVE-2026-64051 * CVE-2026-64052 * CVE-2026-64055 * CVE-2026-64056 * CVE-2026-64073 * CVE-2026-64083 * CVE-2026-64084 * CVE-2026-64085 * CVE-2026-64086 * CVE-2026-64087 * CVE-2026-64088 * CVE-2026-64097 * CVE-2026-64098 * CVE-2026-64099 * CVE-2026-64102 * CVE-2026-64109 * CVE-2026-64112 * CVE-2026-64113 * CVE-2026-64114 * CVE-2026-64115 * CVE-2026-64118 * CVE-2026-64121 * CVE-2026-64125 * CVE-2026-64126 * CVE-2026-64127 * CVE-2026-64128 * CVE-2026-64131 * CVE-2026-64133 * CVE-2026-64134 * CVE-2026-64135 * CVE-2026-64136 * CVE-2026-64137 * CVE-2026-64144 * CVE-2026-64146 * CVE-2026-64148 * CVE-2026-64155 * CVE-2026-64164 * CVE-2026-64166 * CVE-2026-64168 * CVE-2026-64178 * CVE-2026-64180 * CVE-2026-64185 * CVE-2026-64188 * CVE-2026-64190 * CVE-2026-64192 * CVE-2026-64214 * CVE-2026-64217 * CVE-2026-64218 * CVE-2026-64219 * CVE-2026-64222 * CVE-2026-64224 * CVE-2026-64225 * CVE-2026-64237 * CVE-2026-64243 * CVE-2026-64244 * CVE-2026-64245 * CVE-2026-64246 * CVE-2026-64247 * CVE-2026-64249 * CVE-2026-64257 * CVE-2026-64266 * CVE-2026-64268 * CVE-2026-64269 * CVE-2026-64271 * CVE-2026-64273 * CVE-2026-64274 * CVE-2026-64275 * CVE-2026-64276 * CVE-2026-64277 * CVE-2026-64286 * CVE-2026-64287 * CVE-2026-64294 * CVE-2026-64296 * CVE-2026-64303 * CVE-2026-64304 * CVE-2026-64305 * CVE-2026-64306 * CVE-2026-64312 * CVE-2026-64313 * CVE-2026-64315 * CVE-2026-64316 * CVE-2026-64317 * CVE-2026-64322 * CVE-2026-64323 * CVE-2026-64329 * CVE-2026-64331 * CVE-2026-64332 * CVE-2026-64333 * CVE-2026-64334 * CVE-2026-64335 * CVE-2026-64337 * CVE-2026-64338 * CVE-2026-64340 * CVE-2026-64341 * CVE-2026-64342 * CVE-2026-64343 * CVE-2026-64344 * CVE-2026-64346 * CVE-2026-64348 * CVE-2026-64350 * CVE-2026-64351 * CVE-2026-64355 * CVE-2026-64358 * CVE-2026-64362 * CVE-2026-64365 * CVE-2026-64375 * CVE-2026-64376 * CVE-2026-64378 * CVE-2026-64381 * CVE-2026-64382 * CVE-2026-64383 * CVE-2026-64384 * CVE-2026-64385 * CVE-2026-64386 * CVE-2026-64387 * CVE-2026-64388 * CVE-2026-64401 * CVE-2026-64403 * CVE-2026-64406 * CVE-2026-64407 * CVE-2026-64408 * CVE-2026-64409 * CVE-2026-64411 * CVE-2026-64412 * CVE-2026-64420 * CVE-2026-64421 * CVE-2026-64423 * CVE-2026-64427 * CVE-2026-64429 * CVE-2026-64433 * CVE-2026-64434 * CVE-2026-64436 * CVE-2026-64440 * CVE-2026-64442 * CVE-2026-64443 * CVE-2026-64444 * CVE-2026-64445 * CVE-2026-64448 * CVE-2026-64450 * CVE-2026-64452 * CVE-2026-64454 * CVE-2026-64455 * CVE-2026-64463 * CVE-2026-64470 * CVE-2026-64471 * CVE-2026-64472 * CVE-2026-64477 * CVE-2026-64478 * CVE-2026-64479 * CVE-2026-64480 * CVE-2026-64481 * CVE-2026-64482 * CVE-2026-64483 * CVE-2026-64484 * CVE-2026-64486 * CVE-2026-64487 * CVE-2026-64489 * CVE-2026-64494 * CVE-2026-64495 * CVE-2026-64496 * CVE-2026-64497 * CVE-2026-64500 * CVE-2026-64503 * CVE-2026-64504 * CVE-2026-64505 * CVE-2026-64511 * CVE-2026-64512 * CVE-2026-64513 * CVE-2026-64515 * CVE-2026-64517 * CVE-2026-64524 * CVE-2026-64527 * CVE-2026-64536 * CVE-2026-64537 * CVE-2026-64538 * CVE-2026-64539 * CVE-2026-64540 * CVE-2026-64541 * CVE-2026-64543 * CVE-2026-64544 * CVE-2026-64545 * CVE-2026-64546 * CVE-2026-64547 * CVE-2026-64548 * CVE-2026-64549 * CVE-2026-64551 * CVE-2026-64552 * CVE-2026-64553 * CVE-2026-64554 * CVE-2026-64558 * CVE-2026-64559 * CVE-2026-64562 * CVE-2026-64563 * CVE-2026-64565 * CVE-2026-64567 * CVE-2026-64568 * CVE-2026-64569 * CVE-2026-64570 * CVE-2026-64571 * CVE-2026-64572 * CVE-2026-64573 * CVE-2026-64574 * CVE-2026-64576 * CVE-2026-64577 * CVE-2026-64581 * CVE-2026-64582 * CVE-2026-64583 * CVE-2026-64584 * CVE-2026-64585 * CVE-2026-64593 * CVE-2026-64597 * CVE-2026-64598 * CVE-2026-64599 * CVE-2026-64602 * CVE-2026-64603 * CVE-2026-64604 * CVE-2026-68081 * CVE-2026-68082 * CVE-2026-68085 * CVE-2026-68086 * CVE-2026-68088 * CVE-2026-68091 * CVE-2026-68093 * CVE-2026-68102 * CVE-2026-68104 * CVE-2026-68105 * CVE-2026-68106 * CVE-2026-68107 * CVE-2026-68108 * CVE-2026-68110 * CVE-2026-68111 * CVE-2026-68112 * CVE-2026-68113 * CVE-2026-68115 * CVE-2026-68116 * CVE-2026-68117 * CVE-2026-68121 * CVE-2026-68123 * CVE-2026-68124 * CVE-2026-68125 * CVE-2026-68126 * CVE-2026-68127 * CVE-2026-68129 * CVE-2026-68132 * CVE-2026-68133 * CVE-2026-68135 * CVE-2026-68136 * CVE-2026-68137 * CVE-2026-68138 * CVE-2026-68139 * CVE-2026-68142 * CVE-2026-68143 * CVE-2026-68145 * CVE-2026-68149 * CVE-2026-68152 * CVE-2026-68153 * CVE-2026-68154 * CVE-2026-68155 * CVE-2026-68156 * CVE-2026-68157 * CVE-2026-68158 * CVE-2026-68159 * CVE-2026-68160 * CVE-2026-68161 * CVE-2026-68162 * CVE-2026-68166 * CVE-2026-68180 * CVE-2026-68181 * CVE-2026-68182 * CVE-2026-68184 * CVE-2026-68188 * CVE-2026-68189 * CVE-2026-68192 * CVE-2026-68193 * CVE-2026-68194 * CVE-2026-68195 * CVE-2026-68196 * CVE-2026-68197 * CVE-2026-68199 * CVE-2026-68202 * CVE-2026-68204 * CVE-2026-68205 * CVE-2026-68206 * CVE-2026-68207 * CVE-2026-68209 * CVE-2026-68210 * CVE-2026-68212 * CVE-2026-68213 * CVE-2026-68214 * CVE-2026-68215 * CVE-2026-68216 * CVE-2026-68217 * CVE-2026-68218 * CVE-2026-68219 * CVE-2026-68220 * CVE-2026-68222 * CVE-2026-68223 * CVE-2026-68226 * CVE-2026-68227 * CVE-2026-68229 * CVE-2026-68231 * CVE-2026-68234 * CVE-2026-68235 * CVE-2026-68236 * CVE-2026-68238 * CVE-2026-68243 * CVE-2026-68244 * CVE-2026-68245 * CVE-2026-68246 * CVE-2026-68247 * CVE-2026-68248 * CVE-2026-68249 * CVE-2026-68250 * CVE-2026-68251 * CVE-2026-68252 * CVE-2026-68253 * CVE-2026-68254 * CVE-2026-68255 * CVE-2026-68256 * CVE-2026-68257 * CVE-2026-68259 * CVE-2026-68260 * CVE-2026-68261 * CVE-2026-68262 * CVE-2026-68263 * CVE-2026-68267 * CVE-2026-68269 * CVE-2026-68271 * CVE-2026-68272 * CVE-2026-68277 * CVE-2026-68278 * CVE-2026-68279 * CVE-2026-68280 * CVE-2026-68281 * CVE-2026-68284 * CVE-2026-68286 * CVE-2026-68288 * CVE-2026-68289 * CVE-2026-68293 * CVE-2026-68297 * CVE-2026-68299 * CVE-2026-68300 * CVE-2026-68302 * CVE-2026-68303 * CVE-2026-68304 * CVE-2026-68306 * CVE-2026-68308 * CVE-2026-68309 * CVE-2026-68310 * CVE-2026-68312 * CVE-2026-68313 * CVE-2026-68315 * CVE-2026-68320 * CVE-2026-68322 * CVE-2026-68324 * CVE-2026-68325 * CVE-2026-68326 * CVE-2026-68327 * CVE-2026-68328 * CVE-2026-68329 * CVE-2026-68331 * CVE-2026-68333 * CVE-2026-68335 * CVE-2026-68336 * CVE-2026-68339 * CVE-2026-68340 * CVE-2026-68343 * CVE-2026-68346 * CVE-2026-68348 * CVE-2026-68349 * CVE-2026-68350 * CVE-2026-68351 * CVE-2026-68352 * CVE-2026-68353 * CVE-2026-68354 * CVE-2026-68355 * CVE-2026-68357 * CVE-2026-68359 * CVE-2026-68360 * CVE-2026-68361 * CVE-2026-68362 * CVE-2026-68363 * CVE-2026-68365 * CVE-2026-68366 * CVE-2026-68368 * CVE-2026-68369 * CVE-2026-68370 * CVE-2026-68372 * CVE-2026-68373 * CVE-2026-68375 * CVE-2026-68377 * CVE-2026-68386 * CVE-2026-68389 * CVE-2026-68391 * CVE-2026-68392 * CVE-2026-68394 * CVE-2026-68397 * CVE-2026-68398 * CVE-2026-68399 * CVE-2026-68402 * CVE-2026-68403 * CVE-2026-68405 * CVE-2026-68406 * CVE-2026-68407 * CVE-2026-68408 * CVE-2026-68410 * CVE-2026-68413 * CVE-2026-68414 * CVE-2026-68417 * CVE-2026-68418 * CVE-2026-68419 * CVE-2026-68422 * CVE-2026-68425 * CVE-2026-68426 * CVE-2026-68427 * CVE-2026-68428 * CVE-2026-68429 * CVE-2026-68430 * CVE-2026-68432 * CVE-2026-68433 * CVE-2026-68434 * CVE-2026-68437 * CVE-2026-68444 * CVE-2026-68445 * CVE-2026-68446 * CVE-2026-68450 * CVE-2026-68470 * CVE-2026-68480 * CVE-2026-72020 * CVE-2026-72032 * CVE-2026-72035 * CVE-2026-72036 * CVE-2026-72046 * CVE-2026-72069 * CVE-2026-72072 * CVE-2026-72083 * CVE-2026-72084 * CVE-2026-72123 * CVE-2026-72132 * CVE-2026-72221 * CVE-2026-72222 * CVE-2026-72251 * CVE-2026-72254 * CVE-2026-72262 * CVE-2026-72288 * CVE-2026-72289 * CVE-2026-72296 * CVE-2026-72307 * CVE-2026-72308 * CVE-2026-72317 * CVE-2026-72341 * CVE-2026-72342 * CVE-2026-72343 * CVE-2026-72389 * CVE-2026-72463 * CVE-2026-72464 * CVE-2026-72466 * CVE-2026-72467 * CVE-2026-72469 * CVE-2026-72473 * CVE-2026-72494 * CVE-2026-72495 * CVE-2026-72496 * CVE-2026-72497 * CVE-2026-72498 * CVE-2026-72499 * CVE-2026-72500 * CVE-2026-72501 * CVE-2026-72502 * CVE-2026-74269 * CVE-2026-74296 * CVE-2026-74297 * CVE-2026-74318 * CVE-2026-74321 * CVE-2026-74334 * CVE-2026-74345 * CVE-2026-74394 * CVE-2026-74395 * CVE-2026-74454 * CVE-2026-74474 * CVE-2026-74481 * CVE-2026-74482 * CVE-2026-74488 * CVE-2026-74495 * CVE-2026-74496 * CVE-2026-74509 * CVE-2026-74510 * CVE-2026-74512 * CVE-2026-74516 * CVE-2026-74518 * CVE-2026-74527 * CVE-2026-74537 * CVE-2026-74548 * CVE-2026-74550 * CVE-2026-74556 * CVE-2026-74563 * CVE-2026-74566 * CVE-2026-74567 * CVE-2026-74571 * CVE-2026-74577 * CVE-2026-74581 * CVE-2026-74582 * CVE-2026-74584 * CVE-2026-74610 * CVE-2026-74669 * CVE-2026-74692 * CVE-2026-74694 * CVE-2026-74695 * CVE-2026-74712 * CVE-2026-74717 * CVE-2026-74722 * CVE-2026-80529 * CVE-2026-80534 * CVE-2026-80590 * CVE-2026-80654 CVSS scores: * CVE-2024-44981 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L * CVE-2024-44981 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2024-44981 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-57841 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-23137 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-23137 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-23137 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-38469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39939 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39939 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-39939 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-39964 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-39964 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-39964 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-39964 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40022 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-40022 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-40199 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-40199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-40199 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68179 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68179 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68214 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71104 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2025-71104 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-71104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23210 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23230 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23230 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23230 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23230 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-23454 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23454 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23454 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31418 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31418 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31531 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31557 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31658 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31658 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31658 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31663 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31663 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43014 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43014 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43015 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43116 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43163 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43213 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43271 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43271 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43271 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43386 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43386 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43416 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43448 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43448 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45897 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45897 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45897 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46070 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46070 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46078 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46078 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-46091 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46091 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46091 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46107 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46107 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46107 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46115 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46115 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46127 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46127 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46127 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46195 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46195 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52920 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-52920 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-52925 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52925 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52925 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52939 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52939 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52977 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52977 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52990 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53033 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53034 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53034 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53059 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53059 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53059 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53076 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53076 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53077 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53077 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53077 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53089 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53089 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53091 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53091 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53091 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53091 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-53094 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53094 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53096 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53096 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53110 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53111 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53111 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53111 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53142 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53142 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53142 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53180 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53180 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53180 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53207 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53228 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53228 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53238 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53238 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53263 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53263 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53269 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53269 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53269 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53309 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53309 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53309 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53330 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53330 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53336 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53336 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53353 ( SUSE ): 0.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53353 ( SUSE ): 0.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N * CVE-2026-53353 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53365 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53365 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53365 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53381 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63801 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63801 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63801 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63808 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63808 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-63808 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63810 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63810 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63823 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63823 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63823 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63827 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63828 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63828 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63828 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-63842 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63842 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63842 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63850 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63850 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63850 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63860 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63860 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63860 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63865 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63865 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63865 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-63868 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63868 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63879 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63879 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63879 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63881 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63886 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63886 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63886 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63887 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63887 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63887 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63888 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63888 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63888 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63889 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63889 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63889 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63891 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63891 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63898 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63898 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63920 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63920 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63920 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63923 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63923 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-63925 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63925 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63925 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-63926 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63926 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63926 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63928 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63928 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63937 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63937 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63937 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-63944 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63944 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63969 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63969 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63970 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63970 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63972 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63972 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63972 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63973 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63973 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63980 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63985 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63985 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63985 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63990 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63990 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63992 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63992 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63992 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63995 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63995 ( SUSE ): 6.2 CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63995 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63996 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63996 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63996 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63997 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63997 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63998 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63998 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63999 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63999 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64000 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64000 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64000 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64001 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64001 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64002 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64002 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64002 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64004 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64004 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64005 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64005 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64005 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64006 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-64006 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-64007 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64007 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64007 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64010 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64011 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64014 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64014 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64015 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64015 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64018 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-64018 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-64018 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64021 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64021 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64029 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64029 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64029 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64033 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64033 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64033 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64034 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64039 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64039 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64039 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64047 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64047 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64048 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64048 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64048 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64051 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64051 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64051 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64052 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64052 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64052 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64055 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-64055 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-64055 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64056 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64056 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64056 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64073 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64073 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64073 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64083 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64083 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64083 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64084 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64084 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64084 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64085 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64085 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64085 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64086 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64086 ( SUSE ): 5.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64086 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64087 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64087 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64087 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64088 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64088 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64088 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64097 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64097 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64097 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64098 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64099 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64099 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64099 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64102 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-64102 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-64102 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64113 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64113 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64114 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64115 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64118 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64118 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64118 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64121 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64121 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64121 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64125 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64126 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64126 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L * CVE-2026-64126 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-64127 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64127 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64128 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64134 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64134 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64135 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64136 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64136 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64137 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64137 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64137 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64144 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64144 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64144 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64146 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64146 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64146 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64148 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64148 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64148 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64155 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64164 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64166 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64178 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64178 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64180 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64180 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64180 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64185 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64185 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64188 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64188 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64188 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64190 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64190 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64190 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64217 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64217 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64217 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64218 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64219 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64222 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64222 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64222 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64224 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64224 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64224 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64225 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64225 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64225 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64237 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64237 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64244 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64245 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64246 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64246 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64246 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64247 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64247 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-64249 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64249 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64257 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64257 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-64257 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64266 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64266 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64268 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64269 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-64269 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64271 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64271 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64271 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64273 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64275 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64275 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64277 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64286 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64286 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64287 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64303 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64303 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64303 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64304 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64305 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64305 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64306 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64313 ( SUSE ): 7.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-64313 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64313 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64315 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64316 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64316 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64317 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64317 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64317 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64322 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64322 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64322 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64323 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64323 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64329 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64329 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64329 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64331 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64331 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64333 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64333 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64334 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64334 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64334 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64335 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64335 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64335 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64337 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64337 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64338 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64340 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64340 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64340 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64341 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64342 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64343 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64344 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64346 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64348 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64348 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64348 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64350 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64350 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64350 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64351 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64351 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64351 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64355 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64355 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64358 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64358 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64365 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64375 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64375 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64376 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64376 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64376 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64381 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64381 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64382 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64382 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64383 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64383 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64384 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64385 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64386 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64387 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64388 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64388 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-64388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64401 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64401 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64403 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64403 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64403 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64406 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64407 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64407 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64408 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64408 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64409 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64409 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64411 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64411 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64411 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64412 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64412 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64412 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64420 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64421 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64421 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64427 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64427 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64434 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64436 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64436 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64440 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64440 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64440 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64442 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64442 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64443 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64443 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64444 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64444 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64444 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64445 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64448 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64448 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64450 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64452 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64454 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64471 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64477 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64478 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64478 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64479 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64480 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64481 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64481 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64482 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64482 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64483 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64484 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64484 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64486 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64487 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64489 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64497 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64500 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64503 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64504 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64505 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64511 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64511 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64512 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64513 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64515 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64515 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-64517 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64527 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64537 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64537 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64538 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64540 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64540 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64540 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64541 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64541 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64541 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64544 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64544 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64545 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64547 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64547 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64547 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64548 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64548 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64549 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64551 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64551 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64552 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64552 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64552 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64553 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64558 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64558 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64558 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64559 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64559 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64559 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64562 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64562 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64563 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64563 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64565 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64565 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64567 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64567 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64567 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64568 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64568 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64568 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64569 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64569 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64570 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64570 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64570 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64571 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64571 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64572 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64572 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64573 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64573 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64574 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64576 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64576 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64576 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64577 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64577 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64577 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64581 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64581 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64581 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64582 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64583 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64583 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64584 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64585 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64593 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64593 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64598 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64598 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64599 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64599 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64602 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64603 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64604 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68081 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68081 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68082 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68082 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68082 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68085 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68085 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68085 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68086 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-68086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-68088 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68088 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68091 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68091 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68091 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68093 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-68093 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68102 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68102 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68104 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68105 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68105 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68106 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68106 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68106 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68107 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68107 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68107 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68108 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68108 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68108 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68110 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68110 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68111 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68111 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68113 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68113 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68115 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68115 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68116 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68116 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-68116 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68117 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68117 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68121 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68121 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68123 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68123 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68123 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68124 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68124 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-68124 ( NVD ): 9.6 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68125 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68125 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68125 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68126 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68126 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68127 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68127 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68127 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68129 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68129 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68129 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68132 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68132 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68133 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68133 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68135 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68135 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68136 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68136 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68137 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68139 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68139 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68142 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68142 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-68142 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68143 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68143 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68143 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68145 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68145 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68145 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68149 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68149 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68149 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-68152 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68152 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68152 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68153 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68153 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68153 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68154 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68154 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68154 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68155 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68155 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68155 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68156 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68156 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68156 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68157 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68157 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68157 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68158 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68158 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68158 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68159 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68159 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68159 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68160 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68160 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68160 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68161 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68161 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68161 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68162 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68166 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68166 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68180 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68182 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68184 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68184 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68188 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68192 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68192 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68197 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68202 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68204 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68207 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68210 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68210 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68212 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68217 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68218 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68218 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68219 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68219 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68220 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68220 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68222 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68223 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68223 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68226 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68226 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68227 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68227 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68229 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68229 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-68229 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68231 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68231 ( SUSE ): 2.1 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68234 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68235 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68235 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68236 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68236 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68236 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68238 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68238 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68243 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68244 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68245 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-68245 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68246 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68246 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68247 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68247 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68248 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68249 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68250 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68250 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68251 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68251 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68252 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68252 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68256 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68257 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68257 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68259 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68259 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68260 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68261 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68262 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68262 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68263 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68263 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68267 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68269 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68271 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68272 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68278 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68278 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68279 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68279 ( SUSE ): 2.4 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68280 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68280 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68281 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68281 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68284 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68284 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68286 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68286 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68288 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68288 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68289 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68293 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68293 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68299 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68302 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68302 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68308 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68309 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68310 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68312 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68313 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-68322 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68324 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68325 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68327 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68327 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68328 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68333 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68343 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68349 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68350 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68351 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68353 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68353 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68354 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68355 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68357 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68359 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68360 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68361 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68365 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68365 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-68366 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68368 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68369 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68370 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68372 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68375 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68377 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68377 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68386 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68389 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68389 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68391 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68391 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68392 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68392 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68394 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68394 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68402 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68402 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68403 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68405 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68406 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68407 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68408 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68410 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68413 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68414 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68414 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68422 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68425 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68425 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68426 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68426 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68427 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68427 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68427 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68428 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68430 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68430 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68433 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-68434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68437 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68444 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68445 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68445 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68445 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68446 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68446 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68470 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68470 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68470 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68480 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-72020 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72020 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72020 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72032 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-72032 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-72035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72035 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72036 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72046 ( SUSE ): 0.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N * CVE-2026-72046 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72069 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72083 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72084 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72123 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72132 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72132 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72221 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72221 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72221 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72222 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72251 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72251 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72251 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72254 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72262 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72262 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72288 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72289 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72289 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72289 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72296 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72296 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72296 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-72307 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72307 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72308 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72308 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72317 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72317 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72317 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72341 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72342 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72342 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72343 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72343 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72389 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72463 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72463 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72464 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72464 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72467 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72473 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-72473 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72494 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72495 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72496 ( NVD ): 9.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H * CVE-2026-72497 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72497 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72498 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72499 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72499 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72500 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72500 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72501 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74269 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74269 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74318 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74345 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74345 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74345 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74394 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74395 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74395 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74454 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74454 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-74454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74474 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74474 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74481 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74482 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74482 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74488 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74488 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74495 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74495 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74509 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74509 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74516 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-74516 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74518 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74518 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74527 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-74527 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74537 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74537 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74550 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74550 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74556 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-74556 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74563 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74566 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-74567 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74567 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74571 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74577 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-74581 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74581 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74582 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74584 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-74584 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-74584 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-74610 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-74610 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74610 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74692 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74694 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74694 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74695 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74695 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74712 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-74712 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74717 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74717 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74722 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80534 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80534 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80590 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-80654 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80654 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Real Time Module 15-SP7 An update that solves 662 vulnerabilities, contains two features and has 35 security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP7 RT kernel was updated to fix various security issues: The following security issues were fixed: * CVE-2024-57841: net: fix memory leak in tcp_conn_request() (bsc#1235944). * CVE-2025-68214: timers: Fix NULL function pointer race in timer_shutdown_sync() (bsc#1255225). * CVE-2025-71075: scsi: aic94xx: fix use-after-free in device removal path (bsc#1256629). * CVE-2026-31418: netfilter: ipset: drop logically empty buckets in mtype_del (bsc#1262073). * CVE-2026-31531: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() (bsc#1263004). * CVE-2026-31557: nvmet: move async event work off nvmet-wq (bsc#1263061). * CVE-2026-31658: net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (bsc#1263052). * CVE-2026-31663: xfrm: hold device only for the asynchronous decryption (bsc#1263133). * CVE-2026-43014: net: macb: properly unregister fixed rate clocks (bsc#1264012). * CVE-2026-43015: net: macb: fix clk handling on PCI glue driver removal (bsc#1264010). * CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack (bsc#1264619). * CVE-2026-43125: dlm: validate length in dlm_search_rsb_tree (bsc#1264541). * CVE-2026-43163: md/bitmap: fix GPF in write_page caused by resize race (bsc#1264335). * CVE-2026-43213: wifi: rtw89: pci: validate sequence number of TX release report (bsc#1264643). * CVE-2026-43271: md-cluster: fix NULL pointer dereference in process_metadata_update (bsc#1264587). * CVE-2026-43273: ceph: supply snapshot context in ceph_zero_partial_object() (bsc#1264446). * CVE-2026-43363: x86/apic: Disable x2apic on resume if the kernel expects so (bsc#1265068). * CVE-2026-43386: staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie (bsc#1264740). * CVE-2026-43416: powerpc, perf: Check that current->mm is alive before getting user callchain (bsc#1265121). * CVE-2026-43448: nvme-pci: Fix race bug in nvme_poll_irqdisable() (bsc#1264807). * CVE-2026-45897: bpf: Fix UAF in sock clone early bailouts (bsc#1266897). * CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). * CVE-2026-46070: md/raid5: validate payload size before accessing journal metadata (bsc#1267501). * CVE-2026-46078: erofs: fix the out-of-bounds nameoff handling for trailing dirents (bsc#1267505). * CVE-2026-46091: media: rc: igorplugusb: heed coherency rules (bsc#1267238). * CVE-2026-46107: dm-thin: fix metadata refcount underflow (bsc#1267612). * CVE-2026-46115: block: add pgmap check to biovec_phys_mergeable (bsc#1266874). * CVE-2026-46127: RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() (bsc#1267236). * CVE-2026-46195: smb: client: validate dacloffset before building DACL pointers (bsc#1266860). * CVE-2026-52920: netfilter: xt_policy: fix strict mode inbound policy matching (bsc#1269013). * CVE-2026-52925: vrf: Fix a potential NPD when removing a port from a VRF (bsc#1268987). * CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). * CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send (bsc#1268979). * CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion (bsc#1268972). * CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (bsc#1269113). * CVE-2026-52975: bonding: 802.3ad replace MAC_ADDRESS_EQUAL with __agg_has_partner (bsc#1269234). * CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). * CVE-2026-52990: fsnotify: fix inode reference leak in fsnotify_recalc_mask() (bsc#1269108). * CVE-2026-52994: vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting (bsc#1269126). * CVE-2026-53001: netfilter: xtables: restrict several matches to inet family (bsc#1269114). * CVE-2026-53033: bpf, sockmap: Take state lock for af_unix iter (bsc#1269388). * CVE-2026-53034: bpf, sockmap: Fix af_unix null-ptr-deref in proto update (bsc#1269140). * CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). * CVE-2026-53076: bpf: Fix OOB in pcpu_init_value (bsc#1269695). * CVE-2026-53077: net/rds: Restrict use of RDS/IB to the initial network namespace (bsc#1269412). * CVE-2026-53089: bpf: Fix use-after-free in offloaded map/prog info fill (bsc#1269783). * CVE-2026-53091: net: account for encap headers in qdisc pkt len (bsc#1269530). * CVE-2026-53094: bpf: Fix stale offload->prog pointer after constant blinding (bsc#1269965). * CVE-2026-53096: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (bsc#1269969). * CVE-2026-53110: selftests/bpf: Add ASSERT_OK_FD macro (bsc#1269985). * CVE-2026-53111: bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap (bsc#1269167). * CVE-2026-53126: blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() (bsc#1269635). * CVE-2026-53142: drm/xe/display: fix oops in suspend/shutdown without display (bsc#1269402). * CVE-2026-53154: mm/hugetlb: restore reservation on error in hugetlb folio copy paths (bsc#1269665). * CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). * CVE-2026-53180: timers/migration: Fix livelock in tmigr_handle_remote_up() (bsc#1269888). * CVE-2026-53207: mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison (bsc#1269590). * CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers (bsc#1269686). * CVE-2026-53220: netfilter: revalidate bridge ports (bsc#1269381). * CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs (bsc#1269301). * CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads (bsc#1269256). * CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths (bsc#1269774). * CVE-2026-53260: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req() (bsc#1269731). * CVE-2026-53263: 6lowpan: fix off-by-one in multicast context address compression (bsc#1269647). * CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). * CVE-2026-53269: netfilter: synproxy: add mutex to guard hook reference counting (bsc#1269579). * CVE-2026-53273: tee: optee: prevent use-after-free when the client exits before the supplicant (bsc#1269713). * CVE-2026-53309: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (bsc#1269815). * CVE-2026-53330: drm/amd/display: Fix out-of-bounds read in (bsc#1270090). * CVE-2026-53336: nvmem: layouts: onie-tlv: fix hang on unknown types (bsc#1270108). * CVE-2026-53337: net: bonding: fix NULL pointer dereference in bond_do_ioctl() (bsc#1270251). * CVE-2026-53353: hsr: Remove WARN_ONCE() in hsr_addr_is_self() (bsc#1270111). * CVE-2026-53365: vsock/virtio: fix zerocopy completion for multi-skb sends (bsc#1271365). * CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). * CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). * CVE-2026-63808: exfat: fix potential use-after-free in exfat_find_dir_entry() (bsc#1272260). * CVE-2026-63810: block: Avoid mounting the bdev pseudo-filesystem in userspace (bsc#1272297). * CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). * CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179). * CVE-2026-63828: apparmor: mediate the implicit connect of TCP fast open sendmsg (bsc#1272175). * CVE-2026-63860: RDMA/core: Prefer NLA_NUL_STRING (bsc#1272429). * CVE-2026-63865: bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (bsc#1272486). * CVE-2026-63868: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (bsc#1272497). * CVE-2026-63879: drm/amdgpu: fix amdgpu_hmm_range_get_pages (bsc#1272569). * CVE-2026-63881: drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger (bsc#1272571). * CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). * CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). * CVE-2026-63889: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (bsc#1272423). * CVE-2026-63891: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (bsc#1272641). * CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). * CVE-2026-63923: octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify (bsc#1273005). * CVE-2026-63925: macsec: fix replay protection at XPN lower-PN wrap (bsc#1273008). * CVE-2026-63926: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (bsc#1273019). * CVE-2026-63944: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (bsc#1272662). * CVE-2026-63969: ipv6: fix possible infinite loop in rt6_fill_node() (bsc#1272484). * CVE-2026-63970: vsock/virtio: bind uarg before filling zerocopy skb (bsc#1272673). * CVE-2026-63980: net/handshake: Use spin_lock_bh for hn_lock (bsc#1273028). * CVE-2026-63985: ethtool: eeprom: add more safeties to EEPROM Netlink fallback (bsc#1272963). * CVE-2026-63990: bonding: refuse to enslave CAN devices (bsc#1273027). * CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). * CVE-2026-63995: ethtool: cmis: validate start_cmd_payload_size from module (bsc#1273033). * CVE-2026-63996: ethtool: cmis: require exact CDB reply length (bsc#1273032). * CVE-2026-63997: ethtool: module: avoid leaking a netdev ref on module flash errors (bsc#1273036). * CVE-2026-63998: ethtool: module: call ethnl_ops_complete() on module flash errors (bsc#1273037). * CVE-2026-63999: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure (bsc#1273038). * CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273030). * CVE-2026-64001: ALSA: pcm: oss: Fix setup list UAF on proc write error (bsc#1273734). * CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). * CVE-2026-64004: net/iucv: fix locking in .getsockopt (bsc#1273804). * CVE-2026-64005: net/smc: Do not re-initialize smc hashtables (bsc#1273831). * CVE-2026-64006: netfilter: nf_tables: fix dst corruption in same register operation (bsc#1273834). * CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). * CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882). * CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891). * CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762). * CVE-2026-64029: ALSA: seq: Serialize UMP output teardown with event_input (bsc#1273766). * CVE-2026-64033: RDMA/rtrs: Fix use-after-free in path file creation cleanup (bsc#1273134). * CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). * CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). * CVE-2026-64052: block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() (bsc#1272983). * CVE-2026-64055: net: ethernet: cortina: Drop half-assembled SKB (bsc#1272893). * CVE-2026-64056: net: ethernet: cortina: Make RX SKB per-port (bsc#1272502 bsc#1272893). * CVE-2026-64073: irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT (bsc#1273490). * CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488). * CVE-2026-64099: drm/v3d: Fix use-after-free of CPU job query arrays on error path (bsc#1273465). * CVE-2026-64102: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (bsc#1272516). * CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748). * CVE-2026-64112: rbd: eliminate a race in lock_dwork draining on unmap (bsc#1273741). * CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning (bsc#1272262). * CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). * CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). * CVE-2026-64118: qed: fix double free in qed_cxt_tables_alloc() (bsc#1273749). * CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273743). * CVE-2026-64125: net: bcmgenet: keep RBUF EEE/PM disabled (bsc#1272346). * CVE-2026-64131: mm/memory: fix spurious warning when unmapping device- private/exclusive pages (bsc#1274063). * CVE-2026-64136: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (bsc#1272351). * CVE-2026-64146: erofs: fix metabuf leak in inode xattr initialization (bsc#1273681). * CVE-2026-64148: pds_core: check health in devcmd wait (bsc#1273956). * CVE-2026-64164: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (bsc#1273957). * CVE-2026-64180: mm/memory_hotplug: fix memory block reference leak on remove (bsc#1273679). * CVE-2026-64185: sysfs: don't remove existing directory on update failure (bsc#1272200). * CVE-2026-64188: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (bsc#1272150). * CVE-2026-64190: net: team: fix NULL pointer dereference in team_xmit during mode change (bsc#1272210). * CVE-2026-64192: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (bsc#1272213). * CVE-2026-64214: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() (bsc#1272799). * CVE-2026-64217: netfs: Fix overrun check in netfs_extract_user_iter() (bsc#1272798). * CVE-2026-64222: octeontx2-pf: avoid double free of pool->stack on AQ init failure (bsc#1272788). * CVE-2026-64224: octeontx2-pf: fix double free in rvu_rep_rsrc_init() (bsc#1272804). * CVE-2026-64225: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (bsc#1272786). * CVE-2026-64244: drivers/base/memory: set mem->altmap after successful device registration (bsc#1273812). * CVE-2026-64245: fbdev: modedb: fix a possible UAF in fb_find_mode() (bsc#1273905). * CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). * CVE-2026-64269: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg (bsc#1273280). * CVE-2026-64286: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (bsc#1274058). * CVE-2026-64287: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (bsc#1273325). * CVE-2026-64294: mm: do file ownership checks with the proper mount idmap (bsc#1273525). * CVE-2026-64296: exfat: bound uniname advance in exfat_find_dir_entry() (bsc#1273975). * CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944). * CVE-2026-64312: crypto: pcrypt - restore callback for non-parallel fallback (bsc#1273968). * CVE-2026-64315: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1274028). * CVE-2026-64316: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1273598). * CVE-2026-64317: isofs: bound Rock Ridge symlink components to the SL record (bsc#1273936). * CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count (bsc#1273958). * CVE-2026-64323: udf: validate VAT header length against the VAT inode size (bsc#1273305). * CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). * CVE-2026-64375: proc: protect ptrace_may_access() with exec_update_lock (FD links) (bsc#1273868). * CVE-2026-64378: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() (bsc#1273603). * CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard() (bsc#1273860). * CVE-2026-64382: smb: client: fix double-free in SMB2_open() replay (bsc#1273291). * CVE-2026-64383: smb: client: fix double-free in SMB2_flush() replay (bsc#1273426). * CVE-2026-64384: smb: client: fix change notify replay double-free (bsc#1274541). * CVE-2026-64385: smb: client: fix double-free in SMB2_ioctl() replay (bsc#1274539). * CVE-2026-64386: smb: client: fix query_info() replay double-free (bsc#1274543). * CVE-2026-64387: smb: client: fix query directory replay double-free (bsc#1274545). * CVE-2026-64388: smb/client: fix chown/chgrp with SMB3 POSIX Extensions (bsc#1274061). * CVE-2026-64411: netfilter: ebtables: terminate table name before find_table_lock() (bsc#1274077). * CVE-2026-64412: netfilter: ebtables: module names must be null-terminated (bsc#1273780). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). * CVE-2026-64434: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (bsc#1273880). * CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states (bsc#1274277). * CVE-2026-64448: smb: client: restrict implied bcc[0] exemption to responses without data area (bsc#1273982). * CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). * CVE-2026-64452: 6lowpan: fix NHC entry use-after-free on error path (bsc#1273460). * CVE-2026-64463: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres (bsc#1273273). * CVE-2026-64472: vfio/mlx5: Fix racy bitfields and tighten struct layout (bsc#1274075). * CVE-2026-64477: x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled (bsc#1274264). * CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547). * CVE-2026-64515: wifi: mac80211: fix MLE defragmentation (bsc#1273859). * CVE-2026-64537: bridge: cfm: reject invalid CCM interval at configuration time (bsc#1273289). * CVE-2026-64538: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change() (bsc#1273335). * CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). * CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). * CVE-2026-64545: net, bpf: check master for NULL in xdp_master_redirect() (bsc#1273318). * CVE-2026-64548: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (bsc#1273337). * CVE-2026-64551: sctp: validate STALE_COOKIE cause length before reading staleness (bsc#1273813). * CVE-2026-64552: virtio-net: fix len check in receive_big() (bsc#1273323). * CVE-2026-64553: net: psample: fix info leak in PSAMPLE_ATTR_DATA (bsc#1273336). * CVE-2026-64554: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (bsc#1273340). * CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930). * CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). * CVE-2026-64567: btrfs: reject free space cache with more entries than pages (bsc#1274006). * CVE-2026-64569: mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (bsc#1274009). * CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). * CVE-2026-64576: nexthop: initialize extack in nh_res_bucket_migrate() (bsc#1274030). * CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031). * CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). * CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (bsc#1274040). * CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497). * CVE-2026-64597: smb: client: fix double-free in SMB2_close() replay (bsc#1274297). * CVE-2026-64598: smb/client: Fix error code in smb2_aead_req_alloc() (bsc#1274298). * CVE-2026-68081: KVM: nVMX: Add helper to put (unmap) vmcs12 pages (bsc#1274580). * CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers() (bsc#1274581). * CVE-2026-68086: mm/khugepaged: write all dirty file folios when collapsing (bsc#1274713). * CVE-2026-68105: drm/amdgpu: Fix kernel panic during driver load failure (bsc#1274849). * CVE-2026-68116: vxlan: mdb: Fix source list corruption on a failed replace (bsc#1274876). * CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (bsc#1274881). * CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). * CVE-2026-68123: openvswitch: fix GSO userspace truncation underflow (bsc#1275169). * CVE-2026-68124: mctp: serial: handle zero-length frames to prevent rx buffer overflow (bsc#1275192). * CVE-2026-68127: ila: reload IPv6 header after pskb_may_pull in checksum adjust (bsc#1275237). * CVE-2026-68129: gve: fix Rx queue stall on alloc failure (bsc#1275517). * CVE-2026-68132: super: fix emergency thaw deadlock on frozen block devices (bsc#1275553). * CVE-2026-68135: net: hip04: fix RX buffer leak on build_skb failure (bsc#1275557). * CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). * CVE-2026-68139: net/mlx5e: Use sender devcom for MPV master-up (bsc#1275578). * CVE-2026-68142: geneve: require CAP_NET_ADMIN in the device netns for changelink (bsc#1275582). * CVE-2026-68143: net: slip: serialize receive against buffer reallocation (bsc#1275583). * CVE-2026-68145: iomap: fix out-of-bounds bitmap_set() with zero-length range (bsc#1275584). * CVE-2026-68149: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (bsc#1275294). * CVE-2026-68152: amt: fix use-after-free in AMT delayed works (bsc#1275300). * CVE-2026-68153: libceph: remove debugfs files before client teardown (bsc#1275301). * CVE-2026-68154: libceph: reject zero bucket types in crush_decode (bsc#1275303). * CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). * CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after authorizer update (bsc#1275305). * CVE-2026-68157: libceph: guard missing CRUSH type name lookup (bsc#1275306). * CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). * CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). * CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472). * CVE-2026-68161: sctp: close UDP tunnel sockets during netns teardown (bsc#1274892). * CVE-2026-68166: userfaultfd: prevent registration of special VMAs (bsc#1274930). * CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). * CVE-2026-68205: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (bsc#1274934). * CVE-2026-68238: drm/amdgpu: Release VFCT ACPI table reference (bsc#1275704). * CVE-2026-68247: drm/i915/bios: range check LFP Data Block panel_type2 (bsc#1275817). * CVE-2026-68254: drm/i915/vrr: require valid min/max vfreq for VRR (bsc#1275150). * CVE-2026-68267: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (bsc#1275139). * CVE-2026-68284: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (bsc#1275970). * CVE-2026-68286: drop_monitor: perform u64_stats updates under IRQ-disabled section (bsc#1275973). * CVE-2026-68288: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (bsc#1275975). * CVE-2026-68289: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (bsc#1275976). * CVE-2026-68293: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (bsc#1275091). * CVE-2026-68297: tipc: fix u16 MTU truncation in media and bearer MTU validation (bsc#1275040). * CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (bsc#1275088). * CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL (bsc#1275083). * CVE-2026-68302: amt: re-read skb header pointers after every pull (bsc#1275081). * CVE-2026-68312: cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths (bsc#1274663). * CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit (bsc#1274665). * CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq() (bsc#1274662). * CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (bsc#1274659). * CVE-2026-68322: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (bsc#1274656). * CVE-2026-68324: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (bsc#1274649). * CVE-2026-68325: iommu/amd: Bound the early ACPI HID map (bsc#1274651). * CVE-2026-68328: nfp: Check resource mutex allocation (bsc#1274646). * CVE-2026-68329: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (bsc#1274645). * CVE-2026-68331: dpaa2-eth: put MAC endpoint device on disconnect (bsc#1274642). * CVE-2026-68333: dpaa2-switch: put MAC endpoint device on disconnect (bsc#1274644). * CVE-2026-68335: rds: drop incoming messages that cross network namespace boundaries (bsc#1274640). * CVE-2026-68336: bonding: fix devconf_all NULL dereference when IPv6 is disabled (bsc#1274639). * CVE-2026-68343: smb: client: validate DFS referral PathConsumed (bsc#1274629). * CVE-2026-68375: bnxt_en: Handle partially initialized auxiliary devices (bsc#1274835). * CVE-2026-68377: net/sched: act_tunnel_key: Defer dst_release to RCU callback (bsc#1274831). * CVE-2026-68386: bpf, sockmap: Reject unhashed UDP sockets on sockmap update (bsc#1274814). * CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). * CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). * CVE-2026-68408: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (bsc#1274709). * CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). * CVE-2026-68418: RDMA/irdma: Prevent user-triggered null deref on QP create (bsc#1274690). * CVE-2026-68419: RDMA/irdma: Prevent rereg_mr for non-mem regions (bsc#1274698). * CVE-2026-68422: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (bsc#1274706). * CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1274700). * CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). * CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink (bsc#1274800). * CVE-2026-68433: libceph: bound get_version reply decode to front len (bsc#1274801). * CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert (bsc#1274834). * CVE-2026-68470: wifi: cfg80211/mac80211: correctly parse S1G beacon optional elements (bsc#1276500). * CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). * CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). * CVE-2026-72032: net/mlx5: HWS, fix matcher leak on resize target setup failure (bsc#1276955). * CVE-2026-72035: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1276961). * CVE-2026-72036: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1277034). * CVE-2026-72046: gve: fix header buffer corruption with header-split and HW- GRO (bsc#1275519). * CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). * CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155). * CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). * CVE-2026-72084: scsi: target: Bound PR-OUT TransportID parsing to the received buffer (bsc#1275540). * CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523). * CVE-2026-72132: NFS: Charge unstable writes by request size, not folio size (bsc#1277551). * CVE-2026-72221: sunrpc: wait for in-flight TLS handshake callback when cancel loses race (bsc#1275665). * CVE-2026-72222: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback (bsc#1275669). * CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). * CVE-2026-72254: netfilter: nft_fib: reject fib expression on the netdev egress hook (bsc#1277204). * CVE-2026-72262: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (bsc#1277678). * CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). * CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). * CVE-2026-72296: net: ife: require ETH_HLEN to be pullable in ife_decode() (bsc#1275923). * CVE-2026-72307: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (bsc#1277160). * CVE-2026-72308: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (bsc#1277159). * CVE-2026-72317: SUNRPC: pin upper rpc_clnt across the TLS connect_worker (bsc#1275925). * CVE-2026-72341: net/mlx5e: Fix publication race for priv->channel_stats[] (bsc#1277660). * CVE-2026-72342: net/mlx5e: Fix HV VHCA stats agent registration race (bsc#1277775). * CVE-2026-72343: net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation (bsc#1277776). * CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). * CVE-2026-72463: xfrm: Fix dev use-after-free in xfrm async resumption (bsc#1268276 bsc#1277064). * CVE-2026-72464: xprtrdma: Remove temp allocation of rpcrdma_rep objects (bsc#1277069). * CVE-2026-72466: xprtrdma: Fix bcall rep leak and unbounded peek (bsc#1277057). * CVE-2026-72467: xprtrdma: Check frwr_wp_create() during connect (bsc#1277059). * CVE-2026-72469: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE (bsc#1277047). * CVE-2026-72473: xprtrdma: Avoid 250 ms delay on backlog wakeup (bsc#1277037). * CVE-2026-72494: RDMA/irdma: Replace waitqueue and flag with completion (bsc#1276941). * CVE-2026-72495: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages (bsc#1276937). * CVE-2026-72496: RDMA/bnxt_re: Proper rollback if the ioremap fails (bsc#1276943). * CVE-2026-72497: RDMA/bnxt_re: Add a max slot check for SQ (bsc#1276913). * CVE-2026-72498: RDMA/bnxt_re: Avoid displaying the kernel pointer (bsc#1276912). * CVE-2026-72499: RDMA/bnxt_re: Free CQ toggle page after firmware teardown (bsc#1276551). * CVE-2026-72500: RDMA/bnxt_re: Free SRQ toggle page after firmware teardown (bsc#1276552). * CVE-2026-72501: RDMA/bnxt_re: Initialize dpi variable to zero (bsc#1276546). * CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (bsc#1276542). * CVE-2026-74269: bnxt: fix head underflow on XDP head-grow (bsc#1276507). * CVE-2026-74296: RDMA/mlx5: Release the HW-provided UAR index rather than the SW one (bsc#1276452). * CVE-2026-74297: RDMA/mlx5: Fix undefined shift of user RQ WQE size (bsc#1276446). * CVE-2026-74318: btrfs: fix deadlock cloning inline extent when using flushoncommit (bsc#1276864). * CVE-2026-74321: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (bsc#1277202). * CVE-2026-74334: RDMA/nldev: Fix locking when accessing mr->pd (bsc#1277095). * CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). * CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). * CVE-2026-74395: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (bsc#1277077). * CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073). * CVE-2026-74474: vxlan: use pskb_network_may_pull() for transmit path header pulls (bsc#1276335). * CVE-2026-74481: mm/page_reporting: use system_freezable_wq to fix UAF during suspend (bsc#1276355). * CVE-2026-74482: mm/huge_memory: unlock i_mmap_rwsem before releasing after- split folios (bsc#1276346). * CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350). * CVE-2026-74495: igbvf: Fix leak in TX DMA error cleanup (bsc#1275864). * CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). * CVE-2026-74509: Bluetooth: hci_sync: Fix advertising data UAFs (bsc#1275946). * CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation (bsc#1275950). * CVE-2026-74512: audit: fix potential use-after-free in audit_del_rule() (bsc#1275954). * CVE-2026-74516: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (bsc#1275797). * CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). * CVE-2026-74527: octeontx2-af: Block VFs from clobbering special CGX PKIND state (bsc#1275805). * CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). * CVE-2026-74548: forcedeth: fix UAF of txrx_stats in nv_remove (bsc#1275695). * CVE-2026-74550: net: do not send ICMP/NDISC Redirects when peer allocation fails (bsc#1275688). * CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). * CVE-2026-74563: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() (bsc#1275574). * CVE-2026-74566: keys: make keyring key-chunk byte order agree with keyring_diff_objects() (bsc#1275566). * CVE-2026-74567: keys: fix out-of-bounds read in keyring_get_key_chunk() (bsc#1275569). * CVE-2026-74571: btrfs: skip global block reserve accounting for rescue mounts (bsc#1275561). * CVE-2026-74577: net: mpls: initialize rtm_tos in mpls_getroute() (bsc#1275572). * CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782). * CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). * CVE-2026-74584: RDMA/bnxt_re: zero shared page before exposing to userspace (bsc#1277066). * CVE-2026-74610: tls: don't leave a full plaintext sk_msg ring unpushed (bsc#1277054). * CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). * CVE-2026-74692: net/smc: fix TOCTOU race between smc_listen_out() and listener close (bsc#1276927). * CVE-2026-74694: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (bsc#1277625). * CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). * CVE-2026-74712: vdpa/mlx5: Fix buffer length in create_direct_keys() (bsc#1276577). * CVE-2026-74717: net/mlx5: fw_tracer, return NULL on create error (bsc#1276569). * CVE-2026-74722: btrfs: fix memory leak in btrfs_do_encoded_write() (bsc#1276561). * CVE-2026-80529: xfs: don't swallow dquot recovery verification errors (bsc#1277688). * CVE-2026-80534: xfs: fix ilock leak on error in xfs_dq_get_next_id (bsc#1277022). * CVE-2026-80590: inet: frags: strip GSO state from fragments before reassembly (bsc#1277275). * CVE-2026-80654: soc: xilinx: Shutdown and free rx mailbox channel (bsc#1277516). The following non security issues were fixed: * accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() (git-fixes). * accessibility: speakup: unregister tty ldisc on later init failures (git- fixes). * ACPI: APEI: Fix ERST timeout unit conversion (git-fixes). * ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer (git-fixes). * ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root (git- fixes). * ACPI: pfr_update: fix stack buffer overflow in query_capability() (git- fixes). * ACPI: processor: idle: Expand _LPI package sanity checks (git-fixes). * ACPI: processor: validate MADT IOAPIC entry bounds (git-fixes). * ACPI: scan: fix bus ID cleanup on device_add() failures (git-fixes). * ACPI: video: Release PCI device reference after lookup (git-fixes). * add my missing Reviewed-by: tag. * ALSA: 6fire: bound the MIDI event length from the device (git-fixes). * ALSA: 6fire: Fix UAF at error handling during probe (stable-fixes). * ALSA: bcd2000: clear the URB pointers on disconnect (git-fixes). * ALSA: control: Don't add invalid kcontrols to LED layer (git-fixes). * ALSA: core: Fix use-after-free in snd_card_do_free() (git-fixes). * ALSA: dummy: Check card index validity at probe (stable-fixes). * ALSA: hda/ext: preserve PPLCCTL bits when clearing reset (git-fixes). * ALSA: hda: Fix connection list comparison in proc output (git-fixes). * ALSA: hpi: Check transport errors during HPI6000 adapter initialization (git-fixes). * ALSA: pcxhr: initialize mutexes before requesting threaded IRQ (git-fixes). * ALSA: scarlett2: Use a private URB for the notification endpoint (git- fixes). * ALSA: seq: Don't leak the extension cell pointer in the bounce payload (git- fixes). * ALSA: seq: midi: Optimize event_input locking with RCU (git-fixes). * ALSA: seq: midi: Serialize input teardown with event_input (git-fixes). * ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion (git-fixes). * ALSA: usb-audio: Complete cleanup after system-resume errors (git-fixes). * ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (git-fixes). * ALSA: usb-audio: fix OOB write on Type II inbound URBs (git-fixes). * ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (git-fixes). * ALSA: usx2y: bound the hwdep mmap fault offset (git-fixes). * ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() (git- fixes). * apparmor: advertise the tcp fast open fix is applied (git-fixes). * arm64: Exclude nohz_full CPUs from 32bits el0 support (bsc#1269313). * ASoC: adau1761: sort the register default table (git-fixes). * ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC (git-fixes). * ASoC: apple: mca: increase SERDES reset delay (git-fixes). * ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (git-fixes). * ASoC: cs35l33: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l34: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l41: sort the register default table (git-fixes). * ASoC: cs35l45: sort the register default table (git-fixes). * ASoC: cs4265: sort the register default table (git-fixes). * ASoC: cx2072x: sort the register default table (git-fixes). * ASoC: dapm: Fix off-by-one check on the second enum channel (git-fixes). * ASoC: fix unmet dependencies on PPC_BESTCOMM and SND_SOC_AC97_BUS (git- fixes). * ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready (git- fixes). * ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure (git-fixes). * ASoC: fsl_audmix: rework runtime PM handling in probe (git-fixes). * ASoC: fsl_easrc: sort the register default table (git-fixes). * ASoC: hdac_hda: Fix hlink refcount leak on component registration failure (git-fixes). * AsoC: intel: sst: fix PCI device reference leak on probe failure (git- fixes). * ASoC: max9860: sort the register default table (git-fixes). * ASoC: meson: Keep link pointers valid on realloc failure (git-fixes). * ASoC: ml26124: sort the register default table (git-fixes). * ASoC: pcm512x: sort the register default table (git-fixes). * ASoC: pxa: Use devm_clk_get_optional() for extclk clock (git-fixes). * ASoC: qcom: q6apm: keep the graph start count in sync with the DSP (git- fixes). * ASoC: rt274: sort the register default table (git-fixes). * ASoC: rt286: sort the register default table (git-fixes). * ASoC: rt298: sort the register default table (git-fixes). * ASoC: rt700-sdw: always drain jack work on remove (git-fixes). * ASoC: rt700: drop duplicate reg_default entry (git-fixes). * ASoC: rt700: sort the register default table (git-fixes). * ASoC: rt711-sdca: sort the register default tables (git-fixes). * ASoC: rt711: sort the register default table (git-fixes). * ASoC: rt712-sdca-dmic: sort the register default table (git-fixes). * ASoC: rt712-sdca-sdw: sort the register default table (git-fixes). * ASoC: rt715-sdca: drop duplicate reg_default entries (git-fixes). * ASoC: rt715-sdca: sort the register default tables (git-fixes). * ASoC: rt715: sort the register default table (git-fixes). * ASoC: rt1017-sdca-sdw: sort the register default table (git-fixes). * ASoC: rt1316-sdw: sort the register default table (git-fixes). * ASoC: rt1318-sdw: sort the register default table (git-fixes). * ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get (git-fixes). * ASoC: sgtl5000: sort the register default table (git-fixes). * ASoC: SOF: pcm: Move period/buffer configuration print after platform open (stable-fixes). * ASoC: sof: pcm: use snd_pcm_direction_name() (stable-fixes). * ASoC: SOF: Relocate and rework functionality for PCM stream freeing (stable- fixes). * ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() (git- fixes). * ASoC: SOF: validate topology volume range before allocation (git-fixes). * ASoC: sti-sas: sort the register default table (git-fixes). * ASoC: tas2552: sort the register default table (git-fixes). * ASoC: tas2764: sort the register default table (git-fixes). * ASoC: tas2780: sort the register default table (git-fixes). * ASoC: tegra210_i2s: sort the register default table (git-fixes). * ASoC: tegra210_mixer: sort the register default table (git-fixes). * ASoC: tegra: Fix the MIXER enable default value (git-fixes). * ASoC: tegra: Sort MBDRC register defaults (git-fixes). * ASoC: xilinx: formatter_pcm: fix stream_data leak on open error (git-fixes). * ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (git-fixes). * batman-adv: bla: fix freeing of claims on meshif deletion (git-fixes). * batman-adv: bla: prevent CRC corruptions after claim flush (git-fixes). * batman-adv: dat: avoid unaligned fault in IP extraction (git-fixes). * batman-adv: fix stale receive device on merged fragments (git-fixes). * Bluetooth: btintel: Fix diagnostics event detection (git-fixes). * Bluetooth: btmtk: Do not discard the subsystem reset timeout (git-fixes). * Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() (stable- fixes). * Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path (git-fixes). * Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX (git- fixes). * Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event (git- fixes). * Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() (git- fixes). * Bluetooth: do not leak an hci_conn when a second LE connect is rejected (git-fixes). * Bluetooth: eir: Fix OOB read in eir_get_service_data() (git-fixes). * Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378 (git-fixes). * Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_conn: fix the SCO setup context lifetime (git-fixes). * Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (git-fixes). * Bluetooth: hci_conn: re-enable advertising only for peripheral role (git- fixes). * Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb (git- fixes). * Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection (git- fixes). * Bluetooth: hci_event: fix LE list UAF on reset (git-fixes). * Bluetooth: hci_event: validate LE Set CIG Parameters response (git-fixes). * Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request (git-fixes). * Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths (git-fixes). * Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (stable-fixes). * Bluetooth: hci_uart: Fix false success return in hci_uart_setup() (git- fixes). * Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready (git-fixes). * Bluetooth: MGMT: free the mesh send cancel command when it is cancelled (git-fixes). * Bluetooth: MSFT: validate evt_prefix_len against the response length (git- fixes). * Bluetooth: RFCOMM: serialize security confirmation handling (git-fixes). * Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (git- fixes). * Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop (git-fixes). * Bluetooth: virtio_bt: avoid OOB read of build info string (git-fixes). * bnxt_en: Adjust TX rings if reservation is less than requested (jsc#PED-16798). * bnxt_en: Delay for 5 seconds after AER DPC for all chips (jsc#PED-16798). * bnxt_en: Don't assume XDP is never enabled in bnxt_init_dflt_ring_mode() (jsc#PED-16798). * bnxt_en: Drop pci_save_state() after pci_restore_state() (jsc#PED-16798). * bnxt_en: Implement XDP RSS hash metadata extraction (jsc#PED-16798). * bnxt_en: Implement XDP RSS hash metadata extraction for V3_CMP (jsc#PED-16798). * bnxt_en: Move bnxt_rss_ext_op into header (jsc#PED-16798). * bnxt_en: Refactor some basic ring setup and adjustment logic (jsc#PED-16798). * bnxt_en: Restore default stat ctxs for ULP when resource is available (jsc#PED-16798). * bnxt_en: Set bp->max_tpa according to what the FW supports (jsc#PED-16798). * bnxt_en: Use absolute target ns from ptp_clock_request (jsc#PED-16798). * bnxt_en: use bnxt_xdp_buff for xdp context (jsc#PED-16798). * bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation (git-fixes). * bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET (git-fixes). * bus: ti-sysc: Fix /chosen node reference leak (git-fixes). * cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64) (git-fixes). * can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (stable-fixes). * cpufreq: intel_pstate: Use correct scaling factor on Raptor Lake-E (bsc#1240957 bsc#1249104 bsc#1265220). * cpufreq: intel_pstate: Use CPPC to get scaling factors (bsc#1240957 bsc#1249104 bsc#1265220). * cpufreq: intel_pstate: Use HYBRID_SCALING_FACTOR_ADL for Bartlett Lake (bsc#1240957 bsc#1249104 bsc#1265220). * crypto: aspeed - Propagate platform_get_irq() errors (git-fixes). * crypto: atmel-sha204a - fix heap info leak on I2C transfer failure (git- fixes). * crypto: atmel-tdes - use scatterlist length before DMA mapping (git-fixes). * crypto: ccm - Set rfc4309 maxauthsize from child (git-fixes). * crypto: ccp - Fix memory leak in SEV INIT_EX path (git-fixes). * crypto: ccp - Fix possible deadlock in SEV init failure path (git-fixes). * crypto: doc - Remove extra parenthesis (git-fixes). * crypto: hisilicon/sec2 - fix CCM algorithm long packet failure (git-fixes). * crypto: keembay - Initialize completion before requesting IRQ (git-fixes). * crypto: keembay - publish OF module alias for OCS AES/SM4 (git-fixes). * crypto: mxs-dcp - fix source scatterlist length access (git-fixes). * crypto: qat - cancel work on re-enable SR-IOV timeout (git-fixes). * crypto: qat - clear AES key schedule from stack (git-fixes). * crypto: qce - fix CCM AAD buffer underallocation (git-fixes). * crypto: qce - fix error path in devm_qce_register_algs (git-fixes). * crypto: rk3288 - fail ahash requests on HASH idle timeout (git-fixes). * crypto: sa2ul - stop probe if context pool creation fails (git-fixes). * crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping (git- fixes). * device property: fix infinite loop in fwnode_for_each_child_node() (git- fixes). * dmaengine: dw-edma: Clear stale requests on termination (git-fixes). * dmaengine: dw-edma: Complete descriptors before pausing (git-fixes). * dmaengine: dw-edma: Initialize IRQ data before requesting IRQs (git-fixes). * dmaengine: dw-edma: Serialize abort state updates (git-fixes). * dmaengine: dw-edma: Serialize channel state checks (git-fixes). * dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe (git-fixes). * dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure (git-fixes). * dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal (git-fixes). * dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers (git-fixes). * dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout (git-fixes). * driver core: soc: Unregister bus on early device registration failure (git- fixes). * drm/amd/display: Add AV mute wait frames to dce110_set_avmute (stable- fixes). * drm/amd/display: avoid divide-by-zero in __is_lut_linear() (git-fixes). * drm/amd/display: Check for tg ops in dce110_set_avmute (git-fixes). * drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix (git-fixes). * drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE (git-fixes). * drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank() (git-fixes). * drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames (stable- fixes). * drm/amd/display: Remove unused-but-set variable hubp from (git-fixes). * drm/amd/display: validate plane degamma LUT size for private color prop (git-fixes). * drm/amd/pm: adjust the visibility of pp_table sysfs node (stable-fixes). * drm/amd/pm: Use same metric table for APU (stable-fixes). * drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read (git- fixes). * drm/amdgpu/gfx6: Fixup emit_cntxcntl() (git-fixes). * drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets (git-fixes). * drm/amdgpu/gfx6: Use PFP on the compute queues too (git-fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup (git- fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup (git- fixes). * drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check (git- fixes). * drm/amdgpu: cap GTT size to physical RAM on APUs (stable-fixes). * drm/amdgpu: check ASPM on the dGPU host link (git-fixes). * drm/amdgpu: disallow multiple FENCE chunks in one submit (git-fixes). * drm/amdgpu: fix aperture iounmap skipped on device removal (git-fixes). * drm/amdgpu: fix autosuspend cleanup during removal (git-fixes). * drm/amdgpu: fix nbif 6.3.1 l1 low power not functional (git-fixes). * drm/amdgpu: Fix UVD decode image min size calculation (stable-fixes). * drm/amdgpu: Fix UVD dpb min size calculation for H264 (stable-fixes). * drm/amdgpu: Fix UVD min buffer sizes (stable-fixes). * drm/amdgpu: Fix VCE 3 ring align_mask (git-fixes). * drm/amdgpu: Implement insert_end for VCE 3 (git-fixes). * drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini (git-fixes). * drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12 (git-fixes). * drm/amdgpu: reject oversized IBs with per-ring packet limits (stable-fixes). * drm/amdgpu: Reject UVD message with dimensions above 4096 (stable-fixes). * drm/amdgpu: Reject UVD message with invalid number of h265 refs (stable- fixes). * drm/amdgpu: remove unused function parameter (stable-fixes). * drm/amdgpu: restore UMD profile pstate after runtime resume (stable-fixes). * drm/amdgpu: validate GEM_CREATE domain combinations (stable-fixes). * drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (stable-fixes). * drm/amdkfd: fix QID bit leak in pqm_create_queue() (stable-fixes). * drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore (git- fixes). * drm/amdkfd: Handle invalid event type in CRIU event restore (stable-fixes). * drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure (git-fixes). * drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure (git-fixes). * drm/bridge: ps8640: propagate AUX transfer register errors (git-fixes). * drm/bridge: tc358767: clamp the reported AUX read size to the request (git- fixes). * drm/connector/hdmi: Fix out of bounds memory read (git-fixes). * drm/connector: Fix epoch_counter docs to reflect reality (git-fixes). * drm/hibmc: Fix list of formats on the primary plane (git-fixes). * drm/hibmc: Use drm_atomic_helper_check_plane_state() (git-fixes). * drm/i915/fbc: Extract intel_fbc_has_fences() (stable-fixes). * drm/i915/hdcp: check streams bounds before overflow (git-fixes). * drm/i915/hdcp: Move to using intel_display in intel_hdcp (stable-fixes). * drm/i915/hdcp: require monotonically increasing seq_num_v (git-fixes). * drm/i915/hdcp: Skip inactive MST connectors when building stream list (stable-fixes). * drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() (stable- fixes). * drm/i915/vrr: require valid min/max vfreq for VRR (git-fixes). * drm/lima: call drm_mm_init() with a valid allocation range (git-fixes). * drm/msm/a6xx: Fix RBBM_CLOCK_CNTL3_TP0 value in a730_hwcg (git-fixes). * drm/msm/a6xx: Fix stale rpmh votes after suspend (git-fixes). * drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: Drop dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value (git- fixes). * drm/panel-edp: fix i2c adapter leak on probe failure (git-fixes). * drm/panel: samsung-s6d16d0: Power off on prepare failure (git-fixes). * drm/panthor: fix firmware control interface bounds checks (git-fixes). * drm/panthor: return PTR_ERR() from devm_drm_dev_alloc() (git-fixes). * drm/panthor: skip zero-sized firmware sections (git-fixes). * drm/radeon: fix autosuspend cleanup during teardown (git-fixes). * drm/radeon: restore hardware polling in fence_is_signaled to fix performance regression (git-fixes). * drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format (git-fixes). * drm/ssd130x: fix column and row end address in partial updates for ssd132x (git-fixes). * drm/ssd130x: fix column and row end address in partial updates in ssd133x (git-fixes). * drm/sun4i: crtc: Propagate layer initialization error (git-fixes). * drm/sun4i: Drop node references while building component list (git-fixes). * drm/sun4i: dw-hdmi: Drop TCON TOP port reference (git-fixes). * drm/sun4i: fix refcount leak in sun4i_backend_init_sat() (git-fixes). * drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz (git-fixes). * drm/sun4i: hdmi: Don't leak sync polarity bits into packet control (git- fixes). * drm/sun4i: tcon: Drop remote endpoint reference (git-fixes). * drm/sun4i: tcon: Drop TCON TOP device reference (git-fixes). * drm/sun4i: tcon: Set output mux for DSI and LVDS (git-fixes). * drm/sun4i: vi scaler: Fix coefficient selection (git-fixes). * drm/tegra: dsi: Re-add clear enable register if DSI was powered by bootloader (git-fixes). * drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info (git-fixes). * drm/tve200: add OF module alias for autoloading (git-fixes). * drm/xe/oa: Check managed mutex initialization errors (git-fixes). * drm/xe/oa: Fix sync entry leak on OA config emit failure (git-fixes). * drm/xe: Introduce xe_gt_dbg_printer() (stable-fixes). * drm/xe: Order ring writes before ring tail updates (git-fixes). * drm/xe: Stub out new pagefault layer (stable-fixes). * drm/xe: tests: fix error message in xe_migrate_sanity_test() (git-fixes). * drm: fix race between partial drm_dev_register() failure and ioctl (git- fixes). * drm: lcdif: Wait for vblank before disabling DMA (git-fixes). * drm: Remove unused header in drm_dumb_buffers.c (git-fixes). * ethtool: rss: fix hkey leak when indir_size is 0 (git-fixes). * fbdev: bitblit: bound-check glyph index in bit_cursor() (git-fixes). * fbdev: core: Fix pointer desynchronization in fb_io_read() (git-fixes). * fbdev: kyro: Validate overlay viewport coordinates (git-fixes). * fbdev: omapfb: panel-dsi-cm: initialize lock before registering display (git-fixes). * fbdev: ssd1307fb: defer I2C transfers from damage callbacks (git-fixes). * fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() (git-fixes). * fbdev: uvesafb: unregister connector callback on init failure (git-fixes). * firmware: arm_scmi: Avoid IDR updates while cleaning channels (git-fixes). * firmware: arm_scmi: Drop handle on protocol bind failures (git-fixes). * firmware: arm_scmi: Fix requested device removal race (git-fixes). * firmware: arm_scmi: Free transport channel on IDR failure (git-fixes). * firmware: arm_scmi: Protect device request lookup with RCU (git-fixes). * firmware: arm_scmi: Reject out of range DT protocol IDs (git-fixes). * firmware: arm_scmi: Unregister device notifier before IDR teardown (git- fixes). * firmware: arm_scmi: Use channel ID for transport teardown (git-fixes). * firmware_loader: do not queue completed sysfs fallback requests (git-fixes). * fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write (git- fixes). * fpga: dfl: fme: add error handling (git-fixes). * fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration (git- fixes). * gpu: host1x: Avoid stack over-read in debug output helpers (git-fixes). * gpu: host1x: Fix offset calculation in trace_write_gather (git-fixes). * HID: core: fix number/pointer type confusion on long items (git-fixes). * HID: core: fix OOB read of field->usage in hid_set_field() (git-fixes). * HID: hyperv: validate initial device info bounds (git-fixes). * HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure (git-fixes). * HID: lg4ff: validate report length before fixed offsets (git-fixes). * HID: logitech-dj: Fix maxfield check in DJ short report validation (git- fixes). * HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (git- fixes). * HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (stable-fixes). * HID: logitech-dj: Standardise hid_report_enum variable nomenclature (stable- fixes). * HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID (stable-fixes). * HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (git- fixes). * HID: mcp2221: validate report size in mcp2221_raw_event() (git-fixes). * HID: nintendo: Fix imu_timestamp_us double increment per report (git-fixes). * HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() (git- fixes). * HID: picolcd: clamp eeprom debugfs read to bytes actually received (git- fixes). * HID: roccat: bound device-supplied profile index (git-fixes). * HID: roccat: free buffered reports when destroying device (git-fixes). * HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature (git- fixes). * HID: sensor: custom: Fix field sysfs group cleanup on failure (git-fixes). * HID: sensor: custom: Fix use-after-free in enable_sensor (git-fixes). * HID: tmff: Use 64-bit arithmetic for force feedback scaling (git-fixes). * hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (git-fixes). * hwmon: (lm25066) Use i2c_get_match_data() (stable-fixes). * hwmon: (max6621) fix negative temperature offset and crit readings (git- fixes). * hwmon: (max6621) fix temperature clamp range (git-fixes). * hwmon: (nzxt-smart2) Check return value of init_device() in probe (git- fixes). * hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (git-fixes). * hwrng: ks-sa - Fix runtime PM cleanup on registration failure (git-fixes). * hwrng: omap - Fix probe error path cleanup (git-fixes). * hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() (git- fixes). * i2c: bcm-iproc: remove printout on handled timeouts (stable-fixes). * i2c: core: fix debugfs UAF on adapter removal (git-fixes). * i2c: iproc: reset bus after timeout if START_BUSY is stuck (git-fixes). * i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure (git-fixes). * i2c: mux: Fix channel node leak on adapter add failure (git-fixes). * i2c: ocores: Disable clock on failed resume (git-fixes). * i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices (git-fixes). * i3c: master: Fix device_register() error path (git-fixes). * i3c: master: Fix info leak and UAF in device unregister path (git-fixes). * i3c: master: Fix potential UAF in i3c_device_uevent() (git-fixes). * i3c: master: svc: bound IBI payload to the requested max_payload_len (git- fixes). * ibmvnic: Only record tx completed bytes once per handler (bsc#1274620). * iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE (git-fixes). * iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable (git-fixes). * iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF (git-fixes). * iio: chemical: sgp30: Handle IAQ thread creation failure (git-fixes). * iio: dac: m62332: Fix regulator reference count imbalance (git-fixes). * iio: gyro: mpu3050: fix sign of raw angular velocity readings (git-fixes). * iio: light: cm32181: return zero after writing calibscale (git-fixes). * iio: light: gp2ap002: Disable regulators on resume failure (git-fixes). * iio: light: gp2ap002: re-enable irq if runtime suspend fails (git-fixes). * iio: light: isl29028: return zero in write_raw() on success (git-fixes). * iio: light: tsl2583: return zero in write_raw() on success (git-fixes). * iio: light: tsl2772: fix ALS calibscale readback (git-fixes). * iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure (git-fixes). * iio: pressure: dps310: fix NULL pointer dereference on ACPI probe (git- fixes). * iio: pressure: mpl115: Fix runtime PM cleanup (git-fixes). * iio: srf04: fix pm_runtime handling on probe error path (git-fixes). * iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() (git-fixes). * Input: atkbd - skip deactivate for HONOR ZQC-P (git-fixes). * Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (stable-fixes). * Input: evdev - fix information leak in evdev_pass_values() (stable-fixes). * Input: evdev - sanitize event type index when fetching event masks (stable- fixes). * Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (git-fixes). * Input: focaltech - use signed coordinates to prevent underflow (git-fixes). * Input: hynitron_cstxxx - validate touch count and finger IDs (git-fixes). * Input: iforce - validate input packet lengths (stable-fixes). * Input: iqs5xx - validate firmware record destination span (git-fixes). * Input: mms114 - fix Y-resolution configuration (git-fixes). * Input: psxpad-spi - set driver data before use (git-fixes). * Input: sur40 - fix input device registration ordering (stable-fixes). * Input: sur40 - fix V4L error path cleanup (stable-fixes). * Input: synaptics-rmi4 - block s_input when F54 queue is busy (git-fixes). * Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (git-fixes). * Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (git- fixes). * Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (git- fixes). * Input: synaptics-rmi4 - zero report size on F54 work error (git-fixes). * Input: xpad - add support for ZENAIM LEVERLESS (stable-fixes). * interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (git-fixes). * ipmi: ipmb: validate write message length (git-fixes). * ipmi: si: Fix NULL pointer dereference after failed registration (git- fixes). * kthread: Default affine kthread to its preferred NUMA node (bsc#1269313). * kthread: Make sure kthread hasn't started while binding it (bsc#1269313). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: PPC: Book3S HV: Add support for compat CPU capabilities for KVM on PowerNV (bsc#1263864 ltc#217835). * KVM: PPC: Book3S HV: Implement compat CPU capability retrieval for KVM on PowerVM (bsc#1263864 ltc#217835). * KVM: PPC: Book3S HV: Validate arch_compat against host compatibility mode (bsc#1263864 ltc#217835). * KVM: PPC: Document KVM_PPC_GET_COMPAT_CAPS ioctl (bsc#1263864 ltc#217835). * KVM: PPC: Introduce KVM_CAP_PPC_COMPAT_CAPS and wire up ioctl (bsc#1263864 ltc#217835). * KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (git-fixes). * leds: pca9532: Fix inverted GPIO output polarity (git-fixes). * leds: pca9532: Fix phantom device registration on missing hardware (git- fixes). * lib/string: fix memchr_inv() for large ranges (git-fixes). * lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() (git-fixes). * mailbox: qcom-ipcc: fix duplicate channel allocation across holes (git- fixes). * mailbox: rockchip: disable pclk on probe failure and unbind (git-fixes). * maple_tree: fix argument name in header (git-fixes). * md/raid1: create serial pool adding rdev to array with serialize_policy=1 (bsc#1272261). * media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref (git-fixes). * media: amphion: Remove obsolete frame_count check in venc_start_session (git-fixes). * media: cec-pin: Fix event FIFO ordering (git-fixes). * media: cec: disable delayed work before freeing an interrupted transmit (git-fixes). * media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash (git-fixes). * media: cec: Serialize exclusive follower delivery (git-fixes). * media: cec: stm32: prevent out-of-bounds write on RX overflow (git-fixes). * media: cedrus: fix memory leak in cedrus_init_ctrls() (git-fixes). * media: cobalt: Avoid freeing ALSA private data twice (git-fixes). * media: cx231xx: reject geometry changes while the VBI queue is busy (git- fixes). * media: cx23885: cancel NetUP CI work before teardown (git-fixes). * media: em28xx: defer audio-only extension registration (git-fixes). * media: em28xx: fix use-after-free of dev_next->devlist on disconnect (git- fixes). * media: go7007: defer the ALSA v4l2 put until card release (git-fixes). * media: i2c: imx219: Rename VTS to FRM_LENGTH (stable-fixes). * media: i2c: ov02a10: fix endpoint parsing use-after-free (git-fixes). * media: i2c: ov7740: fix use-after-destroy in remove (git-fixes). * media: i2c: rdacm21: Fix missing media_entity_cleanup() (git-fixes). * media: imx219: Fix maximum frame length in lines (git-fixes). * media: intel/ipu6: fix async notifier cleanup leak on parse error (git- fixes). * media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define (git- fixes). * media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define (git-fixes). * media: mc-entity: Add missing kerneldoc (git-fixes). * media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common (git- fixes). * media: nxp: imx8-isi: Correct color map between V4L2 and ISI (git-fixes). * media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing (git-fixes). * media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks (git-fixes). * media: rc: sunxi-cir: Unregister rc device on probe failure (git-fixes). * media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure (git-fixes). * media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak (git-fixes). * media: s2255: bound JPEG frame size before copying into the buffer (git- fixes). * media: s2255: check firmware size before reading trailing marker (git- fixes). * media: saa7164: fix cleanup on resource allocation failure (git-fixes). * media: tda18250: fix possible integer overflow (git-fixes). * media: usbtv: keep device alive while ALSA card exists (git-fixes). * media: v4l2-async: avoid deleting unlinked ASC entry on link error (git- fixes). * media: v4l2-async: Unregister sub-device if asc_list is empty (git-fixes). * media: v4l2-ctrls: Allow unknown HDR10 white point and luminance (git- fixes). * media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link (git-fixes). * media: venus: fix payload size calculation in parse_raw_formats() (git- fixes). * media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() (git-fixes). * media: vicodec: fix out-of-bounds write in FWHT encoder (git-fixes). * media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure (git-fixes). * media: vimc: fix pixel format lookup in enum_framesizes (git-fixes). * media: zoran: Avoid freeing a registered video_device twice (git-fixes). * mei: pull kvfree out of spinlock (git-fixes). * mfd: iqs62x: Reject zero-length firmware records (git-fixes). * mfd: rave-sp: validate received frame payload lengths (git-fixes). * misc: bcm-vk: Use acquire/release for msgq_inited (git-fixes). * misc: fastrpc: fix channel ctx ref leak when session alloc fails (git- fixes). * misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (git-fixes). * misc: fastrpc: Remove buffer from list prior to unmap operation (git-fixes). * misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke (git- fixes). * misc: rtsx: add missing write register handling (git-fixes). * misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() (git- fixes). * mkspec-dtb: Move DTS prefix into package list. * mkspec-dtb: Move provides-obsoletes to package list. * mkspec-dtb: Put per-architecture package lists into a hash. * mkspec-dtb: re-indent. * mm: Create/affine kcompactd to its preferred node (bsc#1269313). * mm: Create/affine kswapd to its preferred node (bsc#1269313). * mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (git- fixes). * mmc: sdhci: unmap the bounce buffer before device release (git-fixes). * mmc: via-sdmmc: stop card-detect handling on probe failure (git-fixes). * mtd: afs: validate v2 image info bounds (git-fixes). * mtd: mtdoops: free page bitmap when the backing MTD is removed (git-fixes). * mtd: mtdswap: Avoid freeing registered blktrans device twice (git-fixes). * mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() (git-fixes). * mtd: rawnand: validate ONFI extended parameter page sections (git-fixes). * net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes). * net: mana: Add handler for sriov configure (bsc#1272756). * net: mana: Cap MSI-X vectors to the device MSI-X table size (git-fixes). * net: mana: Extend RX CQE coalescing up to 8 packets (git-fixes). * net: mana: Fall back to scattered pages for GDMA queues (git-fixes). * net: mana: force full-page RX buffers via ethtool private flag (bsc#1269792). * net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792). * net: mana: Route ring-buffer access through offset-based helpers (git- fixes). * net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). * net: thunderbolt: Count delivered packets in rx_packets and rx_bytes (git- fixes). * net: thunderbolt: Mark the connection down when bringing it up fails (git- fixes). * net: thunderbolt: Release the Rx HopID that was handed out on mismatch (git- fixes). * net: thunderbolt: Tear down DMA paths before stopping the rings (git-fixes). * net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (git-fixes). * net: usb: ipheth: fix carrier_work UAF on disconnect (git-fixes). * nfc: digital: clamp SENSF_RES length to the destination buffer (git-fixes). * nfc: digital: Do not dump a NULL response in command completion (git-fixes). * nfc: fdp: bound the device-reported read length and fix an skb leak (git- fixes). * nfc: llcp: avoid userspace overflow on invalid optlen (git-fixes). * nfc: llcp: bound SNL TLV parsing to the skb and add length checks (git- fixes). * nfc: llcp: bound the connect_sn TLV walk to the skb (git-fixes). * nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (git-fixes). * nfc: llcp: read llcp_sock->local under the socket lock in getsockopt (git- fixes). * nfc: llcp: reject PDUs shorter than the LLCP header (git-fixes). * nfc: microread: validate target discovery payload lengths (git-fixes). * nfc: nci: fix double completion race in nci_data_exchange_complete (git- fixes). * nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (git- fixes). * nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (git- fixes). * nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing (git- fixes). * nfc: nci: free destination parameters when closing a connection (git-fixes). * nfc: pn533: hold a reference to the request skb during send_frame (git- fixes). * nfc: pn533: purge fragmented skbs during cleanup (git-fixes). * nfc: st21nfca: validate ATR_REQ length against the received frame (git- fixes). * nouveau/gem: reserve the bo in the info ioctl around the vma lookup (git- fixes). * of: fix out-of-bounds read in of_alias_scan() stem parser (git-fixes). * PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] (git-fixes). * PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk (git- fixes). * PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git- fixes). * PCI: j721e: Fix incorrect max_lanes for J7200 (git-fixes). * PCI: meson: Fix GPIO state while requesting PERST# (git-fixes). * phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs (git- fixes). * phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend (git-fixes). * phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table (git- fixes). * phy: sunplus: fix error handling in sp_uphy_init() (git-fixes). * pinctrl: bcm2835: Don't remove an unregistered GPIO chip (git-fixes). * pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip (git-fixes). * pinctrl: rockchip: Reset the pin count when recalculating SoC data (git- fixes). * platform/chrome: cros_ec_debugfs: Clean up console log on probe failure (git-fixes). * platform/chrome: cros_ec_debugfs: Unregister panic notifier (git-fixes). * platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count (git- fixes). * platform/chrome: sensorhub: Bound the EC-reported sensor number (git-fixes). * platform/chrome: sensorhub: Fix dropped timestamp events and log spam (git- fixes). * platform/chrome: sensorhub: Fix memory overread in ring handler (git-fixes). * platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL (git- fixes). * platform/surface: acpi-notify: Check ACPI companion before use (git-fixes). * platform/x86/amd/hsmp: Reject negative power cap writes in hwmon (git- fixes). * platform/x86: dell-privacy: Fix race condition (git-fixes). * platform/x86: dell-wmi-base: Fix resource leak on module load failure (git- fixes). * platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (git-fixes). * platform/x86: dell-wmi-sysman: Fix instance ID bounds (git-fixes). * platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS (git-fixes). * platform/x86: hp-bioscfg: advance elem past consumed array elements (git- fixes). * platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() (git-fixes). * platform/x86: hp-bioscfg: fix heap OOB read on empty password write (git- fixes). * platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password (git-fixes). * platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() (git-fixes). * platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed (git- fixes). * platform/x86: hp-bioscfg: fix password encoding bounds check (git-fixes). * platform/x86: hp-bioscfg: warn on element type mismatch instead of failing (git-fixes). * platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path (git-fixes). * platform/x86: ISST: Add a NULL check for sst_inst (git-fixes). * platform/x86: ISST: Just allow 2 bits for SST feature enable (git-fixes). * platform/x86: ISST: Return error during profile addition (git-fixes). * platform/x86: ISST: Use PP level enable mask (git-fixes). * platform/x86: ISST: Validate level in perf mask ioctls (git-fixes). * platform/x86: ISST: Validate logical CPU id and clos id (git-fixes). * platform/x86: ISST: Validate parameter for core power state (git-fixes). * platform/x86: ISST: Validate socket ID in clos_assoc ioctl (git-fixes). * PM: sleep: Fix off-by-one in wakelocks number limit check (git-fixes). * power: supply: bd99954: Drop bad register fields (git-fixes). * power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq27520g4: fix REG_TTES address (git-fixes). * power: supply: bq256xx: drain usb_work before freeing the charger (git- fixes). * power: supply: bq24257: fix use-after-free on remove (git-fixes). * power: supply: bq25890: Fix power_supply reference leak (git-fixes). * power: supply: cros_usbpd-charger: bound the EC-reported port count (git- fixes). * power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS (git- fixes). * power: supply: isp1704_charger: cancel work on remove (git-fixes). * power: supply: lp8727: fix use-after-free in lp8727_release_irq() (git- fixes). * power: supply: max17040: drop incorrect I2C functionality check (git-fixes). * power: supply: max17040: synchronize work cancellation on suspend (git- fixes). * power: supply: qcom_battmgr: terminate the strings from firmware (git- fixes). * power: supply: rt9455: quiesce delayed work before teardown (git-fixes). * power: supply: sbs-battery: Use a per-device serial number buffer (git- fixes). * power: supply: twl4030_charger: cancel workers via devm (git-fixes). * power: supply: ucs1002: fix use-after-free on remove (git-fixes). * powercap: intel_rapl_tpmi: Handle PMU registration failure during probe (git-fixes). * powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors (bsc#1263864 ltc#217835). * powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash (bsc#1271256). * powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). * powerpc/pseries: pci - logic bug (bsc#1274749 ltc#221282 bsc#1274755 ltc#221284 bsc#1274756 ltc#221283). * powerpc: Replace **ASSEMBLY** with **ASSEMBLER** in non-uapi headers (bsc#1263864 ltc#217835). * powerpc: Replace **ASSEMBLY** with **ASSEMBLER** in uapi headers (bsc#1263864 ltc#217835). * ppdev: prevent overflow when setting port timeout (git-fixes). * qede: fix out-of-bounds check for cqe->len_list (git-fixes). * rapidio: clear mport->net when rio_add_net() fails (git-fixes). * rapidio: mport_cdev: fix use-after-free in dma_req_free() (git-fixes). * RDMA/irdma: Remove redundant legacy_mode checks (git-fixes). * RDMA/mana_ib: drain QP references after partial table insertion (git-fixes). * RDMA/mana_ib: unify QP lookup table (git-fixes). * RDMA/mlx5: Fix integer overflow of user QP buffer size (git-fixes). * regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (git-fixes). * regulator: core: use system_freezable_wq for init complete work (git-fixes). * regulator: devres: add API for reference voltage supplies (stable-fixes). * regulator: devres: fix devm_regulator_get_enable_read_voltage() return (git- fixes). * regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata (git-fixes). * regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling (git-fixes). * remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev (git-fixes). * remoteproc: qcom_q6v5_adsp: Fix reference leak for device node (git-fixes). * remoteproc: scp: Fix device reference leak on failed lookup (git-fixes). * Revert "drm/amdgpu: fix aperture mapping leak" (git-fixes). * Revert "media: v4l2-dev: fix error handling in __video_register_device()" (git-fixes). * Revert "thermal/drivers/hwmon: Cleanup coding style a bit" (stable-fixes). * rpmsg: core: Fix incorrect return value documentation (git-fixes). * rpmsg: glink: smem: order FIFO read after availability check (git-fixes). * rtc: gamecube: check return value of devm_rtc_register_device() (git-fixes). * rtc: pcf8563: fix clock provider leak on unbind (git-fixes). * rtc: pcf85363: Add error checking to regmap calls in probe() (git-fixes). * rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers (git-fixes). * rtc: rzn1: Fix weekday underflow when alarm crosses month boundary (git- fixes). * rtc: zynqmp: Return optional clock lookup errors (git-fixes). * sched,arm64: Handle CPU isolation on last resort fallback rq (bsc#1269313). * scsi: fnic: Abort timed-out NVMe LS requests (bsc#1236344). * scsi: fnic: Add FDLS role handling for NVMe initiators (bsc#1236344). * scsi: fnic: Add the NVMe/FC transport path (bsc#1236344). * scsi: fnic: Advertise NVMe initiator service parameters (bsc#1236344). * scsi: fnic: Bump up version number (bsc#1236344). * scsi: fnic: Decode firmware role configuration (bsc#1236344). * scsi: fnic: Do not use GFP_ZERO for mempools (bsc#1236344). * scsi: fnic: Expose NVMe transport state in debugfs (bsc#1236344). * scsi: fnic: Handle NVMe LS frames in FDLS (bsc#1236344). * scsi: fnic: Make debug logging protocol independent (bsc#1236344). * scsi: fnic: Make fnic_queuecommand() easier to analyze (bsc#1236344). * scsi: fnic: Refactor in_remove flag and call to fnic_fcpio_reset() (bsc#1236344). * scsi: fnic: Remove a useless struct mempool forward declaration (bsc#1236344). * scsi: fnic: Rename fnic_scsi_fcpio_reset() (bsc#1236344). * scsi: fnic: Route completions and resets by initiator role (bsc#1236344). * scsi: fnic: Self-assignment of intr_time_type has no effect (bsc#1236344). * scsi: fnic: Send NVMe LS requests through FDLS (bsc#1236344). * scsi: fnic: Switch to use %ptSp (bsc#1236344). * scsi: fnic: Track NVMe transport statistics (bsc#1236344). * scsi: fnic: Use fnic_num for non-SCSI identifiers (bsc#1236344). * scsi: fnic: Use mempool for receive frames (bsc#1236344). * scsi: qla2xxx: Declare qla2xxx_mqueuecommand() static (bsc#1275737). * scsi: qla2xxx: Use nr_cpu_ids instead of NR_CPUS for qp_cpu_map allocation (bsc#1275737). * scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes). * sctp: avoid auth_enable sysctl UAF during netns teardown (git-fixes). * serial: 8250_dma: Clear stale RX state on shutdown (git-fixes). * serial: amba-pl011: unprepare console clock on unregister (git-fixes). * serial: core: clear freed pointers on uart_register_driver() failure (git- fixes). * serial: qcom-geni: fix TX DMA buffer flush (git-fixes). * serial: sc16is7xx: fix copy-paste errors in EFR_SWFLOWx_BIT constants (stable-fixes). * smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). * smb: client: reject overlapping data areas in SMB2 responses (git-fixes). * smb: client: require net admin for CIFS SWN netlink (bsc#1273966). * smb: client: resolve SWN tcon from live registrations (bsc#1273872). * soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() (git- fixes). * soc: qcom: rpmh-rsc: manage PM notifiers with devres (git-fixes). * soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() (git-fixes). * software node: Fix software_node_get_reference_args() with index -1 (git- fixes). * soundwire: qcom: Fix port exhaustion check in stream_alloc_ports (git- fixes). * speakup: keyhelp: guard letter_offsets possible out-of-range indexing (git- fixes). * spi: img-spfi: don't disable runtime PM on DMA deferred probe (git-fixes). * spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (stable-fixes). * spi: sprd-adi: Fix probe succeeding without registering the controller (git- fixes). * staging: fbtft: Use sysfs_emit_at() to print to sysfs file (git-fixes). * staging: media: tegra-video: fix of_node_put() on VIP parse errors (git- fixes). * staging: media: tegra-video: vi: fix probe failure on skipped last port (git-fixes). * staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown (git- fixes). * staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() (git-fixes). * staging: rtl8723bs: fix missing shared-key auth challenge length check (git- fixes). * staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (git-fixes). * staging: rtl8723bs: fix OOB read in WMM_param_handler() (git-fixes). * staging: rtl8723bs: use kfree_sensitive() for key material (git-fixes). * staging: rtl8723bs: validate monitor transmit frame lengths (git-fixes). * staging: sm750fb: gate dualview dataflow using g_dualview (git-fixes). * thermal/drivers/imx: Disable clock on runtime resume failure (git-fixes). * thermal/drivers/qoriq: Disable clock on resume failure (git-fixes). * thermal: intel: int3400: clean up ODVP on probe failures (git-fixes). * thunderbolt: Bound the DROM dual link port number before indexing sw->ports (git-fixes). * thunderbolt: Fix bandwidth group reservation indexing (git-fixes). * thunderbolt: icm: Preserve USB4 proxy data-valid bit (git-fixes). * tlclk: if sscanf() fails, fall back to 0, not random value (git-fixes). * tpm: st33zp24: Return zero on status read failure (git-fixes). * tpm: st33zp24: Validate locality read result (git-fixes). * tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (git-fixes). * tty: clear cdev pointer after cdev_add() failure (git-fixes). * tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 (git-fixes). * tty: skip cdev_del() when no cdev is registered (git-fixes). * uaccess: add copy_struct_to_user helper (bsc#1263864 ltc#217835). * uaccess: fix ignored_trailing logic in copy_struct_to_user() (bsc#1263864 ltc#217835). * uio: Fix stale info pointer in failed registration path (git-fixes). * usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (git-fixes). * usb: atm: usbatm: fix invalid ci_range initialization (git-fixes). * USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (git-fixes). * usb: cdnsp: fix incorrect endian conversions for APB timeout register (git- fixes). * usb: dwc2: add missing @remotewakeup kernel-doc parameter (git-fixes). * usb: dwc2: gadget: Exit partial power down state when changing USB pull-up (git-fixes). * usb: gadget: configfs: fix out-of-bounds read of qw_sign (git-fixes). * usb: gadget: f_fs: Prevent deadlock during ep0 read loop (git-fixes). * usb: gadget: f_ncm: Use unsigned int for ndp_index (git-fixes). * usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() (git-fixes). * usb: gadget: f_uac1_legacy: remove broken string configfs attributes (git- fixes). * usb: gadget: pch_udc: remove excess kernel-doc member for registered (git- fixes). * usb: gadget: r8a66597: avoid double free of ep0_req in probe error path (git-fixes). * usb: gadget: snps_udc_plat: clean up PHY on probe deferral (git-fixes). * usb: gadget: u_audio: Fix use-after-free on sound card disconnect (git- fixes). * usb: gadget: uac: validate rate list length before storing (git-fixes). * usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() (git-fixes). * usb: mtu3: allow system suspend during active gadget connection (git-fixes). * usb: musb: omap2430: clean up probe error handling (stable-fixes). * USB: phy: fsl-usb: fix missing static keywords (git-fixes). * usb: renesas_usbhs: Fix power-off ordering on unbind (git-fixes). * USB: serial: digi_acceleport: fix port registration order (git-fixes). * USB: serial: ftdi_sio: add support for E+H FXA291 (stable-fixes). * USB: serial: option: add TDTECH MT5710-CN (stable-fixes). * USB: serial: option: fix slab OOB read in interrupt URB callback (git- fixes). * USB: serial: spcp8x5: drop broken carrier detect support (git-fixes). * USB: storage: add NO_ATA_1X quirk for Longmai USB Key (stable-fixes). * usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive() (git-fixes). * usb: typec: ucsi: unregister debugfs entries on teardown (git-fixes). * usb: usbfs: fix use-after-free of usb_device in usbdev_release() (git- fixes). * usb: xhci: Handle USB3 port events when there is one roothub (git-fixes). * vt: add permission check for KDSKBMETA ioctl (stable-fixes). * vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (stable- fixes). * w1: ds28e17: reject an oversize length on an I2C block read (git-fixes). * w1: ds2482: Fix signedness bug in ds2482_w1_triplet() (git-fixes). * wifi: ath6kl: avoid buffer overreads in WMI event handlers (git-fixes). * wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (git-fixes). * wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump (git-fixes). * wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() (git-fixes). * wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate (git- fixes). * wifi: ath11k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() (git-fixes). * wifi: ath12k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (git-fixes). * wifi: brcmfmac: fix P2P action frame handling without device vif (git- fixes). * wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs (git-fixes). * wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments (git-fixes). * wifi: iwlwifi: mei: check SAP message length before reading it (git-fixes). * wifi: iwlwifi: mei: pass correct argument to function (git-fixes). * wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser (git-fixes). * wifi: mac80211: disconnect on CSA to channel 0 (git-fixes). * wifi: mac80211: fix multi-link element inheritance (git-fixes). * wifi: mac80211: fix per-STA profile length in cross-link CSA parsing (git- fixes). * wifi: mac80211: send TWT teardown to peer after setup TX failure (git- fixes). * wifi: mac80211: skip default WMM setup for AP_VLAN links (git-fixes). * wifi: mac80211: skip unused probe response countdown offsets (git-fixes). * wifi: mt76: fix 4th chain ACK RSSI bitmask in sta_poll (git-fixes). * wifi: mt76: fix ER-SU 106-tone RU check in RX rate decode (git-fixes). * wifi: mt76: fix HE DCM max-RU capability encoding (git-fixes). * wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length (git- fixes). * wifi: mt76: mt792x: Fix memory leak in SDIO TX path (git-fixes). * wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (git- fixes). * wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss (git- fixes). * wifi: mt76: mt7915: fix double hif2 init on the non-WED path (git-fixes). * wifi: mt76: mt7915: fix ext PHY use-after-free on register error path (git- fixes). * wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 (git- fixes). * wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie (git-fixes). * wifi: mt76: mt7915: release hif2 reference on probe IRQ failure (git-fixes). * wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement (git- fixes). * wifi: mt76: mt7915: unwind state on add_interface failure (git-fixes). * wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields (git- fixes). * wifi: mt76: mt7915: write RX header translation bit to the correct register (git-fixes). * wifi: mt76: mt7921: validate CLC firmware records (git-fixes). * wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (git- fixes). * wifi: mt76: mt7925: fix msg len mismatch between driver and firmware (git- fixes). * wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config (git- fixes). * wifi: mt76: mt7996: don't report a zero TX bitrate (git-fixes). * wifi: mt76: mt7996: fix capability of EHT-MCS 15 in MRU (git-fixes). * wifi: mt76: mt7996: fix reg addr remap when addr is 0 (git-fixes). * wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV (git- fixes). * wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset (git-fixes). * wifi: mt76: mt7996: validate RX band_idx before dereferencing phys (git- fixes). * wifi: mt76: report data NSS for STBC frames in RX rate decode (git-fixes). * wifi: mwifiex: Detach sync cmd buffer on interrupted wait (git-fixes). * wifi: rtl818x: initialize eeprom_93cx6 struct to zero (git-fixes). * wifi: rtlwifi: pci: fix error path in rtl_pci_probe() (git-fixes). * wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (git-fixes). * wifi: rtw89: fix HE extended capability length check (git-fixes). * wifi: zd1211rw: reject secondary interfaces to prevent conflicts (git- fixes). * x86/bugs: Clarify that syscall hardening isn't a BHI mitigation (git-fixes). * x86/cpu: Add CPU model number for Bartlett Lake CPUs with Raptor Cove cores (bsc#1240957 bsc#1249104 bsc#1265220). * xhci: dbgtty: Fix unregister on tty_alloc_driver() failure (git-fixes). * xhci: dbgtty: Fix unregister on tty_register_driver() failure (git-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-4120=1 * SUSE Real Time Module 15-SP7 zypper in -t patch SUSE-SLE-Module-RT-15-SP7-2026-4120=1 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-SLE15-SP7-RT_Update_20-debugsource-1-150700.1.3.1 * kernel-livepatch-6_4_0-150700_7_75-rt-1-150700.1.3.1 * kernel-livepatch-6_4_0-150700_7_75-rt-debuginfo-1-150700.1.3.1 * SUSE Real Time Module 15-SP7 (x86_64) * ocfs2-kmp-rt-6.4.0-150700.7.75.1 * gfs2-kmp-rt-debuginfo-6.4.0-150700.7.75.1 * dlm-kmp-rt-6.4.0-150700.7.75.1 * kernel-rt-devel-6.4.0-150700.7.75.1 * kernel-rt-debugsource-6.4.0-150700.7.75.1 * cluster-md-kmp-rt-6.4.0-150700.7.75.1 * kernel-rt-devel-debuginfo-6.4.0-150700.7.75.1 * kernel-syms-rt-6.4.0-150700.7.75.1 * ocfs2-kmp-rt-debuginfo-6.4.0-150700.7.75.1 * kernel-rt-debuginfo-6.4.0-150700.7.75.1 * gfs2-kmp-rt-6.4.0-150700.7.75.1 * dlm-kmp-rt-debuginfo-6.4.0-150700.7.75.1 * cluster-md-kmp-rt-debuginfo-6.4.0-150700.7.75.1 * SUSE Real Time Module 15-SP7 (noarch) * kernel-source-rt-6.4.0-150700.7.75.1 * kernel-devel-rt-6.4.0-150700.7.75.1 * SUSE Real Time Module 15-SP7 (nosrc x86_64) * kernel-rt-6.4.0-150700.7.75.1 ## References: * https://www.suse.com/security/cve/CVE-2024-44981.html * https://www.suse.com/security/cve/CVE-2024-57841.html * https://www.suse.com/security/cve/CVE-2025-23137.html * https://www.suse.com/security/cve/CVE-2025-38469.html * https://www.suse.com/security/cve/CVE-2025-39939.html * https://www.suse.com/security/cve/CVE-2025-39964.html * https://www.suse.com/security/cve/CVE-2025-40022.html * https://www.suse.com/security/cve/CVE-2025-40199.html * https://www.suse.com/security/cve/CVE-2025-68179.html * https://www.suse.com/security/cve/CVE-2025-68214.html * https://www.suse.com/security/cve/CVE-2025-71075.html * https://www.suse.com/security/cve/CVE-2025-71104.html * https://www.suse.com/security/cve/CVE-2026-23210.html * https://www.suse.com/security/cve/CVE-2026-23227.html * https://www.suse.com/security/cve/CVE-2026-23230.html * https://www.suse.com/security/cve/CVE-2026-23454.html * https://www.suse.com/security/cve/CVE-2026-31418.html * https://www.suse.com/security/cve/CVE-2026-31531.html * https://www.suse.com/security/cve/CVE-2026-31557.html * https://www.suse.com/security/cve/CVE-2026-31658.html * https://www.suse.com/security/cve/CVE-2026-31663.html * https://www.suse.com/security/cve/CVE-2026-43014.html * https://www.suse.com/security/cve/CVE-2026-43015.html * https://www.suse.com/security/cve/CVE-2026-43116.html * https://www.suse.com/security/cve/CVE-2026-43125.html * https://www.suse.com/security/cve/CVE-2026-43163.html * https://www.suse.com/security/cve/CVE-2026-43213.html * https://www.suse.com/security/cve/CVE-2026-43271.html * https://www.suse.com/security/cve/CVE-2026-43273.html * https://www.suse.com/security/cve/CVE-2026-43363.html * https://www.suse.com/security/cve/CVE-2026-43386.html * https://www.suse.com/security/cve/CVE-2026-43416.html * https://www.suse.com/security/cve/CVE-2026-43448.html * https://www.suse.com/security/cve/CVE-2026-45897.html * https://www.suse.com/security/cve/CVE-2026-45968.html * https://www.suse.com/security/cve/CVE-2026-46070.html * https://www.suse.com/security/cve/CVE-2026-46078.html * https://www.suse.com/security/cve/CVE-2026-46091.html * https://www.suse.com/security/cve/CVE-2026-46107.html * https://www.suse.com/security/cve/CVE-2026-46115.html * https://www.suse.com/security/cve/CVE-2026-46127.html * https://www.suse.com/security/cve/CVE-2026-46195.html * https://www.suse.com/security/cve/CVE-2026-52920.html * https://www.suse.com/security/cve/CVE-2026-52925.html * https://www.suse.com/security/cve/CVE-2026-52929.html * https://www.suse.com/security/cve/CVE-2026-52935.html * https://www.suse.com/security/cve/CVE-2026-52939.html * https://www.suse.com/security/cve/CVE-2026-52946.html * https://www.suse.com/security/cve/CVE-2026-52975.html * https://www.suse.com/security/cve/CVE-2026-52977.html * https://www.suse.com/security/cve/CVE-2026-52990.html * https://www.suse.com/security/cve/CVE-2026-52994.html * https://www.suse.com/security/cve/CVE-2026-53001.html * https://www.suse.com/security/cve/CVE-2026-53033.html * https://www.suse.com/security/cve/CVE-2026-53034.html * https://www.suse.com/security/cve/CVE-2026-53059.html * https://www.suse.com/security/cve/CVE-2026-53076.html * https://www.suse.com/security/cve/CVE-2026-53077.html * https://www.suse.com/security/cve/CVE-2026-53089.html * https://www.suse.com/security/cve/CVE-2026-53091.html * https://www.suse.com/security/cve/CVE-2026-53094.html * https://www.suse.com/security/cve/CVE-2026-53096.html * https://www.suse.com/security/cve/CVE-2026-53110.html * https://www.suse.com/security/cve/CVE-2026-53111.html * https://www.suse.com/security/cve/CVE-2026-53126.html * https://www.suse.com/security/cve/CVE-2026-53142.html * https://www.suse.com/security/cve/CVE-2026-53154.html * https://www.suse.com/security/cve/CVE-2026-53163.html * https://www.suse.com/security/cve/CVE-2026-53180.html * https://www.suse.com/security/cve/CVE-2026-53207.html * https://www.suse.com/security/cve/CVE-2026-53219.html * https://www.suse.com/security/cve/CVE-2026-53220.html * https://www.suse.com/security/cve/CVE-2026-53223.html * https://www.suse.com/security/cve/CVE-2026-53228.html * https://www.suse.com/security/cve/CVE-2026-53238.html * https://www.suse.com/security/cve/CVE-2026-53260.html * https://www.suse.com/security/cve/CVE-2026-53263.html * https://www.suse.com/security/cve/CVE-2026-53264.html * https://www.suse.com/security/cve/CVE-2026-53269.html * https://www.suse.com/security/cve/CVE-2026-53273.html * https://www.suse.com/security/cve/CVE-2026-53309.html * https://www.suse.com/security/cve/CVE-2026-53330.html * https://www.suse.com/security/cve/CVE-2026-53336.html * https://www.suse.com/security/cve/CVE-2026-53337.html * https://www.suse.com/security/cve/CVE-2026-53353.html * https://www.suse.com/security/cve/CVE-2026-53365.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://www.suse.com/security/cve/CVE-2026-53381.html * https://www.suse.com/security/cve/CVE-2026-53388.html * https://www.suse.com/security/cve/CVE-2026-63801.html * https://www.suse.com/security/cve/CVE-2026-63808.html * https://www.suse.com/security/cve/CVE-2026-63810.html * https://www.suse.com/security/cve/CVE-2026-63823.html * https://www.suse.com/security/cve/CVE-2026-63827.html * https://www.suse.com/security/cve/CVE-2026-63828.html * https://www.suse.com/security/cve/CVE-2026-63842.html * https://www.suse.com/security/cve/CVE-2026-63850.html * https://www.suse.com/security/cve/CVE-2026-63860.html * https://www.suse.com/security/cve/CVE-2026-63865.html * https://www.suse.com/security/cve/CVE-2026-63868.html * https://www.suse.com/security/cve/CVE-2026-63879.html * https://www.suse.com/security/cve/CVE-2026-63881.html * https://www.suse.com/security/cve/CVE-2026-63886.html * https://www.suse.com/security/cve/CVE-2026-63887.html * https://www.suse.com/security/cve/CVE-2026-63888.html * https://www.suse.com/security/cve/CVE-2026-63889.html * https://www.suse.com/security/cve/CVE-2026-63891.html * https://www.suse.com/security/cve/CVE-2026-63898.html * https://www.suse.com/security/cve/CVE-2026-63920.html * https://www.suse.com/security/cve/CVE-2026-63923.html * https://www.suse.com/security/cve/CVE-2026-63925.html * https://www.suse.com/security/cve/CVE-2026-63926.html * https://www.suse.com/security/cve/CVE-2026-63928.html * https://www.suse.com/security/cve/CVE-2026-63937.html * https://www.suse.com/security/cve/CVE-2026-63944.html * https://www.suse.com/security/cve/CVE-2026-63969.html * https://www.suse.com/security/cve/CVE-2026-63970.html * https://www.suse.com/security/cve/CVE-2026-63972.html * https://www.suse.com/security/cve/CVE-2026-63973.html * https://www.suse.com/security/cve/CVE-2026-63980.html * https://www.suse.com/security/cve/CVE-2026-63985.html * https://www.suse.com/security/cve/CVE-2026-63990.html * https://www.suse.com/security/cve/CVE-2026-63992.html * https://www.suse.com/security/cve/CVE-2026-63995.html * https://www.suse.com/security/cve/CVE-2026-63996.html * https://www.suse.com/security/cve/CVE-2026-63997.html * https://www.suse.com/security/cve/CVE-2026-63998.html * https://www.suse.com/security/cve/CVE-2026-63999.html * https://www.suse.com/security/cve/CVE-2026-64000.html * https://www.suse.com/security/cve/CVE-2026-64001.html * https://www.suse.com/security/cve/CVE-2026-64002.html * https://www.suse.com/security/cve/CVE-2026-64004.html * https://www.suse.com/security/cve/CVE-2026-64005.html * https://www.suse.com/security/cve/CVE-2026-64006.html * https://www.suse.com/security/cve/CVE-2026-64007.html * https://www.suse.com/security/cve/CVE-2026-64010.html * https://www.suse.com/security/cve/CVE-2026-64011.html * https://www.suse.com/security/cve/CVE-2026-64014.html * https://www.suse.com/security/cve/CVE-2026-64015.html * https://www.suse.com/security/cve/CVE-2026-64018.html * https://www.suse.com/security/cve/CVE-2026-64021.html * https://www.suse.com/security/cve/CVE-2026-64029.html * https://www.suse.com/security/cve/CVE-2026-64033.html * https://www.suse.com/security/cve/CVE-2026-64034.html * https://www.suse.com/security/cve/CVE-2026-64039.html * https://www.suse.com/security/cve/CVE-2026-64047.html * https://www.suse.com/security/cve/CVE-2026-64048.html * https://www.suse.com/security/cve/CVE-2026-64051.html * https://www.suse.com/security/cve/CVE-2026-64052.html * https://www.suse.com/security/cve/CVE-2026-64055.html * https://www.suse.com/security/cve/CVE-2026-64056.html * https://www.suse.com/security/cve/CVE-2026-64073.html * https://www.suse.com/security/cve/CVE-2026-64083.html * https://www.suse.com/security/cve/CVE-2026-64084.html * https://www.suse.com/security/cve/CVE-2026-64085.html * https://www.suse.com/security/cve/CVE-2026-64086.html * https://www.suse.com/security/cve/CVE-2026-64087.html * https://www.suse.com/security/cve/CVE-2026-64088.html * https://www.suse.com/security/cve/CVE-2026-64097.html * https://www.suse.com/security/cve/CVE-2026-64098.html * https://www.suse.com/security/cve/CVE-2026-64099.html * https://www.suse.com/security/cve/CVE-2026-64102.html * https://www.suse.com/security/cve/CVE-2026-64109.html * https://www.suse.com/security/cve/CVE-2026-64112.html * https://www.suse.com/security/cve/CVE-2026-64113.html * https://www.suse.com/security/cve/CVE-2026-64114.html * https://www.suse.com/security/cve/CVE-2026-64115.html * https://www.suse.com/security/cve/CVE-2026-64118.html * https://www.suse.com/security/cve/CVE-2026-64121.html * https://www.suse.com/security/cve/CVE-2026-64125.html * https://www.suse.com/security/cve/CVE-2026-64126.html * https://www.suse.com/security/cve/CVE-2026-64127.html * https://www.suse.com/security/cve/CVE-2026-64128.html * https://www.suse.com/security/cve/CVE-2026-64131.html * https://www.suse.com/security/cve/CVE-2026-64133.html * https://www.suse.com/security/cve/CVE-2026-64134.html * https://www.suse.com/security/cve/CVE-2026-64135.html * https://www.suse.com/security/cve/CVE-2026-64136.html * https://www.suse.com/security/cve/CVE-2026-64137.html * https://www.suse.com/security/cve/CVE-2026-64144.html * https://www.suse.com/security/cve/CVE-2026-64146.html * https://www.suse.com/security/cve/CVE-2026-64148.html * https://www.suse.com/security/cve/CVE-2026-64155.html * https://www.suse.com/security/cve/CVE-2026-64164.html * https://www.suse.com/security/cve/CVE-2026-64166.html * https://www.suse.com/security/cve/CVE-2026-64168.html * https://www.suse.com/security/cve/CVE-2026-64178.html * https://www.suse.com/security/cve/CVE-2026-64180.html * https://www.suse.com/security/cve/CVE-2026-64185.html * https://www.suse.com/security/cve/CVE-2026-64188.html * https://www.suse.com/security/cve/CVE-2026-64190.html * https://www.suse.com/security/cve/CVE-2026-64192.html * https://www.suse.com/security/cve/CVE-2026-64214.html * https://www.suse.com/security/cve/CVE-2026-64217.html * https://www.suse.com/security/cve/CVE-2026-64218.html * https://www.suse.com/security/cve/CVE-2026-64219.html * https://www.suse.com/security/cve/CVE-2026-64222.html * https://www.suse.com/security/cve/CVE-2026-64224.html * https://www.suse.com/security/cve/CVE-2026-64225.html * https://www.suse.com/security/cve/CVE-2026-64237.html * https://www.suse.com/security/cve/CVE-2026-64243.html * https://www.suse.com/security/cve/CVE-2026-64244.html * https://www.suse.com/security/cve/CVE-2026-64245.html * https://www.suse.com/security/cve/CVE-2026-64246.html * https://www.suse.com/security/cve/CVE-2026-64247.html * https://www.suse.com/security/cve/CVE-2026-64249.html * https://www.suse.com/security/cve/CVE-2026-64257.html * https://www.suse.com/security/cve/CVE-2026-64266.html * https://www.suse.com/security/cve/CVE-2026-64268.html * https://www.suse.com/security/cve/CVE-2026-64269.html * https://www.suse.com/security/cve/CVE-2026-64271.html * https://www.suse.com/security/cve/CVE-2026-64273.html * https://www.suse.com/security/cve/CVE-2026-64274.html * https://www.suse.com/security/cve/CVE-2026-64275.html * https://www.suse.com/security/cve/CVE-2026-64276.html * https://www.suse.com/security/cve/CVE-2026-64277.html * https://www.suse.com/security/cve/CVE-2026-64286.html * https://www.suse.com/security/cve/CVE-2026-64287.html * https://www.suse.com/security/cve/CVE-2026-64294.html * https://www.suse.com/security/cve/CVE-2026-64296.html * https://www.suse.com/security/cve/CVE-2026-64303.html * https://www.suse.com/security/cve/CVE-2026-64304.html * https://www.suse.com/security/cve/CVE-2026-64305.html * https://www.suse.com/security/cve/CVE-2026-64306.html * https://www.suse.com/security/cve/CVE-2026-64312.html * https://www.suse.com/security/cve/CVE-2026-64313.html * https://www.suse.com/security/cve/CVE-2026-64315.html * https://www.suse.com/security/cve/CVE-2026-64316.html * https://www.suse.com/security/cve/CVE-2026-64317.html * https://www.suse.com/security/cve/CVE-2026-64322.html * https://www.suse.com/security/cve/CVE-2026-64323.html * https://www.suse.com/security/cve/CVE-2026-64329.html * https://www.suse.com/security/cve/CVE-2026-64331.html * https://www.suse.com/security/cve/CVE-2026-64332.html * https://www.suse.com/security/cve/CVE-2026-64333.html * https://www.suse.com/security/cve/CVE-2026-64334.html * https://www.suse.com/security/cve/CVE-2026-64335.html * https://www.suse.com/security/cve/CVE-2026-64337.html * https://www.suse.com/security/cve/CVE-2026-64338.html * https://www.suse.com/security/cve/CVE-2026-64340.html * https://www.suse.com/security/cve/CVE-2026-64341.html * https://www.suse.com/security/cve/CVE-2026-64342.html * https://www.suse.com/security/cve/CVE-2026-64343.html * https://www.suse.com/security/cve/CVE-2026-64344.html * https://www.suse.com/security/cve/CVE-2026-64346.html * https://www.suse.com/security/cve/CVE-2026-64348.html * https://www.suse.com/security/cve/CVE-2026-64350.html * https://www.suse.com/security/cve/CVE-2026-64351.html * https://www.suse.com/security/cve/CVE-2026-64355.html * https://www.suse.com/security/cve/CVE-2026-64358.html * https://www.suse.com/security/cve/CVE-2026-64362.html * https://www.suse.com/security/cve/CVE-2026-64365.html * https://www.suse.com/security/cve/CVE-2026-64375.html * https://www.suse.com/security/cve/CVE-2026-64376.html * https://www.suse.com/security/cve/CVE-2026-64378.html * https://www.suse.com/security/cve/CVE-2026-64381.html * https://www.suse.com/security/cve/CVE-2026-64382.html * https://www.suse.com/security/cve/CVE-2026-64383.html * https://www.suse.com/security/cve/CVE-2026-64384.html * https://www.suse.com/security/cve/CVE-2026-64385.html * https://www.suse.com/security/cve/CVE-2026-64386.html * https://www.suse.com/security/cve/CVE-2026-64387.html * https://www.suse.com/security/cve/CVE-2026-64388.html * https://www.suse.com/security/cve/CVE-2026-64401.html * https://www.suse.com/security/cve/CVE-2026-64403.html * https://www.suse.com/security/cve/CVE-2026-64406.html * https://www.suse.com/security/cve/CVE-2026-64407.html * https://www.suse.com/security/cve/CVE-2026-64408.html * https://www.suse.com/security/cve/CVE-2026-64409.html * https://www.suse.com/security/cve/CVE-2026-64411.html * https://www.suse.com/security/cve/CVE-2026-64412.html * https://www.suse.com/security/cve/CVE-2026-64420.html * https://www.suse.com/security/cve/CVE-2026-64421.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64427.html * https://www.suse.com/security/cve/CVE-2026-64429.html * https://www.suse.com/security/cve/CVE-2026-64433.html * https://www.suse.com/security/cve/CVE-2026-64434.html * https://www.suse.com/security/cve/CVE-2026-64436.html * https://www.suse.com/security/cve/CVE-2026-64440.html * https://www.suse.com/security/cve/CVE-2026-64442.html * https://www.suse.com/security/cve/CVE-2026-64443.html * https://www.suse.com/security/cve/CVE-2026-64444.html * https://www.suse.com/security/cve/CVE-2026-64445.html * https://www.suse.com/security/cve/CVE-2026-64448.html * https://www.suse.com/security/cve/CVE-2026-64450.html * https://www.suse.com/security/cve/CVE-2026-64452.html * https://www.suse.com/security/cve/CVE-2026-64454.html * https://www.suse.com/security/cve/CVE-2026-64455.html * https://www.suse.com/security/cve/CVE-2026-64463.html * https://www.suse.com/security/cve/CVE-2026-64470.html * https://www.suse.com/security/cve/CVE-2026-64471.html * https://www.suse.com/security/cve/CVE-2026-64472.html * https://www.suse.com/security/cve/CVE-2026-64477.html * https://www.suse.com/security/cve/CVE-2026-64478.html * https://www.suse.com/security/cve/CVE-2026-64479.html * https://www.suse.com/security/cve/CVE-2026-64480.html * https://www.suse.com/security/cve/CVE-2026-64481.html * https://www.suse.com/security/cve/CVE-2026-64482.html * https://www.suse.com/security/cve/CVE-2026-64483.html * https://www.suse.com/security/cve/CVE-2026-64484.html * https://www.suse.com/security/cve/CVE-2026-64486.html * https://www.suse.com/security/cve/CVE-2026-64487.html * https://www.suse.com/security/cve/CVE-2026-64489.html * https://www.suse.com/security/cve/CVE-2026-64494.html * https://www.suse.com/security/cve/CVE-2026-64495.html * https://www.suse.com/security/cve/CVE-2026-64496.html * https://www.suse.com/security/cve/CVE-2026-64497.html * https://www.suse.com/security/cve/CVE-2026-64500.html * https://www.suse.com/security/cve/CVE-2026-64503.html * https://www.suse.com/security/cve/CVE-2026-64504.html * https://www.suse.com/security/cve/CVE-2026-64505.html * https://www.suse.com/security/cve/CVE-2026-64511.html * https://www.suse.com/security/cve/CVE-2026-64512.html * https://www.suse.com/security/cve/CVE-2026-64513.html * https://www.suse.com/security/cve/CVE-2026-64515.html * https://www.suse.com/security/cve/CVE-2026-64517.html * https://www.suse.com/security/cve/CVE-2026-64524.html * https://www.suse.com/security/cve/CVE-2026-64527.html * https://www.suse.com/security/cve/CVE-2026-64536.html * https://www.suse.com/security/cve/CVE-2026-64537.html * https://www.suse.com/security/cve/CVE-2026-64538.html * https://www.suse.com/security/cve/CVE-2026-64539.html * https://www.suse.com/security/cve/CVE-2026-64540.html * https://www.suse.com/security/cve/CVE-2026-64541.html * https://www.suse.com/security/cve/CVE-2026-64543.html * https://www.suse.com/security/cve/CVE-2026-64544.html * https://www.suse.com/security/cve/CVE-2026-64545.html * https://www.suse.com/security/cve/CVE-2026-64546.html * https://www.suse.com/security/cve/CVE-2026-64547.html * https://www.suse.com/security/cve/CVE-2026-64548.html * https://www.suse.com/security/cve/CVE-2026-64549.html * https://www.suse.com/security/cve/CVE-2026-64551.html * https://www.suse.com/security/cve/CVE-2026-64552.html * https://www.suse.com/security/cve/CVE-2026-64553.html * https://www.suse.com/security/cve/CVE-2026-64554.html * https://www.suse.com/security/cve/CVE-2026-64558.html * https://www.suse.com/security/cve/CVE-2026-64559.html * https://www.suse.com/security/cve/CVE-2026-64562.html * https://www.suse.com/security/cve/CVE-2026-64563.html * https://www.suse.com/security/cve/CVE-2026-64565.html * https://www.suse.com/security/cve/CVE-2026-64567.html * https://www.suse.com/security/cve/CVE-2026-64568.html * https://www.suse.com/security/cve/CVE-2026-64569.html * https://www.suse.com/security/cve/CVE-2026-64570.html * https://www.suse.com/security/cve/CVE-2026-64571.html * https://www.suse.com/security/cve/CVE-2026-64572.html * https://www.suse.com/security/cve/CVE-2026-64573.html * https://www.suse.com/security/cve/CVE-2026-64574.html * https://www.suse.com/security/cve/CVE-2026-64576.html * https://www.suse.com/security/cve/CVE-2026-64577.html * https://www.suse.com/security/cve/CVE-2026-64581.html * https://www.suse.com/security/cve/CVE-2026-64582.html * https://www.suse.com/security/cve/CVE-2026-64583.html * https://www.suse.com/security/cve/CVE-2026-64584.html * https://www.suse.com/security/cve/CVE-2026-64585.html * https://www.suse.com/security/cve/CVE-2026-64593.html * https://www.suse.com/security/cve/CVE-2026-64597.html * https://www.suse.com/security/cve/CVE-2026-64598.html * https://www.suse.com/security/cve/CVE-2026-64599.html * https://www.suse.com/security/cve/CVE-2026-64602.html * https://www.suse.com/security/cve/CVE-2026-64603.html * https://www.suse.com/security/cve/CVE-2026-64604.html * https://www.suse.com/security/cve/CVE-2026-68081.html * https://www.suse.com/security/cve/CVE-2026-68082.html * https://www.suse.com/security/cve/CVE-2026-68085.html * https://www.suse.com/security/cve/CVE-2026-68086.html * https://www.suse.com/security/cve/CVE-2026-68088.html * https://www.suse.com/security/cve/CVE-2026-68091.html * https://www.suse.com/security/cve/CVE-2026-68093.html * https://www.suse.com/security/cve/CVE-2026-68102.html * https://www.suse.com/security/cve/CVE-2026-68104.html * https://www.suse.com/security/cve/CVE-2026-68105.html * https://www.suse.com/security/cve/CVE-2026-68106.html * https://www.suse.com/security/cve/CVE-2026-68107.html * https://www.suse.com/security/cve/CVE-2026-68108.html * https://www.suse.com/security/cve/CVE-2026-68110.html * https://www.suse.com/security/cve/CVE-2026-68111.html * https://www.suse.com/security/cve/CVE-2026-68112.html * https://www.suse.com/security/cve/CVE-2026-68113.html * https://www.suse.com/security/cve/CVE-2026-68115.html * https://www.suse.com/security/cve/CVE-2026-68116.html * https://www.suse.com/security/cve/CVE-2026-68117.html * https://www.suse.com/security/cve/CVE-2026-68121.html * https://www.suse.com/security/cve/CVE-2026-68123.html * https://www.suse.com/security/cve/CVE-2026-68124.html * https://www.suse.com/security/cve/CVE-2026-68125.html * https://www.suse.com/security/cve/CVE-2026-68126.html * https://www.suse.com/security/cve/CVE-2026-68127.html * https://www.suse.com/security/cve/CVE-2026-68129.html * https://www.suse.com/security/cve/CVE-2026-68132.html * https://www.suse.com/security/cve/CVE-2026-68133.html * https://www.suse.com/security/cve/CVE-2026-68135.html * https://www.suse.com/security/cve/CVE-2026-68136.html * https://www.suse.com/security/cve/CVE-2026-68137.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://www.suse.com/security/cve/CVE-2026-68139.html * https://www.suse.com/security/cve/CVE-2026-68142.html * https://www.suse.com/security/cve/CVE-2026-68143.html * https://www.suse.com/security/cve/CVE-2026-68145.html * https://www.suse.com/security/cve/CVE-2026-68149.html * https://www.suse.com/security/cve/CVE-2026-68152.html * https://www.suse.com/security/cve/CVE-2026-68153.html * https://www.suse.com/security/cve/CVE-2026-68154.html * https://www.suse.com/security/cve/CVE-2026-68155.html * https://www.suse.com/security/cve/CVE-2026-68156.html * https://www.suse.com/security/cve/CVE-2026-68157.html * https://www.suse.com/security/cve/CVE-2026-68158.html * https://www.suse.com/security/cve/CVE-2026-68159.html * https://www.suse.com/security/cve/CVE-2026-68160.html * https://www.suse.com/security/cve/CVE-2026-68161.html * https://www.suse.com/security/cve/CVE-2026-68162.html * https://www.suse.com/security/cve/CVE-2026-68166.html * https://www.suse.com/security/cve/CVE-2026-68180.html * https://www.suse.com/security/cve/CVE-2026-68181.html * https://www.suse.com/security/cve/CVE-2026-68182.html * https://www.suse.com/security/cve/CVE-2026-68184.html * https://www.suse.com/security/cve/CVE-2026-68188.html * https://www.suse.com/security/cve/CVE-2026-68189.html * https://www.suse.com/security/cve/CVE-2026-68192.html * https://www.suse.com/security/cve/CVE-2026-68193.html * https://www.suse.com/security/cve/CVE-2026-68194.html * https://www.suse.com/security/cve/CVE-2026-68195.html * https://www.suse.com/security/cve/CVE-2026-68196.html * https://www.suse.com/security/cve/CVE-2026-68197.html * https://www.suse.com/security/cve/CVE-2026-68199.html * https://www.suse.com/security/cve/CVE-2026-68202.html * https://www.suse.com/security/cve/CVE-2026-68204.html * https://www.suse.com/security/cve/CVE-2026-68205.html * https://www.suse.com/security/cve/CVE-2026-68206.html * https://www.suse.com/security/cve/CVE-2026-68207.html * https://www.suse.com/security/cve/CVE-2026-68209.html * https://www.suse.com/security/cve/CVE-2026-68210.html * https://www.suse.com/security/cve/CVE-2026-68212.html * https://www.suse.com/security/cve/CVE-2026-68213.html * https://www.suse.com/security/cve/CVE-2026-68214.html * https://www.suse.com/security/cve/CVE-2026-68215.html * https://www.suse.com/security/cve/CVE-2026-68216.html * https://www.suse.com/security/cve/CVE-2026-68217.html * https://www.suse.com/security/cve/CVE-2026-68218.html * https://www.suse.com/security/cve/CVE-2026-68219.html * https://www.suse.com/security/cve/CVE-2026-68220.html * https://www.suse.com/security/cve/CVE-2026-68222.html * https://www.suse.com/security/cve/CVE-2026-68223.html * https://www.suse.com/security/cve/CVE-2026-68226.html * https://www.suse.com/security/cve/CVE-2026-68227.html * https://www.suse.com/security/cve/CVE-2026-68229.html * https://www.suse.com/security/cve/CVE-2026-68231.html * https://www.suse.com/security/cve/CVE-2026-68234.html * https://www.suse.com/security/cve/CVE-2026-68235.html * https://www.suse.com/security/cve/CVE-2026-68236.html * https://www.suse.com/security/cve/CVE-2026-68238.html * https://www.suse.com/security/cve/CVE-2026-68243.html * https://www.suse.com/security/cve/CVE-2026-68244.html * https://www.suse.com/security/cve/CVE-2026-68245.html * https://www.suse.com/security/cve/CVE-2026-68246.html * https://www.suse.com/security/cve/CVE-2026-68247.html * https://www.suse.com/security/cve/CVE-2026-68248.html * https://www.suse.com/security/cve/CVE-2026-68249.html * https://www.suse.com/security/cve/CVE-2026-68250.html * https://www.suse.com/security/cve/CVE-2026-68251.html * https://www.suse.com/security/cve/CVE-2026-68252.html * https://www.suse.com/security/cve/CVE-2026-68253.html * https://www.suse.com/security/cve/CVE-2026-68254.html * https://www.suse.com/security/cve/CVE-2026-68255.html * https://www.suse.com/security/cve/CVE-2026-68256.html * https://www.suse.com/security/cve/CVE-2026-68257.html * https://www.suse.com/security/cve/CVE-2026-68259.html * https://www.suse.com/security/cve/CVE-2026-68260.html * https://www.suse.com/security/cve/CVE-2026-68261.html * https://www.suse.com/security/cve/CVE-2026-68262.html * https://www.suse.com/security/cve/CVE-2026-68263.html * https://www.suse.com/security/cve/CVE-2026-68267.html * https://www.suse.com/security/cve/CVE-2026-68269.html * https://www.suse.com/security/cve/CVE-2026-68271.html * https://www.suse.com/security/cve/CVE-2026-68272.html * https://www.suse.com/security/cve/CVE-2026-68277.html * https://www.suse.com/security/cve/CVE-2026-68278.html * https://www.suse.com/security/cve/CVE-2026-68279.html * https://www.suse.com/security/cve/CVE-2026-68280.html * https://www.suse.com/security/cve/CVE-2026-68281.html * https://www.suse.com/security/cve/CVE-2026-68284.html * https://www.suse.com/security/cve/CVE-2026-68286.html * https://www.suse.com/security/cve/CVE-2026-68288.html * https://www.suse.com/security/cve/CVE-2026-68289.html * https://www.suse.com/security/cve/CVE-2026-68293.html * https://www.suse.com/security/cve/CVE-2026-68297.html * https://www.suse.com/security/cve/CVE-2026-68299.html * https://www.suse.com/security/cve/CVE-2026-68300.html * https://www.suse.com/security/cve/CVE-2026-68302.html * https://www.suse.com/security/cve/CVE-2026-68303.html * https://www.suse.com/security/cve/CVE-2026-68304.html * https://www.suse.com/security/cve/CVE-2026-68306.html * https://www.suse.com/security/cve/CVE-2026-68308.html * https://www.suse.com/security/cve/CVE-2026-68309.html * https://www.suse.com/security/cve/CVE-2026-68310.html * https://www.suse.com/security/cve/CVE-2026-68312.html * https://www.suse.com/security/cve/CVE-2026-68313.html * https://www.suse.com/security/cve/CVE-2026-68315.html * https://www.suse.com/security/cve/CVE-2026-68320.html * https://www.suse.com/security/cve/CVE-2026-68322.html * https://www.suse.com/security/cve/CVE-2026-68324.html * https://www.suse.com/security/cve/CVE-2026-68325.html * https://www.suse.com/security/cve/CVE-2026-68326.html * https://www.suse.com/security/cve/CVE-2026-68327.html * https://www.suse.com/security/cve/CVE-2026-68328.html * https://www.suse.com/security/cve/CVE-2026-68329.html * https://www.suse.com/security/cve/CVE-2026-68331.html * https://www.suse.com/security/cve/CVE-2026-68333.html * https://www.suse.com/security/cve/CVE-2026-68335.html * https://www.suse.com/security/cve/CVE-2026-68336.html * https://www.suse.com/security/cve/CVE-2026-68339.html * https://www.suse.com/security/cve/CVE-2026-68340.html * https://www.suse.com/security/cve/CVE-2026-68343.html * https://www.suse.com/security/cve/CVE-2026-68346.html * https://www.suse.com/security/cve/CVE-2026-68348.html * https://www.suse.com/security/cve/CVE-2026-68349.html * https://www.suse.com/security/cve/CVE-2026-68350.html * https://www.suse.com/security/cve/CVE-2026-68351.html * https://www.suse.com/security/cve/CVE-2026-68352.html * https://www.suse.com/security/cve/CVE-2026-68353.html * https://www.suse.com/security/cve/CVE-2026-68354.html * https://www.suse.com/security/cve/CVE-2026-68355.html * https://www.suse.com/security/cve/CVE-2026-68357.html * https://www.suse.com/security/cve/CVE-2026-68359.html * https://www.suse.com/security/cve/CVE-2026-68360.html * https://www.suse.com/security/cve/CVE-2026-68361.html * https://www.suse.com/security/cve/CVE-2026-68362.html * https://www.suse.com/security/cve/CVE-2026-68363.html * https://www.suse.com/security/cve/CVE-2026-68365.html * https://www.suse.com/security/cve/CVE-2026-68366.html * https://www.suse.com/security/cve/CVE-2026-68368.html * https://www.suse.com/security/cve/CVE-2026-68369.html * https://www.suse.com/security/cve/CVE-2026-68370.html * https://www.suse.com/security/cve/CVE-2026-68372.html * https://www.suse.com/security/cve/CVE-2026-68373.html * https://www.suse.com/security/cve/CVE-2026-68375.html * https://www.suse.com/security/cve/CVE-2026-68377.html * https://www.suse.com/security/cve/CVE-2026-68386.html * https://www.suse.com/security/cve/CVE-2026-68389.html * https://www.suse.com/security/cve/CVE-2026-68391.html * https://www.suse.com/security/cve/CVE-2026-68392.html * https://www.suse.com/security/cve/CVE-2026-68394.html * https://www.suse.com/security/cve/CVE-2026-68397.html * https://www.suse.com/security/cve/CVE-2026-68398.html * https://www.suse.com/security/cve/CVE-2026-68399.html * https://www.suse.com/security/cve/CVE-2026-68402.html * https://www.suse.com/security/cve/CVE-2026-68403.html * https://www.suse.com/security/cve/CVE-2026-68405.html * https://www.suse.com/security/cve/CVE-2026-68406.html * https://www.suse.com/security/cve/CVE-2026-68407.html * https://www.suse.com/security/cve/CVE-2026-68408.html * https://www.suse.com/security/cve/CVE-2026-68410.html * https://www.suse.com/security/cve/CVE-2026-68413.html * https://www.suse.com/security/cve/CVE-2026-68414.html * https://www.suse.com/security/cve/CVE-2026-68417.html * https://www.suse.com/security/cve/CVE-2026-68418.html * https://www.suse.com/security/cve/CVE-2026-68419.html * https://www.suse.com/security/cve/CVE-2026-68422.html * https://www.suse.com/security/cve/CVE-2026-68425.html * https://www.suse.com/security/cve/CVE-2026-68426.html * https://www.suse.com/security/cve/CVE-2026-68427.html * https://www.suse.com/security/cve/CVE-2026-68428.html * https://www.suse.com/security/cve/CVE-2026-68429.html * https://www.suse.com/security/cve/CVE-2026-68430.html * https://www.suse.com/security/cve/CVE-2026-68432.html * https://www.suse.com/security/cve/CVE-2026-68433.html * https://www.suse.com/security/cve/CVE-2026-68434.html * https://www.suse.com/security/cve/CVE-2026-68437.html * https://www.suse.com/security/cve/CVE-2026-68444.html * https://www.suse.com/security/cve/CVE-2026-68445.html * https://www.suse.com/security/cve/CVE-2026-68446.html * https://www.suse.com/security/cve/CVE-2026-68450.html * https://www.suse.com/security/cve/CVE-2026-68470.html * https://www.suse.com/security/cve/CVE-2026-68480.html * https://www.suse.com/security/cve/CVE-2026-72020.html * https://www.suse.com/security/cve/CVE-2026-72032.html * https://www.suse.com/security/cve/CVE-2026-72035.html * https://www.suse.com/security/cve/CVE-2026-72036.html * https://www.suse.com/security/cve/CVE-2026-72046.html * https://www.suse.com/security/cve/CVE-2026-72069.html * https://www.suse.com/security/cve/CVE-2026-72072.html * https://www.suse.com/security/cve/CVE-2026-72083.html * https://www.suse.com/security/cve/CVE-2026-72084.html * https://www.suse.com/security/cve/CVE-2026-72123.html * https://www.suse.com/security/cve/CVE-2026-72132.html * https://www.suse.com/security/cve/CVE-2026-72221.html * https://www.suse.com/security/cve/CVE-2026-72222.html * https://www.suse.com/security/cve/CVE-2026-72251.html * https://www.suse.com/security/cve/CVE-2026-72254.html * https://www.suse.com/security/cve/CVE-2026-72262.html * https://www.suse.com/security/cve/CVE-2026-72288.html * https://www.suse.com/security/cve/CVE-2026-72289.html * https://www.suse.com/security/cve/CVE-2026-72296.html * https://www.suse.com/security/cve/CVE-2026-72307.html * https://www.suse.com/security/cve/CVE-2026-72308.html * https://www.suse.com/security/cve/CVE-2026-72317.html * https://www.suse.com/security/cve/CVE-2026-72341.html * https://www.suse.com/security/cve/CVE-2026-72342.html * https://www.suse.com/security/cve/CVE-2026-72343.html * https://www.suse.com/security/cve/CVE-2026-72389.html * https://www.suse.com/security/cve/CVE-2026-72463.html * https://www.suse.com/security/cve/CVE-2026-72464.html * https://www.suse.com/security/cve/CVE-2026-72466.html * https://www.suse.com/security/cve/CVE-2026-72467.html * https://www.suse.com/security/cve/CVE-2026-72469.html * https://www.suse.com/security/cve/CVE-2026-72473.html * https://www.suse.com/security/cve/CVE-2026-72494.html * https://www.suse.com/security/cve/CVE-2026-72495.html * https://www.suse.com/security/cve/CVE-2026-72496.html * https://www.suse.com/security/cve/CVE-2026-72497.html * https://www.suse.com/security/cve/CVE-2026-72498.html * https://www.suse.com/security/cve/CVE-2026-72499.html * https://www.suse.com/security/cve/CVE-2026-72500.html * https://www.suse.com/security/cve/CVE-2026-72501.html * https://www.suse.com/security/cve/CVE-2026-72502.html * https://www.suse.com/security/cve/CVE-2026-74269.html * https://www.suse.com/security/cve/CVE-2026-74296.html * https://www.suse.com/security/cve/CVE-2026-74297.html * https://www.suse.com/security/cve/CVE-2026-74318.html * https://www.suse.com/security/cve/CVE-2026-74321.html * https://www.suse.com/security/cve/CVE-2026-74334.html * https://www.suse.com/security/cve/CVE-2026-74345.html * https://www.suse.com/security/cve/CVE-2026-74394.html * https://www.suse.com/security/cve/CVE-2026-74395.html * https://www.suse.com/security/cve/CVE-2026-74454.html * https://www.suse.com/security/cve/CVE-2026-74474.html * https://www.suse.com/security/cve/CVE-2026-74481.html * https://www.suse.com/security/cve/CVE-2026-74482.html * https://www.suse.com/security/cve/CVE-2026-74488.html * https://www.suse.com/security/cve/CVE-2026-74495.html * https://www.suse.com/security/cve/CVE-2026-74496.html * https://www.suse.com/security/cve/CVE-2026-74509.html * https://www.suse.com/security/cve/CVE-2026-74510.html * https://www.suse.com/security/cve/CVE-2026-74512.html * https://www.suse.com/security/cve/CVE-2026-74516.html * https://www.suse.com/security/cve/CVE-2026-74518.html * https://www.suse.com/security/cve/CVE-2026-74527.html * https://www.suse.com/security/cve/CVE-2026-74537.html * https://www.suse.com/security/cve/CVE-2026-74548.html * https://www.suse.com/security/cve/CVE-2026-74550.html * https://www.suse.com/security/cve/CVE-2026-74556.html * https://www.suse.com/security/cve/CVE-2026-74563.html * https://www.suse.com/security/cve/CVE-2026-74566.html * https://www.suse.com/security/cve/CVE-2026-74567.html * https://www.suse.com/security/cve/CVE-2026-74571.html * https://www.suse.com/security/cve/CVE-2026-74577.html * https://www.suse.com/security/cve/CVE-2026-74581.html * https://www.suse.com/security/cve/CVE-2026-74582.html * https://www.suse.com/security/cve/CVE-2026-74584.html * https://www.suse.com/security/cve/CVE-2026-74610.html * https://www.suse.com/security/cve/CVE-2026-74669.html * https://www.suse.com/security/cve/CVE-2026-74692.html * https://www.suse.com/security/cve/CVE-2026-74694.html * https://www.suse.com/security/cve/CVE-2026-74695.html * https://www.suse.com/security/cve/CVE-2026-74712.html * https://www.suse.com/security/cve/CVE-2026-74717.html * https://www.suse.com/security/cve/CVE-2026-74722.html * https://www.suse.com/security/cve/CVE-2026-80529.html * https://www.suse.com/security/cve/CVE-2026-80534.html * https://www.suse.com/security/cve/CVE-2026-80590.html * https://www.suse.com/security/cve/CVE-2026-80654.html * https://bugzilla.suse.com/show_bug.cgi?id=1230238 * https://bugzilla.suse.com/show_bug.cgi?id=1235944 * https://bugzilla.suse.com/show_bug.cgi?id=1236344 * https://bugzilla.suse.com/show_bug.cgi?id=1240957 * https://bugzilla.suse.com/show_bug.cgi?id=1241363 * https://bugzilla.suse.com/show_bug.cgi?id=1247180 * https://bugzilla.suse.com/show_bug.cgi?id=1247455 * https://bugzilla.suse.com/show_bug.cgi?id=1249104 * https://bugzilla.suse.com/show_bug.cgi?id=1250748 * https://bugzilla.suse.com/show_bug.cgi?id=1251130 * https://bugzilla.suse.com/show_bug.cgi?id=1251966 * https://bugzilla.suse.com/show_bug.cgi?id=1252682 * https://bugzilla.suse.com/show_bug.cgi?id=1253454 * https://bugzilla.suse.com/show_bug.cgi?id=1254306 * https://bugzilla.suse.com/show_bug.cgi?id=1255225 * https://bugzilla.suse.com/show_bug.cgi?id=1255250 * https://bugzilla.suse.com/show_bug.cgi?id=1256629 * https://bugzilla.suse.com/show_bug.cgi?id=1256708 * https://bugzilla.suse.com/show_bug.cgi?id=1257154 * https://bugzilla.suse.com/show_bug.cgi?id=1258430 * https://bugzilla.suse.com/show_bug.cgi?id=1258472 * https://bugzilla.suse.com/show_bug.cgi?id=1258517 * https://bugzilla.suse.com/show_bug.cgi?id=1260522 * https://bugzilla.suse.com/show_bug.cgi?id=1261562 * https://bugzilla.suse.com/show_bug.cgi?id=1261780 * https://bugzilla.suse.com/show_bug.cgi?id=1262073 * https://bugzilla.suse.com/show_bug.cgi?id=1263004 * https://bugzilla.suse.com/show_bug.cgi?id=1263052 * https://bugzilla.suse.com/show_bug.cgi?id=1263061 * https://bugzilla.suse.com/show_bug.cgi?id=1263133 * https://bugzilla.suse.com/show_bug.cgi?id=1263864 * https://bugzilla.suse.com/show_bug.cgi?id=1264010 * https://bugzilla.suse.com/show_bug.cgi?id=1264012 * https://bugzilla.suse.com/show_bug.cgi?id=1264335 * https://bugzilla.suse.com/show_bug.cgi?id=1264446 * https://bugzilla.suse.com/show_bug.cgi?id=1264541 * https://bugzilla.suse.com/show_bug.cgi?id=1264587 * https://bugzilla.suse.com/show_bug.cgi?id=1264619 * https://bugzilla.suse.com/show_bug.cgi?id=1264643 * https://bugzilla.suse.com/show_bug.cgi?id=1264740 * https://bugzilla.suse.com/show_bug.cgi?id=1264807 * https://bugzilla.suse.com/show_bug.cgi?id=1265068 * https://bugzilla.suse.com/show_bug.cgi?id=1265121 * https://bugzilla.suse.com/show_bug.cgi?id=1265220 * https://bugzilla.suse.com/show_bug.cgi?id=1265449 * https://bugzilla.suse.com/show_bug.cgi?id=1265928 * https://bugzilla.suse.com/show_bug.cgi?id=1266402 * https://bugzilla.suse.com/show_bug.cgi?id=1266860 * https://bugzilla.suse.com/show_bug.cgi?id=1266874 * https://bugzilla.suse.com/show_bug.cgi?id=1266897 * https://bugzilla.suse.com/show_bug.cgi?id=1267023 * https://bugzilla.suse.com/show_bug.cgi?id=1267236 * https://bugzilla.suse.com/show_bug.cgi?id=1267238 * https://bugzilla.suse.com/show_bug.cgi?id=1267501 * https://bugzilla.suse.com/show_bug.cgi?id=1267505 * https://bugzilla.suse.com/show_bug.cgi?id=1267612 * https://bugzilla.suse.com/show_bug.cgi?id=1268276 * https://bugzilla.suse.com/show_bug.cgi?id=1268972 * https://bugzilla.suse.com/show_bug.cgi?id=1268979 * https://bugzilla.suse.com/show_bug.cgi?id=1268987 * https://bugzilla.suse.com/show_bug.cgi?id=1269004 * https://bugzilla.suse.com/show_bug.cgi?id=1269013 * https://bugzilla.suse.com/show_bug.cgi?id=1269108 * https://bugzilla.suse.com/show_bug.cgi?id=1269113 * https://bugzilla.suse.com/show_bug.cgi?id=1269114 * https://bugzilla.suse.com/show_bug.cgi?id=1269126 * https://bugzilla.suse.com/show_bug.cgi?id=1269140 * https://bugzilla.suse.com/show_bug.cgi?id=1269167 * https://bugzilla.suse.com/show_bug.cgi?id=1269234 * https://bugzilla.suse.com/show_bug.cgi?id=1269238 * https://bugzilla.suse.com/show_bug.cgi?id=1269242 * https://bugzilla.suse.com/show_bug.cgi?id=1269256 * https://bugzilla.suse.com/show_bug.cgi?id=1269301 * https://bugzilla.suse.com/show_bug.cgi?id=1269306 * https://bugzilla.suse.com/show_bug.cgi?id=1269313 * https://bugzilla.suse.com/show_bug.cgi?id=1269381 * https://bugzilla.suse.com/show_bug.cgi?id=1269388 * https://bugzilla.suse.com/show_bug.cgi?id=1269402 * https://bugzilla.suse.com/show_bug.cgi?id=1269412 * https://bugzilla.suse.com/show_bug.cgi?id=1269530 * https://bugzilla.suse.com/show_bug.cgi?id=1269579 * https://bugzilla.suse.com/show_bug.cgi?id=1269590 * https://bugzilla.suse.com/show_bug.cgi?id=1269635 * https://bugzilla.suse.com/show_bug.cgi?id=1269647 * https://bugzilla.suse.com/show_bug.cgi?id=1269655 * https://bugzilla.suse.com/show_bug.cgi?id=1269665 * https://bugzilla.suse.com/show_bug.cgi?id=1269686 * https://bugzilla.suse.com/show_bug.cgi?id=1269695 * https://bugzilla.suse.com/show_bug.cgi?id=1269713 * https://bugzilla.suse.com/show_bug.cgi?id=1269731 * https://bugzilla.suse.com/show_bug.cgi?id=1269774 * https://bugzilla.suse.com/show_bug.cgi?id=1269783 * https://bugzilla.suse.com/show_bug.cgi?id=1269792 * https://bugzilla.suse.com/show_bug.cgi?id=1269815 * https://bugzilla.suse.com/show_bug.cgi?id=1269888 * https://bugzilla.suse.com/show_bug.cgi?id=1269965 * https://bugzilla.suse.com/show_bug.cgi?id=1269969 * https://bugzilla.suse.com/show_bug.cgi?id=1269981 * https://bugzilla.suse.com/show_bug.cgi?id=1269985 * https://bugzilla.suse.com/show_bug.cgi?id=1270090 * https://bugzilla.suse.com/show_bug.cgi?id=1270108 * https://bugzilla.suse.com/show_bug.cgi?id=1270111 * https://bugzilla.suse.com/show_bug.cgi?id=1270251 * https://bugzilla.suse.com/show_bug.cgi?id=1270263 * https://bugzilla.suse.com/show_bug.cgi?id=1270268 * https://bugzilla.suse.com/show_bug.cgi?id=1271256 * https://bugzilla.suse.com/show_bug.cgi?id=1271365 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 * https://bugzilla.suse.com/show_bug.cgi?id=1271825 * https://bugzilla.suse.com/show_bug.cgi?id=1271830 * https://bugzilla.suse.com/show_bug.cgi?id=1272150 * https://bugzilla.suse.com/show_bug.cgi?id=1272175 * https://bugzilla.suse.com/show_bug.cgi?id=1272179 * https://bugzilla.suse.com/show_bug.cgi?id=1272182 * https://bugzilla.suse.com/show_bug.cgi?id=1272200 * https://bugzilla.suse.com/show_bug.cgi?id=1272210 * https://bugzilla.suse.com/show_bug.cgi?id=1272213 * https://bugzilla.suse.com/show_bug.cgi?id=1272230 * https://bugzilla.suse.com/show_bug.cgi?id=1272260 * https://bugzilla.suse.com/show_bug.cgi?id=1272261 * https://bugzilla.suse.com/show_bug.cgi?id=1272262 * https://bugzilla.suse.com/show_bug.cgi?id=1272297 * https://bugzilla.suse.com/show_bug.cgi?id=1272346 * https://bugzilla.suse.com/show_bug.cgi?id=1272351 * https://bugzilla.suse.com/show_bug.cgi?id=1272359 * https://bugzilla.suse.com/show_bug.cgi?id=1272381 * https://bugzilla.suse.com/show_bug.cgi?id=1272383 * https://bugzilla.suse.com/show_bug.cgi?id=1272385 * https://bugzilla.suse.com/show_bug.cgi?id=1272390 * https://bugzilla.suse.com/show_bug.cgi?id=1272423 * https://bugzilla.suse.com/show_bug.cgi?id=1272429 * https://bugzilla.suse.com/show_bug.cgi?id=1272484 * https://bugzilla.suse.com/show_bug.cgi?id=1272486 * https://bugzilla.suse.com/show_bug.cgi?id=1272497 * https://bugzilla.suse.com/show_bug.cgi?id=1272502 * https://bugzilla.suse.com/show_bug.cgi?id=1272516 * https://bugzilla.suse.com/show_bug.cgi?id=1272569 * https://bugzilla.suse.com/show_bug.cgi?id=1272571 * https://bugzilla.suse.com/show_bug.cgi?id=1272618 * https://bugzilla.suse.com/show_bug.cgi?id=1272641 * https://bugzilla.suse.com/show_bug.cgi?id=1272643 * https://bugzilla.suse.com/show_bug.cgi?id=1272662 * https://bugzilla.suse.com/show_bug.cgi?id=1272673 * https://bugzilla.suse.com/show_bug.cgi?id=1272680 * https://bugzilla.suse.com/show_bug.cgi?id=1272682 * https://bugzilla.suse.com/show_bug.cgi?id=1272756 * https://bugzilla.suse.com/show_bug.cgi?id=1272786 * https://bugzilla.suse.com/show_bug.cgi?id=1272788 * https://bugzilla.suse.com/show_bug.cgi?id=1272798 * https://bugzilla.suse.com/show_bug.cgi?id=1272799 * https://bugzilla.suse.com/show_bug.cgi?id=1272804 * https://bugzilla.suse.com/show_bug.cgi?id=1272868 * https://bugzilla.suse.com/show_bug.cgi?id=1272877 * https://bugzilla.suse.com/show_bug.cgi?id=1272891 * https://bugzilla.suse.com/show_bug.cgi?id=1272893 * https://bugzilla.suse.com/show_bug.cgi?id=1272963 * https://bugzilla.suse.com/show_bug.cgi?id=1272983 * https://bugzilla.suse.com/show_bug.cgi?id=1272993 * https://bugzilla.suse.com/show_bug.cgi?id=1273005 * https://bugzilla.suse.com/show_bug.cgi?id=1273008 * https://bugzilla.suse.com/show_bug.cgi?id=1273019 * https://bugzilla.suse.com/show_bug.cgi?id=1273027 * https://bugzilla.suse.com/show_bug.cgi?id=1273028 * https://bugzilla.suse.com/show_bug.cgi?id=1273030 * https://bugzilla.suse.com/show_bug.cgi?id=1273032 * https://bugzilla.suse.com/show_bug.cgi?id=1273033 * https://bugzilla.suse.com/show_bug.cgi?id=1273036 * https://bugzilla.suse.com/show_bug.cgi?id=1273037 * https://bugzilla.suse.com/show_bug.cgi?id=1273038 * https://bugzilla.suse.com/show_bug.cgi?id=1273053 * https://bugzilla.suse.com/show_bug.cgi?id=1273054 * https://bugzilla.suse.com/show_bug.cgi?id=1273060 * https://bugzilla.suse.com/show_bug.cgi?id=1273105 * https://bugzilla.suse.com/show_bug.cgi?id=1273134 * https://bugzilla.suse.com/show_bug.cgi?id=1273249 * https://bugzilla.suse.com/show_bug.cgi?id=1273250 * https://bugzilla.suse.com/show_bug.cgi?id=1273260 * https://bugzilla.suse.com/show_bug.cgi?id=1273273 * https://bugzilla.suse.com/show_bug.cgi?id=1273274 * https://bugzilla.suse.com/show_bug.cgi?id=1273276 * https://bugzilla.suse.com/show_bug.cgi?id=1273277 * https://bugzilla.suse.com/show_bug.cgi?id=1273280 * https://bugzilla.suse.com/show_bug.cgi?id=1273281 * https://bugzilla.suse.com/show_bug.cgi?id=1273284 * https://bugzilla.suse.com/show_bug.cgi?id=1273285 * https://bugzilla.suse.com/show_bug.cgi?id=1273289 * https://bugzilla.suse.com/show_bug.cgi?id=1273291 * https://bugzilla.suse.com/show_bug.cgi?id=1273294 * https://bugzilla.suse.com/show_bug.cgi?id=1273302 * https://bugzilla.suse.com/show_bug.cgi?id=1273303 * https://bugzilla.suse.com/show_bug.cgi?id=1273305 * https://bugzilla.suse.com/show_bug.cgi?id=1273310 * https://bugzilla.suse.com/show_bug.cgi?id=1273311 * https://bugzilla.suse.com/show_bug.cgi?id=1273316 * https://bugzilla.suse.com/show_bug.cgi?id=1273318 * https://bugzilla.suse.com/show_bug.cgi?id=1273319 * https://bugzilla.suse.com/show_bug.cgi?id=1273323 * https://bugzilla.suse.com/show_bug.cgi?id=1273325 * https://bugzilla.suse.com/show_bug.cgi?id=1273327 * https://bugzilla.suse.com/show_bug.cgi?id=1273334 * https://bugzilla.suse.com/show_bug.cgi?id=1273335 * https://bugzilla.suse.com/show_bug.cgi?id=1273336 * https://bugzilla.suse.com/show_bug.cgi?id=1273337 * https://bugzilla.suse.com/show_bug.cgi?id=1273338 * https://bugzilla.suse.com/show_bug.cgi?id=1273340 * https://bugzilla.suse.com/show_bug.cgi?id=1273341 * https://bugzilla.suse.com/show_bug.cgi?id=1273346 * https://bugzilla.suse.com/show_bug.cgi?id=1273422 * https://bugzilla.suse.com/show_bug.cgi?id=1273426 * https://bugzilla.suse.com/show_bug.cgi?id=1273443 * https://bugzilla.suse.com/show_bug.cgi?id=1273460 * https://bugzilla.suse.com/show_bug.cgi?id=1273463 * https://bugzilla.suse.com/show_bug.cgi?id=1273465 * https://bugzilla.suse.com/show_bug.cgi?id=1273468 * https://bugzilla.suse.com/show_bug.cgi?id=1273469 * https://bugzilla.suse.com/show_bug.cgi?id=1273471 * https://bugzilla.suse.com/show_bug.cgi?id=1273479 * https://bugzilla.suse.com/show_bug.cgi?id=1273480 * https://bugzilla.suse.com/show_bug.cgi?id=1273482 * https://bugzilla.suse.com/show_bug.cgi?id=1273484 * https://bugzilla.suse.com/show_bug.cgi?id=1273488 * https://bugzilla.suse.com/show_bug.cgi?id=1273490 * https://bugzilla.suse.com/show_bug.cgi?id=1273501 * https://bugzilla.suse.com/show_bug.cgi?id=1273503 * https://bugzilla.suse.com/show_bug.cgi?id=1273504 * https://bugzilla.suse.com/show_bug.cgi?id=1273506 * https://bugzilla.suse.com/show_bug.cgi?id=1273523 * https://bugzilla.suse.com/show_bug.cgi?id=1273525 * https://bugzilla.suse.com/show_bug.cgi?id=1273533 * https://bugzilla.suse.com/show_bug.cgi?id=1273536 * https://bugzilla.suse.com/show_bug.cgi?id=1273542 * https://bugzilla.suse.com/show_bug.cgi?id=1273555 * https://bugzilla.suse.com/show_bug.cgi?id=1273578 * https://bugzilla.suse.com/show_bug.cgi?id=1273579 * https://bugzilla.suse.com/show_bug.cgi?id=1273581 * https://bugzilla.suse.com/show_bug.cgi?id=1273582 * https://bugzilla.suse.com/show_bug.cgi?id=1273596 * https://bugzilla.suse.com/show_bug.cgi?id=1273597 * https://bugzilla.suse.com/show_bug.cgi?id=1273598 * https://bugzilla.suse.com/show_bug.cgi?id=1273600 * https://bugzilla.suse.com/show_bug.cgi?id=1273601 * https://bugzilla.suse.com/show_bug.cgi?id=1273602 * https://bugzilla.suse.com/show_bug.cgi?id=1273603 * https://bugzilla.suse.com/show_bug.cgi?id=1273679 * https://bugzilla.suse.com/show_bug.cgi?id=1273681 * https://bugzilla.suse.com/show_bug.cgi?id=1273682 * https://bugzilla.suse.com/show_bug.cgi?id=1273734 * https://bugzilla.suse.com/show_bug.cgi?id=1273738 * https://bugzilla.suse.com/show_bug.cgi?id=1273739 * https://bugzilla.suse.com/show_bug.cgi?id=1273741 * https://bugzilla.suse.com/show_bug.cgi?id=1273742 * https://bugzilla.suse.com/show_bug.cgi?id=1273743 * https://bugzilla.suse.com/show_bug.cgi?id=1273745 * https://bugzilla.suse.com/show_bug.cgi?id=1273748 * https://bugzilla.suse.com/show_bug.cgi?id=1273749 * https://bugzilla.suse.com/show_bug.cgi?id=1273755 * https://bugzilla.suse.com/show_bug.cgi?id=1273762 * https://bugzilla.suse.com/show_bug.cgi?id=1273765 * https://bugzilla.suse.com/show_bug.cgi?id=1273766 * https://bugzilla.suse.com/show_bug.cgi?id=1273769 * https://bugzilla.suse.com/show_bug.cgi?id=1273774 * https://bugzilla.suse.com/show_bug.cgi?id=1273778 * https://bugzilla.suse.com/show_bug.cgi?id=1273780 * https://bugzilla.suse.com/show_bug.cgi?id=1273790 * https://bugzilla.suse.com/show_bug.cgi?id=1273796 * https://bugzilla.suse.com/show_bug.cgi?id=1273797 * https://bugzilla.suse.com/show_bug.cgi?id=1273801 * https://bugzilla.suse.com/show_bug.cgi?id=1273804 * https://bugzilla.suse.com/show_bug.cgi?id=1273810 * https://bugzilla.suse.com/show_bug.cgi?id=1273811 * https://bugzilla.suse.com/show_bug.cgi?id=1273812 * https://bugzilla.suse.com/show_bug.cgi?id=1273813 * https://bugzilla.suse.com/show_bug.cgi?id=1273817 * https://bugzilla.suse.com/show_bug.cgi?id=1273822 * https://bugzilla.suse.com/show_bug.cgi?id=1273824 * https://bugzilla.suse.com/show_bug.cgi?id=1273831 * https://bugzilla.suse.com/show_bug.cgi?id=1273832 * https://bugzilla.suse.com/show_bug.cgi?id=1273834 * https://bugzilla.suse.com/show_bug.cgi?id=1273838 * https://bugzilla.suse.com/show_bug.cgi?id=1273844 * https://bugzilla.suse.com/show_bug.cgi?id=1273849 * https://bugzilla.suse.com/show_bug.cgi?id=1273859 * https://bugzilla.suse.com/show_bug.cgi?id=1273860 * https://bugzilla.suse.com/show_bug.cgi?id=1273862 * https://bugzilla.suse.com/show_bug.cgi?id=1273867 * https://bugzilla.suse.com/show_bug.cgi?id=1273868 * https://bugzilla.suse.com/show_bug.cgi?id=1273869 * https://bugzilla.suse.com/show_bug.cgi?id=1273872 * https://bugzilla.suse.com/show_bug.cgi?id=1273876 * https://bugzilla.suse.com/show_bug.cgi?id=1273877 * https://bugzilla.suse.com/show_bug.cgi?id=1273880 * https://bugzilla.suse.com/show_bug.cgi?id=1273882 * https://bugzilla.suse.com/show_bug.cgi?id=1273890 * https://bugzilla.suse.com/show_bug.cgi?id=1273891 * https://bugzilla.suse.com/show_bug.cgi?id=1273892 * https://bugzilla.suse.com/show_bug.cgi?id=1273895 * https://bugzilla.suse.com/show_bug.cgi?id=1273896 * https://bugzilla.suse.com/show_bug.cgi?id=1273903 * https://bugzilla.suse.com/show_bug.cgi?id=1273905 * https://bugzilla.suse.com/show_bug.cgi?id=1273930 * https://bugzilla.suse.com/show_bug.cgi?id=1273933 * https://bugzilla.suse.com/show_bug.cgi?id=1273934 * https://bugzilla.suse.com/show_bug.cgi?id=1273935 * https://bugzilla.suse.com/show_bug.cgi?id=1273936 * https://bugzilla.suse.com/show_bug.cgi?id=1273939 * https://bugzilla.suse.com/show_bug.cgi?id=1273940 * https://bugzilla.suse.com/show_bug.cgi?id=1273941 * https://bugzilla.suse.com/show_bug.cgi?id=1273942 * https://bugzilla.suse.com/show_bug.cgi?id=1273944 * https://bugzilla.suse.com/show_bug.cgi?id=1273945 * https://bugzilla.suse.com/show_bug.cgi?id=1273946 * https://bugzilla.suse.com/show_bug.cgi?id=1273956 * https://bugzilla.suse.com/show_bug.cgi?id=1273957 * https://bugzilla.suse.com/show_bug.cgi?id=1273958 * https://bugzilla.suse.com/show_bug.cgi?id=1273966 * https://bugzilla.suse.com/show_bug.cgi?id=1273967 * https://bugzilla.suse.com/show_bug.cgi?id=1273968 * https://bugzilla.suse.com/show_bug.cgi?id=1273972 * https://bugzilla.suse.com/show_bug.cgi?id=1273974 * https://bugzilla.suse.com/show_bug.cgi?id=1273975 * https://bugzilla.suse.com/show_bug.cgi?id=1273977 * https://bugzilla.suse.com/show_bug.cgi?id=1273982 * https://bugzilla.suse.com/show_bug.cgi?id=1273988 * https://bugzilla.suse.com/show_bug.cgi?id=1273990 * https://bugzilla.suse.com/show_bug.cgi?id=1273991 * https://bugzilla.suse.com/show_bug.cgi?id=1273995 * https://bugzilla.suse.com/show_bug.cgi?id=1274001 * https://bugzilla.suse.com/show_bug.cgi?id=1274003 * https://bugzilla.suse.com/show_bug.cgi?id=1274006 * https://bugzilla.suse.com/show_bug.cgi?id=1274008 * https://bugzilla.suse.com/show_bug.cgi?id=1274009 * https://bugzilla.suse.com/show_bug.cgi?id=1274010 * https://bugzilla.suse.com/show_bug.cgi?id=1274011 * https://bugzilla.suse.com/show_bug.cgi?id=1274012 * https://bugzilla.suse.com/show_bug.cgi?id=1274014 * https://bugzilla.suse.com/show_bug.cgi?id=1274017 * https://bugzilla.suse.com/show_bug.cgi?id=1274019 * https://bugzilla.suse.com/show_bug.cgi?id=1274020 * https://bugzilla.suse.com/show_bug.cgi?id=1274026 * https://bugzilla.suse.com/show_bug.cgi?id=1274028 * https://bugzilla.suse.com/show_bug.cgi?id=1274030 * https://bugzilla.suse.com/show_bug.cgi?id=1274031 * https://bugzilla.suse.com/show_bug.cgi?id=1274035 * https://bugzilla.suse.com/show_bug.cgi?id=1274040 * https://bugzilla.suse.com/show_bug.cgi?id=1274041 * https://bugzilla.suse.com/show_bug.cgi?id=1274055 * https://bugzilla.suse.com/show_bug.cgi?id=1274057 * https://bugzilla.suse.com/show_bug.cgi?id=1274058 * https://bugzilla.suse.com/show_bug.cgi?id=1274061 * https://bugzilla.suse.com/show_bug.cgi?id=1274063 * https://bugzilla.suse.com/show_bug.cgi?id=1274065 * https://bugzilla.suse.com/show_bug.cgi?id=1274067 * https://bugzilla.suse.com/show_bug.cgi?id=1274071 * https://bugzilla.suse.com/show_bug.cgi?id=1274075 * https://bugzilla.suse.com/show_bug.cgi?id=1274076 * https://bugzilla.suse.com/show_bug.cgi?id=1274077 * https://bugzilla.suse.com/show_bug.cgi?id=1274078 * https://bugzilla.suse.com/show_bug.cgi?id=1274208 * https://bugzilla.suse.com/show_bug.cgi?id=1274226 * https://bugzilla.suse.com/show_bug.cgi?id=1274239 * https://bugzilla.suse.com/show_bug.cgi?id=1274243 * https://bugzilla.suse.com/show_bug.cgi?id=1274258 * https://bugzilla.suse.com/show_bug.cgi?id=1274264 * https://bugzilla.suse.com/show_bug.cgi?id=1274265 * https://bugzilla.suse.com/show_bug.cgi?id=1274267 * https://bugzilla.suse.com/show_bug.cgi?id=1274274 * https://bugzilla.suse.com/show_bug.cgi?id=1274277 * https://bugzilla.suse.com/show_bug.cgi?id=1274278 * https://bugzilla.suse.com/show_bug.cgi?id=1274281 * https://bugzilla.suse.com/show_bug.cgi?id=1274283 * https://bugzilla.suse.com/show_bug.cgi?id=1274286 * https://bugzilla.suse.com/show_bug.cgi?id=1274290 * https://bugzilla.suse.com/show_bug.cgi?id=1274294 * https://bugzilla.suse.com/show_bug.cgi?id=1274295 * https://bugzilla.suse.com/show_bug.cgi?id=1274296 * https://bugzilla.suse.com/show_bug.cgi?id=1274297 * https://bugzilla.suse.com/show_bug.cgi?id=1274298 * https://bugzilla.suse.com/show_bug.cgi?id=1274314 * https://bugzilla.suse.com/show_bug.cgi?id=1274321 * https://bugzilla.suse.com/show_bug.cgi?id=1274491 * https://bugzilla.suse.com/show_bug.cgi?id=1274497 * https://bugzilla.suse.com/show_bug.cgi?id=1274539 * https://bugzilla.suse.com/show_bug.cgi?id=1274541 * https://bugzilla.suse.com/show_bug.cgi?id=1274543 * https://bugzilla.suse.com/show_bug.cgi?id=1274545 * https://bugzilla.suse.com/show_bug.cgi?id=1274547 * https://bugzilla.suse.com/show_bug.cgi?id=1274550 * https://bugzilla.suse.com/show_bug.cgi?id=1274573 * https://bugzilla.suse.com/show_bug.cgi?id=1274578 * https://bugzilla.suse.com/show_bug.cgi?id=1274580 * https://bugzilla.suse.com/show_bug.cgi?id=1274581 * https://bugzilla.suse.com/show_bug.cgi?id=1274620 * https://bugzilla.suse.com/show_bug.cgi?id=1274622 * https://bugzilla.suse.com/show_bug.cgi?id=1274624 * https://bugzilla.suse.com/show_bug.cgi?id=1274629 * https://bugzilla.suse.com/show_bug.cgi?id=1274632 * https://bugzilla.suse.com/show_bug.cgi?id=1274636 * https://bugzilla.suse.com/show_bug.cgi?id=1274639 * https://bugzilla.suse.com/show_bug.cgi?id=1274640 * https://bugzilla.suse.com/show_bug.cgi?id=1274642 * https://bugzilla.suse.com/show_bug.cgi?id=1274644 * https://bugzilla.suse.com/show_bug.cgi?id=1274645 * https://bugzilla.suse.com/show_bug.cgi?id=1274646 * https://bugzilla.suse.com/show_bug.cgi?id=1274649 * https://bugzilla.suse.com/show_bug.cgi?id=1274650 * https://bugzilla.suse.com/show_bug.cgi?id=1274651 * https://bugzilla.suse.com/show_bug.cgi?id=1274656 * https://bugzilla.suse.com/show_bug.cgi?id=1274659 * https://bugzilla.suse.com/show_bug.cgi?id=1274662 * https://bugzilla.suse.com/show_bug.cgi?id=1274663 * https://bugzilla.suse.com/show_bug.cgi?id=1274665 * https://bugzilla.suse.com/show_bug.cgi?id=1274667 * https://bugzilla.suse.com/show_bug.cgi?id=1274670 * https://bugzilla.suse.com/show_bug.cgi?id=1274675 * https://bugzilla.suse.com/show_bug.cgi?id=1274677 * https://bugzilla.suse.com/show_bug.cgi?id=1274678 * https://bugzilla.suse.com/show_bug.cgi?id=1274679 * https://bugzilla.suse.com/show_bug.cgi?id=1274681 * https://bugzilla.suse.com/show_bug.cgi?id=1274682 * https://bugzilla.suse.com/show_bug.cgi?id=1274690 * https://bugzilla.suse.com/show_bug.cgi?id=1274694 * https://bugzilla.suse.com/show_bug.cgi?id=1274696 * https://bugzilla.suse.com/show_bug.cgi?id=1274698 * https://bugzilla.suse.com/show_bug.cgi?id=1274699 * https://bugzilla.suse.com/show_bug.cgi?id=1274700 * https://bugzilla.suse.com/show_bug.cgi?id=1274702 * https://bugzilla.suse.com/show_bug.cgi?id=1274703 * https://bugzilla.suse.com/show_bug.cgi?id=1274705 * https://bugzilla.suse.com/show_bug.cgi?id=1274706 * https://bugzilla.suse.com/show_bug.cgi?id=1274709 * https://bugzilla.suse.com/show_bug.cgi?id=1274710 * https://bugzilla.suse.com/show_bug.cgi?id=1274713 * https://bugzilla.suse.com/show_bug.cgi?id=1274716 * https://bugzilla.suse.com/show_bug.cgi?id=1274721 * https://bugzilla.suse.com/show_bug.cgi?id=1274725 * https://bugzilla.suse.com/show_bug.cgi?id=1274737 * https://bugzilla.suse.com/show_bug.cgi?id=1274738 * https://bugzilla.suse.com/show_bug.cgi?id=1274749 * https://bugzilla.suse.com/show_bug.cgi?id=1274752 * https://bugzilla.suse.com/show_bug.cgi?id=1274753 * https://bugzilla.suse.com/show_bug.cgi?id=1274754 * https://bugzilla.suse.com/show_bug.cgi?id=1274755 * https://bugzilla.suse.com/show_bug.cgi?id=1274756 * https://bugzilla.suse.com/show_bug.cgi?id=1274764 * https://bugzilla.suse.com/show_bug.cgi?id=1274768 * https://bugzilla.suse.com/show_bug.cgi?id=1274770 * https://bugzilla.suse.com/show_bug.cgi?id=1274783 * https://bugzilla.suse.com/show_bug.cgi?id=1274787 * https://bugzilla.suse.com/show_bug.cgi?id=1274800 * https://bugzilla.suse.com/show_bug.cgi?id=1274801 * https://bugzilla.suse.com/show_bug.cgi?id=1274802 * https://bugzilla.suse.com/show_bug.cgi?id=1274804 * https://bugzilla.suse.com/show_bug.cgi?id=1274805 * https://bugzilla.suse.com/show_bug.cgi?id=1274807 * https://bugzilla.suse.com/show_bug.cgi?id=1274808 * https://bugzilla.suse.com/show_bug.cgi?id=1274811 * https://bugzilla.suse.com/show_bug.cgi?id=1274813 * https://bugzilla.suse.com/show_bug.cgi?id=1274814 * https://bugzilla.suse.com/show_bug.cgi?id=1274831 * https://bugzilla.suse.com/show_bug.cgi?id=1274834 * https://bugzilla.suse.com/show_bug.cgi?id=1274835 * https://bugzilla.suse.com/show_bug.cgi?id=1274847 * https://bugzilla.suse.com/show_bug.cgi?id=1274849 * https://bugzilla.suse.com/show_bug.cgi?id=1274853 * https://bugzilla.suse.com/show_bug.cgi?id=1274868 * https://bugzilla.suse.com/show_bug.cgi?id=1274869 * https://bugzilla.suse.com/show_bug.cgi?id=1274872 * https://bugzilla.suse.com/show_bug.cgi?id=1274873 * https://bugzilla.suse.com/show_bug.cgi?id=1274874 * https://bugzilla.suse.com/show_bug.cgi?id=1274876 * https://bugzilla.suse.com/show_bug.cgi?id=1274877 * https://bugzilla.suse.com/show_bug.cgi?id=1274879 * https://bugzilla.suse.com/show_bug.cgi?id=1274881 * https://bugzilla.suse.com/show_bug.cgi?id=1274883 * https://bugzilla.suse.com/show_bug.cgi?id=1274886 * https://bugzilla.suse.com/show_bug.cgi?id=1274888 * https://bugzilla.suse.com/show_bug.cgi?id=1274891 * https://bugzilla.suse.com/show_bug.cgi?id=1274892 * https://bugzilla.suse.com/show_bug.cgi?id=1274893 * https://bugzilla.suse.com/show_bug.cgi?id=1274894 * https://bugzilla.suse.com/show_bug.cgi?id=1274895 * https://bugzilla.suse.com/show_bug.cgi?id=1274896 * https://bugzilla.suse.com/show_bug.cgi?id=1274897 * https://bugzilla.suse.com/show_bug.cgi?id=1274898 * https://bugzilla.suse.com/show_bug.cgi?id=1274899 * https://bugzilla.suse.com/show_bug.cgi?id=1274901 * https://bugzilla.suse.com/show_bug.cgi?id=1274902 * https://bugzilla.suse.com/show_bug.cgi?id=1274905 * https://bugzilla.suse.com/show_bug.cgi?id=1274906 * https://bugzilla.suse.com/show_bug.cgi?id=1274907 * https://bugzilla.suse.com/show_bug.cgi?id=1274908 * https://bugzilla.suse.com/show_bug.cgi?id=1274913 * https://bugzilla.suse.com/show_bug.cgi?id=1274914 * https://bugzilla.suse.com/show_bug.cgi?id=1274920 * https://bugzilla.suse.com/show_bug.cgi?id=1274921 * https://bugzilla.suse.com/show_bug.cgi?id=1274924 * https://bugzilla.suse.com/show_bug.cgi?id=1274925 * https://bugzilla.suse.com/show_bug.cgi?id=1274929 * https://bugzilla.suse.com/show_bug.cgi?id=1274930 * https://bugzilla.suse.com/show_bug.cgi?id=1274933 * https://bugzilla.suse.com/show_bug.cgi?id=1274934 * https://bugzilla.suse.com/show_bug.cgi?id=1274935 * https://bugzilla.suse.com/show_bug.cgi?id=1274941 * https://bugzilla.suse.com/show_bug.cgi?id=1274945 * https://bugzilla.suse.com/show_bug.cgi?id=1274947 * https://bugzilla.suse.com/show_bug.cgi?id=1274951 * https://bugzilla.suse.com/show_bug.cgi?id=1274953 * https://bugzilla.suse.com/show_bug.cgi?id=1274958 * https://bugzilla.suse.com/show_bug.cgi?id=1274968 * https://bugzilla.suse.com/show_bug.cgi?id=1274981 * https://bugzilla.suse.com/show_bug.cgi?id=1275040 * https://bugzilla.suse.com/show_bug.cgi?id=1275069 * https://bugzilla.suse.com/show_bug.cgi?id=1275071 * https://bugzilla.suse.com/show_bug.cgi?id=1275073 * https://bugzilla.suse.com/show_bug.cgi?id=1275076 * https://bugzilla.suse.com/show_bug.cgi?id=1275080 * https://bugzilla.suse.com/show_bug.cgi?id=1275081 * https://bugzilla.suse.com/show_bug.cgi?id=1275083 * https://bugzilla.suse.com/show_bug.cgi?id=1275088 * https://bugzilla.suse.com/show_bug.cgi?id=1275091 * https://bugzilla.suse.com/show_bug.cgi?id=1275125 * https://bugzilla.suse.com/show_bug.cgi?id=1275126 * https://bugzilla.suse.com/show_bug.cgi?id=1275131 * https://bugzilla.suse.com/show_bug.cgi?id=1275132 * https://bugzilla.suse.com/show_bug.cgi?id=1275139 * https://bugzilla.suse.com/show_bug.cgi?id=1275141 * https://bugzilla.suse.com/show_bug.cgi?id=1275146 * https://bugzilla.suse.com/show_bug.cgi?id=1275148 * https://bugzilla.suse.com/show_bug.cgi?id=1275149 * https://bugzilla.suse.com/show_bug.cgi?id=1275150 * https://bugzilla.suse.com/show_bug.cgi?id=1275152 * https://bugzilla.suse.com/show_bug.cgi?id=1275154 * https://bugzilla.suse.com/show_bug.cgi?id=1275155 * https://bugzilla.suse.com/show_bug.cgi?id=1275156 * https://bugzilla.suse.com/show_bug.cgi?id=1275157 * https://bugzilla.suse.com/show_bug.cgi?id=1275158 * https://bugzilla.suse.com/show_bug.cgi?id=1275161 * https://bugzilla.suse.com/show_bug.cgi?id=1275163 * https://bugzilla.suse.com/show_bug.cgi?id=1275164 * https://bugzilla.suse.com/show_bug.cgi?id=1275169 * https://bugzilla.suse.com/show_bug.cgi?id=1275173 * https://bugzilla.suse.com/show_bug.cgi?id=1275176 * https://bugzilla.suse.com/show_bug.cgi?id=1275185 * https://bugzilla.suse.com/show_bug.cgi?id=1275190 * https://bugzilla.suse.com/show_bug.cgi?id=1275192 * https://bugzilla.suse.com/show_bug.cgi?id=1275236 * https://bugzilla.suse.com/show_bug.cgi?id=1275237 * https://bugzilla.suse.com/show_bug.cgi?id=1275239 * https://bugzilla.suse.com/show_bug.cgi?id=1275294 * https://bugzilla.suse.com/show_bug.cgi?id=1275300 * https://bugzilla.suse.com/show_bug.cgi?id=1275301 * https://bugzilla.suse.com/show_bug.cgi?id=1275303 * https://bugzilla.suse.com/show_bug.cgi?id=1275304 * https://bugzilla.suse.com/show_bug.cgi?id=1275305 * https://bugzilla.suse.com/show_bug.cgi?id=1275306 * https://bugzilla.suse.com/show_bug.cgi?id=1275307 * https://bugzilla.suse.com/show_bug.cgi?id=1275470 * https://bugzilla.suse.com/show_bug.cgi?id=1275472 * https://bugzilla.suse.com/show_bug.cgi?id=1275474 * https://bugzilla.suse.com/show_bug.cgi?id=1275479 * https://bugzilla.suse.com/show_bug.cgi?id=1275483 * https://bugzilla.suse.com/show_bug.cgi?id=1275486 * https://bugzilla.suse.com/show_bug.cgi?id=1275487 * https://bugzilla.suse.com/show_bug.cgi?id=1275506 * https://bugzilla.suse.com/show_bug.cgi?id=1275509 * https://bugzilla.suse.com/show_bug.cgi?id=1275511 * https://bugzilla.suse.com/show_bug.cgi?id=1275517 * https://bugzilla.suse.com/show_bug.cgi?id=1275519 * https://bugzilla.suse.com/show_bug.cgi?id=1275528 * https://bugzilla.suse.com/show_bug.cgi?id=1275535 * https://bugzilla.suse.com/show_bug.cgi?id=1275540 * https://bugzilla.suse.com/show_bug.cgi?id=1275553 * https://bugzilla.suse.com/show_bug.cgi?id=1275555 * https://bugzilla.suse.com/show_bug.cgi?id=1275557 * https://bugzilla.suse.com/show_bug.cgi?id=1275561 * https://bugzilla.suse.com/show_bug.cgi?id=1275566 * https://bugzilla.suse.com/show_bug.cgi?id=1275569 * https://bugzilla.suse.com/show_bug.cgi?id=1275572 * https://bugzilla.suse.com/show_bug.cgi?id=1275574 * https://bugzilla.suse.com/show_bug.cgi?id=1275578 * https://bugzilla.suse.com/show_bug.cgi?id=1275582 * https://bugzilla.suse.com/show_bug.cgi?id=1275583 * https://bugzilla.suse.com/show_bug.cgi?id=1275584 * https://bugzilla.suse.com/show_bug.cgi?id=1275591 * https://bugzilla.suse.com/show_bug.cgi?id=1275595 * https://bugzilla.suse.com/show_bug.cgi?id=1275633 * https://bugzilla.suse.com/show_bug.cgi?id=1275636 * https://bugzilla.suse.com/show_bug.cgi?id=1275650 * https://bugzilla.suse.com/show_bug.cgi?id=1275656 * https://bugzilla.suse.com/show_bug.cgi?id=1275659 * https://bugzilla.suse.com/show_bug.cgi?id=1275665 * https://bugzilla.suse.com/show_bug.cgi?id=1275669 * https://bugzilla.suse.com/show_bug.cgi?id=1275687 * https://bugzilla.suse.com/show_bug.cgi?id=1275688 * https://bugzilla.suse.com/show_bug.cgi?id=1275695 * https://bugzilla.suse.com/show_bug.cgi?id=1275696 * https://bugzilla.suse.com/show_bug.cgi?id=1275704 * https://bugzilla.suse.com/show_bug.cgi?id=1275737 * https://bugzilla.suse.com/show_bug.cgi?id=1275782 * https://bugzilla.suse.com/show_bug.cgi?id=1275784 * https://bugzilla.suse.com/show_bug.cgi?id=1275787 * https://bugzilla.suse.com/show_bug.cgi?id=1275788 * https://bugzilla.suse.com/show_bug.cgi?id=1275789 * https://bugzilla.suse.com/show_bug.cgi?id=1275790 * https://bugzilla.suse.com/show_bug.cgi?id=1275797 * https://bugzilla.suse.com/show_bug.cgi?id=1275798 * https://bugzilla.suse.com/show_bug.cgi?id=1275805 * https://bugzilla.suse.com/show_bug.cgi?id=1275817 * https://bugzilla.suse.com/show_bug.cgi?id=1275818 * https://bugzilla.suse.com/show_bug.cgi?id=1275819 * https://bugzilla.suse.com/show_bug.cgi?id=1275820 * https://bugzilla.suse.com/show_bug.cgi?id=1275821 * https://bugzilla.suse.com/show_bug.cgi?id=1275822 * https://bugzilla.suse.com/show_bug.cgi?id=1275823 * https://bugzilla.suse.com/show_bug.cgi?id=1275827 * https://bugzilla.suse.com/show_bug.cgi?id=1275864 * https://bugzilla.suse.com/show_bug.cgi?id=1275867 * https://bugzilla.suse.com/show_bug.cgi?id=1275869 * https://bugzilla.suse.com/show_bug.cgi?id=1275870 * https://bugzilla.suse.com/show_bug.cgi?id=1275871 * https://bugzilla.suse.com/show_bug.cgi?id=1275872 * https://bugzilla.suse.com/show_bug.cgi?id=1275886 * https://bugzilla.suse.com/show_bug.cgi?id=1275905 * https://bugzilla.suse.com/show_bug.cgi?id=1275923 * https://bugzilla.suse.com/show_bug.cgi?id=1275925 * https://bugzilla.suse.com/show_bug.cgi?id=1275928 * https://bugzilla.suse.com/show_bug.cgi?id=1275946 * https://bugzilla.suse.com/show_bug.cgi?id=1275950 * https://bugzilla.suse.com/show_bug.cgi?id=1275954 * https://bugzilla.suse.com/show_bug.cgi?id=1275970 * https://bugzilla.suse.com/show_bug.cgi?id=1275973 * https://bugzilla.suse.com/show_bug.cgi?id=1275975 * https://bugzilla.suse.com/show_bug.cgi?id=1275976 * https://bugzilla.suse.com/show_bug.cgi?id=1276029 * https://bugzilla.suse.com/show_bug.cgi?id=1276257 * https://bugzilla.suse.com/show_bug.cgi?id=1276263 * https://bugzilla.suse.com/show_bug.cgi?id=1276270 * https://bugzilla.suse.com/show_bug.cgi?id=1276273 * https://bugzilla.suse.com/show_bug.cgi?id=1276277 * https://bugzilla.suse.com/show_bug.cgi?id=1276335 * https://bugzilla.suse.com/show_bug.cgi?id=1276346 * https://bugzilla.suse.com/show_bug.cgi?id=1276350 * https://bugzilla.suse.com/show_bug.cgi?id=1276355 * https://bugzilla.suse.com/show_bug.cgi?id=1276446 * https://bugzilla.suse.com/show_bug.cgi?id=1276452 * https://bugzilla.suse.com/show_bug.cgi?id=1276500 * https://bugzilla.suse.com/show_bug.cgi?id=1276507 * https://bugzilla.suse.com/show_bug.cgi?id=1276542 * https://bugzilla.suse.com/show_bug.cgi?id=1276546 * https://bugzilla.suse.com/show_bug.cgi?id=1276551 * https://bugzilla.suse.com/show_bug.cgi?id=1276552 * https://bugzilla.suse.com/show_bug.cgi?id=1276561 * https://bugzilla.suse.com/show_bug.cgi?id=1276569 * https://bugzilla.suse.com/show_bug.cgi?id=1276577 * https://bugzilla.suse.com/show_bug.cgi?id=1276665 * https://bugzilla.suse.com/show_bug.cgi?id=1276864 * https://bugzilla.suse.com/show_bug.cgi?id=1276912 * https://bugzilla.suse.com/show_bug.cgi?id=1276913 * https://bugzilla.suse.com/show_bug.cgi?id=1276927 * https://bugzilla.suse.com/show_bug.cgi?id=1276931 * https://bugzilla.suse.com/show_bug.cgi?id=1276937 * https://bugzilla.suse.com/show_bug.cgi?id=1276941 * https://bugzilla.suse.com/show_bug.cgi?id=1276943 * https://bugzilla.suse.com/show_bug.cgi?id=1276944 * https://bugzilla.suse.com/show_bug.cgi?id=1276955 * https://bugzilla.suse.com/show_bug.cgi?id=1276961 * https://bugzilla.suse.com/show_bug.cgi?id=1277022 * https://bugzilla.suse.com/show_bug.cgi?id=1277034 * https://bugzilla.suse.com/show_bug.cgi?id=1277037 * https://bugzilla.suse.com/show_bug.cgi?id=1277047 * https://bugzilla.suse.com/show_bug.cgi?id=1277054 * https://bugzilla.suse.com/show_bug.cgi?id=1277057 * https://bugzilla.suse.com/show_bug.cgi?id=1277059 * https://bugzilla.suse.com/show_bug.cgi?id=1277064 * https://bugzilla.suse.com/show_bug.cgi?id=1277066 * https://bugzilla.suse.com/show_bug.cgi?id=1277069 * https://bugzilla.suse.com/show_bug.cgi?id=1277073 * https://bugzilla.suse.com/show_bug.cgi?id=1277077 * https://bugzilla.suse.com/show_bug.cgi?id=1277095 * https://bugzilla.suse.com/show_bug.cgi?id=1277155 * https://bugzilla.suse.com/show_bug.cgi?id=1277159 * https://bugzilla.suse.com/show_bug.cgi?id=1277160 * https://bugzilla.suse.com/show_bug.cgi?id=1277202 * https://bugzilla.suse.com/show_bug.cgi?id=1277204 * https://bugzilla.suse.com/show_bug.cgi?id=1277275 * https://bugzilla.suse.com/show_bug.cgi?id=1277285 * https://bugzilla.suse.com/show_bug.cgi?id=1277391 * https://bugzilla.suse.com/show_bug.cgi?id=1277408 * https://bugzilla.suse.com/show_bug.cgi?id=1277516 * https://bugzilla.suse.com/show_bug.cgi?id=1277523 * https://bugzilla.suse.com/show_bug.cgi?id=1277551 * https://bugzilla.suse.com/show_bug.cgi?id=1277625 * https://bugzilla.suse.com/show_bug.cgi?id=1277660 * https://bugzilla.suse.com/show_bug.cgi?id=1277678 * https://bugzilla.suse.com/show_bug.cgi?id=1277688 * https://bugzilla.suse.com/show_bug.cgi?id=1277775 * https://bugzilla.suse.com/show_bug.cgi?id=1277776 * https://jira.suse.com/browse/PED-15880 * https://jira.suse.com/browse/PED-16798 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 16:48:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 16:48:32 -0000 Subject: SUSE-SU-2026:4123-1: moderate: Security update for opensc Message-ID: <178905891296.3779.10575903789087659592@a0307d149aa3> # Security update for opensc Announcement ID: SUSE-SU-2026:4123-1 Release Date: 2026-09-10T11:47:08Z Rating: moderate References: * bsc#1266964 Cross-References: * CVE-2026-40510 CVSS scores: * CVE-2026-40510 ( SUSE ): 4.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-40510 ( SUSE ): 5.7 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-40510 ( NVD ): 1.0 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40510 ( NVD ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-40510 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for opensc fixes the following issue: * CVE-2026-40510: stack buffer overflow in `piv_process_history()` allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device (bsc#1266964). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4123=1 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4123=1 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * opensc-0.22.0-150600.11.14.1 * opensc-debuginfo-0.22.0-150600.11.14.1 * opensc-debugsource-0.22.0-150600.11.14.1 * openSUSE Leap 15.6 (x86_64) * opensc-32bit-0.22.0-150600.11.14.1 * opensc-32bit-debuginfo-0.22.0-150600.11.14.1 * openSUSE Leap 15.6 (aarch64_ilp32) * opensc-64bit-0.22.0-150600.11.14.1 * opensc-64bit-debuginfo-0.22.0-150600.11.14.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * opensc-0.22.0-150600.11.14.1 * opensc-debuginfo-0.22.0-150600.11.14.1 * opensc-debugsource-0.22.0-150600.11.14.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40510.html * https://bugzilla.suse.com/show_bug.cgi?id=1266964 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 16:49:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 16:49:28 -0000 Subject: SUSE-SU-2026:4122-1: moderate: Security update for opensc Message-ID: <178905896804.3779.12105993715728165006@a0307d149aa3> # Security update for opensc Announcement ID: SUSE-SU-2026:4122-1 Release Date: 2026-09-10T11:46:37Z Rating: moderate References: * bsc#1266964 Cross-References: * CVE-2026-40510 CVSS scores: * CVE-2026-40510 ( SUSE ): 4.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-40510 ( SUSE ): 5.7 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-40510 ( NVD ): 1.0 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40510 ( NVD ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-40510 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves one vulnerability can now be installed. ## Description: This update for opensc fixes the following issue: * CVE-2026-40510: stack buffer overflow in `piv_process_history()` allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device (bsc#1266964). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4122=1 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4122=1 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4122=1 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4122=1 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4122=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4122=1 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * opensc-debugsource-0.22.0-150400.3.20.1 * opensc-debuginfo-0.22.0-150400.3.20.1 * opensc-0.22.0-150400.3.20.1 * openSUSE Leap 15.4 (x86_64) * opensc-32bit-0.22.0-150400.3.20.1 * opensc-32bit-debuginfo-0.22.0-150400.3.20.1 * openSUSE Leap 15.4 (aarch64_ilp32) * opensc-64bit-0.22.0-150400.3.20.1 * opensc-64bit-debuginfo-0.22.0-150400.3.20.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * opensc-debugsource-0.22.0-150400.3.20.1 * opensc-debuginfo-0.22.0-150400.3.20.1 * opensc-0.22.0-150400.3.20.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * opensc-debugsource-0.22.0-150400.3.20.1 * opensc-debuginfo-0.22.0-150400.3.20.1 * opensc-0.22.0-150400.3.20.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * opensc-debugsource-0.22.0-150400.3.20.1 * opensc-debuginfo-0.22.0-150400.3.20.1 * opensc-0.22.0-150400.3.20.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * opensc-debugsource-0.22.0-150400.3.20.1 * opensc-debuginfo-0.22.0-150400.3.20.1 * opensc-0.22.0-150400.3.20.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * opensc-debugsource-0.22.0-150400.3.20.1 * opensc-debuginfo-0.22.0-150400.3.20.1 * opensc-0.22.0-150400.3.20.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40510.html * https://bugzilla.suse.com/show_bug.cgi?id=1266964 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 10 16:51:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 10 Sep 2026 16:51:07 -0000 Subject: SUSE-SU-2026:4119-1: important: Security update for tomcat10 Message-ID: <178905906702.3779.9948091400532084154@a0307d149aa3> # Security update for tomcat10 Announcement ID: SUSE-SU-2026:4119-1 Release Date: 2026-09-10T08:16:51Z Rating: important References: * bsc#1273150 * bsc#1276893 * bsc#1276894 * bsc#1276895 * bsc#1276896 * bsc#1276897 * bsc#1276898 * bsc#1276899 * bsc#1276900 * bsc#1276901 * bsc#1276902 Cross-References: * CVE-2026-65182 * CVE-2026-65183 * CVE-2026-65637 * CVE-2026-65905 * CVE-2026-65927 * CVE-2026-66299 * CVE-2026-66422 * CVE-2026-68525 * CVE-2026-68569 * CVE-2026-68763 * CVE-2026-73180 CVSS scores: * CVE-2026-65182 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65182 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-65182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-65183 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65183 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65637 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65637 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65637 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65905 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65905 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-65905 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65927 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65927 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-66299 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-66422 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-66422 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-66422 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-68525 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68525 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68525 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68569 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68569 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68569 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68763 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68763 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68763 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73180 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-73180 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-73180 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for tomcat10 fixes the following issues: * CVE-2026-65182: Apache Tomcat: Bypass longest prefix security constraint (bsc#1276893). * CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets (bsc#1276894). * CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - fix incomplete (bsc#1276895). * CVE-2026-65905: Apache Tomcat: Limited replay attack possible with DIGEST authentication (bsc#1276896). * CVE-2026-65927: Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control (bsc#1276897). * CVE-2026-66299: memory exhaustion via maliciously slow clients due to the WebSocket chat example providing an unbounded buffer for undelivered messages (bsc#1273150). * CVE-2026-66422: Apache Tomcat: Servlet role references can bypass declarative role constraints (bsc#1276898). * CVE-2026-68525: Apache Tomcat: Redirect after FORM auth may bypass method specific constraints (bsc#1276899). * CVE-2026-68569: Apache Tomcat: Principal lookup can fail open in some cases (bsc#1276900). * CVE-2026-68763: Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset (bsc#1276901). * CVE-2026-73180: Apache Tomcat: Authenticated WebSocket session survives end of HTTP session (bsc#1276902). Changes for tomcat10: * Updated to version 10.1.59 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4119=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4119=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4119=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4119=1 * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-4119=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4119=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4119=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * tomcat10-10.1.59-150200.5.79.1 * tomcat10-admin-webapps-10.1.59-150200.5.79.1 * tomcat10-jsp-3_1-api-10.1.59-150200.5.79.1 * tomcat10-lib-10.1.59-150200.5.79.1 * tomcat10-webapps-10.1.59-150200.5.79.1 * tomcat10-el-5_0-api-10.1.59-150200.5.79.1 * tomcat10-servlet-6_0-api-10.1.59-150200.5.79.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * tomcat10-10.1.59-150200.5.79.1 * tomcat10-admin-webapps-10.1.59-150200.5.79.1 * tomcat10-jsp-3_1-api-10.1.59-150200.5.79.1 * tomcat10-lib-10.1.59-150200.5.79.1 * tomcat10-webapps-10.1.59-150200.5.79.1 * tomcat10-el-5_0-api-10.1.59-150200.5.79.1 * tomcat10-servlet-6_0-api-10.1.59-150200.5.79.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * tomcat10-10.1.59-150200.5.79.1 * tomcat10-admin-webapps-10.1.59-150200.5.79.1 * tomcat10-jsp-3_1-api-10.1.59-150200.5.79.1 * tomcat10-lib-10.1.59-150200.5.79.1 * tomcat10-webapps-10.1.59-150200.5.79.1 * tomcat10-el-5_0-api-10.1.59-150200.5.79.1 * tomcat10-servlet-6_0-api-10.1.59-150200.5.79.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * tomcat10-10.1.59-150200.5.79.1 * tomcat10-admin-webapps-10.1.59-150200.5.79.1 * tomcat10-jsp-3_1-api-10.1.59-150200.5.79.1 * tomcat10-lib-10.1.59-150200.5.79.1 * tomcat10-webapps-10.1.59-150200.5.79.1 * tomcat10-el-5_0-api-10.1.59-150200.5.79.1 * tomcat10-servlet-6_0-api-10.1.59-150200.5.79.1 * Web and Scripting Module 15-SP7 (noarch) * tomcat10-10.1.59-150200.5.79.1 * tomcat10-admin-webapps-10.1.59-150200.5.79.1 * tomcat10-jsp-3_1-api-10.1.59-150200.5.79.1 * tomcat10-lib-10.1.59-150200.5.79.1 * tomcat10-webapps-10.1.59-150200.5.79.1 * tomcat10-el-5_0-api-10.1.59-150200.5.79.1 * tomcat10-servlet-6_0-api-10.1.59-150200.5.79.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * tomcat10-10.1.59-150200.5.79.1 * tomcat10-admin-webapps-10.1.59-150200.5.79.1 * tomcat10-jsp-3_1-api-10.1.59-150200.5.79.1 * tomcat10-lib-10.1.59-150200.5.79.1 * tomcat10-webapps-10.1.59-150200.5.79.1 * tomcat10-el-5_0-api-10.1.59-150200.5.79.1 * tomcat10-servlet-6_0-api-10.1.59-150200.5.79.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * tomcat10-10.1.59-150200.5.79.1 * tomcat10-admin-webapps-10.1.59-150200.5.79.1 * tomcat10-jsp-3_1-api-10.1.59-150200.5.79.1 * tomcat10-lib-10.1.59-150200.5.79.1 * tomcat10-webapps-10.1.59-150200.5.79.1 * tomcat10-el-5_0-api-10.1.59-150200.5.79.1 * tomcat10-servlet-6_0-api-10.1.59-150200.5.79.1 ## References: * https://www.suse.com/security/cve/CVE-2026-65182.html * https://www.suse.com/security/cve/CVE-2026-65183.html * https://www.suse.com/security/cve/CVE-2026-65637.html * https://www.suse.com/security/cve/CVE-2026-65905.html * https://www.suse.com/security/cve/CVE-2026-65927.html * https://www.suse.com/security/cve/CVE-2026-66299.html * https://www.suse.com/security/cve/CVE-2026-66422.html * https://www.suse.com/security/cve/CVE-2026-68525.html * https://www.suse.com/security/cve/CVE-2026-68569.html * https://www.suse.com/security/cve/CVE-2026-68763.html * https://www.suse.com/security/cve/CVE-2026-73180.html * https://bugzilla.suse.com/show_bug.cgi?id=1273150 * https://bugzilla.suse.com/show_bug.cgi?id=1276893 * https://bugzilla.suse.com/show_bug.cgi?id=1276894 * https://bugzilla.suse.com/show_bug.cgi?id=1276895 * https://bugzilla.suse.com/show_bug.cgi?id=1276896 * https://bugzilla.suse.com/show_bug.cgi?id=1276897 * https://bugzilla.suse.com/show_bug.cgi?id=1276898 * https://bugzilla.suse.com/show_bug.cgi?id=1276899 * https://bugzilla.suse.com/show_bug.cgi?id=1276900 * https://bugzilla.suse.com/show_bug.cgi?id=1276901 * https://bugzilla.suse.com/show_bug.cgi?id=1276902 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 12:30:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 12:30:56 -0000 Subject: SUSE-SU-2026:4129-1: critical: Security update for libzypp, zypper Message-ID: <178912985606.1292.1240310960761346781@07c0de5f7757> # Security update for libzypp, zypper Announcement ID: SUSE-SU-2026:4129-1 Release Date: 2026-09-11T06:52:57Z Rating: critical References: * bsc#1257249 * bsc#1261038 * bsc#1268321 * bsc#1271730 * bsc#1272534 * bsc#1273242 * bsc#1274091 * bsc#1274625 * bsc#1277790 Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise Desktop 15 SP5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that has nine security fixes can now be installed. ## Description: This update for libzypp, zypper fixes the following issues: Security issue fixed: * invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY- CACHE-01] (bsc#1274625). * hasCredentials() requires both username AND password to be non-empty (bsc#1273242). * GPG Key hints in repoindex.xml require at least a long id to allow auto- import (bsc#1271730). Non security issues fixed: * Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). * libzypp: X-ZYpp-AnonymousId header anomaly (bsc#1268321). * Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). * zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). * Zypper patch doesn't give enough details about conflicts (bsc#1277790). * dependency issue for package "python3-vsts-cd-manager" after starting the upgrade (bsc#1261038). Changes for libzypp: * Update to version 17.38.15: * Prevent libgpgme from launching gpg-agents; we don't need them. * defaultLoadSystem: Hand out the ZYpp::Ptr as return value. * Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) * zypp: Improve Testcase Loading for MCP Tools. * spec: Remove useless %bcond visibility_hidden (is always ON in cmake) * zypp.conf: add solver.NoUpdateProvide (default: false) option. Changes for zypper: * Update to version 1.14.101. ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Performance Computing 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-4129=1 * SUSE Linux Enterprise Desktop 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-4129=1 * SUSE Linux Enterprise Server 15 SP5 zypper in -t patch SUSE-SLE-INSTALLER-15-SP5-2026-4129=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4129=1 SUSE-SLE- INSTALLER-15-SP5-2026-4129=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4129=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4129=1 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-4129=1 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4129=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4129=1 ## Package List: * SUSE Linux Enterprise High Performance Computing 15 SP5 (aarch64 x86_64) * libzypp-17.38.15-150500.6.77.1 * SUSE Linux Enterprise Desktop 15 SP5 (x86_64) * libzypp-17.38.15-150500.6.77.1 * SUSE Linux Enterprise Server 15 SP5 (aarch64 ppc64le s390x x86_64) * libzypp-17.38.15-150500.6.77.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * zypper-debugsource-1.14.101-150500.6.48.1 * libzypp-17.38.15-150500.6.77.1 * libzypp-debugsource-17.38.15-150500.6.77.1 * zypper-1.14.101-150500.6.48.1 * libzypp-debuginfo-17.38.15-150500.6.77.1 * libzypp-devel-17.38.15-150500.6.77.1 * zypper-debuginfo-1.14.101-150500.6.48.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * zypper-log-1.14.101-150500.6.48.1 * zypper-needs-restarting-1.14.101-150500.6.48.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * zypper-debugsource-1.14.101-150500.6.48.1 * libzypp-17.38.15-150500.6.77.1 * libzypp-debugsource-17.38.15-150500.6.77.1 * zypper-1.14.101-150500.6.48.1 * libzypp-debuginfo-17.38.15-150500.6.77.1 * libzypp-devel-17.38.15-150500.6.77.1 * zypper-debuginfo-1.14.101-150500.6.48.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * zypper-log-1.14.101-150500.6.48.1 * zypper-needs-restarting-1.14.101-150500.6.48.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * zypper-debugsource-1.14.101-150500.6.48.1 * libzypp-17.38.15-150500.6.77.1 * libzypp-debugsource-17.38.15-150500.6.77.1 * zypper-1.14.101-150500.6.48.1 * libzypp-debuginfo-17.38.15-150500.6.77.1 * libzypp-devel-17.38.15-150500.6.77.1 * zypper-debuginfo-1.14.101-150500.6.48.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * zypper-log-1.14.101-150500.6.48.1 * zypper-needs-restarting-1.14.101-150500.6.48.1 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * zypper-debugsource-1.14.101-150500.6.48.1 * libzypp-17.38.15-150500.6.77.1 * libzypp-devel-doc-17.38.15-150500.6.77.1 * libzypp-debugsource-17.38.15-150500.6.77.1 * zypper-1.14.101-150500.6.48.1 * libzypp-debuginfo-17.38.15-150500.6.77.1 * libzypp-devel-17.38.15-150500.6.77.1 * zypper-debuginfo-1.14.101-150500.6.48.1 * openSUSE Leap 15.5 (noarch) * zypper-log-1.14.101-150500.6.48.1 * zypper-needs-restarting-1.14.101-150500.6.48.1 * zypper-aptitude-1.14.101-150500.6.48.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * zypper-debugsource-1.14.101-150500.6.48.1 * libzypp-17.38.15-150500.6.77.1 * libzypp-debugsource-17.38.15-150500.6.77.1 * zypper-1.14.101-150500.6.48.1 * libzypp-debuginfo-17.38.15-150500.6.77.1 * zypper-debuginfo-1.14.101-150500.6.48.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * zypper-needs-restarting-1.14.101-150500.6.48.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * zypper-debugsource-1.14.101-150500.6.48.1 * libzypp-17.38.15-150500.6.77.1 * libzypp-debugsource-17.38.15-150500.6.77.1 * zypper-1.14.101-150500.6.48.1 * libzypp-debuginfo-17.38.15-150500.6.77.1 * libzypp-devel-17.38.15-150500.6.77.1 * zypper-debuginfo-1.14.101-150500.6.48.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * zypper-log-1.14.101-150500.6.48.1 * zypper-needs-restarting-1.14.101-150500.6.48.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1257249 * https://bugzilla.suse.com/show_bug.cgi?id=1261038 * https://bugzilla.suse.com/show_bug.cgi?id=1268321 * https://bugzilla.suse.com/show_bug.cgi?id=1271730 * https://bugzilla.suse.com/show_bug.cgi?id=1272534 * https://bugzilla.suse.com/show_bug.cgi?id=1273242 * https://bugzilla.suse.com/show_bug.cgi?id=1274091 * https://bugzilla.suse.com/show_bug.cgi?id=1274625 * https://bugzilla.suse.com/show_bug.cgi?id=1277790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 12:32:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 12:32:01 -0000 Subject: SUSE-SU-2026:4128-1: moderate: Security update for php7 Message-ID: <178912992120.1292.1043499738213283540@07c0de5f7757> # Security update for php7 Announcement ID: SUSE-SU-2026:4128-1 Release Date: 2026-09-11T06:51:27Z Rating: moderate References: * bsc#1205782 * bsc#1273077 * bsc#1276531 Cross-References: * CVE-2026-7260 CVSS scores: * CVE-2026-7260 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-7260 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7260 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Legacy Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability and has two security fixes can now be installed. ## Description: This update for php7 fixes the following issue: * CVE-2026-7260: Stack overflow in phar with circular symlinks (bsc#1273077). Other changes: * Allow removal of apache2-mod_php7 even if the php7 module is not enabled (bsc#1205782, bsc#1276531). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4128=1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4128=1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4128=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4128=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4128=1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4128=1 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4128=1 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-4128=1 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4128=1 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4128=1 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4128=1 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * php7-soap-7.4.33-150400.4.73.1 * php7-pcntl-7.4.33-150400.4.73.1 * php7-pdo-7.4.33-150400.4.73.1 * php7-7.4.33-150400.4.73.1 * php7-odbc-debuginfo-7.4.33-150400.4.73.1 * php7-dom-7.4.33-150400.4.73.1 * php7-intl-7.4.33-150400.4.73.1 * php7-cli-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-7.4.33-150400.4.73.1 * php7-bz2-debuginfo-7.4.33-150400.4.73.1 * php7-soap-debuginfo-7.4.33-150400.4.73.1 * php7-mysql-7.4.33-150400.4.73.1 * php7-sockets-7.4.33-150400.4.73.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-7.4.33-150400.4.73.1 * php7-snmp-debuginfo-7.4.33-150400.4.73.1 * php7-json-7.4.33-150400.4.73.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.73.1 * php7-dba-7.4.33-150400.4.73.1 * php7-calendar-7.4.33-150400.4.73.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.73.1 * php7-fastcgi-debugsource-7.4.33-150400.4.73.1 * php7-ftp-debuginfo-7.4.33-150400.4.73.1 * php7-sysvmsg-7.4.33-150400.4.73.1 * php7-pgsql-debuginfo-7.4.33-150400.4.73.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.73.1 * php7-zlib-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-7.4.33-150400.4.73.1 * php7-xsl-7.4.33-150400.4.73.1 * php7-debuginfo-7.4.33-150400.4.73.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.73.1 * php7-sysvsem-7.4.33-150400.4.73.1 * php7-mysql-debuginfo-7.4.33-150400.4.73.1 * php7-odbc-7.4.33-150400.4.73.1 * php7-xmlwriter-7.4.33-150400.4.73.1 * php7-readline-debuginfo-7.4.33-150400.4.73.1 * php7-gmp-7.4.33-150400.4.73.1 * php7-xsl-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-debuginfo-7.4.33-150400.4.73.1 * php7-bz2-7.4.33-150400.4.73.1 * php7-iconv-7.4.33-150400.4.73.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.73.1 * php7-devel-7.4.33-150400.4.73.1 * php7-zlib-7.4.33-150400.4.73.1 * php7-exif-debuginfo-7.4.33-150400.4.73.1 * php7-intl-debuginfo-7.4.33-150400.4.73.1 * php7-calendar-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-debuginfo-7.4.33-150400.4.73.1 * php7-enchant-7.4.33-150400.4.73.1 * php7-iconv-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-debuginfo-7.4.33-150400.4.73.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.73.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debugsource-7.4.33-150400.4.73.1 * php7-fileinfo-7.4.33-150400.4.73.1 * php7-phar-7.4.33-150400.4.73.1 * php7-json-debuginfo-7.4.33-150400.4.73.1 * php7-ftp-7.4.33-150400.4.73.1 * php7-gmp-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-7.4.33-150400.4.73.1 * php7-exif-7.4.33-150400.4.73.1 * php7-sysvshm-7.4.33-150400.4.73.1 * php7-curl-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-7.4.33-150400.4.73.1 * php7-sodium-7.4.33-150400.4.73.1 * php7-snmp-7.4.33-150400.4.73.1 * php7-zip-debuginfo-7.4.33-150400.4.73.1 * php7-openssl-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-7.4.33-150400.4.73.1 * php7-dom-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.73.1 * php7-zip-7.4.33-150400.4.73.1 * php7-enchant-debuginfo-7.4.33-150400.4.73.1 * php7-phar-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debuginfo-7.4.33-150400.4.73.1 * php7-pcntl-debuginfo-7.4.33-150400.4.73.1 * php7-posix-7.4.33-150400.4.73.1 * php7-pdo-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-debuginfo-7.4.33-150400.4.73.1 * php7-debugsource-7.4.33-150400.4.73.1 * php7-pgsql-7.4.33-150400.4.73.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-7.4.33-150400.4.73.1 * php7-openssl-7.4.33-150400.4.73.1 * apache2-mod_php7-7.4.33-150400.4.73.1 * php7-xmlrpc-7.4.33-150400.4.73.1 * php7-sqlite-7.4.33-150400.4.73.1 * php7-bcmath-7.4.33-150400.4.73.1 * php7-tokenizer-7.4.33-150400.4.73.1 * php7-bcmath-debuginfo-7.4.33-150400.4.73.1 * php7-gd-7.4.33-150400.4.73.1 * php7-readline-7.4.33-150400.4.73.1 * php7-cli-7.4.33-150400.4.73.1 * php7-gd-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-7.4.33-150400.4.73.1 * php7-tidy-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-debuginfo-7.4.33-150400.4.73.1 * php7-tidy-7.4.33-150400.4.73.1 * php7-posix-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-debuginfo-7.4.33-150400.4.73.1 * php7-dba-debuginfo-7.4.33-150400.4.73.1 * php7-sockets-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-7.4.33-150400.4.73.1 * php7-sqlite-debuginfo-7.4.33-150400.4.73.1 * php7-curl-7.4.33-150400.4.73.1 * php7-sodium-debuginfo-7.4.33-150400.4.73.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * php7-soap-7.4.33-150400.4.73.1 * php7-pcntl-7.4.33-150400.4.73.1 * php7-pdo-7.4.33-150400.4.73.1 * php7-7.4.33-150400.4.73.1 * php7-odbc-debuginfo-7.4.33-150400.4.73.1 * php7-dom-7.4.33-150400.4.73.1 * php7-intl-7.4.33-150400.4.73.1 * php7-cli-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-7.4.33-150400.4.73.1 * php7-bz2-debuginfo-7.4.33-150400.4.73.1 * php7-soap-debuginfo-7.4.33-150400.4.73.1 * php7-mysql-7.4.33-150400.4.73.1 * php7-sockets-7.4.33-150400.4.73.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-7.4.33-150400.4.73.1 * php7-snmp-debuginfo-7.4.33-150400.4.73.1 * php7-json-7.4.33-150400.4.73.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.73.1 * php7-dba-7.4.33-150400.4.73.1 * php7-calendar-7.4.33-150400.4.73.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.73.1 * php7-fastcgi-debugsource-7.4.33-150400.4.73.1 * php7-ftp-debuginfo-7.4.33-150400.4.73.1 * php7-sysvmsg-7.4.33-150400.4.73.1 * php7-pgsql-debuginfo-7.4.33-150400.4.73.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.73.1 * php7-zlib-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-7.4.33-150400.4.73.1 * php7-xsl-7.4.33-150400.4.73.1 * php7-debuginfo-7.4.33-150400.4.73.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.73.1 * php7-sysvsem-7.4.33-150400.4.73.1 * php7-mysql-debuginfo-7.4.33-150400.4.73.1 * php7-odbc-7.4.33-150400.4.73.1 * php7-xmlwriter-7.4.33-150400.4.73.1 * php7-readline-debuginfo-7.4.33-150400.4.73.1 * php7-gmp-7.4.33-150400.4.73.1 * php7-xsl-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-debuginfo-7.4.33-150400.4.73.1 * php7-bz2-7.4.33-150400.4.73.1 * php7-iconv-7.4.33-150400.4.73.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.73.1 * php7-devel-7.4.33-150400.4.73.1 * php7-zlib-7.4.33-150400.4.73.1 * php7-exif-debuginfo-7.4.33-150400.4.73.1 * php7-intl-debuginfo-7.4.33-150400.4.73.1 * php7-calendar-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-debuginfo-7.4.33-150400.4.73.1 * php7-enchant-7.4.33-150400.4.73.1 * php7-iconv-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-debuginfo-7.4.33-150400.4.73.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.73.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debugsource-7.4.33-150400.4.73.1 * php7-fileinfo-7.4.33-150400.4.73.1 * php7-phar-7.4.33-150400.4.73.1 * php7-json-debuginfo-7.4.33-150400.4.73.1 * php7-ftp-7.4.33-150400.4.73.1 * php7-gmp-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-7.4.33-150400.4.73.1 * php7-exif-7.4.33-150400.4.73.1 * php7-sysvshm-7.4.33-150400.4.73.1 * php7-curl-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-7.4.33-150400.4.73.1 * php7-sodium-7.4.33-150400.4.73.1 * php7-snmp-7.4.33-150400.4.73.1 * php7-zip-debuginfo-7.4.33-150400.4.73.1 * php7-openssl-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-7.4.33-150400.4.73.1 * php7-dom-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.73.1 * php7-zip-7.4.33-150400.4.73.1 * php7-enchant-debuginfo-7.4.33-150400.4.73.1 * php7-phar-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debuginfo-7.4.33-150400.4.73.1 * php7-pcntl-debuginfo-7.4.33-150400.4.73.1 * php7-posix-7.4.33-150400.4.73.1 * php7-pdo-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-debuginfo-7.4.33-150400.4.73.1 * php7-debugsource-7.4.33-150400.4.73.1 * php7-pgsql-7.4.33-150400.4.73.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-7.4.33-150400.4.73.1 * php7-openssl-7.4.33-150400.4.73.1 * apache2-mod_php7-7.4.33-150400.4.73.1 * php7-xmlrpc-7.4.33-150400.4.73.1 * php7-sqlite-7.4.33-150400.4.73.1 * php7-bcmath-7.4.33-150400.4.73.1 * php7-tokenizer-7.4.33-150400.4.73.1 * php7-bcmath-debuginfo-7.4.33-150400.4.73.1 * php7-gd-7.4.33-150400.4.73.1 * php7-readline-7.4.33-150400.4.73.1 * php7-cli-7.4.33-150400.4.73.1 * php7-gd-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-7.4.33-150400.4.73.1 * php7-tidy-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-debuginfo-7.4.33-150400.4.73.1 * php7-tidy-7.4.33-150400.4.73.1 * php7-posix-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-debuginfo-7.4.33-150400.4.73.1 * php7-dba-debuginfo-7.4.33-150400.4.73.1 * php7-sockets-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-7.4.33-150400.4.73.1 * php7-sqlite-debuginfo-7.4.33-150400.4.73.1 * php7-curl-7.4.33-150400.4.73.1 * php7-sodium-debuginfo-7.4.33-150400.4.73.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * php7-soap-7.4.33-150400.4.73.1 * php7-pcntl-7.4.33-150400.4.73.1 * php7-pdo-7.4.33-150400.4.73.1 * php7-7.4.33-150400.4.73.1 * php7-odbc-debuginfo-7.4.33-150400.4.73.1 * php7-dom-7.4.33-150400.4.73.1 * php7-intl-7.4.33-150400.4.73.1 * php7-cli-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-7.4.33-150400.4.73.1 * php7-bz2-debuginfo-7.4.33-150400.4.73.1 * php7-soap-debuginfo-7.4.33-150400.4.73.1 * php7-mysql-7.4.33-150400.4.73.1 * php7-sockets-7.4.33-150400.4.73.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-7.4.33-150400.4.73.1 * php7-snmp-debuginfo-7.4.33-150400.4.73.1 * php7-json-7.4.33-150400.4.73.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.73.1 * php7-dba-7.4.33-150400.4.73.1 * php7-calendar-7.4.33-150400.4.73.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.73.1 * php7-fastcgi-debugsource-7.4.33-150400.4.73.1 * php7-ftp-debuginfo-7.4.33-150400.4.73.1 * php7-sysvmsg-7.4.33-150400.4.73.1 * php7-pgsql-debuginfo-7.4.33-150400.4.73.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.73.1 * php7-zlib-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-7.4.33-150400.4.73.1 * php7-xsl-7.4.33-150400.4.73.1 * php7-debuginfo-7.4.33-150400.4.73.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.73.1 * php7-sysvsem-7.4.33-150400.4.73.1 * php7-mysql-debuginfo-7.4.33-150400.4.73.1 * php7-odbc-7.4.33-150400.4.73.1 * php7-xmlwriter-7.4.33-150400.4.73.1 * php7-readline-debuginfo-7.4.33-150400.4.73.1 * php7-gmp-7.4.33-150400.4.73.1 * php7-xsl-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-debuginfo-7.4.33-150400.4.73.1 * php7-bz2-7.4.33-150400.4.73.1 * php7-iconv-7.4.33-150400.4.73.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.73.1 * php7-devel-7.4.33-150400.4.73.1 * php7-zlib-7.4.33-150400.4.73.1 * php7-exif-debuginfo-7.4.33-150400.4.73.1 * php7-intl-debuginfo-7.4.33-150400.4.73.1 * php7-calendar-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-debuginfo-7.4.33-150400.4.73.1 * php7-enchant-7.4.33-150400.4.73.1 * php7-iconv-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-debuginfo-7.4.33-150400.4.73.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.73.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debugsource-7.4.33-150400.4.73.1 * php7-fileinfo-7.4.33-150400.4.73.1 * php7-phar-7.4.33-150400.4.73.1 * php7-json-debuginfo-7.4.33-150400.4.73.1 * php7-ftp-7.4.33-150400.4.73.1 * php7-gmp-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-7.4.33-150400.4.73.1 * php7-exif-7.4.33-150400.4.73.1 * php7-sysvshm-7.4.33-150400.4.73.1 * php7-curl-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-7.4.33-150400.4.73.1 * php7-sodium-7.4.33-150400.4.73.1 * php7-snmp-7.4.33-150400.4.73.1 * php7-zip-debuginfo-7.4.33-150400.4.73.1 * php7-openssl-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-7.4.33-150400.4.73.1 * php7-dom-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.73.1 * php7-zip-7.4.33-150400.4.73.1 * php7-enchant-debuginfo-7.4.33-150400.4.73.1 * php7-phar-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debuginfo-7.4.33-150400.4.73.1 * php7-pcntl-debuginfo-7.4.33-150400.4.73.1 * php7-posix-7.4.33-150400.4.73.1 * php7-pdo-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-debuginfo-7.4.33-150400.4.73.1 * php7-debugsource-7.4.33-150400.4.73.1 * php7-pgsql-7.4.33-150400.4.73.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-7.4.33-150400.4.73.1 * php7-openssl-7.4.33-150400.4.73.1 * apache2-mod_php7-7.4.33-150400.4.73.1 * php7-xmlrpc-7.4.33-150400.4.73.1 * php7-sqlite-7.4.33-150400.4.73.1 * php7-bcmath-7.4.33-150400.4.73.1 * php7-tokenizer-7.4.33-150400.4.73.1 * php7-bcmath-debuginfo-7.4.33-150400.4.73.1 * php7-gd-7.4.33-150400.4.73.1 * php7-readline-7.4.33-150400.4.73.1 * php7-cli-7.4.33-150400.4.73.1 * php7-gd-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-7.4.33-150400.4.73.1 * php7-tidy-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-debuginfo-7.4.33-150400.4.73.1 * php7-tidy-7.4.33-150400.4.73.1 * php7-posix-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-debuginfo-7.4.33-150400.4.73.1 * php7-dba-debuginfo-7.4.33-150400.4.73.1 * php7-sockets-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-7.4.33-150400.4.73.1 * php7-sqlite-debuginfo-7.4.33-150400.4.73.1 * php7-curl-7.4.33-150400.4.73.1 * php7-sodium-debuginfo-7.4.33-150400.4.73.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * php7-soap-7.4.33-150400.4.73.1 * php7-pcntl-7.4.33-150400.4.73.1 * php7-test-7.4.33-150400.4.73.1 * php7-pdo-7.4.33-150400.4.73.1 * php7-7.4.33-150400.4.73.1 * php7-odbc-debuginfo-7.4.33-150400.4.73.1 * php7-dom-7.4.33-150400.4.73.1 * php7-intl-7.4.33-150400.4.73.1 * php7-cli-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-7.4.33-150400.4.73.1 * php7-bz2-debuginfo-7.4.33-150400.4.73.1 * php7-soap-debuginfo-7.4.33-150400.4.73.1 * php7-mysql-7.4.33-150400.4.73.1 * php7-sockets-7.4.33-150400.4.73.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.73.1 * php7-embed-debugsource-7.4.33-150400.4.73.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-7.4.33-150400.4.73.1 * php7-snmp-debuginfo-7.4.33-150400.4.73.1 * php7-json-7.4.33-150400.4.73.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.73.1 * php7-dba-7.4.33-150400.4.73.1 * php7-calendar-7.4.33-150400.4.73.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.73.1 * php7-fastcgi-debugsource-7.4.33-150400.4.73.1 * php7-ftp-debuginfo-7.4.33-150400.4.73.1 * php7-sysvmsg-7.4.33-150400.4.73.1 * php7-pgsql-debuginfo-7.4.33-150400.4.73.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.73.1 * php7-zlib-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-7.4.33-150400.4.73.1 * php7-xsl-7.4.33-150400.4.73.1 * php7-debuginfo-7.4.33-150400.4.73.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.73.1 * php7-sysvsem-7.4.33-150400.4.73.1 * php7-mysql-debuginfo-7.4.33-150400.4.73.1 * php7-odbc-7.4.33-150400.4.73.1 * php7-xmlwriter-7.4.33-150400.4.73.1 * php7-readline-debuginfo-7.4.33-150400.4.73.1 * php7-gmp-7.4.33-150400.4.73.1 * php7-xsl-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-debuginfo-7.4.33-150400.4.73.1 * php7-bz2-7.4.33-150400.4.73.1 * php7-iconv-7.4.33-150400.4.73.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.73.1 * php7-devel-7.4.33-150400.4.73.1 * php7-zlib-7.4.33-150400.4.73.1 * php7-exif-debuginfo-7.4.33-150400.4.73.1 * php7-intl-debuginfo-7.4.33-150400.4.73.1 * php7-calendar-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-debuginfo-7.4.33-150400.4.73.1 * php7-enchant-7.4.33-150400.4.73.1 * php7-iconv-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-debuginfo-7.4.33-150400.4.73.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.73.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debugsource-7.4.33-150400.4.73.1 * php7-fileinfo-7.4.33-150400.4.73.1 * php7-phar-7.4.33-150400.4.73.1 * php7-json-debuginfo-7.4.33-150400.4.73.1 * php7-ftp-7.4.33-150400.4.73.1 * php7-gmp-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-7.4.33-150400.4.73.1 * php7-exif-7.4.33-150400.4.73.1 * php7-sysvshm-7.4.33-150400.4.73.1 * php7-curl-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-7.4.33-150400.4.73.1 * php7-sodium-7.4.33-150400.4.73.1 * php7-snmp-7.4.33-150400.4.73.1 * php7-zip-debuginfo-7.4.33-150400.4.73.1 * php7-embed-7.4.33-150400.4.73.1 * php7-openssl-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-7.4.33-150400.4.73.1 * php7-dom-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.73.1 * php7-zip-7.4.33-150400.4.73.1 * php7-enchant-debuginfo-7.4.33-150400.4.73.1 * php7-phar-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debuginfo-7.4.33-150400.4.73.1 * php7-pcntl-debuginfo-7.4.33-150400.4.73.1 * php7-posix-7.4.33-150400.4.73.1 * php7-pdo-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-debuginfo-7.4.33-150400.4.73.1 * php7-debugsource-7.4.33-150400.4.73.1 * php7-pgsql-7.4.33-150400.4.73.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-7.4.33-150400.4.73.1 * php7-openssl-7.4.33-150400.4.73.1 * apache2-mod_php7-7.4.33-150400.4.73.1 * php7-xmlrpc-7.4.33-150400.4.73.1 * php7-sqlite-7.4.33-150400.4.73.1 * php7-bcmath-7.4.33-150400.4.73.1 * php7-tokenizer-7.4.33-150400.4.73.1 * php7-bcmath-debuginfo-7.4.33-150400.4.73.1 * php7-gd-7.4.33-150400.4.73.1 * php7-readline-7.4.33-150400.4.73.1 * php7-cli-7.4.33-150400.4.73.1 * php7-gd-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-7.4.33-150400.4.73.1 * php7-tidy-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-debuginfo-7.4.33-150400.4.73.1 * php7-tidy-7.4.33-150400.4.73.1 * php7-embed-debuginfo-7.4.33-150400.4.73.1 * php7-posix-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-debuginfo-7.4.33-150400.4.73.1 * php7-dba-debuginfo-7.4.33-150400.4.73.1 * php7-sockets-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-7.4.33-150400.4.73.1 * php7-sqlite-debuginfo-7.4.33-150400.4.73.1 * php7-curl-7.4.33-150400.4.73.1 * php7-sodium-debuginfo-7.4.33-150400.4.73.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * php7-soap-7.4.33-150400.4.73.1 * php7-pcntl-7.4.33-150400.4.73.1 * php7-pdo-7.4.33-150400.4.73.1 * php7-7.4.33-150400.4.73.1 * php7-odbc-debuginfo-7.4.33-150400.4.73.1 * php7-dom-7.4.33-150400.4.73.1 * php7-intl-7.4.33-150400.4.73.1 * php7-cli-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-7.4.33-150400.4.73.1 * php7-bz2-debuginfo-7.4.33-150400.4.73.1 * php7-soap-debuginfo-7.4.33-150400.4.73.1 * php7-mysql-7.4.33-150400.4.73.1 * php7-sockets-7.4.33-150400.4.73.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-7.4.33-150400.4.73.1 * php7-snmp-debuginfo-7.4.33-150400.4.73.1 * php7-json-7.4.33-150400.4.73.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.73.1 * php7-dba-7.4.33-150400.4.73.1 * php7-calendar-7.4.33-150400.4.73.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.73.1 * php7-fastcgi-debugsource-7.4.33-150400.4.73.1 * php7-ftp-debuginfo-7.4.33-150400.4.73.1 * php7-sysvmsg-7.4.33-150400.4.73.1 * php7-pgsql-debuginfo-7.4.33-150400.4.73.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.73.1 * php7-zlib-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-7.4.33-150400.4.73.1 * php7-xsl-7.4.33-150400.4.73.1 * php7-debuginfo-7.4.33-150400.4.73.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.73.1 * php7-sysvsem-7.4.33-150400.4.73.1 * php7-mysql-debuginfo-7.4.33-150400.4.73.1 * php7-odbc-7.4.33-150400.4.73.1 * php7-xmlwriter-7.4.33-150400.4.73.1 * php7-readline-debuginfo-7.4.33-150400.4.73.1 * php7-gmp-7.4.33-150400.4.73.1 * php7-xsl-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-debuginfo-7.4.33-150400.4.73.1 * php7-bz2-7.4.33-150400.4.73.1 * php7-iconv-7.4.33-150400.4.73.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.73.1 * php7-devel-7.4.33-150400.4.73.1 * php7-zlib-7.4.33-150400.4.73.1 * php7-exif-debuginfo-7.4.33-150400.4.73.1 * php7-intl-debuginfo-7.4.33-150400.4.73.1 * php7-calendar-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-debuginfo-7.4.33-150400.4.73.1 * php7-enchant-7.4.33-150400.4.73.1 * php7-iconv-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-debuginfo-7.4.33-150400.4.73.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.73.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debugsource-7.4.33-150400.4.73.1 * php7-fileinfo-7.4.33-150400.4.73.1 * php7-phar-7.4.33-150400.4.73.1 * php7-json-debuginfo-7.4.33-150400.4.73.1 * php7-ftp-7.4.33-150400.4.73.1 * php7-gmp-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-7.4.33-150400.4.73.1 * php7-exif-7.4.33-150400.4.73.1 * php7-sysvshm-7.4.33-150400.4.73.1 * php7-curl-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-7.4.33-150400.4.73.1 * php7-sodium-7.4.33-150400.4.73.1 * php7-snmp-7.4.33-150400.4.73.1 * php7-zip-debuginfo-7.4.33-150400.4.73.1 * php7-openssl-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-7.4.33-150400.4.73.1 * php7-dom-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.73.1 * php7-zip-7.4.33-150400.4.73.1 * php7-enchant-debuginfo-7.4.33-150400.4.73.1 * php7-phar-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debuginfo-7.4.33-150400.4.73.1 * php7-pcntl-debuginfo-7.4.33-150400.4.73.1 * php7-posix-7.4.33-150400.4.73.1 * php7-pdo-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-debuginfo-7.4.33-150400.4.73.1 * php7-debugsource-7.4.33-150400.4.73.1 * php7-pgsql-7.4.33-150400.4.73.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-7.4.33-150400.4.73.1 * php7-openssl-7.4.33-150400.4.73.1 * apache2-mod_php7-7.4.33-150400.4.73.1 * php7-xmlrpc-7.4.33-150400.4.73.1 * php7-sqlite-7.4.33-150400.4.73.1 * php7-bcmath-7.4.33-150400.4.73.1 * php7-tokenizer-7.4.33-150400.4.73.1 * php7-bcmath-debuginfo-7.4.33-150400.4.73.1 * php7-gd-7.4.33-150400.4.73.1 * php7-readline-7.4.33-150400.4.73.1 * php7-cli-7.4.33-150400.4.73.1 * php7-gd-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-7.4.33-150400.4.73.1 * php7-tidy-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-debuginfo-7.4.33-150400.4.73.1 * php7-tidy-7.4.33-150400.4.73.1 * php7-posix-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-debuginfo-7.4.33-150400.4.73.1 * php7-dba-debuginfo-7.4.33-150400.4.73.1 * php7-sockets-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-7.4.33-150400.4.73.1 * php7-sqlite-debuginfo-7.4.33-150400.4.73.1 * php7-curl-7.4.33-150400.4.73.1 * php7-sodium-debuginfo-7.4.33-150400.4.73.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * php7-soap-7.4.33-150400.4.73.1 * php7-pcntl-7.4.33-150400.4.73.1 * php7-pdo-7.4.33-150400.4.73.1 * php7-7.4.33-150400.4.73.1 * php7-odbc-debuginfo-7.4.33-150400.4.73.1 * php7-dom-7.4.33-150400.4.73.1 * php7-intl-7.4.33-150400.4.73.1 * php7-cli-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-7.4.33-150400.4.73.1 * php7-bz2-debuginfo-7.4.33-150400.4.73.1 * php7-soap-debuginfo-7.4.33-150400.4.73.1 * php7-mysql-7.4.33-150400.4.73.1 * php7-sockets-7.4.33-150400.4.73.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-7.4.33-150400.4.73.1 * php7-snmp-debuginfo-7.4.33-150400.4.73.1 * php7-json-7.4.33-150400.4.73.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.73.1 * php7-dba-7.4.33-150400.4.73.1 * php7-calendar-7.4.33-150400.4.73.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.73.1 * php7-fastcgi-debugsource-7.4.33-150400.4.73.1 * php7-ftp-debuginfo-7.4.33-150400.4.73.1 * php7-sysvmsg-7.4.33-150400.4.73.1 * php7-pgsql-debuginfo-7.4.33-150400.4.73.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.73.1 * php7-zlib-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-7.4.33-150400.4.73.1 * php7-xsl-7.4.33-150400.4.73.1 * php7-debuginfo-7.4.33-150400.4.73.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.73.1 * php7-sysvsem-7.4.33-150400.4.73.1 * php7-mysql-debuginfo-7.4.33-150400.4.73.1 * php7-odbc-7.4.33-150400.4.73.1 * php7-xmlwriter-7.4.33-150400.4.73.1 * php7-readline-debuginfo-7.4.33-150400.4.73.1 * php7-gmp-7.4.33-150400.4.73.1 * php7-xsl-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-debuginfo-7.4.33-150400.4.73.1 * php7-bz2-7.4.33-150400.4.73.1 * php7-iconv-7.4.33-150400.4.73.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.73.1 * php7-devel-7.4.33-150400.4.73.1 * php7-zlib-7.4.33-150400.4.73.1 * php7-exif-debuginfo-7.4.33-150400.4.73.1 * php7-intl-debuginfo-7.4.33-150400.4.73.1 * php7-calendar-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-debuginfo-7.4.33-150400.4.73.1 * php7-enchant-7.4.33-150400.4.73.1 * php7-iconv-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-debuginfo-7.4.33-150400.4.73.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.73.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debugsource-7.4.33-150400.4.73.1 * php7-fileinfo-7.4.33-150400.4.73.1 * php7-phar-7.4.33-150400.4.73.1 * php7-json-debuginfo-7.4.33-150400.4.73.1 * php7-ftp-7.4.33-150400.4.73.1 * php7-gmp-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-7.4.33-150400.4.73.1 * php7-exif-7.4.33-150400.4.73.1 * php7-sysvshm-7.4.33-150400.4.73.1 * php7-curl-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-7.4.33-150400.4.73.1 * php7-sodium-7.4.33-150400.4.73.1 * php7-snmp-7.4.33-150400.4.73.1 * php7-zip-debuginfo-7.4.33-150400.4.73.1 * php7-openssl-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-7.4.33-150400.4.73.1 * php7-dom-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.73.1 * php7-zip-7.4.33-150400.4.73.1 * php7-enchant-debuginfo-7.4.33-150400.4.73.1 * php7-phar-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debuginfo-7.4.33-150400.4.73.1 * php7-pcntl-debuginfo-7.4.33-150400.4.73.1 * php7-posix-7.4.33-150400.4.73.1 * php7-pdo-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-debuginfo-7.4.33-150400.4.73.1 * php7-debugsource-7.4.33-150400.4.73.1 * php7-pgsql-7.4.33-150400.4.73.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-7.4.33-150400.4.73.1 * php7-openssl-7.4.33-150400.4.73.1 * apache2-mod_php7-7.4.33-150400.4.73.1 * php7-xmlrpc-7.4.33-150400.4.73.1 * php7-sqlite-7.4.33-150400.4.73.1 * php7-bcmath-7.4.33-150400.4.73.1 * php7-tokenizer-7.4.33-150400.4.73.1 * php7-bcmath-debuginfo-7.4.33-150400.4.73.1 * php7-gd-7.4.33-150400.4.73.1 * php7-readline-7.4.33-150400.4.73.1 * php7-cli-7.4.33-150400.4.73.1 * php7-gd-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-7.4.33-150400.4.73.1 * php7-tidy-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-debuginfo-7.4.33-150400.4.73.1 * php7-tidy-7.4.33-150400.4.73.1 * php7-posix-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-debuginfo-7.4.33-150400.4.73.1 * php7-dba-debuginfo-7.4.33-150400.4.73.1 * php7-sockets-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-7.4.33-150400.4.73.1 * php7-sqlite-debuginfo-7.4.33-150400.4.73.1 * php7-curl-7.4.33-150400.4.73.1 * php7-sodium-debuginfo-7.4.33-150400.4.73.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * php7-soap-7.4.33-150400.4.73.1 * php7-pcntl-7.4.33-150400.4.73.1 * php7-pdo-7.4.33-150400.4.73.1 * php7-7.4.33-150400.4.73.1 * php7-odbc-debuginfo-7.4.33-150400.4.73.1 * php7-dom-7.4.33-150400.4.73.1 * php7-intl-7.4.33-150400.4.73.1 * php7-cli-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-7.4.33-150400.4.73.1 * php7-bz2-debuginfo-7.4.33-150400.4.73.1 * php7-soap-debuginfo-7.4.33-150400.4.73.1 * php7-mysql-7.4.33-150400.4.73.1 * php7-sockets-7.4.33-150400.4.73.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-7.4.33-150400.4.73.1 * php7-snmp-debuginfo-7.4.33-150400.4.73.1 * php7-json-7.4.33-150400.4.73.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.73.1 * php7-dba-7.4.33-150400.4.73.1 * php7-calendar-7.4.33-150400.4.73.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.73.1 * php7-fastcgi-debugsource-7.4.33-150400.4.73.1 * php7-ftp-debuginfo-7.4.33-150400.4.73.1 * php7-sysvmsg-7.4.33-150400.4.73.1 * php7-pgsql-debuginfo-7.4.33-150400.4.73.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.73.1 * php7-zlib-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-7.4.33-150400.4.73.1 * php7-xsl-7.4.33-150400.4.73.1 * php7-debuginfo-7.4.33-150400.4.73.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.73.1 * php7-sysvsem-7.4.33-150400.4.73.1 * php7-mysql-debuginfo-7.4.33-150400.4.73.1 * php7-odbc-7.4.33-150400.4.73.1 * php7-xmlwriter-7.4.33-150400.4.73.1 * php7-readline-debuginfo-7.4.33-150400.4.73.1 * php7-gmp-7.4.33-150400.4.73.1 * php7-xsl-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-debuginfo-7.4.33-150400.4.73.1 * php7-bz2-7.4.33-150400.4.73.1 * php7-iconv-7.4.33-150400.4.73.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.73.1 * php7-devel-7.4.33-150400.4.73.1 * php7-zlib-7.4.33-150400.4.73.1 * php7-exif-debuginfo-7.4.33-150400.4.73.1 * php7-intl-debuginfo-7.4.33-150400.4.73.1 * php7-calendar-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-debuginfo-7.4.33-150400.4.73.1 * php7-enchant-7.4.33-150400.4.73.1 * php7-iconv-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-debuginfo-7.4.33-150400.4.73.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.73.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debugsource-7.4.33-150400.4.73.1 * php7-fileinfo-7.4.33-150400.4.73.1 * php7-phar-7.4.33-150400.4.73.1 * php7-json-debuginfo-7.4.33-150400.4.73.1 * php7-ftp-7.4.33-150400.4.73.1 * php7-gmp-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-7.4.33-150400.4.73.1 * php7-exif-7.4.33-150400.4.73.1 * php7-sysvshm-7.4.33-150400.4.73.1 * php7-curl-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-7.4.33-150400.4.73.1 * php7-sodium-7.4.33-150400.4.73.1 * php7-snmp-7.4.33-150400.4.73.1 * php7-zip-debuginfo-7.4.33-150400.4.73.1 * php7-openssl-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-7.4.33-150400.4.73.1 * php7-dom-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.73.1 * php7-zip-7.4.33-150400.4.73.1 * php7-enchant-debuginfo-7.4.33-150400.4.73.1 * php7-phar-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debuginfo-7.4.33-150400.4.73.1 * php7-pcntl-debuginfo-7.4.33-150400.4.73.1 * php7-posix-7.4.33-150400.4.73.1 * php7-pdo-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-debuginfo-7.4.33-150400.4.73.1 * php7-debugsource-7.4.33-150400.4.73.1 * php7-pgsql-7.4.33-150400.4.73.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-7.4.33-150400.4.73.1 * php7-openssl-7.4.33-150400.4.73.1 * apache2-mod_php7-7.4.33-150400.4.73.1 * php7-xmlrpc-7.4.33-150400.4.73.1 * php7-sqlite-7.4.33-150400.4.73.1 * php7-bcmath-7.4.33-150400.4.73.1 * php7-tokenizer-7.4.33-150400.4.73.1 * php7-bcmath-debuginfo-7.4.33-150400.4.73.1 * php7-gd-7.4.33-150400.4.73.1 * php7-readline-7.4.33-150400.4.73.1 * php7-cli-7.4.33-150400.4.73.1 * php7-gd-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-7.4.33-150400.4.73.1 * php7-tidy-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-debuginfo-7.4.33-150400.4.73.1 * php7-tidy-7.4.33-150400.4.73.1 * php7-posix-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-debuginfo-7.4.33-150400.4.73.1 * php7-dba-debuginfo-7.4.33-150400.4.73.1 * php7-sockets-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-7.4.33-150400.4.73.1 * php7-sqlite-debuginfo-7.4.33-150400.4.73.1 * php7-curl-7.4.33-150400.4.73.1 * php7-sodium-debuginfo-7.4.33-150400.4.73.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * php7-debugsource-7.4.33-150400.4.73.1 * php7-debuginfo-7.4.33-150400.4.73.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.73.1 * apache2-mod_php7-7.4.33-150400.4.73.1 * php7-7.4.33-150400.4.73.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.73.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * php7-soap-7.4.33-150400.4.73.1 * php7-pcntl-7.4.33-150400.4.73.1 * php7-test-7.4.33-150400.4.73.1 * php7-pdo-7.4.33-150400.4.73.1 * php7-7.4.33-150400.4.73.1 * php7-odbc-debuginfo-7.4.33-150400.4.73.1 * php7-dom-7.4.33-150400.4.73.1 * php7-intl-7.4.33-150400.4.73.1 * php7-cli-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-7.4.33-150400.4.73.1 * php7-bz2-debuginfo-7.4.33-150400.4.73.1 * php7-soap-debuginfo-7.4.33-150400.4.73.1 * php7-mysql-7.4.33-150400.4.73.1 * php7-sockets-7.4.33-150400.4.73.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.73.1 * php7-embed-debugsource-7.4.33-150400.4.73.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-7.4.33-150400.4.73.1 * php7-snmp-debuginfo-7.4.33-150400.4.73.1 * php7-json-7.4.33-150400.4.73.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.73.1 * php7-dba-7.4.33-150400.4.73.1 * php7-calendar-7.4.33-150400.4.73.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.73.1 * php7-fastcgi-debugsource-7.4.33-150400.4.73.1 * php7-ftp-debuginfo-7.4.33-150400.4.73.1 * php7-sysvmsg-7.4.33-150400.4.73.1 * php7-pgsql-debuginfo-7.4.33-150400.4.73.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.73.1 * php7-zlib-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-7.4.33-150400.4.73.1 * php7-xsl-7.4.33-150400.4.73.1 * php7-debuginfo-7.4.33-150400.4.73.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.73.1 * php7-sysvsem-7.4.33-150400.4.73.1 * php7-mysql-debuginfo-7.4.33-150400.4.73.1 * php7-odbc-7.4.33-150400.4.73.1 * php7-xmlwriter-7.4.33-150400.4.73.1 * php7-readline-debuginfo-7.4.33-150400.4.73.1 * php7-gmp-7.4.33-150400.4.73.1 * php7-xsl-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-debuginfo-7.4.33-150400.4.73.1 * php7-bz2-7.4.33-150400.4.73.1 * php7-iconv-7.4.33-150400.4.73.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.73.1 * php7-zlib-7.4.33-150400.4.73.1 * php7-exif-debuginfo-7.4.33-150400.4.73.1 * php7-intl-debuginfo-7.4.33-150400.4.73.1 * php7-calendar-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-debuginfo-7.4.33-150400.4.73.1 * php7-enchant-7.4.33-150400.4.73.1 * php7-iconv-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-debuginfo-7.4.33-150400.4.73.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.73.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debugsource-7.4.33-150400.4.73.1 * php7-fileinfo-7.4.33-150400.4.73.1 * php7-phar-7.4.33-150400.4.73.1 * php7-json-debuginfo-7.4.33-150400.4.73.1 * php7-ftp-7.4.33-150400.4.73.1 * php7-gmp-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-7.4.33-150400.4.73.1 * php7-exif-7.4.33-150400.4.73.1 * php7-sysvshm-7.4.33-150400.4.73.1 * php7-curl-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-7.4.33-150400.4.73.1 * php7-sodium-7.4.33-150400.4.73.1 * php7-snmp-7.4.33-150400.4.73.1 * php7-zip-debuginfo-7.4.33-150400.4.73.1 * php7-embed-7.4.33-150400.4.73.1 * php7-openssl-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-7.4.33-150400.4.73.1 * php7-dom-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.73.1 * php7-zip-7.4.33-150400.4.73.1 * php7-enchant-debuginfo-7.4.33-150400.4.73.1 * php7-phar-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debuginfo-7.4.33-150400.4.73.1 * php7-pcntl-debuginfo-7.4.33-150400.4.73.1 * php7-posix-7.4.33-150400.4.73.1 * php7-pdo-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-debuginfo-7.4.33-150400.4.73.1 * php7-debugsource-7.4.33-150400.4.73.1 * php7-pgsql-7.4.33-150400.4.73.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-7.4.33-150400.4.73.1 * php7-openssl-7.4.33-150400.4.73.1 * apache2-mod_php7-7.4.33-150400.4.73.1 * php7-xmlrpc-7.4.33-150400.4.73.1 * php7-sqlite-7.4.33-150400.4.73.1 * php7-bcmath-7.4.33-150400.4.73.1 * php7-tokenizer-7.4.33-150400.4.73.1 * php7-bcmath-debuginfo-7.4.33-150400.4.73.1 * php7-gd-7.4.33-150400.4.73.1 * php7-readline-7.4.33-150400.4.73.1 * php7-cli-7.4.33-150400.4.73.1 * php7-gd-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-7.4.33-150400.4.73.1 * php7-tidy-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-debuginfo-7.4.33-150400.4.73.1 * php7-tidy-7.4.33-150400.4.73.1 * php7-embed-debuginfo-7.4.33-150400.4.73.1 * php7-posix-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-debuginfo-7.4.33-150400.4.73.1 * php7-dba-debuginfo-7.4.33-150400.4.73.1 * php7-sockets-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-7.4.33-150400.4.73.1 * php7-sqlite-debuginfo-7.4.33-150400.4.73.1 * php7-curl-7.4.33-150400.4.73.1 * php7-sodium-debuginfo-7.4.33-150400.4.73.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * php7-soap-7.4.33-150400.4.73.1 * php7-pcntl-7.4.33-150400.4.73.1 * php7-pdo-7.4.33-150400.4.73.1 * php7-7.4.33-150400.4.73.1 * php7-odbc-debuginfo-7.4.33-150400.4.73.1 * php7-dom-7.4.33-150400.4.73.1 * php7-intl-7.4.33-150400.4.73.1 * php7-cli-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-7.4.33-150400.4.73.1 * php7-bz2-debuginfo-7.4.33-150400.4.73.1 * php7-soap-debuginfo-7.4.33-150400.4.73.1 * php7-mysql-7.4.33-150400.4.73.1 * php7-sockets-7.4.33-150400.4.73.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-7.4.33-150400.4.73.1 * php7-snmp-debuginfo-7.4.33-150400.4.73.1 * php7-json-7.4.33-150400.4.73.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.73.1 * php7-dba-7.4.33-150400.4.73.1 * php7-calendar-7.4.33-150400.4.73.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.73.1 * php7-fastcgi-debugsource-7.4.33-150400.4.73.1 * php7-ftp-debuginfo-7.4.33-150400.4.73.1 * php7-sysvmsg-7.4.33-150400.4.73.1 * php7-pgsql-debuginfo-7.4.33-150400.4.73.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.73.1 * php7-zlib-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-7.4.33-150400.4.73.1 * php7-xsl-7.4.33-150400.4.73.1 * php7-debuginfo-7.4.33-150400.4.73.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.73.1 * php7-sysvsem-7.4.33-150400.4.73.1 * php7-mysql-debuginfo-7.4.33-150400.4.73.1 * php7-odbc-7.4.33-150400.4.73.1 * php7-xmlwriter-7.4.33-150400.4.73.1 * php7-readline-debuginfo-7.4.33-150400.4.73.1 * php7-gmp-7.4.33-150400.4.73.1 * php7-xsl-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-debuginfo-7.4.33-150400.4.73.1 * php7-bz2-7.4.33-150400.4.73.1 * php7-iconv-7.4.33-150400.4.73.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.73.1 * php7-devel-7.4.33-150400.4.73.1 * php7-zlib-7.4.33-150400.4.73.1 * php7-exif-debuginfo-7.4.33-150400.4.73.1 * php7-intl-debuginfo-7.4.33-150400.4.73.1 * php7-calendar-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-debuginfo-7.4.33-150400.4.73.1 * php7-enchant-7.4.33-150400.4.73.1 * php7-iconv-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-debuginfo-7.4.33-150400.4.73.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.73.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debugsource-7.4.33-150400.4.73.1 * php7-fileinfo-7.4.33-150400.4.73.1 * php7-phar-7.4.33-150400.4.73.1 * php7-json-debuginfo-7.4.33-150400.4.73.1 * php7-ftp-7.4.33-150400.4.73.1 * php7-gmp-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-7.4.33-150400.4.73.1 * php7-exif-7.4.33-150400.4.73.1 * php7-sysvshm-7.4.33-150400.4.73.1 * php7-curl-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-7.4.33-150400.4.73.1 * php7-sodium-7.4.33-150400.4.73.1 * php7-snmp-7.4.33-150400.4.73.1 * php7-zip-debuginfo-7.4.33-150400.4.73.1 * php7-openssl-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-7.4.33-150400.4.73.1 * php7-dom-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.73.1 * php7-zip-7.4.33-150400.4.73.1 * php7-enchant-debuginfo-7.4.33-150400.4.73.1 * php7-phar-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debuginfo-7.4.33-150400.4.73.1 * php7-pcntl-debuginfo-7.4.33-150400.4.73.1 * php7-posix-7.4.33-150400.4.73.1 * php7-pdo-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-debuginfo-7.4.33-150400.4.73.1 * php7-debugsource-7.4.33-150400.4.73.1 * php7-pgsql-7.4.33-150400.4.73.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-7.4.33-150400.4.73.1 * php7-openssl-7.4.33-150400.4.73.1 * apache2-mod_php7-7.4.33-150400.4.73.1 * php7-xmlrpc-7.4.33-150400.4.73.1 * php7-sqlite-7.4.33-150400.4.73.1 * php7-bcmath-7.4.33-150400.4.73.1 * php7-tokenizer-7.4.33-150400.4.73.1 * php7-bcmath-debuginfo-7.4.33-150400.4.73.1 * php7-gd-7.4.33-150400.4.73.1 * php7-readline-7.4.33-150400.4.73.1 * php7-cli-7.4.33-150400.4.73.1 * php7-gd-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-7.4.33-150400.4.73.1 * php7-tidy-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-debuginfo-7.4.33-150400.4.73.1 * php7-tidy-7.4.33-150400.4.73.1 * php7-posix-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-debuginfo-7.4.33-150400.4.73.1 * php7-dba-debuginfo-7.4.33-150400.4.73.1 * php7-sockets-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-7.4.33-150400.4.73.1 * php7-sqlite-debuginfo-7.4.33-150400.4.73.1 * php7-curl-7.4.33-150400.4.73.1 * php7-sodium-debuginfo-7.4.33-150400.4.73.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * php7-soap-7.4.33-150400.4.73.1 * php7-pcntl-7.4.33-150400.4.73.1 * php7-pdo-7.4.33-150400.4.73.1 * php7-7.4.33-150400.4.73.1 * php7-odbc-debuginfo-7.4.33-150400.4.73.1 * php7-dom-7.4.33-150400.4.73.1 * php7-intl-7.4.33-150400.4.73.1 * php7-cli-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-7.4.33-150400.4.73.1 * php7-bz2-debuginfo-7.4.33-150400.4.73.1 * php7-soap-debuginfo-7.4.33-150400.4.73.1 * php7-mysql-7.4.33-150400.4.73.1 * php7-sockets-7.4.33-150400.4.73.1 * php7-sysvsem-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-7.4.33-150400.4.73.1 * php7-snmp-debuginfo-7.4.33-150400.4.73.1 * php7-json-7.4.33-150400.4.73.1 * php7-sysvmsg-debuginfo-7.4.33-150400.4.73.1 * php7-dba-7.4.33-150400.4.73.1 * php7-calendar-7.4.33-150400.4.73.1 * apache2-mod_php7-debugsource-7.4.33-150400.4.73.1 * php7-fastcgi-debugsource-7.4.33-150400.4.73.1 * php7-ftp-debuginfo-7.4.33-150400.4.73.1 * php7-sysvmsg-7.4.33-150400.4.73.1 * php7-pgsql-debuginfo-7.4.33-150400.4.73.1 * php7-sysvshm-debuginfo-7.4.33-150400.4.73.1 * php7-zlib-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-7.4.33-150400.4.73.1 * php7-xsl-7.4.33-150400.4.73.1 * php7-debuginfo-7.4.33-150400.4.73.1 * php7-fileinfo-debuginfo-7.4.33-150400.4.73.1 * php7-sysvsem-7.4.33-150400.4.73.1 * php7-mysql-debuginfo-7.4.33-150400.4.73.1 * php7-odbc-7.4.33-150400.4.73.1 * php7-xmlwriter-7.4.33-150400.4.73.1 * php7-readline-debuginfo-7.4.33-150400.4.73.1 * php7-gmp-7.4.33-150400.4.73.1 * php7-xsl-debuginfo-7.4.33-150400.4.73.1 * php7-mbstring-debuginfo-7.4.33-150400.4.73.1 * php7-bz2-7.4.33-150400.4.73.1 * php7-iconv-7.4.33-150400.4.73.1 * apache2-mod_php7-debuginfo-7.4.33-150400.4.73.1 * php7-devel-7.4.33-150400.4.73.1 * php7-zlib-7.4.33-150400.4.73.1 * php7-exif-debuginfo-7.4.33-150400.4.73.1 * php7-intl-debuginfo-7.4.33-150400.4.73.1 * php7-calendar-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-debuginfo-7.4.33-150400.4.73.1 * php7-enchant-7.4.33-150400.4.73.1 * php7-iconv-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-debuginfo-7.4.33-150400.4.73.1 * php7-xmlwriter-debuginfo-7.4.33-150400.4.73.1 * php7-xmlrpc-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debugsource-7.4.33-150400.4.73.1 * php7-fileinfo-7.4.33-150400.4.73.1 * php7-phar-7.4.33-150400.4.73.1 * php7-json-debuginfo-7.4.33-150400.4.73.1 * php7-ftp-7.4.33-150400.4.73.1 * php7-gmp-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-7.4.33-150400.4.73.1 * php7-exif-7.4.33-150400.4.73.1 * php7-sysvshm-7.4.33-150400.4.73.1 * php7-curl-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-7.4.33-150400.4.73.1 * php7-sodium-7.4.33-150400.4.73.1 * php7-snmp-7.4.33-150400.4.73.1 * php7-zip-debuginfo-7.4.33-150400.4.73.1 * php7-openssl-debuginfo-7.4.33-150400.4.73.1 * php7-xmlreader-7.4.33-150400.4.73.1 * php7-dom-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-debuginfo-7.4.33-150400.4.73.1 * php7-zip-7.4.33-150400.4.73.1 * php7-enchant-debuginfo-7.4.33-150400.4.73.1 * php7-phar-debuginfo-7.4.33-150400.4.73.1 * php7-fpm-debuginfo-7.4.33-150400.4.73.1 * php7-pcntl-debuginfo-7.4.33-150400.4.73.1 * php7-posix-7.4.33-150400.4.73.1 * php7-pdo-debuginfo-7.4.33-150400.4.73.1 * php7-gettext-debuginfo-7.4.33-150400.4.73.1 * php7-debugsource-7.4.33-150400.4.73.1 * php7-pgsql-7.4.33-150400.4.73.1 * php7-tokenizer-debuginfo-7.4.33-150400.4.73.1 * php7-ctype-7.4.33-150400.4.73.1 * php7-openssl-7.4.33-150400.4.73.1 * apache2-mod_php7-7.4.33-150400.4.73.1 * php7-xmlrpc-7.4.33-150400.4.73.1 * php7-sqlite-7.4.33-150400.4.73.1 * php7-bcmath-7.4.33-150400.4.73.1 * php7-tokenizer-7.4.33-150400.4.73.1 * php7-bcmath-debuginfo-7.4.33-150400.4.73.1 * php7-gd-7.4.33-150400.4.73.1 * php7-readline-7.4.33-150400.4.73.1 * php7-cli-7.4.33-150400.4.73.1 * php7-gd-debuginfo-7.4.33-150400.4.73.1 * php7-fastcgi-7.4.33-150400.4.73.1 * php7-tidy-debuginfo-7.4.33-150400.4.73.1 * php7-shmop-debuginfo-7.4.33-150400.4.73.1 * php7-tidy-7.4.33-150400.4.73.1 * php7-posix-debuginfo-7.4.33-150400.4.73.1 * php7-ldap-debuginfo-7.4.33-150400.4.73.1 * php7-dba-debuginfo-7.4.33-150400.4.73.1 * php7-sockets-debuginfo-7.4.33-150400.4.73.1 * php7-opcache-7.4.33-150400.4.73.1 * php7-sqlite-debuginfo-7.4.33-150400.4.73.1 * php7-curl-7.4.33-150400.4.73.1 * php7-sodium-debuginfo-7.4.33-150400.4.73.1 ## References: * https://www.suse.com/security/cve/CVE-2026-7260.html * https://bugzilla.suse.com/show_bug.cgi?id=1205782 * https://bugzilla.suse.com/show_bug.cgi?id=1273077 * https://bugzilla.suse.com/show_bug.cgi?id=1276531 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 12:33:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 12:33:35 -0000 Subject: SUSE-SU-2026:4126-1: important: Security update for tomcat Message-ID: <178913001521.1292.297449021327667246@07c0de5f7757> # Security update for tomcat Announcement ID: SUSE-SU-2026:4126-1 Release Date: 2026-09-11T06:49:29Z Rating: important References: * bsc#1273150 * bsc#1276893 * bsc#1276894 * bsc#1276895 * bsc#1276896 * bsc#1276897 * bsc#1276898 * bsc#1276899 * bsc#1276900 * bsc#1276901 * bsc#1276902 Cross-References: * CVE-2026-65182 * CVE-2026-65183 * CVE-2026-65637 * CVE-2026-65905 * CVE-2026-65927 * CVE-2026-66299 * CVE-2026-66422 * CVE-2026-68525 * CVE-2026-68569 * CVE-2026-68763 * CVE-2026-73180 CVSS scores: * CVE-2026-65182 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65182 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-65182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-65183 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65183 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65637 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65637 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65637 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65905 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65905 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-65905 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65927 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65927 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-66299 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-66422 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-66422 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-66422 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-68525 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68525 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68525 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68569 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68569 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68569 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68763 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68763 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68763 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73180 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-73180 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-73180 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for tomcat fixes the following issues: * CVE-2026-65182: Apache Tomcat: Bypass longest prefix security constraint (bsc#1276893). * CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets (bsc#1276894). * CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - fix incomplete (bsc#1276895). * CVE-2026-65905: Apache Tomcat: Limited replay attack possible with DIGEST authentication (bsc#1276896). * CVE-2026-65927: Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control (bsc#1276897). * CVE-2026-66299: memory exhaustion via maliciously slow clients due to the WebSocket chat example providing an unbounded buffer for undelivered messages (bsc#1273150). * CVE-2026-66422: Apache Tomcat: Servlet role references can bypass declarative role constraints (bsc#1276898). * CVE-2026-68525: Apache Tomcat: Redirect after FORM auth may bypass method specific constraints (bsc#1276899). * CVE-2026-68569: Apache Tomcat: Principal lookup can fail open in some cases (bsc#1276900). * CVE-2026-68763: Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset (bsc#1276901). * CVE-2026-73180: Apache Tomcat: Authenticated WebSocket session survives end of HTTP session (bsc#1276902). Changes for tomcat: * Updated to version 9.0.121 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4126=1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4126=1 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * tomcat-jsp-2_3-api-9.0.121-3.177.3 * tomcat-el-3_0-api-9.0.121-3.177.3 * tomcat-javadoc-9.0.121-3.177.3 * tomcat-webapps-9.0.121-3.177.3 * tomcat-docs-webapp-9.0.121-3.177.3 * tomcat-admin-webapps-9.0.121-3.177.3 * tomcat-9.0.121-3.177.3 * tomcat-lib-9.0.121-3.177.3 * tomcat-servlet-4_0-api-9.0.121-3.177.3 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * tomcat-jsp-2_3-api-9.0.121-3.177.3 * tomcat-el-3_0-api-9.0.121-3.177.3 * tomcat-javadoc-9.0.121-3.177.3 * tomcat-webapps-9.0.121-3.177.3 * tomcat-docs-webapp-9.0.121-3.177.3 * tomcat-admin-webapps-9.0.121-3.177.3 * tomcat-9.0.121-3.177.3 * tomcat-lib-9.0.121-3.177.3 * tomcat-servlet-4_0-api-9.0.121-3.177.3 ## References: * https://www.suse.com/security/cve/CVE-2026-65182.html * https://www.suse.com/security/cve/CVE-2026-65183.html * https://www.suse.com/security/cve/CVE-2026-65637.html * https://www.suse.com/security/cve/CVE-2026-65905.html * https://www.suse.com/security/cve/CVE-2026-65927.html * https://www.suse.com/security/cve/CVE-2026-66299.html * https://www.suse.com/security/cve/CVE-2026-66422.html * https://www.suse.com/security/cve/CVE-2026-68525.html * https://www.suse.com/security/cve/CVE-2026-68569.html * https://www.suse.com/security/cve/CVE-2026-68763.html * https://www.suse.com/security/cve/CVE-2026-73180.html * https://bugzilla.suse.com/show_bug.cgi?id=1273150 * https://bugzilla.suse.com/show_bug.cgi?id=1276893 * https://bugzilla.suse.com/show_bug.cgi?id=1276894 * https://bugzilla.suse.com/show_bug.cgi?id=1276895 * https://bugzilla.suse.com/show_bug.cgi?id=1276896 * https://bugzilla.suse.com/show_bug.cgi?id=1276897 * https://bugzilla.suse.com/show_bug.cgi?id=1276898 * https://bugzilla.suse.com/show_bug.cgi?id=1276899 * https://bugzilla.suse.com/show_bug.cgi?id=1276900 * https://bugzilla.suse.com/show_bug.cgi?id=1276901 * https://bugzilla.suse.com/show_bug.cgi?id=1276902 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 12:34:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 12:34:14 -0000 Subject: SUSE-SU-2026:4125-1: important: Security update for azure-storage-azcopy Message-ID: <178913005413.1292.7249878086532399906@07c0de5f7757> # Security update for azure-storage-azcopy Announcement ID: SUSE-SU-2026:4125-1 Release Date: 2026-09-11T06:49:14Z Rating: important References: * bsc#1276733 * bsc#1279026 * bsc#1279223 * bsc#1279330 Cross-References: * CVE-2026-41178 * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves four vulnerabilities can now be installed. ## Description: This update for azure-storage-azcopy fixes the following issues: * CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276733). * CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279330). * CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279223). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1279026). Changes for azure-storage-azcopy: * Update to 10.32.8 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-4125=1 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4125=1 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-4125=1 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-4125=1 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-4125=1 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le x86_64) * azure-storage-azcopy-10.32.8-150400.9.21.1 * openSUSE Leap 15.4 (aarch64 ppc64le x86_64) * azure-storage-azcopy-10.32.8-150400.9.21.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le x86_64) * azure-storage-azcopy-10.32.8-150400.9.21.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le x86_64) * azure-storage-azcopy-10.32.8-150400.9.21.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le x86_64) * azure-storage-azcopy-10.32.8-150400.9.21.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41178.html * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1276733 * https://bugzilla.suse.com/show_bug.cgi?id=1279026 * https://bugzilla.suse.com/show_bug.cgi?id=1279223 * https://bugzilla.suse.com/show_bug.cgi?id=1279330 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 16:31:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 16:31:13 -0000 Subject: SUSE-SU-2026:23541-1: important: Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178914427332.7040.16331564274302289385@bab013902bd8> # Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23541-1 Release Date: 2026-09-08T13:48:22Z Rating: important References: * bsc#1253437 * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264078 * bsc#1264483 * bsc#1265306 * bsc#1266668 * bsc#1267362 * bsc#1268281 * bsc#1268624 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2025-40204 * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-31759 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-43206 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46274 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2025-40204 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-40204 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-40204 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31759 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31759 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-31759 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 22 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues: The following security issues were fixed: * CVE-2025-40204: sctp: Fix MAC comparison to be constant-time (bsc#1253437). * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-31759: usb: ulpi: fix double free in ulpi_register_interface() error path (bsc#1264078). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-43206: drm/amdkfd: Fix out-of-bounds write in kfd_event_page_set() (bsc#1266668). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46274: io-wq: check that the predecessor is hashed in io_wq_remove_pending() (bsc#1268624). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-605=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_14-debugsource-11-1.1 * kernel-livepatch-6_4_0-38-rt-debuginfo-11-1.1 * kernel-livepatch-6_4_0-38-rt-11-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-40204.html * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-31759.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-43206.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46274.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1253437 * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264078 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1266668 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1268624 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 16:31:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 16:31:50 -0000 Subject: SUSE-SU-2026:23540-1: important: Security update for kernel-livepatch-MICRO-6-0-RT_Update_29 Message-ID: <178914431059.7040.8121580975055964586@bab013902bd8> # Security update for kernel-livepatch-MICRO-6-0-RT_Update_29 Announcement ID: SUSE-SU-2026:23540-1 Release Date: 2026-09-08T11:34:19Z Rating: important References: Affected Products: * SUSE Linux Micro 6.1 An update that can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0-RT_Update_29 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 29 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-604=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_29-debugsource-1-1.1 * kernel-livepatch-6_4_0-52-rt-1-1.1 * kernel-livepatch-6_4_0-52-rt-debuginfo-1-1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 16:32:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 16:32:29 -0000 Subject: SUSE-SU-2026:23539-1: important: Security update for ucode-intel Message-ID: <178914434965.7040.15209628961998466882@bab013902bd8> # Security update for ucode-intel Announcement ID: SUSE-SU-2026:23539-1 Release Date: 2026-09-03T09:05:53Z Rating: important References: * bsc#1274785 Cross-References: * CVE-2025-31936 * CVE-2025-31938 * CVE-2025-35973 * CVE-2026-20707 * CVE-2026-20713 * CVE-2026-20716 * CVE-2026-20760 * CVE-2026-20901 * CVE-2026-20917 CVSS scores: * CVE-2025-31936 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31936 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2025-31936 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31938 ( SUSE ): 4.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31938 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2025-31938 ( NVD ): 4.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35973 ( SUSE ): 4.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35973 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N * CVE-2025-35973 ( NVD ): 4.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20707 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20707 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-20707 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20713 ( SUSE ): 4.5 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20713 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N * CVE-2026-20713 ( NVD ): 4.5 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( SUSE ): 7.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-20716 ( NVD ): 7.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20760 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20760 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20760 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20901 ( NVD ): 4.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20901 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N * CVE-2026-20917 ( SUSE ): 4.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20917 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2026-20917 ( NVD ): 4.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.1 An update that solves nine vulnerabilities can now be installed. ## Description: This update for ucode-intel fixes the following issues: * Intel CPU Microcode was updated to the 20260812 release (bsc#1274785) * Removed MTL/06-aa-04/c0 due to functional issues observed when loading the MCU in some platforms. * Intel CPU Microcode was updated to the 20260811 release (bsc#1274785) * Security updates for INTEL-SA-01379 / CVE-2025-31936 * Security updates for INTEL-SA-01404 / CVE-2025-31938 * Security updates for INTEL-SA-01423 / CVE-2026-20917 * Security updates for INTEL-SA-01428 / CVE-2025-35973 * Security updates for INTEL-SA-01435 / CVE-2026-20716 * Security updates for INTEL-SA-01441 / CVE-2026-20760 * Security updates for INTEL-SA-01442 / CVE-2026-20713 / CVE-2026-20901 * Security updates for INTEL-SA-01443 / CVE-2026-20707 * Update for functional issues. ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-704=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * ucode-intel-20260812-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-31936.html * https://www.suse.com/security/cve/CVE-2025-31938.html * https://www.suse.com/security/cve/CVE-2025-35973.html * https://www.suse.com/security/cve/CVE-2026-20707.html * https://www.suse.com/security/cve/CVE-2026-20713.html * https://www.suse.com/security/cve/CVE-2026-20716.html * https://www.suse.com/security/cve/CVE-2026-20760.html * https://www.suse.com/security/cve/CVE-2026-20901.html * https://www.suse.com/security/cve/CVE-2026-20917.html * https://bugzilla.suse.com/show_bug.cgi?id=1274785 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 16:33:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 16:33:14 -0000 Subject: SUSE-SU-2026:23538-1: important: Security update for openssl-3-livepatches Message-ID: <178914439487.7040.18225165252858108324@bab013902bd8> # Security update for openssl-3-livepatches Announcement ID: SUSE-SU-2026:23538-1 Release Date: 2026-09-02T09:18:15Z Rating: important References: * bsc#1274788 * bsc#1274790 * bsc#1274792 * bsc#1275133 * bsc#1275143 * bsc#1275145 Cross-References: * CVE-2026-14457 * CVE-2026-63072 * CVE-2026-63076 CVSS scores: * CVE-2026-14457 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-14457 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves three vulnerabilities and has three fixes can now be installed. ## Description: This update for openssl-3-livepatches fixes the following issues: * CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1275145, bsc#1274792). * CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1275133, bsc#1274788). * CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1275143, bsc#1274790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-699=1 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * openssl-3-livepatches-debuginfo-0.6-slfo.1.1_1.1 * openssl-3-livepatches-0.6-slfo.1.1_1.1 * openssl-3-livepatches-debugsource-0.6-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14457.html * https://www.suse.com/security/cve/CVE-2026-63072.html * https://www.suse.com/security/cve/CVE-2026-63076.html * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1274790 * https://bugzilla.suse.com/show_bug.cgi?id=1274792 * https://bugzilla.suse.com/show_bug.cgi?id=1275133 * https://bugzilla.suse.com/show_bug.cgi?id=1275143 * https://bugzilla.suse.com/show_bug.cgi?id=1275145 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 16:34:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 16:34:03 -0000 Subject: SUSE-SU-2026:23537-1: important: Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178914444364.7040.7682319552391563738@bab013902bd8> # Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23537-1 Release Date: 2026-09-08T13:50:06Z Rating: important References: * bsc#1270023 * bsc#1270024 * bsc#1271543 * bsc#1271867 Cross-References: * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-50.2 fixes various security issues: The following security issues were fixed: * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-612=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-50-default-debuginfo-2-1.1 * kernel-livepatch-6_4_0-50-default-2-1.1 * kernel-livepatch-MICRO-6-0_Update_27-debugsource-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 16:34:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 16:34:50 -0000 Subject: SUSE-SU-2026:23536-1: important: Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178914449083.7040.11851998208491508525@bab013902bd8> # Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23536-1 Release Date: 2026-09-08T13:50:06Z Rating: important References: * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271370 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-46242 * CVE-2026-52956 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-53366 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves seven vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-49.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-53366: ipv4: account for fraggap on the paged allocation path (bsc#1271370). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-611=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-49-default-debuginfo-2-1.1 * kernel-livepatch-MICRO-6-0_Update_26-debugsource-2-1.1 * kernel-livepatch-6_4_0-49-default-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271370 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 16:35:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 16:35:41 -0000 Subject: SUSE-SU-2026:23535-1: important: Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178914454106.7040.8852455580254511673@bab013902bd8> # Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23535-1 Release Date: 2026-09-08T13:50:06Z Rating: important References: * bsc#1268281 * bsc#1269034 * bsc#1269822 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-53133 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves nine vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-48.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-610=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-48-default-debuginfo-3-1.1 * kernel-livepatch-6_4_0-48-default-3-1.1 * kernel-livepatch-MICRO-6-0_Update_25-debugsource-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 16:36:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 16:36:34 -0000 Subject: SUSE-SU-2026:23534-1: important: Security update for the Linux Kernel (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178914459438.7040.7579636996736313849@bab013902bd8> # Security update for the Linux Kernel (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23534-1 Release Date: 2026-09-08T13:50:06Z Rating: important References: * bsc#1267362 * bsc#1268281 * bsc#1269034 * bsc#1269196 * bsc#1269822 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-47.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-609=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_24-debugsource-4-1.1 * kernel-livepatch-6_4_0-47-default-4-1.1 * kernel-livepatch-6_4_0-47-default-debuginfo-4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 16:37:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 16:37:30 -0000 Subject: SUSE-SU-2026:23533-1: important: Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178914465053.7040.7934641100023448634@bab013902bd8> # Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23533-1 Release Date: 2026-09-08T13:50:06Z Rating: important References: * bsc#1267362 * bsc#1268281 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-43109 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 13 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues: The following security issues were fixed: * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-608=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-46-default-5-1.1 * kernel-livepatch-6_4_0-46-default-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0_Update_23-debugsource-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 16:38:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 16:38:32 -0000 Subject: SUSE-SU-2026:23532-1: important: Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178914471250.7040.2357977813633119097@bab013902bd8> # Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23532-1 Release Date: 2026-09-08T13:50:06Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 18 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-607=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-45-default-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0_Update_22-debugsource-5-1.1 * kernel-livepatch-6_4_0-45-default-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 16:39:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 16:39:33 -0000 Subject: SUSE-SU-2026:23531-1: important: Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178914477397.7040.15489781640721016087@bab013902bd8> # Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23531-1 Release Date: 2026-09-08T13:50:06Z Rating: important References: * bsc#1262213 * bsc#1262404 * bsc#1263791 * bsc#1264483 * bsc#1265306 * bsc#1267362 * bsc#1268281 * bsc#1269034 * bsc#1269196 * bsc#1269282 * bsc#1269822 * bsc#1269885 * bsc#1270023 * bsc#1270024 * bsc#1270300 * bsc#1271543 * bsc#1271867 * bsc#1272139 Cross-References: * CVE-2026-23240 * CVE-2026-23449 * CVE-2026-31629 * CVE-2026-43077 * CVE-2026-43109 * CVE-2026-43110 * CVE-2026-46037 * CVE-2026-46242 * CVE-2026-46319 * CVE-2026-52923 * CVE-2026-52956 * CVE-2026-52972 * CVE-2026-53133 * CVE-2026-53182 * CVE-2026-53224 * CVE-2026-53246 * CVE-2026-64530 * CVE-2026-64600 CVSS scores: * CVE-2026-23240 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23240 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23240 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23449 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23449 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31629 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31629 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43077 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43077 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43110 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43110 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43110 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46037 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46037 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46037 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46242 ( SUSE ): 8.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-46242 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46242 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46319 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52923 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52956 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52956 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52972 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52972 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52972 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53133 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53133 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53182 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53182 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53224 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53224 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53246 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53246 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-53246 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 18 vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-44.1 fixes various security issues: The following security issues were fixed: * CVE-2026-23240: tls: Fix race condition in tls_sw_cancel_work_tx() (bsc#1262404). * CVE-2026-23449: net/sched: teql: Fix double-free in teql_master_xmit (bsc#1262213). * CVE-2026-31629: nfc: llcp: add missing return after LLCP_CLOSED checks (bsc#1263791). * CVE-2026-43077: crypto: algif_aead - Fix minimum RX size check for decryption (bsc#1265306). * CVE-2026-43109: x86: shadow stacks: proper error handling for mmap lock (bsc#1269282). * CVE-2026-43110: wifi: brcmfmac: validate bsscfg indices in IF events (bsc#1264483). * CVE-2026-46037: ipv4: icmp: validate reply type before using icmp_pointers (bsc#1267362). * CVE-2026-46242: eventpoll: fix ep_remove struct eventpoll / struct file UAF (bsc#1270300). * CVE-2026-46319: net/sched: act_ct: Only release RCU read lock after ct_ft (bsc#1268281). * CVE-2026-52923: ipc: limit next_id allocation to the valid ID range (bsc#1269034). * CVE-2026-52956: libceph: Fix potential out-of-bounds access in __ceph_x_decrypt() (bsc#1272139). * CVE-2026-52972: crypto: af_alg - Cap AEAD AD length to 0x80000000 (bsc#1269196). * CVE-2026-53133: RDMA/umem: Fix truncation for block sizes >= 4G (bsc#1269822). * CVE-2026-53182: wifi: nl80211: reject oversized EMA RNR lists (bsc#1269885). * CVE-2026-53224: sctp: validate embedded INIT chunk and address list lengths in cookie (bsc#1270023). * CVE-2026-53246: sctp: validate cached peer INIT chunk length in COOKIE_ECHO processing (bsc#1270024). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-606=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-44-default-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0_Update_21-debugsource-5-1.1 * kernel-livepatch-6_4_0-44-default-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23240.html * https://www.suse.com/security/cve/CVE-2026-23449.html * https://www.suse.com/security/cve/CVE-2026-31629.html * https://www.suse.com/security/cve/CVE-2026-43077.html * https://www.suse.com/security/cve/CVE-2026-43109.html * https://www.suse.com/security/cve/CVE-2026-43110.html * https://www.suse.com/security/cve/CVE-2026-46037.html * https://www.suse.com/security/cve/CVE-2026-46242.html * https://www.suse.com/security/cve/CVE-2026-46319.html * https://www.suse.com/security/cve/CVE-2026-52923.html * https://www.suse.com/security/cve/CVE-2026-52956.html * https://www.suse.com/security/cve/CVE-2026-52972.html * https://www.suse.com/security/cve/CVE-2026-53133.html * https://www.suse.com/security/cve/CVE-2026-53182.html * https://www.suse.com/security/cve/CVE-2026-53224.html * https://www.suse.com/security/cve/CVE-2026-53246.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://bugzilla.suse.com/show_bug.cgi?id=1262213 * https://bugzilla.suse.com/show_bug.cgi?id=1262404 * https://bugzilla.suse.com/show_bug.cgi?id=1263791 * https://bugzilla.suse.com/show_bug.cgi?id=1264483 * https://bugzilla.suse.com/show_bug.cgi?id=1265306 * https://bugzilla.suse.com/show_bug.cgi?id=1267362 * https://bugzilla.suse.com/show_bug.cgi?id=1268281 * https://bugzilla.suse.com/show_bug.cgi?id=1269034 * https://bugzilla.suse.com/show_bug.cgi?id=1269196 * https://bugzilla.suse.com/show_bug.cgi?id=1269282 * https://bugzilla.suse.com/show_bug.cgi?id=1269822 * https://bugzilla.suse.com/show_bug.cgi?id=1269885 * https://bugzilla.suse.com/show_bug.cgi?id=1270023 * https://bugzilla.suse.com/show_bug.cgi?id=1270024 * https://bugzilla.suse.com/show_bug.cgi?id=1270300 * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1272139 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 16:40:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 16:40:11 -0000 Subject: SUSE-SU-2026:23530-1: important: Security update for kernel-livepatch-MICRO-6-0_Update_29 Message-ID: <178914481176.7040.1493985385678269030@bab013902bd8> # Security update for kernel-livepatch-MICRO-6-0_Update_29 Announcement ID: SUSE-SU-2026:23530-1 Release Date: 2026-09-08T11:00:55Z Rating: important References: Affected Products: * SUSE Linux Micro 6.1 An update that can now be installed. ## Description: This update for kernel-livepatch-MICRO-6-0_Update_29 fixes the following issues: * New livepatch SLE Micro 6.0/6.1 kernel update 29 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-602=1 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-52-default-debuginfo-1-1.1 * kernel-livepatch-6_4_0-52-default-1-1.1 * kernel-livepatch-MICRO-6-0_Update_29-debugsource-1-1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 16:53:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 16:53:46 -0000 Subject: SUSE-SU-2026:23529-1: important: Security update for the Linux Kernel Message-ID: <178914562664.7040.5143793088323122554@bab013902bd8> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:23529-1 Release Date: 2026-09-08T13:00:49Z Rating: important References: * bsc#1230238 * bsc#1235944 * bsc#1247455 * bsc#1250748 * bsc#1251966 * bsc#1252682 * bsc#1254306 * bsc#1255225 * bsc#1255250 * bsc#1256629 * bsc#1256708 * bsc#1257154 * bsc#1258430 * bsc#1258517 * bsc#1260522 * bsc#1261780 * bsc#1261788 * bsc#1262073 * bsc#1263004 * bsc#1263061 * bsc#1263133 * bsc#1264335 * bsc#1264446 * bsc#1264541 * bsc#1264584 * bsc#1264587 * bsc#1264619 * bsc#1264788 * bsc#1265068 * bsc#1265121 * bsc#1265449 * bsc#1265928 * bsc#1266402 * bsc#1266860 * bsc#1266874 * bsc#1266897 * bsc#1267023 * bsc#1267238 * bsc#1267501 * bsc#1267612 * bsc#1268276 * bsc#1268972 * bsc#1268979 * bsc#1268987 * bsc#1269004 * bsc#1269013 * bsc#1269108 * bsc#1269113 * bsc#1269114 * bsc#1269126 * bsc#1269167 * bsc#1269234 * bsc#1269238 * bsc#1269242 * bsc#1269256 * bsc#1269301 * bsc#1269306 * bsc#1269381 * bsc#1269388 * bsc#1269412 * bsc#1269530 * bsc#1269579 * bsc#1269590 * bsc#1269635 * bsc#1269655 * bsc#1269665 * bsc#1269686 * bsc#1269695 * bsc#1269713 * bsc#1269731 * bsc#1269774 * bsc#1269783 * bsc#1269792 * bsc#1269815 * bsc#1269965 * bsc#1269969 * bsc#1269981 * bsc#1269985 * bsc#1270090 * bsc#1270108 * bsc#1270111 * bsc#1270251 * bsc#1271256 * bsc#1271365 * bsc#1271366 * bsc#1271825 * bsc#1271830 * bsc#1272150 * bsc#1272175 * bsc#1272179 * bsc#1272182 * bsc#1272200 * bsc#1272210 * bsc#1272213 * bsc#1272230 * bsc#1272260 * bsc#1272261 * bsc#1272262 * bsc#1272297 * bsc#1272346 * bsc#1272381 * bsc#1272385 * bsc#1272390 * bsc#1272423 * bsc#1272429 * bsc#1272484 * bsc#1272486 * bsc#1272497 * bsc#1272516 * bsc#1272569 * bsc#1272571 * bsc#1272641 * bsc#1272643 * bsc#1272662 * bsc#1272673 * bsc#1272680 * bsc#1272682 * bsc#1272756 * bsc#1272786 * bsc#1272788 * bsc#1272798 * bsc#1272799 * bsc#1272868 * bsc#1272877 * bsc#1272891 * bsc#1272963 * bsc#1272983 * bsc#1273008 * bsc#1273019 * bsc#1273027 * bsc#1273028 * bsc#1273030 * bsc#1273038 * bsc#1273053 * bsc#1273054 * bsc#1273060 * bsc#1273105 * bsc#1273249 * bsc#1273250 * bsc#1273260 * bsc#1273273 * bsc#1273274 * bsc#1273276 * bsc#1273281 * bsc#1273284 * bsc#1273285 * bsc#1273289 * bsc#1273291 * bsc#1273294 * bsc#1273302 * bsc#1273303 * bsc#1273305 * bsc#1273310 * bsc#1273311 * bsc#1273316 * bsc#1273318 * bsc#1273319 * bsc#1273323 * bsc#1273325 * bsc#1273327 * bsc#1273334 * bsc#1273335 * bsc#1273336 * bsc#1273337 * bsc#1273338 * bsc#1273340 * bsc#1273341 * bsc#1273346 * bsc#1273422 * bsc#1273426 * bsc#1273443 * bsc#1273463 * bsc#1273468 * bsc#1273469 * bsc#1273471 * bsc#1273479 * bsc#1273480 * bsc#1273482 * bsc#1273484 * bsc#1273488 * bsc#1273490 * bsc#1273501 * bsc#1273503 * bsc#1273504 * bsc#1273506 * bsc#1273523 * bsc#1273525 * bsc#1273533 * bsc#1273536 * bsc#1273542 * bsc#1273555 * bsc#1273578 * bsc#1273579 * bsc#1273582 * bsc#1273596 * bsc#1273597 * bsc#1273598 * bsc#1273600 * bsc#1273601 * bsc#1273602 * bsc#1273603 * bsc#1273682 * bsc#1273734 * bsc#1273738 * bsc#1273739 * bsc#1273741 * bsc#1273742 * bsc#1273743 * bsc#1273745 * bsc#1273748 * bsc#1273749 * bsc#1273755 * bsc#1273762 * bsc#1273765 * bsc#1273766 * bsc#1273769 * bsc#1273774 * bsc#1273778 * bsc#1273780 * bsc#1273790 * bsc#1273796 * bsc#1273804 * bsc#1273810 * bsc#1273811 * bsc#1273813 * bsc#1273817 * bsc#1273822 * bsc#1273824 * bsc#1273831 * bsc#1273832 * bsc#1273834 * bsc#1273838 * bsc#1273844 * bsc#1273849 * bsc#1273860 * bsc#1273862 * bsc#1273867 * bsc#1273868 * bsc#1273869 * bsc#1273872 * bsc#1273876 * bsc#1273877 * bsc#1273880 * bsc#1273882 * bsc#1273890 * bsc#1273891 * bsc#1273892 * bsc#1273895 * bsc#1273896 * bsc#1273903 * bsc#1273905 * bsc#1273930 * bsc#1273933 * bsc#1273934 * bsc#1273935 * bsc#1273936 * bsc#1273939 * bsc#1273940 * bsc#1273941 * bsc#1273942 * bsc#1273944 * bsc#1273945 * bsc#1273946 * bsc#1273956 * bsc#1273957 * bsc#1273958 * bsc#1273966 * bsc#1273967 * bsc#1273968 * bsc#1273972 * bsc#1273974 * bsc#1273975 * bsc#1273977 * bsc#1273982 * bsc#1273988 * bsc#1273990 * bsc#1273991 * bsc#1273995 * bsc#1274001 * bsc#1274003 * bsc#1274006 * bsc#1274011 * bsc#1274012 * bsc#1274014 * bsc#1274017 * bsc#1274019 * bsc#1274020 * bsc#1274026 * bsc#1274028 * bsc#1274030 * bsc#1274031 * bsc#1274035 * bsc#1274040 * bsc#1274041 * bsc#1274057 * bsc#1274058 * bsc#1274061 * bsc#1274063 * bsc#1274065 * bsc#1274067 * bsc#1274075 * bsc#1274076 * bsc#1274077 * bsc#1274078 * bsc#1274208 * bsc#1274226 * bsc#1274239 * bsc#1274243 * bsc#1274258 * bsc#1274265 * bsc#1274274 * bsc#1274277 * bsc#1274278 * bsc#1274281 * bsc#1274283 * bsc#1274286 * bsc#1274290 * bsc#1274294 * bsc#1274296 * bsc#1274297 * bsc#1274298 * bsc#1274314 * bsc#1274321 * bsc#1274491 * bsc#1274497 * bsc#1274539 * bsc#1274541 * bsc#1274543 * bsc#1274545 * bsc#1274547 * bsc#1274550 * bsc#1274573 * bsc#1274578 * bsc#1274580 * bsc#1274581 * bsc#1274620 * bsc#1274622 * bsc#1274624 * bsc#1274629 * bsc#1274632 * bsc#1274636 * bsc#1274639 * bsc#1274640 * bsc#1274642 * bsc#1274644 * bsc#1274645 * bsc#1274646 * bsc#1274649 * bsc#1274650 * bsc#1274651 * bsc#1274656 * bsc#1274659 * bsc#1274662 * bsc#1274663 * bsc#1274665 * bsc#1274667 * bsc#1274670 * bsc#1274675 * bsc#1274677 * bsc#1274678 * bsc#1274679 * bsc#1274681 * bsc#1274682 * bsc#1274690 * bsc#1274694 * bsc#1274696 * bsc#1274698 * bsc#1274699 * bsc#1274700 * bsc#1274702 * bsc#1274703 * bsc#1274705 * bsc#1274706 * bsc#1274709 * bsc#1274710 * bsc#1274713 * bsc#1274716 * bsc#1274721 * bsc#1274725 * bsc#1274737 * bsc#1274738 * bsc#1274749 * bsc#1274752 * bsc#1274753 * bsc#1274754 * bsc#1274755 * bsc#1274756 * bsc#1274764 * bsc#1274768 * bsc#1274770 * bsc#1274787 * bsc#1274800 * bsc#1274801 * bsc#1274802 * bsc#1274804 * bsc#1274805 * bsc#1274807 * bsc#1274808 * bsc#1274811 * bsc#1274813 * bsc#1274814 * bsc#1274831 * bsc#1274834 * bsc#1274847 * bsc#1274853 * bsc#1274868 * bsc#1274869 * bsc#1274872 * bsc#1274873 * bsc#1274874 * bsc#1274876 * bsc#1274879 * bsc#1274881 * bsc#1274883 * bsc#1274886 * bsc#1274888 * bsc#1274891 * bsc#1274892 * bsc#1274893 * bsc#1274894 * bsc#1274896 * bsc#1274897 * bsc#1274898 * bsc#1274899 * bsc#1274901 * bsc#1274902 * bsc#1274905 * bsc#1274907 * bsc#1274908 * bsc#1274913 * bsc#1274914 * bsc#1274920 * bsc#1274921 * bsc#1274924 * bsc#1274925 * bsc#1274929 * bsc#1274930 * bsc#1274933 * bsc#1274934 * bsc#1274935 * bsc#1274941 * bsc#1274945 * bsc#1274947 * bsc#1274951 * bsc#1274953 * bsc#1274958 * bsc#1274968 * bsc#1274981 * bsc#1275040 * bsc#1275069 * bsc#1275071 * bsc#1275073 * bsc#1275076 * bsc#1275080 * bsc#1275083 * bsc#1275088 * bsc#1275091 * bsc#1275125 * bsc#1275126 * bsc#1275131 * bsc#1275132 * bsc#1275150 * bsc#1275152 * bsc#1275154 * bsc#1275155 * bsc#1275157 * bsc#1275158 * bsc#1275161 * bsc#1275163 * bsc#1275164 * bsc#1275169 * bsc#1275173 * bsc#1275176 * bsc#1275185 * bsc#1275190 * bsc#1275236 * bsc#1275237 * bsc#1275239 * bsc#1275294 * bsc#1275301 * bsc#1275303 * bsc#1275304 * bsc#1275305 * bsc#1275306 * bsc#1275307 * bsc#1275470 * bsc#1275472 * bsc#1275474 * bsc#1275479 * bsc#1275483 * bsc#1275486 * bsc#1275487 * bsc#1275506 * bsc#1275509 * bsc#1275511 * bsc#1275517 * bsc#1275528 * bsc#1275535 * bsc#1275540 * bsc#1275553 * bsc#1275555 * bsc#1275561 * bsc#1275566 * bsc#1275569 * bsc#1275574 * bsc#1275578 * bsc#1275582 * bsc#1275583 * bsc#1275584 * bsc#1275591 * bsc#1275595 * bsc#1275633 * bsc#1275636 * bsc#1275650 * bsc#1275659 * bsc#1275665 * bsc#1275669 * bsc#1275687 * bsc#1275688 * bsc#1275695 * bsc#1275696 * bsc#1275704 * bsc#1275782 * bsc#1275784 * bsc#1275787 * bsc#1275788 * bsc#1275790 * bsc#1275797 * bsc#1275798 * bsc#1275805 * bsc#1275817 * bsc#1275818 * bsc#1275819 * bsc#1275820 * bsc#1275821 * bsc#1275827 * bsc#1275864 * bsc#1275867 * bsc#1275869 * bsc#1275870 * bsc#1275871 * bsc#1275872 * bsc#1275886 * bsc#1275905 * bsc#1275923 * bsc#1275925 * bsc#1275946 * bsc#1275950 * bsc#1275954 * bsc#1275970 * bsc#1275973 * bsc#1275975 * bsc#1275976 * bsc#1276029 * bsc#1276257 * bsc#1276263 * bsc#1276270 * bsc#1276273 * bsc#1276277 * bsc#1276335 * bsc#1276346 * bsc#1276350 * bsc#1276355 * bsc#1276446 * bsc#1276452 * bsc#1276500 * bsc#1276507 * bsc#1276542 * bsc#1276546 * bsc#1276551 * bsc#1276561 * bsc#1276569 * bsc#1276665 * bsc#1276864 * bsc#1276927 * bsc#1276931 * bsc#1276937 * bsc#1276941 * bsc#1276943 * bsc#1276961 * bsc#1277022 * bsc#1277034 * bsc#1277037 * bsc#1277047 * bsc#1277054 * bsc#1277057 * bsc#1277059 * bsc#1277064 * bsc#1277066 * bsc#1277069 * bsc#1277073 * bsc#1277077 * bsc#1277095 * bsc#1277155 * bsc#1277159 * bsc#1277160 * bsc#1277202 * bsc#1277204 * bsc#1277275 * bsc#1277285 * bsc#1277391 * bsc#1277408 * bsc#1277516 * bsc#1277523 * bsc#1277551 * bsc#1277625 * bsc#1277660 * bsc#1277678 * bsc#1277688 * bsc#1277775 * bsc#1277776 Cross-References: * CVE-2024-44981 * CVE-2024-57841 * CVE-2025-38469 * CVE-2025-39964 * CVE-2025-40022 * CVE-2025-68179 * CVE-2025-68214 * CVE-2025-71075 * CVE-2025-71104 * CVE-2026-23210 * CVE-2026-23230 * CVE-2026-23454 * CVE-2026-31392 * CVE-2026-31418 * CVE-2026-31531 * CVE-2026-31557 * CVE-2026-31663 * CVE-2026-43116 * CVE-2026-43125 * CVE-2026-43163 * CVE-2026-43271 * CVE-2026-43273 * CVE-2026-43278 * CVE-2026-43319 * CVE-2026-43363 * CVE-2026-43416 * CVE-2026-45897 * CVE-2026-45968 * CVE-2026-46070 * CVE-2026-46091 * CVE-2026-46107 * CVE-2026-46115 * CVE-2026-46195 * CVE-2026-52920 * CVE-2026-52925 * CVE-2026-52929 * CVE-2026-52935 * CVE-2026-52939 * CVE-2026-52946 * CVE-2026-52975 * CVE-2026-52977 * CVE-2026-52990 * CVE-2026-52994 * CVE-2026-53001 * CVE-2026-53033 * CVE-2026-53059 * CVE-2026-53076 * CVE-2026-53077 * CVE-2026-53089 * CVE-2026-53091 * CVE-2026-53094 * CVE-2026-53096 * CVE-2026-53110 * CVE-2026-53111 * CVE-2026-53126 * CVE-2026-53154 * CVE-2026-53163 * CVE-2026-53207 * CVE-2026-53219 * CVE-2026-53220 * CVE-2026-53223 * CVE-2026-53228 * CVE-2026-53238 * CVE-2026-53260 * CVE-2026-53264 * CVE-2026-53269 * CVE-2026-53273 * CVE-2026-53309 * CVE-2026-53330 * CVE-2026-53336 * CVE-2026-53337 * CVE-2026-53353 * CVE-2026-53365 * CVE-2026-53366 * CVE-2026-53381 * CVE-2026-53388 * CVE-2026-63801 * CVE-2026-63808 * CVE-2026-63810 * CVE-2026-63823 * CVE-2026-63827 * CVE-2026-63828 * CVE-2026-63860 * CVE-2026-63865 * CVE-2026-63868 * CVE-2026-63879 * CVE-2026-63881 * CVE-2026-63886 * CVE-2026-63887 * CVE-2026-63888 * CVE-2026-63889 * CVE-2026-63891 * CVE-2026-63898 * CVE-2026-63920 * CVE-2026-63925 * CVE-2026-63926 * CVE-2026-63928 * CVE-2026-63944 * CVE-2026-63969 * CVE-2026-63970 * CVE-2026-63972 * CVE-2026-63973 * CVE-2026-63980 * CVE-2026-63985 * CVE-2026-63990 * CVE-2026-63992 * CVE-2026-63999 * CVE-2026-64000 * CVE-2026-64001 * CVE-2026-64002 * CVE-2026-64004 * CVE-2026-64005 * CVE-2026-64006 * CVE-2026-64007 * CVE-2026-64010 * CVE-2026-64011 * CVE-2026-64014 * CVE-2026-64015 * CVE-2026-64018 * CVE-2026-64029 * CVE-2026-64034 * CVE-2026-64039 * CVE-2026-64047 * CVE-2026-64048 * CVE-2026-64051 * CVE-2026-64052 * CVE-2026-64073 * CVE-2026-64083 * CVE-2026-64084 * CVE-2026-64085 * CVE-2026-64086 * CVE-2026-64087 * CVE-2026-64088 * CVE-2026-64097 * CVE-2026-64098 * CVE-2026-64102 * CVE-2026-64109 * CVE-2026-64112 * CVE-2026-64113 * CVE-2026-64114 * CVE-2026-64115 * CVE-2026-64118 * CVE-2026-64121 * CVE-2026-64125 * CVE-2026-64126 * CVE-2026-64128 * CVE-2026-64131 * CVE-2026-64133 * CVE-2026-64135 * CVE-2026-64137 * CVE-2026-64148 * CVE-2026-64155 * CVE-2026-64164 * CVE-2026-64166 * CVE-2026-64168 * CVE-2026-64178 * CVE-2026-64185 * CVE-2026-64188 * CVE-2026-64190 * CVE-2026-64192 * CVE-2026-64214 * CVE-2026-64217 * CVE-2026-64218 * CVE-2026-64219 * CVE-2026-64222 * CVE-2026-64225 * CVE-2026-64237 * CVE-2026-64243 * CVE-2026-64245 * CVE-2026-64246 * CVE-2026-64247 * CVE-2026-64249 * CVE-2026-64257 * CVE-2026-64266 * CVE-2026-64268 * CVE-2026-64271 * CVE-2026-64273 * CVE-2026-64274 * CVE-2026-64275 * CVE-2026-64276 * CVE-2026-64277 * CVE-2026-64286 * CVE-2026-64287 * CVE-2026-64294 * CVE-2026-64296 * CVE-2026-64303 * CVE-2026-64304 * CVE-2026-64305 * CVE-2026-64306 * CVE-2026-64312 * CVE-2026-64313 * CVE-2026-64315 * CVE-2026-64316 * CVE-2026-64317 * CVE-2026-64322 * CVE-2026-64323 * CVE-2026-64329 * CVE-2026-64331 * CVE-2026-64332 * CVE-2026-64333 * CVE-2026-64334 * CVE-2026-64335 * CVE-2026-64337 * CVE-2026-64338 * CVE-2026-64340 * CVE-2026-64341 * CVE-2026-64342 * CVE-2026-64343 * CVE-2026-64344 * CVE-2026-64346 * CVE-2026-64348 * CVE-2026-64350 * CVE-2026-64351 * CVE-2026-64355 * CVE-2026-64358 * CVE-2026-64362 * CVE-2026-64365 * CVE-2026-64375 * CVE-2026-64376 * CVE-2026-64378 * CVE-2026-64381 * CVE-2026-64382 * CVE-2026-64383 * CVE-2026-64384 * CVE-2026-64385 * CVE-2026-64386 * CVE-2026-64387 * CVE-2026-64388 * CVE-2026-64401 * CVE-2026-64403 * CVE-2026-64406 * CVE-2026-64408 * CVE-2026-64409 * CVE-2026-64411 * CVE-2026-64412 * CVE-2026-64420 * CVE-2026-64421 * CVE-2026-64423 * CVE-2026-64427 * CVE-2026-64429 * CVE-2026-64433 * CVE-2026-64434 * CVE-2026-64436 * CVE-2026-64440 * CVE-2026-64442 * CVE-2026-64443 * CVE-2026-64444 * CVE-2026-64445 * CVE-2026-64448 * CVE-2026-64450 * CVE-2026-64454 * CVE-2026-64455 * CVE-2026-64463 * CVE-2026-64470 * CVE-2026-64471 * CVE-2026-64472 * CVE-2026-64478 * CVE-2026-64479 * CVE-2026-64480 * CVE-2026-64481 * CVE-2026-64482 * CVE-2026-64483 * CVE-2026-64484 * CVE-2026-64486 * CVE-2026-64487 * CVE-2026-64489 * CVE-2026-64494 * CVE-2026-64495 * CVE-2026-64496 * CVE-2026-64497 * CVE-2026-64500 * CVE-2026-64503 * CVE-2026-64504 * CVE-2026-64505 * CVE-2026-64511 * CVE-2026-64512 * CVE-2026-64513 * CVE-2026-64524 * CVE-2026-64527 * CVE-2026-64536 * CVE-2026-64537 * CVE-2026-64538 * CVE-2026-64539 * CVE-2026-64540 * CVE-2026-64541 * CVE-2026-64543 * CVE-2026-64544 * CVE-2026-64545 * CVE-2026-64546 * CVE-2026-64547 * CVE-2026-64548 * CVE-2026-64549 * CVE-2026-64551 * CVE-2026-64552 * CVE-2026-64553 * CVE-2026-64554 * CVE-2026-64562 * CVE-2026-64563 * CVE-2026-64565 * CVE-2026-64567 * CVE-2026-64571 * CVE-2026-64572 * CVE-2026-64573 * CVE-2026-64574 * CVE-2026-64576 * CVE-2026-64577 * CVE-2026-64581 * CVE-2026-64582 * CVE-2026-64583 * CVE-2026-64584 * CVE-2026-64585 * CVE-2026-64593 * CVE-2026-64597 * CVE-2026-64598 * CVE-2026-64599 * CVE-2026-64602 * CVE-2026-64604 * CVE-2026-68081 * CVE-2026-68082 * CVE-2026-68085 * CVE-2026-68086 * CVE-2026-68088 * CVE-2026-68091 * CVE-2026-68093 * CVE-2026-68102 * CVE-2026-68104 * CVE-2026-68106 * CVE-2026-68107 * CVE-2026-68108 * CVE-2026-68110 * CVE-2026-68111 * CVE-2026-68112 * CVE-2026-68115 * CVE-2026-68116 * CVE-2026-68117 * CVE-2026-68121 * CVE-2026-68123 * CVE-2026-68125 * CVE-2026-68126 * CVE-2026-68127 * CVE-2026-68129 * CVE-2026-68132 * CVE-2026-68133 * CVE-2026-68136 * CVE-2026-68137 * CVE-2026-68138 * CVE-2026-68139 * CVE-2026-68142 * CVE-2026-68143 * CVE-2026-68145 * CVE-2026-68149 * CVE-2026-68153 * CVE-2026-68154 * CVE-2026-68155 * CVE-2026-68156 * CVE-2026-68157 * CVE-2026-68158 * CVE-2026-68159 * CVE-2026-68160 * CVE-2026-68161 * CVE-2026-68162 * CVE-2026-68166 * CVE-2026-68180 * CVE-2026-68181 * CVE-2026-68182 * CVE-2026-68184 * CVE-2026-68188 * CVE-2026-68189 * CVE-2026-68192 * CVE-2026-68193 * CVE-2026-68194 * CVE-2026-68195 * CVE-2026-68196 * CVE-2026-68197 * CVE-2026-68199 * CVE-2026-68202 * CVE-2026-68204 * CVE-2026-68205 * CVE-2026-68206 * CVE-2026-68207 * CVE-2026-68209 * CVE-2026-68210 * CVE-2026-68212 * CVE-2026-68213 * CVE-2026-68214 * CVE-2026-68215 * CVE-2026-68216 * CVE-2026-68217 * CVE-2026-68218 * CVE-2026-68219 * CVE-2026-68220 * CVE-2026-68222 * CVE-2026-68223 * CVE-2026-68226 * CVE-2026-68227 * CVE-2026-68229 * CVE-2026-68231 * CVE-2026-68234 * CVE-2026-68236 * CVE-2026-68238 * CVE-2026-68243 * CVE-2026-68244 * CVE-2026-68246 * CVE-2026-68247 * CVE-2026-68248 * CVE-2026-68249 * CVE-2026-68250 * CVE-2026-68251 * CVE-2026-68254 * CVE-2026-68255 * CVE-2026-68256 * CVE-2026-68259 * CVE-2026-68269 * CVE-2026-68271 * CVE-2026-68272 * CVE-2026-68277 * CVE-2026-68278 * CVE-2026-68279 * CVE-2026-68280 * CVE-2026-68284 * CVE-2026-68286 * CVE-2026-68288 * CVE-2026-68289 * CVE-2026-68293 * CVE-2026-68297 * CVE-2026-68299 * CVE-2026-68300 * CVE-2026-68303 * CVE-2026-68304 * CVE-2026-68306 * CVE-2026-68308 * CVE-2026-68309 * CVE-2026-68310 * CVE-2026-68312 * CVE-2026-68313 * CVE-2026-68315 * CVE-2026-68320 * CVE-2026-68322 * CVE-2026-68324 * CVE-2026-68325 * CVE-2026-68326 * CVE-2026-68327 * CVE-2026-68328 * CVE-2026-68329 * CVE-2026-68331 * CVE-2026-68333 * CVE-2026-68335 * CVE-2026-68336 * CVE-2026-68339 * CVE-2026-68340 * CVE-2026-68343 * CVE-2026-68346 * CVE-2026-68348 * CVE-2026-68349 * CVE-2026-68350 * CVE-2026-68351 * CVE-2026-68352 * CVE-2026-68353 * CVE-2026-68354 * CVE-2026-68355 * CVE-2026-68357 * CVE-2026-68359 * CVE-2026-68360 * CVE-2026-68361 * CVE-2026-68362 * CVE-2026-68363 * CVE-2026-68365 * CVE-2026-68366 * CVE-2026-68368 * CVE-2026-68369 * CVE-2026-68370 * CVE-2026-68372 * CVE-2026-68373 * CVE-2026-68377 * CVE-2026-68386 * CVE-2026-68391 * CVE-2026-68392 * CVE-2026-68397 * CVE-2026-68398 * CVE-2026-68399 * CVE-2026-68402 * CVE-2026-68403 * CVE-2026-68405 * CVE-2026-68406 * CVE-2026-68407 * CVE-2026-68408 * CVE-2026-68410 * CVE-2026-68413 * CVE-2026-68414 * CVE-2026-68417 * CVE-2026-68418 * CVE-2026-68419 * CVE-2026-68422 * CVE-2026-68425 * CVE-2026-68426 * CVE-2026-68427 * CVE-2026-68428 * CVE-2026-68429 * CVE-2026-68430 * CVE-2026-68432 * CVE-2026-68433 * CVE-2026-68434 * CVE-2026-68444 * CVE-2026-68445 * CVE-2026-68446 * CVE-2026-68450 * CVE-2026-68470 * CVE-2026-68480 * CVE-2026-72020 * CVE-2026-72035 * CVE-2026-72036 * CVE-2026-72069 * CVE-2026-72072 * CVE-2026-72083 * CVE-2026-72084 * CVE-2026-72123 * CVE-2026-72132 * CVE-2026-72221 * CVE-2026-72222 * CVE-2026-72251 * CVE-2026-72254 * CVE-2026-72262 * CVE-2026-72288 * CVE-2026-72289 * CVE-2026-72296 * CVE-2026-72307 * CVE-2026-72308 * CVE-2026-72317 * CVE-2026-72341 * CVE-2026-72342 * CVE-2026-72343 * CVE-2026-72389 * CVE-2026-72463 * CVE-2026-72464 * CVE-2026-72466 * CVE-2026-72467 * CVE-2026-72469 * CVE-2026-72473 * CVE-2026-72494 * CVE-2026-72495 * CVE-2026-72496 * CVE-2026-72499 * CVE-2026-72501 * CVE-2026-72502 * CVE-2026-74269 * CVE-2026-74296 * CVE-2026-74297 * CVE-2026-74318 * CVE-2026-74321 * CVE-2026-74334 * CVE-2026-74345 * CVE-2026-74394 * CVE-2026-74395 * CVE-2026-74454 * CVE-2026-74474 * CVE-2026-74481 * CVE-2026-74482 * CVE-2026-74488 * CVE-2026-74495 * CVE-2026-74496 * CVE-2026-74509 * CVE-2026-74510 * CVE-2026-74512 * CVE-2026-74516 * CVE-2026-74518 * CVE-2026-74527 * CVE-2026-74537 * CVE-2026-74548 * CVE-2026-74550 * CVE-2026-74556 * CVE-2026-74563 * CVE-2026-74566 * CVE-2026-74567 * CVE-2026-74571 * CVE-2026-74581 * CVE-2026-74582 * CVE-2026-74584 * CVE-2026-74610 * CVE-2026-74669 * CVE-2026-74692 * CVE-2026-74694 * CVE-2026-74695 * CVE-2026-74717 * CVE-2026-74722 * CVE-2026-80529 * CVE-2026-80534 * CVE-2026-80590 * CVE-2026-80654 CVSS scores: * CVE-2024-44981 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L * CVE-2024-44981 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2024-44981 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-57841 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-38469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39964 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-39964 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-39964 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-39964 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-40022 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-40022 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-68179 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68179 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68214 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71104 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2025-71104 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-71104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23210 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23230 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23230 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23230 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-23230 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23454 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23454 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23454 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31392 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-31392 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-31392 ( NVD ): 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L * CVE-2026-31418 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31418 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31531 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31557 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31663 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31663 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43116 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43163 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43271 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43271 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43271 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43319 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43319 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45897 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45897 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45897 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46070 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46070 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46091 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46091 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46091 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46107 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46107 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46107 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46115 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46115 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46195 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46195 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52920 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-52920 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-52925 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52925 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52925 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52939 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52939 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52977 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52977 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52990 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53033 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53059 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53059 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53059 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53076 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53076 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53077 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53077 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53077 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53089 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53089 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53091 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53091 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53091 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-53091 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53094 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53094 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53096 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53096 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53110 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53111 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53111 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53111 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53207 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53228 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53228 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53238 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53238 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53269 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53269 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53269 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53309 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53309 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53309 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53330 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53330 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53336 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53336 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53353 ( SUSE ): 0.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53353 ( SUSE ): 0.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N * CVE-2026-53353 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53365 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53365 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53365 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53381 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63801 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63801 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63801 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63808 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63808 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-63808 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63810 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63810 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63823 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63823 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63823 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63827 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63828 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63828 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63828 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-63860 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63860 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63860 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63865 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63865 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63865 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-63868 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63868 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63879 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63879 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63879 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63881 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63886 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63886 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63886 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63887 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63887 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63887 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63888 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63888 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63888 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63889 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63889 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63889 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63891 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63891 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63898 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63898 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63920 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63920 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63920 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63925 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63925 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63925 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-63926 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63926 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63926 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63928 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63928 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63944 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63944 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63969 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63969 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63970 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63970 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63972 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63972 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63972 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63973 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63973 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63980 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63985 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63985 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63985 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63990 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63990 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63992 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63992 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63992 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63999 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63999 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64000 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64000 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64000 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64001 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64001 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64002 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64002 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64002 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64004 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64004 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64005 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64005 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64005 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64006 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-64006 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-64007 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64007 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64007 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64010 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64011 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64014 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64014 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64015 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64015 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64018 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-64018 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-64018 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64029 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64029 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64029 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64034 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64039 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64039 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64039 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64047 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64047 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64048 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64048 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64048 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64051 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64051 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64051 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64052 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64052 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64052 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64073 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64073 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64073 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64083 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64083 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64083 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64084 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64084 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64084 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64085 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64085 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64085 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64086 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64086 ( SUSE ): 5.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64086 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64087 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64087 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64087 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64088 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64088 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64088 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64097 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64097 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64097 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64098 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64102 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-64102 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-64102 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64113 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64113 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64114 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64115 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64118 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64118 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64118 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64121 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64121 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64121 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64125 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64126 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64126 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L * CVE-2026-64126 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-64128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64128 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64135 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64137 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64137 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64137 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64148 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64148 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64148 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64155 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64164 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64166 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64178 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64178 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64185 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64185 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64188 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64188 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64188 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64190 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64190 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64190 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64217 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64217 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64217 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64218 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64219 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64222 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64222 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64222 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64225 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64225 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64225 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64237 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64237 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64245 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64246 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64246 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64246 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64247 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64247 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-64249 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64249 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64257 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64257 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-64257 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64266 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64266 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64268 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64271 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64271 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64271 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64273 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64275 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64275 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64277 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64286 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64286 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64287 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64303 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64303 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64303 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64304 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64305 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64305 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64306 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64313 ( SUSE ): 7.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-64313 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64313 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64315 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64316 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64316 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64317 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64317 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64317 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64322 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64322 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64322 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64323 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64323 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64329 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64329 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64329 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64331 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64331 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64333 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64333 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64334 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64334 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64334 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64335 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64335 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64335 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64337 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64337 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64338 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64340 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64340 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64340 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64341 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64342 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64343 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64344 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64346 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64348 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64348 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64348 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64350 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64350 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64350 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64351 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64351 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64351 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64355 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64355 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64358 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64358 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64365 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64375 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64375 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64376 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64376 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64376 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64381 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64381 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64382 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64382 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64383 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64383 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64384 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64385 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64386 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64387 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64388 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64388 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-64388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64401 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64401 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64403 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64403 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64403 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64406 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64408 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64409 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64409 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64411 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64411 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64411 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64412 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64412 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64412 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64420 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64421 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64421 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64427 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64427 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64434 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64436 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64436 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64440 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64440 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64440 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64442 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64442 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64443 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64443 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64444 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64444 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64444 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64445 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64448 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64448 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64450 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64454 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64471 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64478 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64478 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64479 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64480 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64481 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64481 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64482 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64482 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64483 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64484 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64484 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64486 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64487 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64489 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64497 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64500 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64503 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64504 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64505 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64511 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64511 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64512 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64513 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64527 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64537 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64537 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64538 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64540 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64540 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64540 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64541 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64541 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64541 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64544 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64544 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64545 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64547 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64547 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64547 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64548 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64548 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64549 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64551 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64551 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64552 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64552 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64552 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64553 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64562 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64562 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64563 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64563 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64565 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64565 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64567 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64567 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64567 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64571 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64571 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64572 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64572 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64573 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64573 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64574 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64576 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64576 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64576 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64577 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64577 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64577 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64581 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64581 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64581 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64582 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64583 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64583 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64584 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64585 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64593 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64593 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64598 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64598 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64599 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64599 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64602 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64604 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68081 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68081 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68082 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68082 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68082 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68085 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68085 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68085 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68086 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-68086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-68088 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68088 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68091 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68091 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68091 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68093 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-68093 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68102 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68102 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68104 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68106 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68106 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68106 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68107 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68107 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68107 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68108 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68108 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68108 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68110 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68110 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68111 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68111 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68115 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68115 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68116 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68116 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-68116 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68117 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68117 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68121 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68121 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68123 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68123 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68123 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68125 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68125 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68125 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68126 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68126 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68127 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68127 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68127 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68129 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68129 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68129 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68132 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68132 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68133 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68133 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68136 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68136 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68137 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68139 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68139 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68142 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68142 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-68142 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68143 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68143 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68143 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68145 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68145 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68145 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68149 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68149 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68149 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-68153 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68153 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68153 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68154 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68154 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68154 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68155 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68155 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68155 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68156 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68156 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68156 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68157 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68157 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68157 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68158 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68158 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68158 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68159 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68159 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68159 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68160 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68160 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68160 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68161 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68161 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68161 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68162 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68166 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68166 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68180 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68182 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68184 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68184 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68188 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68192 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68192 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68197 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68202 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68204 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68207 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68210 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68210 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68212 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68217 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68218 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68218 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68219 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68219 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68220 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68220 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68222 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68223 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68223 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68226 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68226 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68227 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68227 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68229 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68229 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-68229 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68231 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68231 ( SUSE ): 2.1 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68234 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68236 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68236 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68236 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68238 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68238 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68243 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68244 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68246 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68246 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68247 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68247 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68248 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68249 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68250 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68250 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68251 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68251 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68256 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68259 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68259 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68269 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68271 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68272 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68278 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68278 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68279 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68279 ( SUSE ): 2.4 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68280 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68280 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68284 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68284 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68286 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68286 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68288 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68288 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68289 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68293 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68293 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68299 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68308 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68309 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68310 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68312 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68313 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-68322 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68324 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68325 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68327 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68327 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68328 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68333 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68343 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68349 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68350 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68351 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68353 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68353 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68354 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68355 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68357 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68359 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68360 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68361 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68365 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68365 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-68366 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68368 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68369 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68370 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68372 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68377 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68377 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68386 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68391 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68391 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68392 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68392 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68402 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68402 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68403 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68405 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68406 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68407 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68408 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68410 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68413 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68414 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68414 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68422 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68425 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68425 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68426 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68426 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68427 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68427 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68427 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68428 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68430 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68430 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68433 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-68434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68444 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68445 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68445 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68445 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68446 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68446 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68470 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68470 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68470 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68480 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-72020 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72020 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72020 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72035 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72036 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72069 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72083 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72084 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72123 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72132 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72132 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72221 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72221 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72221 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72222 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72251 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72251 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72251 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72254 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72262 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72262 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72288 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72289 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72289 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72289 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72296 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72296 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72296 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-72307 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72307 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72308 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72308 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72317 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72317 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72317 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72341 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72342 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72342 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72343 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72343 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72389 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72463 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72463 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72464 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72464 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72467 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72473 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-72473 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72494 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72495 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72496 ( NVD ): 9.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H * CVE-2026-72499 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72499 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72501 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74269 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74269 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74318 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74345 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74345 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74345 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74394 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74395 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74395 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74454 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74454 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-74454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74474 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74474 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74481 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74482 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74482 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74488 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74488 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74495 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74495 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74509 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74509 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74516 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-74516 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74518 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74518 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74527 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-74527 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74537 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74537 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74550 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74550 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74556 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-74556 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74563 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74566 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-74567 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74567 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74571 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74581 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74581 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74582 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74584 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-74584 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-74584 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-74610 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-74610 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74610 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74692 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74694 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74694 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74695 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74695 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74717 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74717 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74722 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80534 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80534 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80590 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-80654 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80654 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 588 vulnerabilities and has 23 fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 kernel was updated to fix various security issues: The following security issues were fixed: * CVE-2024-57841: net: fix memory leak in tcp_conn_request() (bsc#1269731). * CVE-2025-68214: timers: Fix NULL function pointer race in timer_shutdown_sync() (bsc#1255225). * CVE-2025-71075: scsi: aic94xx: fix use-after-free in device removal path (bsc#1256629). * CVE-2026-31392: smb: client: fix krb5 mount with username option (bsc#1261788). * CVE-2026-31418: netfilter: ipset: drop logically empty buckets in mtype_del (bsc#1262073). * CVE-2026-31531: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() (bsc#1263004). * CVE-2026-31557: nvmet: move async event work off nvmet-wq (bsc#1263061). * CVE-2026-31663: xfrm: hold device only for the asynchronous decryption (bsc#1263133). * CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack (bsc#1264619). * CVE-2026-43125: dlm: validate length in dlm_search_rsb_tree (bsc#1264541). * CVE-2026-43163: md/bitmap: fix GPF in write_page caused by resize race (bsc#1264335). * CVE-2026-43271: md-cluster: fix NULL pointer dereference in process_metadata_update (bsc#1264587). * CVE-2026-43273: ceph: supply snapshot context in ceph_zero_partial_object() (bsc#1264446). * CVE-2026-43278: dm: clear cloned request bio pointer when last clone bio completes (bsc#1264584). * CVE-2026-43319: spi: spidev: fix lock inversion between spi_lock and buf_lock (bsc#1264788). * CVE-2026-43363: x86/apic: Disable x2apic on resume if the kernel expects so (bsc#1265068). * CVE-2026-43416: powerpc, perf: Check that current->mm is alive before getting user callchain (bsc#1265121). * CVE-2026-45897: bpf: Fix UAF in sock clone early bailouts (bsc#1266897). * CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). * CVE-2026-46070: md/raid5: validate payload size before accessing journal metadata (bsc#1267501). * CVE-2026-46091: media: rc: igorplugusb: heed coherency rules (bsc#1267238). * CVE-2026-46107: dm-thin: fix metadata refcount underflow (bsc#1267612). * CVE-2026-46115: block: add pgmap check to biovec_phys_mergeable (bsc#1266874). * CVE-2026-46195: smb: client: validate dacloffset before building DACL pointers (bsc#1266860). * CVE-2026-52920: netfilter: xt_policy: fix strict mode inbound policy matching (bsc#1269013). * CVE-2026-52925: vrf: Fix a potential NPD when removing a port from a VRF (bsc#1268987). * CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). * CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send (bsc#1268979). * CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion (bsc#1268972). * CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (bsc#1269113). * CVE-2026-52975: bonding: 802.3ad replace MAC_ADDRESS_EQUAL with __agg_has_partner (bsc#1269234). * CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). * CVE-2026-52990: fsnotify: fix inode reference leak in fsnotify_recalc_mask() (bsc#1269108). * CVE-2026-52994: vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting (bsc#1269126). * CVE-2026-53001: netfilter: xtables: restrict several matches to inet family (bsc#1269114). * CVE-2026-53033: bpf, sockmap: Take state lock for af_unix iter (bsc#1269388). * CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). * CVE-2026-53076: bpf: Fix OOB in pcpu_init_value (bsc#1269695). * CVE-2026-53077: net/rds: Restrict use of RDS/IB to the initial network namespace (bsc#1269412). * CVE-2026-53089: bpf: Fix use-after-free in offloaded map/prog info fill (bsc#1269783). * CVE-2026-53091: net: account for encap headers in qdisc pkt len (bsc#1269530). * CVE-2026-53094: bpf: Fix stale offload->prog pointer after constant blinding (bsc#1269965). * CVE-2026-53096: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (bsc#1269969). * CVE-2026-53110: selftests/bpf: Add ASSERT_OK_FD macro (bsc#1269985). * CVE-2026-53111: bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap (bsc#1269167). * CVE-2026-53126: blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() (bsc#1269635). * CVE-2026-53154: mm/hugetlb: restore reservation on error in hugetlb folio copy paths (bsc#1269665). * CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). * CVE-2026-53207: mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison (bsc#1269590). * CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers (bsc#1269686). * CVE-2026-53220: netfilter: revalidate bridge ports (bsc#1269381). * CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs (bsc#1269301). * CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads (bsc#1269256). * CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths (bsc#1269774). * CVE-2026-53260: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req() (bsc#1269731) * CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). * CVE-2026-53269: netfilter: synproxy: add mutex to guard hook reference counting (bsc#1269579). * CVE-2026-53273: tee: optee: prevent use-after-free when the client exits before the supplicant (bsc#1269713). * CVE-2026-53309: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (bsc#1269815). * CVE-2026-53330: drm/amd/display: Fix out-of-bounds read in (bsc#1270090). * CVE-2026-53336: nvmem: layouts: onie-tlv: fix hang on unknown types (bsc#1270108). * CVE-2026-53337: net: bonding: fix NULL pointer dereference in bond_do_ioctl() (bsc#1270251). * CVE-2026-53353: hsr: Remove WARN_ONCE() in hsr_addr_is_self() (bsc#1270111). * CVE-2026-53365: vsock/virtio: fix zerocopy completion for multi-skb sends (bsc#1271365). * CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). * CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). * CVE-2026-63808: exfat: fix potential use-after-free in exfat_find_dir_entry() (bsc#1272260). * CVE-2026-63810: block: Avoid mounting the bdev pseudo-filesystem in userspace (bsc#1272297). * CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). * CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179). * CVE-2026-63828: apparmor: mediate the implicit connect of TCP fast open sendmsg (bsc#1272175). * CVE-2026-63860: RDMA/core: Prefer NLA_NUL_STRING (bsc#1272429). * CVE-2026-63865: bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (bsc#1272486). * CVE-2026-63868: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (bsc#1272497). * CVE-2026-63879: drm/amdgpu: fix amdgpu_hmm_range_get_pages (bsc#1272569). * CVE-2026-63881: drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger (bsc#1272571). * CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). * CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). * CVE-2026-63889: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (bsc#1272423). * CVE-2026-63891: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (bsc#1272641). * CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). * CVE-2026-63925: macsec: fix replay protection at XPN lower-PN wrap (bsc#1273008). * CVE-2026-63926: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (bsc#1273019). * CVE-2026-63944: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (bsc#1272662). * CVE-2026-63969: ipv6: fix possible infinite loop in rt6_fill_node() (bsc#1272484). * CVE-2026-63970: vsock/virtio: bind uarg before filling zerocopy skb (bsc#1272673). * CVE-2026-63980: net/handshake: Use spin_lock_bh for hn_lock (bsc#1273028). * CVE-2026-63985: ethtool: eeprom: add more safeties to EEPROM Netlink fallback (bsc#1272963). * CVE-2026-63990: bonding: refuse to enslave CAN devices (bsc#1273027). * CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). * CVE-2026-63999: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure (bsc#1273038). * CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273030). * CVE-2026-64001: ALSA: pcm: oss: Fix setup list UAF on proc write error (bsc#1273734). * CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). * CVE-2026-64004: net/iucv: fix locking in .getsockopt (bsc#1273804). * CVE-2026-64005: net/smc: Do not re-initialize smc hashtables (bsc#1273831). * CVE-2026-64006: netfilter: nf_tables: fix dst corruption in same register operation (bsc#1273834). * CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). * CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882). * CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891). * CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762). * CVE-2026-64029: ALSA: seq: Serialize UMP output teardown with event_input (bsc#1273766). * CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). * CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). * CVE-2026-64052: block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() (bsc#1272983). * CVE-2026-64073: irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT (bsc#1273490). * CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488). * CVE-2026-64102: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (bsc#1272516). * CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748). * CVE-2026-64112: rbd: eliminate a race in lock_dwork draining on unmap (bsc#1273741). * CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning (bsc#1272262). * CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). * CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). * CVE-2026-64118: qed: fix double free in qed_cxt_tables_alloc() (bsc#1273749). * CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273743). * CVE-2026-64125: net: bcmgenet: keep RBUF EEE/PM disabled (bsc#1272346). * CVE-2026-64131: mm/memory: fix spurious warning when unmapping device- private/exclusive pages (bsc#1274063). * CVE-2026-64148: pds_core: check health in devcmd wait (bsc#1273956). * CVE-2026-64164: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (bsc#1273957). * CVE-2026-64185: sysfs: don't remove existing directory on update failure (bsc#1272200). * CVE-2026-64188: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (bsc#1272150). * CVE-2026-64190: net: team: fix NULL pointer dereference in team_xmit during mode change (bsc#1272210). * CVE-2026-64192: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (bsc#1272213). * CVE-2026-64214: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() (bsc#1272799). * CVE-2026-64217: netfs: Fix overrun check in netfs_extract_user_iter() (bsc#1272798). * CVE-2026-64222: octeontx2-pf: avoid double free of pool->stack on AQ init failure (bsc#1272788). * CVE-2026-64225: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (bsc#1272786). * CVE-2026-64245: fbdev: modedb: fix a possible UAF in fb_find_mode() (bsc#1273905). * CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). * CVE-2026-64286: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (bsc#1274058). * CVE-2026-64287: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (bsc#1273325). * CVE-2026-64294: mm: do file ownership checks with the proper mount idmap (bsc#1273525). * CVE-2026-64296: exfat: bound uniname advance in exfat_find_dir_entry() (bsc#1273975). * CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944). * CVE-2026-64312: crypto: pcrypt - restore callback for non-parallel fallback (bsc#1273968). * CVE-2026-64315: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1274028). * CVE-2026-64316: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1273598). * CVE-2026-64317: isofs: bound Rock Ridge symlink components to the SL record (bsc#1273936). * CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count (bsc#1273958). * CVE-2026-64323: udf: validate VAT header length against the VAT inode size (bsc#1273305). * CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). * CVE-2026-64375: proc: protect ptrace_may_access() with exec_update_lock (FD links) (bsc#1273868). * CVE-2026-64378: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() (bsc#1273603). * CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard() (bsc#1273860). * CVE-2026-64382: smb: client: fix double-free in SMB2_open() replay (bsc#1273291). * CVE-2026-64383: smb: client: fix double-free in SMB2_flush() replay (bsc#1273426). * CVE-2026-64384: smb: client: fix change notify replay double-free (bsc#1274541). * CVE-2026-64385: smb: client: fix double-free in SMB2_ioctl() replay (bsc#1274539). * CVE-2026-64386: smb: client: fix query_info() replay double-free (bsc#1274543). * CVE-2026-64387: smb: client: fix query directory replay double-free (bsc#1274545). * CVE-2026-64388: smb/client: fix chown/chgrp with SMB3 POSIX Extensions (bsc#1274061). * CVE-2026-64411: netfilter: ebtables: terminate table name before find_table_lock() (bsc#1274077). * CVE-2026-64412: netfilter: ebtables: module names must be null-terminated (bsc#1273780). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). * CVE-2026-64434: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (bsc#1273880). * CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states (bsc#1274277). * CVE-2026-64448: smb: client: restrict implied bcc[0] exemption to responses without data area (bsc#1273982). * CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). * CVE-2026-64463: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres (bsc#1273273). * CVE-2026-64472: vfio/mlx5: Fix racy bitfields and tighten struct layout (bsc#1274075). * CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547). * CVE-2026-64537: bridge: cfm: reject invalid CCM interval at configuration time (bsc#1273289). * CVE-2026-64538: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change() (bsc#1273335). * CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). * CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). * CVE-2026-64545: net, bpf: check master for NULL in xdp_master_redirect() (bsc#1273318). * CVE-2026-64548: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (bsc#1273337). * CVE-2026-64551: sctp: validate STALE_COOKIE cause length before reading staleness (bsc#1273813). * CVE-2026-64552: virtio-net: fix len check in receive_big() (bsc#1273323). * CVE-2026-64553: net: psample: fix info leak in PSAMPLE_ATTR_DATA (bsc#1273336). * CVE-2026-64554: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (bsc#1273340). * CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930). * CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). * CVE-2026-64567: btrfs: reject free space cache with more entries than pages (bsc#1274006). * CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). * CVE-2026-64576: nexthop: initialize extack in nh_res_bucket_migrate() (bsc#1274030). * CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031). * CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). * CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (bsc#1274040). * CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497). * CVE-2026-64597: smb: client: fix double-free in SMB2_close() replay (bsc#1274297). * CVE-2026-64598: smb/client: Fix error code in smb2_aead_req_alloc() (bsc#1274298). * CVE-2026-68081: KVM: nVMX: Add helper to put (unmap) vmcs12 pages (bsc#1274580). * CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers() (bsc#1274581). * CVE-2026-68086: mm/khugepaged: write all dirty file folios when collapsing (bsc#1274713). * CVE-2026-68116: vxlan: mdb: Fix source list corruption on a failed replace (bsc#1274876). * CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (bsc#1274881). * CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). * CVE-2026-68123: openvswitch: fix GSO userspace truncation underflow (bsc#1275169). * CVE-2026-68127: ila: reload IPv6 header after pskb_may_pull in checksum adjust (bsc#1275237). * CVE-2026-68129: gve: fix Rx queue stall on alloc failure (bsc#1275517). * CVE-2026-68132: super: fix emergency thaw deadlock on frozen block devices (bsc#1275553). * CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). * CVE-2026-68139: net/mlx5e: Use sender devcom for MPV master-up (bsc#1275578). * CVE-2026-68142: geneve: require CAP_NET_ADMIN in the device netns for changelink (bsc#1275582). * CVE-2026-68143: net: slip: serialize receive against buffer reallocation (bsc#1275583). * CVE-2026-68145: iomap: fix out-of-bounds bitmap_set() with zero-length range (bsc#1275584). * CVE-2026-68149: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (bsc#1275294). * CVE-2026-68153: libceph: remove debugfs files before client teardown (bsc#1275301). * CVE-2026-68154: libceph: reject zero bucket types in crush_decode (bsc#1275303). * CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). * CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after authorizer update (bsc#1275305). * CVE-2026-68157: libceph: guard missing CRUSH type name lookup (bsc#1275306). * CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). * CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). * CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472). * CVE-2026-68161: sctp: close UDP tunnel sockets during netns teardown (bsc#1274892). * CVE-2026-68166: userfaultfd: prevent registration of special VMAs (bsc#1274930). * CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). * CVE-2026-68205: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (bsc#1274934). * CVE-2026-68238: drm/amdgpu: Release VFCT ACPI table reference (bsc#1275704). * CVE-2026-68247: drm/i915/bios: range check LFP Data Block panel_type2 (bsc#1275817). * CVE-2026-68254: drm/i915/vrr: require valid min/max vfreq for VRR (bsc#1275150). * CVE-2026-68284: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (bsc#1275970). * CVE-2026-68286: drop_monitor: perform u64_stats updates under IRQ-disabled section (bsc#1275973). * CVE-2026-68288: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (bsc#1275975). * CVE-2026-68289: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (bsc#1275976). * CVE-2026-68293: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (bsc#1275091). * CVE-2026-68297: tipc: fix u16 MTU truncation in media and bearer MTU validation (bsc#1275040). * CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (bsc#1275088). * CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL (bsc#1275083). * CVE-2026-68312: cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths (bsc#1274663). * CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit (bsc#1274665). * CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq() (bsc#1274662). * CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (bsc#1274659). * CVE-2026-68322: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (bsc#1274656). * CVE-2026-68324: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (bsc#1274649). * CVE-2026-68325: iommu/amd: Bound the early ACPI HID map (bsc#1274651). * CVE-2026-68328: nfp: Check resource mutex allocation (bsc#1274646). * CVE-2026-68329: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (bsc#1274645). * CVE-2026-68331: dpaa2-eth: put MAC endpoint device on disconnect (bsc#1274642). * CVE-2026-68333: dpaa2-switch: put MAC endpoint device on disconnect (bsc#1274644). * CVE-2026-68335: rds: drop incoming messages that cross network namespace boundaries (bsc#1274640). * CVE-2026-68336: bonding: fix devconf_all NULL dereference when IPv6 is disabled (bsc#1274639). * CVE-2026-68343: smb: client: validate DFS referral PathConsumed (bsc#1274629). * CVE-2026-68377: net/sched: act_tunnel_key: Defer dst_release to RCU callback (bsc#1274831). * CVE-2026-68386: bpf, sockmap: Reject unhashed UDP sockets on sockmap update (bsc#1274814). * CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). * CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). * CVE-2026-68408: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (bsc#1274709). * CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). * CVE-2026-68418: RDMA/irdma: Prevent user-triggered null deref on QP create (bsc#1274690). * CVE-2026-68419: RDMA/irdma: Prevent rereg_mr for non-mem regions (bsc#1274698). * CVE-2026-68422: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (bsc#1274706). * CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1274700). * CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). * CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink (bsc#1274800). * CVE-2026-68433: libceph: bound get_version reply decode to front len (bsc#1274801). * CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert (bsc#1274834). * CVE-2026-68470: wifi: cfg80211/mac80211: correctly parse S1G beacon optional elements (bsc#1276500). * CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). * CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). * CVE-2026-72035: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1276961). * CVE-2026-72036: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1277034). * CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). * CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155). * CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). * CVE-2026-72084: scsi: target: Bound PR-OUT TransportID parsing to the received buffer (bsc#1275540). * CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523). * CVE-2026-72132: NFS: Charge unstable writes by request size, not folio size (bsc#1277551). * CVE-2026-72221: sunrpc: wait for in-flight TLS handshake callback when cancel loses race (bsc#1275665). * CVE-2026-72222: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback (bsc#1275669). * CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). * CVE-2026-72254: netfilter: nft_fib: reject fib expression on the netdev egress hook (bsc#1277204). * CVE-2026-72262: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (bsc#1277678). * CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). * CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). * CVE-2026-72296: net: ife: require ETH_HLEN to be pullable in ife_decode() (bsc#1275923). * CVE-2026-72307: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (bsc#1277160). * CVE-2026-72308: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (bsc#1277159). * CVE-2026-72317: SUNRPC: pin upper rpc_clnt across the TLS connect_worker (bsc#1275925). * CVE-2026-72341: net/mlx5e: Fix publication race for priv->channel_stats[] (bsc#1277660). * CVE-2026-72342: net/mlx5e: Fix HV VHCA stats agent registration race (bsc#1277775). * CVE-2026-72343: net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation (bsc#1277776). * CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). * CVE-2026-72463: xfrm: Fix dev use-after-free in xfrm async resumption (bsc#1268276 bsc#1277064). * CVE-2026-72464: xprtrdma: Remove temp allocation of rpcrdma_rep objects (bsc#1277069). * CVE-2026-72466: xprtrdma: Fix bcall rep leak and unbounded peek (bsc#1277057). * CVE-2026-72467: xprtrdma: Check frwr_wp_create() during connect (bsc#1277059). * CVE-2026-72469: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE (bsc#1277047). * CVE-2026-72473: xprtrdma: Avoid 250 ms delay on backlog wakeup (bsc#1277037). * CVE-2026-72494: RDMA/irdma: Replace waitqueue and flag with completion (bsc#1276941). * CVE-2026-72495: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages (bsc#1276937). * CVE-2026-72496: RDMA/bnxt_re: Proper rollback if the ioremap fails (bsc#1276943). * CVE-2026-72499: RDMA/bnxt_re: Free CQ toggle page after firmware teardown (bsc#1276551). * CVE-2026-72501: RDMA/bnxt_re: Initialize dpi variable to zero (bsc#1276546). * CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (bsc#1276542). * CVE-2026-74269: bnxt: fix head underflow on XDP head-grow (bsc#1276507). * CVE-2026-74296: RDMA/mlx5: Release the HW-provided UAR index rather than the SW one (bsc#1276452). * CVE-2026-74297: RDMA/mlx5: Fix undefined shift of user RQ WQE size (bsc#1276446). * CVE-2026-74318: btrfs: fix deadlock cloning inline extent when using flushoncommit (bsc#1276864). * CVE-2026-74321: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (bsc#1277202). * CVE-2026-74334: RDMA/nldev: Fix locking when accessing mr->pd (bsc#1277095). * CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). * CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). * CVE-2026-74395: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (bsc#1277077). * CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073). * CVE-2026-74474: vxlan: use pskb_network_may_pull() for transmit path header pulls (bsc#1276335). * CVE-2026-74481: mm/page_reporting: use system_freezable_wq to fix UAF during suspend (bsc#1276355). * CVE-2026-74482: mm/huge_memory: unlock i_mmap_rwsem before releasing after- split folios (bsc#1276346). * CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350). * CVE-2026-74495: igbvf: Fix leak in TX DMA error cleanup (bsc#1275864). * CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). * CVE-2026-74509: Bluetooth: hci_sync: Fix advertising data UAFs (bsc#1275946). * CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation (bsc#1275950). * CVE-2026-74512: audit: fix potential use-after-free in audit_del_rule() (bsc#1275954). * CVE-2026-74516: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (bsc#1275797). * CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). * CVE-2026-74527: octeontx2-af: Block VFs from clobbering special CGX PKIND state (bsc#1275805). * CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). * CVE-2026-74548: forcedeth: fix UAF of txrx_stats in nv_remove (bsc#1275695). * CVE-2026-74550: net: do not send ICMP/NDISC Redirects when peer allocation fails (bsc#1275688). * CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). * CVE-2026-74563: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() (bsc#1275574). * CVE-2026-74566: keys: make keyring key-chunk byte order agree with keyring_diff_objects() (bsc#1275566). * CVE-2026-74567: keys: fix out-of-bounds read in keyring_get_key_chunk() (bsc#1275569). * CVE-2026-74571: btrfs: skip global block reserve accounting for rescue mounts (bsc#1275561). * CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782). * CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). * CVE-2026-74584: RDMA/bnxt_re: zero shared page before exposing to userspace (bsc#1277066). * CVE-2026-74610: tls: don't leave a full plaintext sk_msg ring unpushed (bsc#1277054). * CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). * CVE-2026-74692: net/smc: fix TOCTOU race between smc_listen_out() and listener close (bsc#1276927). * CVE-2026-74694: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (bsc#1277625). * CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). * CVE-2026-74717: net/mlx5: fw_tracer, return NULL on create error (bsc#1276569). * CVE-2026-74722: btrfs: fix memory leak in btrfs_do_encoded_write() (bsc#1276561). * CVE-2026-80529: xfs: don't swallow dquot recovery verification errors (bsc#1277688). * CVE-2026-80534: xfs: fix ilock leak on error in xfs_dq_get_next_id (bsc#1277022). * CVE-2026-80590: inet: frags: strip GSO state from fragments before reassembly (bsc#1277275). * CVE-2026-80654: soc: xilinx: Shutdown and free rx mailbox channel (bsc#1277516). The following non security issues were fixed: * accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() (git-fixes). * accessibility: speakup: unregister tty ldisc on later init failures (git- fixes). * ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer (git-fixes). * ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root (git- fixes). * ACPI: pfr_update: fix stack buffer overflow in query_capability() (git- fixes). * ACPI: processor: idle: Expand _LPI package sanity checks (git-fixes). * ACPI: processor: validate MADT IOAPIC entry bounds (git-fixes). * ACPI: scan: fix bus ID cleanup on device_add() failures (git-fixes). * ACPI: video: Release PCI device reference after lookup (git-fixes). * add my missing Reviewed-by: tag. * ALSA: 6fire: bound the MIDI event length from the device (git-fixes). * ALSA: 6fire: Fix UAF at error handling during probe (stable-fixes). * ALSA: bcd2000: clear the URB pointers on disconnect (git-fixes). * ALSA: core: Fix use-after-free in snd_card_do_free() (git-fixes). * ALSA: dummy: Check card index validity at probe (stable-fixes). * ALSA: hda/ext: preserve PPLCCTL bits when clearing reset (git-fixes). * ALSA: hda: Fix connection list comparison in proc output (git-fixes). * ALSA: hpi: Check transport errors during HPI6000 adapter initialization (git-fixes). * ALSA: pcxhr: initialize mutexes before requesting threaded IRQ (git-fixes). * ALSA: seq: midi: Optimize event_input locking with RCU (git-fixes). * ALSA: seq: midi: Serialize input teardown with event_input (git-fixes). * ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion (git-fixes). * ALSA: usb-audio: Complete cleanup after system-resume errors (git-fixes). * ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (git-fixes). * ALSA: usb-audio: fix OOB write on Type II inbound URBs (git-fixes). * ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (git-fixes). * ALSA: usx2y: bound the hwdep mmap fault offset (git-fixes). * ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() (git- fixes). * apparmor: advertise the tcp fast open fix is applied (git-fixes). * ASoC: adau1761: sort the register default table (git-fixes). * ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC (git-fixes). * ASoC: apple: mca: increase SERDES reset delay (git-fixes). * ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (git-fixes). * ASoC: cs35l33: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l34: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l41: sort the register default table (git-fixes). * ASoC: cs35l45: sort the register default table (git-fixes). * ASoC: cs4265: sort the register default table (git-fixes). * ASoC: cx2072x: sort the register default table (git-fixes). * ASoC: dapm: Fix off-by-one check on the second enum channel (git-fixes). * ASoC: fix unmet dependencies on PPC_BESTCOMM and SND_SOC_AC97_BUS (git- fixes). * ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready (git- fixes). * ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure (git-fixes). * ASoC: fsl_audmix: rework runtime PM handling in probe (git-fixes). * ASoC: fsl_easrc: sort the register default table (git-fixes). * AsoC: intel: sst: fix PCI device reference leak on probe failure (git- fixes). * ASoC: max9860: sort the register default table (git-fixes). * ASoC: meson: Keep link pointers valid on realloc failure (git-fixes). * ASoC: ml26124: sort the register default table (git-fixes). * ASoC: pcm512x: sort the register default table (git-fixes). * ASoC: pxa: Use devm_clk_get_optional() for extclk clock (git-fixes). * ASoC: qcom: q6apm: keep the graph start count in sync with the DSP (git- fixes). * ASoC: rt274: sort the register default table (git-fixes). * ASoC: rt286: sort the register default table (git-fixes). * ASoC: rt298: sort the register default table (git-fixes). * ASoC: rt700-sdw: always drain jack work on remove (git-fixes). * ASoC: rt700: drop duplicate reg_default entry (git-fixes). * ASoC: rt700: sort the register default table (git-fixes). * ASoC: rt711-sdca: sort the register default tables (git-fixes). * ASoC: rt711: sort the register default table (git-fixes). * ASoC: rt712-sdca-dmic: sort the register default table (git-fixes). * ASoC: rt715-sdca: drop duplicate reg_default entries (git-fixes). * ASoC: rt715-sdca: sort the register default tables (git-fixes). * ASoC: rt715: sort the register default table (git-fixes). * ASoC: rt1316-sdw: sort the register default table (git-fixes). * ASoC: rt1318-sdw: sort the register default table (git-fixes). * ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get (git-fixes). * ASoC: sgtl5000: sort the register default table (git-fixes). * ASoC: SOF: pcm: Move period/buffer configuration print after platform open (stable-fixes). * ASoC: sof: pcm: use snd_pcm_direction_name() (stable-fixes). * ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() (git- fixes). * ASoC: SOF: validate topology volume range before allocation (git-fixes). * ASoC: sti-sas: sort the register default table (git-fixes). * ASoC: tas2552: sort the register default table (git-fixes). * ASoC: tas2764: sort the register default table (git-fixes). * ASoC: tas2780: sort the register default table (git-fixes). * ASoC: tegra210_i2s: sort the register default table (git-fixes). * ASoC: tegra210_mixer: sort the register default table (git-fixes). * ASoC: tegra: Fix the MIXER enable default value (git-fixes). * ASoC: tegra: Sort MBDRC register defaults (git-fixes). * ASoC: xilinx: formatter_pcm: fix stream_data leak on open error (git-fixes). * ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (git-fixes). * batman-adv: bla: fix freeing of claims on meshif deletion (git-fixes). * batman-adv: bla: prevent CRC corruptions after claim flush (git-fixes). * batman-adv: dat: avoid unaligned fault in IP extraction (git-fixes). * batman-adv: fix stale receive device on merged fragments (git-fixes). * Bluetooth: btintel: Fix diagnostics event detection (git-fixes). * Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path (git-fixes). * Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX (git- fixes). * Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event (git- fixes). * Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() (git- fixes). * Bluetooth: do not leak an hci_conn when a second LE connect is rejected (git-fixes). * Bluetooth: eir: Fix OOB read in eir_get_service_data() (git-fixes). * Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (git-fixes). * Bluetooth: hci_conn: re-enable advertising only for peripheral role (git- fixes). * Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection (git- fixes). * Bluetooth: hci_event: fix LE list UAF on reset (git-fixes). * Bluetooth: hci_event: validate LE Set CIG Parameters response (git-fixes). * Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths (git-fixes). * Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (stable-fixes). * Bluetooth: hci_uart: Fix false success return in hci_uart_setup() (git- fixes). * Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready (git-fixes). * Bluetooth: MGMT: free the mesh send cancel command when it is cancelled (git-fixes). * Bluetooth: MSFT: validate evt_prefix_len against the response length (git- fixes). * Bluetooth: RFCOMM: serialize security confirmation handling (git-fixes). * Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (git- fixes). * Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop (git-fixes). * Bluetooth: virtio_bt: avoid OOB read of build info string (git-fixes). * bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation (git-fixes). * bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET (git-fixes). * bus: ti-sysc: Fix /chosen node reference leak (git-fixes). * cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64) (git-fixes). * can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (stable-fixes). * crypto: aspeed - Propagate platform_get_irq() errors (git-fixes). * crypto: atmel-sha204a - fix heap info leak on I2C transfer failure (git- fixes). * crypto: atmel-tdes - use scatterlist length before DMA mapping (git-fixes). * crypto: ccm - Set rfc4309 maxauthsize from child (git-fixes). * crypto: ccp - Fix memory leak in SEV INIT_EX path (git-fixes). * crypto: ccp - Fix possible deadlock in SEV init failure path (git-fixes). * crypto: doc - Remove extra parenthesis (git-fixes). * crypto: hisilicon/sec2 - fix CCM algorithm long packet failure (git-fixes). * crypto: keembay - Initialize completion before requesting IRQ (git-fixes). * crypto: keembay - publish OF module alias for OCS AES/SM4 (git-fixes). * crypto: mxs-dcp - fix source scatterlist length access (git-fixes). * crypto: qat - cancel work on re-enable SR-IOV timeout (git-fixes). * crypto: qat - clear AES key schedule from stack (git-fixes). * crypto: qce - fix CCM AAD buffer underallocation (git-fixes). * crypto: qce - fix error path in devm_qce_register_algs (git-fixes). * crypto: rk3288 - fail ahash requests on HASH idle timeout (git-fixes). * crypto: sa2ul - stop probe if context pool creation fails (git-fixes). * crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping (git- fixes). * device property: fix infinite loop in fwnode_for_each_child_node() (git- fixes). * dmaengine: dw-edma: Clear stale requests on termination (git-fixes). * dmaengine: dw-edma: Complete descriptors before pausing (git-fixes). * dmaengine: dw-edma: Initialize IRQ data before requesting IRQs (git-fixes). * dmaengine: dw-edma: Serialize abort state updates (git-fixes). * dmaengine: dw-edma: Serialize channel state checks (git-fixes). * dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe (git-fixes). * dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure (git-fixes). * dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal (git-fixes). * dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers (git-fixes). * dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout (git-fixes). * driver core: soc: Unregister bus on early device registration failure (git- fixes). * drm/amd/display: avoid divide-by-zero in __is_lut_linear() (git-fixes). * drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read (git- fixes). * drm/amdgpu/gfx6: Fixup emit_cntxcntl() (git-fixes). * drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets (git-fixes). * drm/amdgpu/gfx6: Use PFP on the compute queues too (git-fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup (git- fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup (git- fixes). * drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check (git- fixes). * drm/amdgpu: cap GTT size to physical RAM on APUs (stable-fixes). * drm/amdgpu: check ASPM on the dGPU host link (git-fixes). * drm/amdgpu: disallow multiple FENCE chunks in one submit (git-fixes). * drm/amdgpu: fix aperture iounmap skipped on device removal (git-fixes). * drm/amdgpu: fix autosuspend cleanup during removal (git-fixes). * drm/amdgpu: Fix UVD decode image min size calculation (stable-fixes). * drm/amdgpu: Fix UVD dpb min size calculation for H264 (stable-fixes). * drm/amdgpu: Fix UVD min buffer sizes (stable-fixes). * drm/amdgpu: Fix VCE 3 ring align_mask (git-fixes). * drm/amdgpu: Implement insert_end for VCE 3 (git-fixes). * drm/amdgpu: Reject UVD message with dimensions above 4096 (stable-fixes). * drm/amdgpu: Reject UVD message with invalid number of h265 refs (stable- fixes). * drm/amdgpu: restore UMD profile pstate after runtime resume (stable-fixes). * drm/amdgpu: validate GEM_CREATE domain combinations (stable-fixes). * drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (stable-fixes). * drm/amdkfd: fix QID bit leak in pqm_create_queue() (stable-fixes). * drm/amdkfd: Handle invalid event type in CRIU event restore (stable-fixes). * drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure (git-fixes). * drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure (git-fixes). * drm/bridge: ps8640: propagate AUX transfer register errors (git-fixes). * drm/bridge: tc358767: clamp the reported AUX read size to the request (git- fixes). * drm/connector: Fix epoch_counter docs to reflect reality (git-fixes). * drm/hibmc: Fix list of formats on the primary plane (git-fixes). * drm/hibmc: Use drm_atomic_helper_check_plane_state() (git-fixes). * drm/i915/fbc: Extract intel_fbc_has_fences() (stable-fixes). * drm/lima: call drm_mm_init() with a valid allocation range (git-fixes). * drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: Drop dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value (git- fixes). * drm/panel-edp: fix i2c adapter leak on probe failure (git-fixes). * drm/panel: samsung-s6d16d0: Power off on prepare failure (git-fixes). * drm/radeon: fix autosuspend cleanup during teardown (git-fixes). * drm/radeon: restore hardware polling in fence_is_signaled to fix performance regression (git-fixes). * drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format (git-fixes). * drm/ssd130x: fix column and row end address in partial updates for ssd132x (git-fixes). * drm/sun4i: crtc: Propagate layer initialization error (git-fixes). * drm/sun4i: Drop node references while building component list (git-fixes). * drm/sun4i: dw-hdmi: Drop TCON TOP port reference (git-fixes). * drm/sun4i: fix refcount leak in sun4i_backend_init_sat() (git-fixes). * drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz (git-fixes). * drm/sun4i: tcon: Drop remote endpoint reference (git-fixes). * drm/sun4i: tcon: Drop TCON TOP device reference (git-fixes). * drm/sun4i: tcon: Set output mux for DSI and LVDS (git-fixes). * drm/sun4i: vi scaler: Fix coefficient selection (git-fixes). * drm/tegra: dsi: Re-add clear enable register if DSI was powered by bootloader (git-fixes). * drm/tve200: add OF module alias for autoloading (git-fixes). * drm: fix race between partial drm_dev_register() failure and ioctl (git- fixes). * drm: lcdif: Wait for vblank before disabling DMA (git-fixes). * drm: Remove unused header in drm_dumb_buffers.c (git-fixes). * ethtool: rss: fix hkey leak when indir_size is 0 (git-fixes). * fbdev: bitblit: bound-check glyph index in bit_cursor() (git-fixes). * fbdev: core: Fix pointer desynchronization in fb_io_read() (git-fixes). * fbdev: kyro: Validate overlay viewport coordinates (git-fixes). * fbdev: omapfb: panel-dsi-cm: initialize lock before registering display (git-fixes). * fbdev: ssd1307fb: defer I2C transfers from damage callbacks (git-fixes). * fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() (git-fixes). * fbdev: uvesafb: unregister connector callback on init failure (git-fixes). * firmware: arm_scmi: Avoid IDR updates while cleaning channels (git-fixes). * firmware: arm_scmi: Drop handle on protocol bind failures (git-fixes). * firmware: arm_scmi: Fix requested device removal race (git-fixes). * firmware: arm_scmi: Free transport channel on IDR failure (git-fixes). * firmware: arm_scmi: Protect device request lookup with RCU (git-fixes). * firmware: arm_scmi: Reject out of range DT protocol IDs (git-fixes). * firmware: arm_scmi: Unregister device notifier before IDR teardown (git- fixes). * firmware: arm_scmi: Use channel ID for transport teardown (git-fixes). * firmware_loader: do not queue completed sysfs fallback requests (git-fixes). * fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write (git- fixes). * fpga: dfl: fme: add error handling (git-fixes). * fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration (git- fixes). * gpu: host1x: Avoid stack over-read in debug output helpers (git-fixes). * gpu: host1x: Fix offset calculation in trace_write_gather (git-fixes). * HID: core: fix number/pointer type confusion on long items (git-fixes). * HID: core: fix OOB read of field->usage in hid_set_field() (git-fixes). * HID: hyperv: validate initial device info bounds (git-fixes). * HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure (git-fixes). * HID: lg4ff: validate report length before fixed offsets (git-fixes). * HID: logitech-dj: Fix maxfield check in DJ short report validation (git- fixes). * HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (git- fixes). * HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (stable-fixes). * HID: logitech-dj: Standardise hid_report_enum variable nomenclature (stable- fixes). * HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID (stable-fixes). * HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (git- fixes). * HID: mcp2221: validate report size in mcp2221_raw_event() (git-fixes). * HID: nintendo: Fix imu_timestamp_us double increment per report (git-fixes). * HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() (git- fixes). * HID: picolcd: clamp eeprom debugfs read to bytes actually received (git- fixes). * HID: roccat: bound device-supplied profile index (git-fixes). * HID: roccat: free buffered reports when destroying device (git-fixes). * HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature (git- fixes). * HID: sensor: custom: Fix field sysfs group cleanup on failure (git-fixes). * HID: sensor: custom: Fix use-after-free in enable_sensor (git-fixes). * HID: tmff: Use 64-bit arithmetic for force feedback scaling (git-fixes). * hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (git-fixes). * hwmon: (lm25066) Use i2c_get_match_data() (stable-fixes). * hwmon: (max6621) fix negative temperature offset and crit readings (git- fixes). * hwmon: (max6621) fix temperature clamp range (git-fixes). * hwmon: (nzxt-smart2) Check return value of init_device() in probe (git- fixes). * hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (git-fixes). * hwrng: ks-sa - Fix runtime PM cleanup on registration failure (git-fixes). * hwrng: omap - Fix probe error path cleanup (git-fixes). * hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() (git- fixes). * i2c: bcm-iproc: remove printout on handled timeouts (stable-fixes). * i2c: iproc: reset bus after timeout if START_BUSY is stuck (git-fixes). * i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure (git-fixes). * i2c: mux: Fix channel node leak on adapter add failure (git-fixes). * i2c: ocores: Disable clock on failed resume (git-fixes). * i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices (git-fixes). * i3c: master: Fix device_register() error path (git-fixes). * i3c: master: Fix info leak and UAF in device unregister path (git-fixes). * i3c: master: svc: bound IBI payload to the requested max_payload_len (git- fixes). * ibmvnic: Only record tx completed bytes once per handler (bsc#1274620). * iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE (git-fixes). * iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable (git-fixes). * iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF (git-fixes). * iio: chemical: sgp30: Handle IAQ thread creation failure (git-fixes). * iio: dac: m62332: Fix regulator reference count imbalance (git-fixes). * iio: gyro: mpu3050: fix sign of raw angular velocity readings (git-fixes). * iio: light: cm32181: return zero after writing calibscale (git-fixes). * iio: light: gp2ap002: Disable regulators on resume failure (git-fixes). * iio: light: gp2ap002: re-enable irq if runtime suspend fails (git-fixes). * iio: light: isl29028: return zero in write_raw() on success (git-fixes). * iio: light: tsl2583: return zero in write_raw() on success (git-fixes). * iio: light: tsl2772: fix ALS calibscale readback (git-fixes). * iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure (git-fixes). * iio: pressure: dps310: fix NULL pointer dereference on ACPI probe (git- fixes). * iio: pressure: mpl115: Fix runtime PM cleanup (git-fixes). * iio: srf04: fix pm_runtime handling on probe error path (git-fixes). * iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() (git-fixes). * Input: atkbd - skip deactivate for HONOR ZQC-P (git-fixes). * Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (stable-fixes). * Input: evdev - fix information leak in evdev_pass_values() (stable-fixes). * Input: evdev - sanitize event type index when fetching event masks (stable- fixes). * Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (git-fixes). * Input: focaltech - use signed coordinates to prevent underflow (git-fixes). * Input: hynitron_cstxxx - validate touch count and finger IDs (git-fixes). * Input: iforce - validate input packet lengths (stable-fixes). * Input: iqs5xx - validate firmware record destination span (git-fixes). * Input: mms114 - fix Y-resolution configuration (git-fixes). * Input: psxpad-spi - set driver data before use (git-fixes). * Input: sur40 - fix input device registration ordering (stable-fixes). * Input: sur40 - fix V4L error path cleanup (stable-fixes). * Input: synaptics-rmi4 - block s_input when F54 queue is busy (git-fixes). * Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (git-fixes). * Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (git- fixes). * Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (git- fixes). * Input: synaptics-rmi4 - zero report size on F54 work error (git-fixes). * Input: xpad - add support for ZENAIM LEVERLESS (stable-fixes). * interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (git-fixes). * ipmi: ipmb: validate write message length (git-fixes). * ipmi: si: Fix NULL pointer dereference after failed registration (git- fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (git-fixes). * leds: pca9532: Fix inverted GPIO output polarity (git-fixes). * leds: pca9532: Fix phantom device registration on missing hardware (git- fixes). * lib/string: fix memchr_inv() for large ranges (git-fixes). * lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() (git-fixes). * mailbox: qcom-ipcc: fix duplicate channel allocation across holes (git- fixes). * mailbox: rockchip: disable pclk on probe failure and unbind (git-fixes). * maple_tree: fix argument name in header (git-fixes). * md/raid1: create serial pool adding rdev to array with serialize_policy=1 (bsc#1272261). * media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref (git-fixes). * media: cec-pin: Fix event FIFO ordering (git-fixes). * media: cec: disable delayed work before freeing an interrupted transmit (git-fixes). * media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash (git-fixes). * media: cec: Serialize exclusive follower delivery (git-fixes). * media: cec: stm32: prevent out-of-bounds write on RX overflow (git-fixes). * media: cedrus: fix memory leak in cedrus_init_ctrls() (git-fixes). * media: cobalt: Avoid freeing ALSA private data twice (git-fixes). * media: cx231xx: reject geometry changes while the VBI queue is busy (git- fixes). * media: cx23885: cancel NetUP CI work before teardown (git-fixes). * media: em28xx: defer audio-only extension registration (git-fixes). * media: em28xx: fix use-after-free of dev_next->devlist on disconnect (git- fixes). * media: go7007: defer the ALSA v4l2 put until card release (git-fixes). * media: i2c: ov02a10: fix endpoint parsing use-after-free (git-fixes). * media: i2c: ov7740: fix use-after-destroy in remove (git-fixes). * media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define (git- fixes). * media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define (git-fixes). * media: mc-entity: Add missing kerneldoc (git-fixes). * media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common (git- fixes). * media: nxp: imx8-isi: Correct color map between V4L2 and ISI (git-fixes). * media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing (git-fixes). * media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks (git-fixes). * media: rc: sunxi-cir: Unregister rc device on probe failure (git-fixes). * media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure (git-fixes). * media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak (git-fixes). * media: s2255: bound JPEG frame size before copying into the buffer (git- fixes). * media: s2255: check firmware size before reading trailing marker (git- fixes). * media: saa7164: fix cleanup on resource allocation failure (git-fixes). * media: tda18250: fix possible integer overflow (git-fixes). * media: usbtv: keep device alive while ALSA card exists (git-fixes). * media: v4l2-ctrls: Allow unknown HDR10 white point and luminance (git- fixes). * media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link (git-fixes). * media: venus: fix payload size calculation in parse_raw_formats() (git- fixes). * media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() (git-fixes). * media: vicodec: fix out-of-bounds write in FWHT encoder (git-fixes). * media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure (git-fixes). * media: vimc: fix pixel format lookup in enum_framesizes (git-fixes). * media: zoran: Avoid freeing a registered video_device twice (git-fixes). * mei: pull kvfree out of spinlock (git-fixes). * mfd: iqs62x: Reject zero-length firmware records (git-fixes). * mfd: rave-sp: validate received frame payload lengths (git-fixes). * misc: bcm-vk: Use acquire/release for msgq_inited (git-fixes). * misc: fastrpc: fix channel ctx ref leak when session alloc fails (git- fixes). * misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (git-fixes). * misc: fastrpc: Remove buffer from list prior to unmap operation (git-fixes). * misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke (git- fixes). * misc: rtsx: add missing write register handling (git-fixes). * misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() (git- fixes). * mkspec-dtb: Move DTS prefix into package list. * mkspec-dtb: Move provides-obsoletes to package list. * mkspec-dtb: Put per-architecture package lists into a hash. * mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (git- fixes). * mmc: sdhci: unmap the bounce buffer before device release (git-fixes). * mmc: via-sdmmc: stop card-detect handling on probe failure (git-fixes). * mtd: afs: validate v2 image info bounds (git-fixes). * mtd: mtdoops: free page bitmap when the backing MTD is removed (git-fixes). * mtd: mtdswap: Avoid freeing registered blktrans device twice (git-fixes). * mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() (git-fixes). * mtd: rawnand: validate ONFI extended parameter page sections (git-fixes). * net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes). * net: mana: Add handler for sriov configure (bsc#1272756). * net: mana: Cap MSI-X vectors to the device MSI-X table size (git-fixes). * net: mana: Extend RX CQE coalescing up to 8 packets (git-fixes). * net: mana: Fall back to scattered pages for GDMA queues (git-fixes). * net: mana: force full-page RX buffers via ethtool private flag (bsc#1269792). * net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792). * net: mana: Route ring-buffer access through offset-based helpers (git- fixes). * net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). * net: thunderbolt: Count delivered packets in rx_packets and rx_bytes (git- fixes). * net: thunderbolt: Mark the connection down when bringing it up fails (git- fixes). * net: thunderbolt: Release the Rx HopID that was handed out on mismatch (git- fixes). * net: thunderbolt: Tear down DMA paths before stopping the rings (git-fixes). * net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (git-fixes). * net: usb: ipheth: fix carrier_work UAF on disconnect (git-fixes). * nfc: digital: clamp SENSF_RES length to the destination buffer (git-fixes). * nfc: digital: Do not dump a NULL response in command completion (git-fixes). * nfc: fdp: bound the device-reported read length and fix an skb leak (git- fixes). * nfc: llcp: avoid userspace overflow on invalid optlen (git-fixes). * nfc: llcp: bound SNL TLV parsing to the skb and add length checks (git- fixes). * nfc: llcp: bound the connect_sn TLV walk to the skb (git-fixes). * nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (git-fixes). * nfc: llcp: read llcp_sock->local under the socket lock in getsockopt (git- fixes). * nfc: llcp: reject PDUs shorter than the LLCP header (git-fixes). * nfc: microread: validate target discovery payload lengths (git-fixes). * nfc: nci: fix double completion race in nci_data_exchange_complete (git- fixes). * nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (git- fixes). * nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (git- fixes). * nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing (git- fixes). * nfc: nci: free destination parameters when closing a connection (git-fixes). * nfc: pn533: hold a reference to the request skb during send_frame (git- fixes). * nfc: pn533: purge fragmented skbs during cleanup (git-fixes). * nfc: st21nfca: validate ATR_REQ length against the received frame (git- fixes). * nouveau/gem: reserve the bo in the info ioctl around the vma lookup (git- fixes). * PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] (git-fixes). * PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk (git- fixes). * PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git- fixes). * PCI: j721e: Fix incorrect max_lanes for J7200 (git-fixes). * PCI: meson: Fix GPIO state while requesting PERST# (git-fixes). * phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs (git- fixes). * phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend (git-fixes). * phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table (git- fixes). * phy: sunplus: fix error handling in sp_uphy_init() (git-fixes). * pinctrl: bcm2835: Don't remove an unregistered GPIO chip (git-fixes). * pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip (git-fixes). * pinctrl: rockchip: Reset the pin count when recalculating SoC data (git- fixes). * platform/chrome: cros_ec_debugfs: Clean up console log on probe failure (git-fixes). * platform/chrome: cros_ec_debugfs: Unregister panic notifier (git-fixes). * platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count (git- fixes). * platform/chrome: sensorhub: Bound the EC-reported sensor number (git-fixes). * platform/chrome: sensorhub: Fix dropped timestamp events and log spam (git- fixes). * platform/chrome: sensorhub: Fix memory overread in ring handler (git-fixes). * platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL (git- fixes). * platform/surface: acpi-notify: Check ACPI companion before use (git-fixes). * platform/x86: dell-privacy: Fix race condition (git-fixes). * platform/x86: dell-wmi-base: Fix resource leak on module load failure (git- fixes). * platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (git-fixes). * platform/x86: dell-wmi-sysman: Fix instance ID bounds (git-fixes). * platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path (git-fixes). * platform/x86: ISST: Just allow 2 bits for SST feature enable (git-fixes). * platform/x86: ISST: Validate level in perf mask ioctls (git-fixes). * platform/x86: ISST: Validate logical CPU id and clos id (git-fixes). * platform/x86: ISST: Validate socket ID in clos_assoc ioctl (git-fixes). * PM: sleep: Fix off-by-one in wakelocks number limit check (git-fixes). * power: supply: bd99954: Drop bad register fields (git-fixes). * power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq27520g4: fix REG_TTES address (git-fixes). * power: supply: bq256xx: drain usb_work before freeing the charger (git- fixes). * power: supply: bq24257: fix use-after-free on remove (git-fixes). * power: supply: bq25890: Fix power_supply reference leak (git-fixes). * power: supply: cros_usbpd-charger: bound the EC-reported port count (git- fixes). * power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS (git- fixes). * power: supply: isp1704_charger: cancel work on remove (git-fixes). * power: supply: lp8727: fix use-after-free in lp8727_release_irq() (git- fixes). * power: supply: max17040: drop incorrect I2C functionality check (git-fixes). * power: supply: max17040: synchronize work cancellation on suspend (git- fixes). * power: supply: qcom_battmgr: terminate the strings from firmware (git- fixes). * power: supply: rt9455: quiesce delayed work before teardown (git-fixes). * power: supply: sbs-battery: Use a per-device serial number buffer (git- fixes). * power: supply: twl4030_charger: cancel workers via devm (git-fixes). * power: supply: ucs1002: fix use-after-free on remove (git-fixes). * powercap: intel_rapl_tpmi: Handle PMU registration failure during probe (git-fixes). * powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash (bsc#1271256). * powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). * powerpc/pseries: pci - logic bug (bsc#1274749 ltc#221282 bsc#1274755 ltc#221284 bsc#1274756 ltc#221283). * ppdev: prevent overflow when setting port timeout (git-fixes). * qede: fix out-of-bounds check for cqe->len_list (git-fixes). * rapidio: clear mport->net when rio_add_net() fails (git-fixes). * rapidio: mport_cdev: fix use-after-free in dma_req_free() (git-fixes). * RDMA/irdma: Remove redundant legacy_mode checks (git-fixes). * RDMA/mana_ib: drain QP references after partial table insertion (git-fixes). * RDMA/mana_ib: unify QP lookup table (git-fixes). * RDMA/mlx5: Fix integer overflow of user QP buffer size (git-fixes). * regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (git-fixes). * regulator: core: use system_freezable_wq for init complete work (git-fixes). * regulator: devres: add API for reference voltage supplies (stable-fixes). * regulator: devres: fix devm_regulator_get_enable_read_voltage() return (git- fixes). * regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata (git-fixes). * regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling (git-fixes). * remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev (git-fixes). * remoteproc: qcom_q6v5_adsp: Fix reference leak for device node (git-fixes). * remoteproc: scp: Fix device reference leak on failed lookup (git-fixes). * Revert "drm/amdgpu: fix aperture mapping leak" (git-fixes). * Revert "media: v4l2-dev: fix error handling in __video_register_device()" (git-fixes). * Revert "thermal/drivers/hwmon: Cleanup coding style a bit" (stable-fixes). * rpmsg: core: Fix incorrect return value documentation (git-fixes). * rpmsg: glink: smem: order FIFO read after availability check (git-fixes). * rtc: gamecube: check return value of devm_rtc_register_device() (git-fixes). * rtc: pcf8563: fix clock provider leak on unbind (git-fixes). * rtc: pcf85363: Add error checking to regmap calls in probe() (git-fixes). * rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers (git-fixes). * rtc: rzn1: Fix weekday underflow when alarm crosses month boundary (git- fixes). * rtc: zynqmp: Return optional clock lookup errors (git-fixes). * scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes). * sctp: avoid auth_enable sysctl UAF during netns teardown (git-fixes). * serial: 8250_dma: Clear stale RX state on shutdown (git-fixes). * serial: amba-pl011: unprepare console clock on unregister (git-fixes). * serial: core: clear freed pointers on uart_register_driver() failure (git- fixes). * serial: qcom-geni: fix TX DMA buffer flush (git-fixes). * serial: sc16is7xx: fix copy-paste errors in EFR_SWFLOWx_BIT constants (stable-fixes). * smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). * smb: client: reject overlapping data areas in SMB2 responses (git-fixes). * smb: client: require net admin for CIFS SWN netlink (bsc#1273966). * smb: client: resolve SWN tcon from live registrations (bsc#1273872). * soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() (git- fixes). * soc: qcom: rpmh-rsc: manage PM notifiers with devres (git-fixes). * soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() (git-fixes). * software node: Fix software_node_get_reference_args() with index -1 (git- fixes). * soundwire: qcom: Fix port exhaustion check in stream_alloc_ports (git- fixes). * speakup: keyhelp: guard letter_offsets possible out-of-range indexing (git- fixes). * spi: img-spfi: don't disable runtime PM on DMA deferred probe (git-fixes). * spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (stable-fixes). * spi: sprd-adi: Fix probe succeeding without registering the controller (git- fixes). * staging: fbtft: Use sysfs_emit_at() to print to sysfs file (git-fixes). * staging: media: tegra-video: vi: fix probe failure on skipped last port (git-fixes). * staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown (git- fixes). * staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() (git-fixes). * staging: rtl8723bs: fix missing shared-key auth challenge length check (git- fixes). * staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (git-fixes). * staging: rtl8723bs: fix OOB read in WMM_param_handler() (git-fixes). * staging: rtl8723bs: use kfree_sensitive() for key material (git-fixes). * staging: rtl8723bs: validate monitor transmit frame lengths (git-fixes). * staging: sm750fb: gate dualview dataflow using g_dualview (git-fixes). * thermal/drivers/imx: Disable clock on runtime resume failure (git-fixes). * thermal/drivers/qoriq: Disable clock on resume failure (git-fixes). * thermal: intel: int3400: clean up ODVP on probe failures (git-fixes). * thunderbolt: Bound the DROM dual link port number before indexing sw->ports (git-fixes). * thunderbolt: icm: Preserve USB4 proxy data-valid bit (git-fixes). * tlclk: if sscanf() fails, fall back to 0, not random value (git-fixes). * tpm: st33zp24: Return zero on status read failure (git-fixes). * tpm: st33zp24: Validate locality read result (git-fixes). * tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (git-fixes). * tty: clear cdev pointer after cdev_add() failure (git-fixes). * tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 (git-fixes). * tty: skip cdev_del() when no cdev is registered (git-fixes). * uio: Fix stale info pointer in failed registration path (git-fixes). * usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (git-fixes). * usb: atm: usbatm: fix invalid ci_range initialization (git-fixes). * USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (git-fixes). * usb: cdnsp: fix incorrect endian conversions for APB timeout register (git- fixes). * usb: dwc2: add missing @remotewakeup kernel-doc parameter (git-fixes). * usb: dwc2: gadget: Exit partial power down state when changing USB pull-up (git-fixes). * usb: gadget: configfs: fix out-of-bounds read of qw_sign (git-fixes). * usb: gadget: f_fs: Prevent deadlock during ep0 read loop (git-fixes). * usb: gadget: f_ncm: Use unsigned int for ndp_index (git-fixes). * usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() (git-fixes). * usb: gadget: f_uac1_legacy: remove broken string configfs attributes (git- fixes). * usb: gadget: pch_udc: remove excess kernel-doc member for registered (git- fixes). * usb: gadget: r8a66597: avoid double free of ep0_req in probe error path (git-fixes). * usb: gadget: snps_udc_plat: clean up PHY on probe deferral (git-fixes). * usb: gadget: u_audio: Fix use-after-free on sound card disconnect (git- fixes). * usb: gadget: uac: validate rate list length before storing (git-fixes). * usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() (git-fixes). * usb: mtu3: allow system suspend during active gadget connection (git-fixes). * usb: musb: omap2430: clean up probe error handling (stable-fixes). * USB: phy: fsl-usb: fix missing static keywords (git-fixes). * usb: renesas_usbhs: Fix power-off ordering on unbind (git-fixes). * USB: serial: digi_acceleport: fix port registration order (git-fixes). * USB: serial: ftdi_sio: add support for E+H FXA291 (stable-fixes). * USB: serial: option: add TDTECH MT5710-CN (stable-fixes). * USB: serial: option: fix slab OOB read in interrupt URB callback (git- fixes). * USB: serial: spcp8x5: drop broken carrier detect support (git-fixes). * USB: storage: add NO_ATA_1X quirk for Longmai USB Key (stable-fixes). * usb: typec: ucsi: unregister debugfs entries on teardown (git-fixes). * usb: usbfs: fix use-after-free of usb_device in usbdev_release() (git- fixes). * usb: xhci: Handle USB3 port events when there is one roothub (git-fixes). * vt: add permission check for KDSKBMETA ioctl (stable-fixes). * vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (stable- fixes). * w1: ds28e17: reject an oversize length on an I2C block read (git-fixes). * w1: ds2482: Fix signedness bug in ds2482_w1_triplet() (git-fixes). * wifi: ath6kl: avoid buffer overreads in WMI event handlers (git-fixes). * wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (git-fixes). * wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump (git-fixes). * wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() (git-fixes). * wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate (git- fixes). * wifi: ath11k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() (git-fixes). * wifi: ath12k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (git-fixes). * wifi: brcmfmac: fix P2P action frame handling without device vif (git- fixes). * wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs (git-fixes). * wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments (git-fixes). * wifi: iwlwifi: mei: pass correct argument to function (git-fixes). * wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser (git-fixes). * wifi: mac80211: send TWT teardown to peer after setup TX failure (git- fixes). * wifi: mac80211: skip default WMM setup for AP_VLAN links (git-fixes). * wifi: mac80211: skip unused probe response countdown offsets (git-fixes). * wifi: mt76: fix 4th chain ACK RSSI bitmask in sta_poll (git-fixes). * wifi: mt76: fix ER-SU 106-tone RU check in RX rate decode (git-fixes). * wifi: mt76: fix HE DCM max-RU capability encoding (git-fixes). * wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length (git- fixes). * wifi: mt76: mt792x: Fix memory leak in SDIO TX path (git-fixes). * wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (git- fixes). * wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss (git- fixes). * wifi: mt76: mt7915: fix double hif2 init on the non-WED path (git-fixes). * wifi: mt76: mt7915: fix ext PHY use-after-free on register error path (git- fixes). * wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 (git- fixes). * wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie (git-fixes). * wifi: mt76: mt7915: release hif2 reference on probe IRQ failure (git-fixes). * wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement (git- fixes). * wifi: mt76: mt7915: unwind state on add_interface failure (git-fixes). * wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields (git- fixes). * wifi: mt76: mt7915: write RX header translation bit to the correct register (git-fixes). * wifi: mt76: mt7921: validate CLC firmware records (git-fixes). * wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (git- fixes). * wifi: mt76: mt7925: fix msg len mismatch between driver and firmware (git- fixes). * wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config (git- fixes). * wifi: mt76: mt7996: don't report a zero TX bitrate (git-fixes). * wifi: mt76: mt7996: fix reg addr remap when addr is 0 (git-fixes). * wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV (git- fixes). * wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset (git-fixes). * wifi: mt76: mt7996: validate RX band_idx before dereferencing phys (git- fixes). * wifi: mt76: report data NSS for STBC frames in RX rate decode (git-fixes). * wifi: mwifiex: Detach sync cmd buffer on interrupted wait (git-fixes). * wifi: rtlwifi: pci: fix error path in rtl_pci_probe() (git-fixes). * wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (git-fixes). * wifi: rtw89: fix HE extended capability length check (git-fixes). * wifi: zd1211rw: reject secondary interfaces to prevent conflicts (git- fixes). * x86/bugs: Clarify that syscall hardening isn't a BHI mitigation (git-fixes). * xhci: dbgtty: Fix unregister on tty_alloc_driver() failure (git-fixes). * xhci: dbgtty: Fix unregister on tty_register_driver() failure (git-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-601=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-6.4.0-52.1 * SUSE Linux Micro 6.1 (aarch64) * kernel-default-base-6.4.0-52.1.21.36 * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * kernel-default-debugsource-6.4.0-52.1 * kernel-default-devel-6.4.0-52.1 * kernel-default-debuginfo-6.4.0-52.1 * SUSE Linux Micro 6.1 (noarch) * kernel-devel-6.4.0-52.1 * kernel-source-6.4.0-52.1 * kernel-macros-6.4.0-52.1 * SUSE Linux Micro 6.1 (ppc64le) * kernel-default-base-6.4.0-52.1.21.34 * SUSE Linux Micro 6.1 (ppc64le x86_64) * kernel-default-devel-debuginfo-6.4.0-52.1 * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-default-livepatch-6.4.0-52.1 * SUSE Linux Micro 6.1 (x86_64) * kernel-default-base-6.4.0-52.1.21.35 * kernel-kvmsmall-debuginfo-6.4.0-52.1 * kernel-kvmsmall-debugsource-6.4.0-52.1 * SUSE Linux Micro 6.1 (nosrc x86_64) * kernel-kvmsmall-6.4.0-52.1 ## References: * https://www.suse.com/security/cve/CVE-2024-44981.html * https://www.suse.com/security/cve/CVE-2024-57841.html * https://www.suse.com/security/cve/CVE-2025-38469.html * https://www.suse.com/security/cve/CVE-2025-39964.html * https://www.suse.com/security/cve/CVE-2025-40022.html * https://www.suse.com/security/cve/CVE-2025-68179.html * https://www.suse.com/security/cve/CVE-2025-68214.html * https://www.suse.com/security/cve/CVE-2025-71075.html * https://www.suse.com/security/cve/CVE-2025-71104.html * https://www.suse.com/security/cve/CVE-2026-23210.html * https://www.suse.com/security/cve/CVE-2026-23230.html * https://www.suse.com/security/cve/CVE-2026-23454.html * https://www.suse.com/security/cve/CVE-2026-31392.html * https://www.suse.com/security/cve/CVE-2026-31418.html * https://www.suse.com/security/cve/CVE-2026-31531.html * https://www.suse.com/security/cve/CVE-2026-31557.html * https://www.suse.com/security/cve/CVE-2026-31663.html * https://www.suse.com/security/cve/CVE-2026-43116.html * https://www.suse.com/security/cve/CVE-2026-43125.html * https://www.suse.com/security/cve/CVE-2026-43163.html * https://www.suse.com/security/cve/CVE-2026-43271.html * https://www.suse.com/security/cve/CVE-2026-43273.html * https://www.suse.com/security/cve/CVE-2026-43278.html * https://www.suse.com/security/cve/CVE-2026-43319.html * https://www.suse.com/security/cve/CVE-2026-43363.html * https://www.suse.com/security/cve/CVE-2026-43416.html * https://www.suse.com/security/cve/CVE-2026-45897.html * https://www.suse.com/security/cve/CVE-2026-45968.html * https://www.suse.com/security/cve/CVE-2026-46070.html * https://www.suse.com/security/cve/CVE-2026-46091.html * https://www.suse.com/security/cve/CVE-2026-46107.html * https://www.suse.com/security/cve/CVE-2026-46115.html * https://www.suse.com/security/cve/CVE-2026-46195.html * https://www.suse.com/security/cve/CVE-2026-52920.html * https://www.suse.com/security/cve/CVE-2026-52925.html * https://www.suse.com/security/cve/CVE-2026-52929.html * https://www.suse.com/security/cve/CVE-2026-52935.html * https://www.suse.com/security/cve/CVE-2026-52939.html * https://www.suse.com/security/cve/CVE-2026-52946.html * https://www.suse.com/security/cve/CVE-2026-52975.html * https://www.suse.com/security/cve/CVE-2026-52977.html * https://www.suse.com/security/cve/CVE-2026-52990.html * https://www.suse.com/security/cve/CVE-2026-52994.html * https://www.suse.com/security/cve/CVE-2026-53001.html * https://www.suse.com/security/cve/CVE-2026-53033.html * https://www.suse.com/security/cve/CVE-2026-53059.html * https://www.suse.com/security/cve/CVE-2026-53076.html * https://www.suse.com/security/cve/CVE-2026-53077.html * https://www.suse.com/security/cve/CVE-2026-53089.html * https://www.suse.com/security/cve/CVE-2026-53091.html * https://www.suse.com/security/cve/CVE-2026-53094.html * https://www.suse.com/security/cve/CVE-2026-53096.html * https://www.suse.com/security/cve/CVE-2026-53110.html * https://www.suse.com/security/cve/CVE-2026-53111.html * https://www.suse.com/security/cve/CVE-2026-53126.html * https://www.suse.com/security/cve/CVE-2026-53154.html * https://www.suse.com/security/cve/CVE-2026-53163.html * https://www.suse.com/security/cve/CVE-2026-53207.html * https://www.suse.com/security/cve/CVE-2026-53219.html * https://www.suse.com/security/cve/CVE-2026-53220.html * https://www.suse.com/security/cve/CVE-2026-53223.html * https://www.suse.com/security/cve/CVE-2026-53228.html * https://www.suse.com/security/cve/CVE-2026-53238.html * https://www.suse.com/security/cve/CVE-2026-53260.html * https://www.suse.com/security/cve/CVE-2026-53264.html * https://www.suse.com/security/cve/CVE-2026-53269.html * https://www.suse.com/security/cve/CVE-2026-53273.html * https://www.suse.com/security/cve/CVE-2026-53309.html * https://www.suse.com/security/cve/CVE-2026-53330.html * https://www.suse.com/security/cve/CVE-2026-53336.html * https://www.suse.com/security/cve/CVE-2026-53337.html * https://www.suse.com/security/cve/CVE-2026-53353.html * https://www.suse.com/security/cve/CVE-2026-53365.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://www.suse.com/security/cve/CVE-2026-53381.html * https://www.suse.com/security/cve/CVE-2026-53388.html * https://www.suse.com/security/cve/CVE-2026-63801.html * https://www.suse.com/security/cve/CVE-2026-63808.html * https://www.suse.com/security/cve/CVE-2026-63810.html * https://www.suse.com/security/cve/CVE-2026-63823.html * https://www.suse.com/security/cve/CVE-2026-63827.html * https://www.suse.com/security/cve/CVE-2026-63828.html * https://www.suse.com/security/cve/CVE-2026-63860.html * https://www.suse.com/security/cve/CVE-2026-63865.html * https://www.suse.com/security/cve/CVE-2026-63868.html * https://www.suse.com/security/cve/CVE-2026-63879.html * https://www.suse.com/security/cve/CVE-2026-63881.html * https://www.suse.com/security/cve/CVE-2026-63886.html * https://www.suse.com/security/cve/CVE-2026-63887.html * https://www.suse.com/security/cve/CVE-2026-63888.html * https://www.suse.com/security/cve/CVE-2026-63889.html * https://www.suse.com/security/cve/CVE-2026-63891.html * https://www.suse.com/security/cve/CVE-2026-63898.html * https://www.suse.com/security/cve/CVE-2026-63920.html * https://www.suse.com/security/cve/CVE-2026-63925.html * https://www.suse.com/security/cve/CVE-2026-63926.html * https://www.suse.com/security/cve/CVE-2026-63928.html * https://www.suse.com/security/cve/CVE-2026-63944.html * https://www.suse.com/security/cve/CVE-2026-63969.html * https://www.suse.com/security/cve/CVE-2026-63970.html * https://www.suse.com/security/cve/CVE-2026-63972.html * https://www.suse.com/security/cve/CVE-2026-63973.html * https://www.suse.com/security/cve/CVE-2026-63980.html * https://www.suse.com/security/cve/CVE-2026-63985.html * https://www.suse.com/security/cve/CVE-2026-63990.html * https://www.suse.com/security/cve/CVE-2026-63992.html * https://www.suse.com/security/cve/CVE-2026-63999.html * https://www.suse.com/security/cve/CVE-2026-64000.html * https://www.suse.com/security/cve/CVE-2026-64001.html * https://www.suse.com/security/cve/CVE-2026-64002.html * https://www.suse.com/security/cve/CVE-2026-64004.html * https://www.suse.com/security/cve/CVE-2026-64005.html * https://www.suse.com/security/cve/CVE-2026-64006.html * https://www.suse.com/security/cve/CVE-2026-64007.html * https://www.suse.com/security/cve/CVE-2026-64010.html * https://www.suse.com/security/cve/CVE-2026-64011.html * https://www.suse.com/security/cve/CVE-2026-64014.html * https://www.suse.com/security/cve/CVE-2026-64015.html * https://www.suse.com/security/cve/CVE-2026-64018.html * https://www.suse.com/security/cve/CVE-2026-64029.html * https://www.suse.com/security/cve/CVE-2026-64034.html * https://www.suse.com/security/cve/CVE-2026-64039.html * https://www.suse.com/security/cve/CVE-2026-64047.html * https://www.suse.com/security/cve/CVE-2026-64048.html * https://www.suse.com/security/cve/CVE-2026-64051.html * https://www.suse.com/security/cve/CVE-2026-64052.html * https://www.suse.com/security/cve/CVE-2026-64073.html * https://www.suse.com/security/cve/CVE-2026-64083.html * https://www.suse.com/security/cve/CVE-2026-64084.html * https://www.suse.com/security/cve/CVE-2026-64085.html * https://www.suse.com/security/cve/CVE-2026-64086.html * https://www.suse.com/security/cve/CVE-2026-64087.html * https://www.suse.com/security/cve/CVE-2026-64088.html * https://www.suse.com/security/cve/CVE-2026-64097.html * https://www.suse.com/security/cve/CVE-2026-64098.html * https://www.suse.com/security/cve/CVE-2026-64102.html * https://www.suse.com/security/cve/CVE-2026-64109.html * https://www.suse.com/security/cve/CVE-2026-64112.html * https://www.suse.com/security/cve/CVE-2026-64113.html * https://www.suse.com/security/cve/CVE-2026-64114.html * https://www.suse.com/security/cve/CVE-2026-64115.html * https://www.suse.com/security/cve/CVE-2026-64118.html * https://www.suse.com/security/cve/CVE-2026-64121.html * https://www.suse.com/security/cve/CVE-2026-64125.html * https://www.suse.com/security/cve/CVE-2026-64126.html * https://www.suse.com/security/cve/CVE-2026-64128.html * https://www.suse.com/security/cve/CVE-2026-64131.html * https://www.suse.com/security/cve/CVE-2026-64133.html * https://www.suse.com/security/cve/CVE-2026-64135.html * https://www.suse.com/security/cve/CVE-2026-64137.html * https://www.suse.com/security/cve/CVE-2026-64148.html * https://www.suse.com/security/cve/CVE-2026-64155.html * https://www.suse.com/security/cve/CVE-2026-64164.html * https://www.suse.com/security/cve/CVE-2026-64166.html * https://www.suse.com/security/cve/CVE-2026-64168.html * https://www.suse.com/security/cve/CVE-2026-64178.html * https://www.suse.com/security/cve/CVE-2026-64185.html * https://www.suse.com/security/cve/CVE-2026-64188.html * https://www.suse.com/security/cve/CVE-2026-64190.html * https://www.suse.com/security/cve/CVE-2026-64192.html * https://www.suse.com/security/cve/CVE-2026-64214.html * https://www.suse.com/security/cve/CVE-2026-64217.html * https://www.suse.com/security/cve/CVE-2026-64218.html * https://www.suse.com/security/cve/CVE-2026-64219.html * https://www.suse.com/security/cve/CVE-2026-64222.html * https://www.suse.com/security/cve/CVE-2026-64225.html * https://www.suse.com/security/cve/CVE-2026-64237.html * https://www.suse.com/security/cve/CVE-2026-64243.html * https://www.suse.com/security/cve/CVE-2026-64245.html * https://www.suse.com/security/cve/CVE-2026-64246.html * https://www.suse.com/security/cve/CVE-2026-64247.html * https://www.suse.com/security/cve/CVE-2026-64249.html * https://www.suse.com/security/cve/CVE-2026-64257.html * https://www.suse.com/security/cve/CVE-2026-64266.html * https://www.suse.com/security/cve/CVE-2026-64268.html * https://www.suse.com/security/cve/CVE-2026-64271.html * https://www.suse.com/security/cve/CVE-2026-64273.html * https://www.suse.com/security/cve/CVE-2026-64274.html * https://www.suse.com/security/cve/CVE-2026-64275.html * https://www.suse.com/security/cve/CVE-2026-64276.html * https://www.suse.com/security/cve/CVE-2026-64277.html * https://www.suse.com/security/cve/CVE-2026-64286.html * https://www.suse.com/security/cve/CVE-2026-64287.html * https://www.suse.com/security/cve/CVE-2026-64294.html * https://www.suse.com/security/cve/CVE-2026-64296.html * https://www.suse.com/security/cve/CVE-2026-64303.html * https://www.suse.com/security/cve/CVE-2026-64304.html * https://www.suse.com/security/cve/CVE-2026-64305.html * https://www.suse.com/security/cve/CVE-2026-64306.html * https://www.suse.com/security/cve/CVE-2026-64312.html * https://www.suse.com/security/cve/CVE-2026-64313.html * https://www.suse.com/security/cve/CVE-2026-64315.html * https://www.suse.com/security/cve/CVE-2026-64316.html * https://www.suse.com/security/cve/CVE-2026-64317.html * https://www.suse.com/security/cve/CVE-2026-64322.html * https://www.suse.com/security/cve/CVE-2026-64323.html * https://www.suse.com/security/cve/CVE-2026-64329.html * https://www.suse.com/security/cve/CVE-2026-64331.html * https://www.suse.com/security/cve/CVE-2026-64332.html * https://www.suse.com/security/cve/CVE-2026-64333.html * https://www.suse.com/security/cve/CVE-2026-64334.html * https://www.suse.com/security/cve/CVE-2026-64335.html * https://www.suse.com/security/cve/CVE-2026-64337.html * https://www.suse.com/security/cve/CVE-2026-64338.html * https://www.suse.com/security/cve/CVE-2026-64340.html * https://www.suse.com/security/cve/CVE-2026-64341.html * https://www.suse.com/security/cve/CVE-2026-64342.html * https://www.suse.com/security/cve/CVE-2026-64343.html * https://www.suse.com/security/cve/CVE-2026-64344.html * https://www.suse.com/security/cve/CVE-2026-64346.html * https://www.suse.com/security/cve/CVE-2026-64348.html * https://www.suse.com/security/cve/CVE-2026-64350.html * https://www.suse.com/security/cve/CVE-2026-64351.html * https://www.suse.com/security/cve/CVE-2026-64355.html * https://www.suse.com/security/cve/CVE-2026-64358.html * https://www.suse.com/security/cve/CVE-2026-64362.html * https://www.suse.com/security/cve/CVE-2026-64365.html * https://www.suse.com/security/cve/CVE-2026-64375.html * https://www.suse.com/security/cve/CVE-2026-64376.html * https://www.suse.com/security/cve/CVE-2026-64378.html * https://www.suse.com/security/cve/CVE-2026-64381.html * https://www.suse.com/security/cve/CVE-2026-64382.html * https://www.suse.com/security/cve/CVE-2026-64383.html * https://www.suse.com/security/cve/CVE-2026-64384.html * https://www.suse.com/security/cve/CVE-2026-64385.html * https://www.suse.com/security/cve/CVE-2026-64386.html * https://www.suse.com/security/cve/CVE-2026-64387.html * https://www.suse.com/security/cve/CVE-2026-64388.html * https://www.suse.com/security/cve/CVE-2026-64401.html * https://www.suse.com/security/cve/CVE-2026-64403.html * https://www.suse.com/security/cve/CVE-2026-64406.html * https://www.suse.com/security/cve/CVE-2026-64408.html * https://www.suse.com/security/cve/CVE-2026-64409.html * https://www.suse.com/security/cve/CVE-2026-64411.html * https://www.suse.com/security/cve/CVE-2026-64412.html * https://www.suse.com/security/cve/CVE-2026-64420.html * https://www.suse.com/security/cve/CVE-2026-64421.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64427.html * https://www.suse.com/security/cve/CVE-2026-64429.html * https://www.suse.com/security/cve/CVE-2026-64433.html * https://www.suse.com/security/cve/CVE-2026-64434.html * https://www.suse.com/security/cve/CVE-2026-64436.html * https://www.suse.com/security/cve/CVE-2026-64440.html * https://www.suse.com/security/cve/CVE-2026-64442.html * https://www.suse.com/security/cve/CVE-2026-64443.html * https://www.suse.com/security/cve/CVE-2026-64444.html * https://www.suse.com/security/cve/CVE-2026-64445.html * https://www.suse.com/security/cve/CVE-2026-64448.html * https://www.suse.com/security/cve/CVE-2026-64450.html * https://www.suse.com/security/cve/CVE-2026-64454.html * https://www.suse.com/security/cve/CVE-2026-64455.html * https://www.suse.com/security/cve/CVE-2026-64463.html * https://www.suse.com/security/cve/CVE-2026-64470.html * https://www.suse.com/security/cve/CVE-2026-64471.html * https://www.suse.com/security/cve/CVE-2026-64472.html * https://www.suse.com/security/cve/CVE-2026-64478.html * https://www.suse.com/security/cve/CVE-2026-64479.html * https://www.suse.com/security/cve/CVE-2026-64480.html * https://www.suse.com/security/cve/CVE-2026-64481.html * https://www.suse.com/security/cve/CVE-2026-64482.html * https://www.suse.com/security/cve/CVE-2026-64483.html * https://www.suse.com/security/cve/CVE-2026-64484.html * https://www.suse.com/security/cve/CVE-2026-64486.html * https://www.suse.com/security/cve/CVE-2026-64487.html * https://www.suse.com/security/cve/CVE-2026-64489.html * https://www.suse.com/security/cve/CVE-2026-64494.html * https://www.suse.com/security/cve/CVE-2026-64495.html * https://www.suse.com/security/cve/CVE-2026-64496.html * https://www.suse.com/security/cve/CVE-2026-64497.html * https://www.suse.com/security/cve/CVE-2026-64500.html * https://www.suse.com/security/cve/CVE-2026-64503.html * https://www.suse.com/security/cve/CVE-2026-64504.html * https://www.suse.com/security/cve/CVE-2026-64505.html * https://www.suse.com/security/cve/CVE-2026-64511.html * https://www.suse.com/security/cve/CVE-2026-64512.html * https://www.suse.com/security/cve/CVE-2026-64513.html * https://www.suse.com/security/cve/CVE-2026-64524.html * https://www.suse.com/security/cve/CVE-2026-64527.html * https://www.suse.com/security/cve/CVE-2026-64536.html * https://www.suse.com/security/cve/CVE-2026-64537.html * https://www.suse.com/security/cve/CVE-2026-64538.html * https://www.suse.com/security/cve/CVE-2026-64539.html * https://www.suse.com/security/cve/CVE-2026-64540.html * https://www.suse.com/security/cve/CVE-2026-64541.html * https://www.suse.com/security/cve/CVE-2026-64543.html * https://www.suse.com/security/cve/CVE-2026-64544.html * https://www.suse.com/security/cve/CVE-2026-64545.html * https://www.suse.com/security/cve/CVE-2026-64546.html * https://www.suse.com/security/cve/CVE-2026-64547.html * https://www.suse.com/security/cve/CVE-2026-64548.html * https://www.suse.com/security/cve/CVE-2026-64549.html * https://www.suse.com/security/cve/CVE-2026-64551.html * https://www.suse.com/security/cve/CVE-2026-64552.html * https://www.suse.com/security/cve/CVE-2026-64553.html * https://www.suse.com/security/cve/CVE-2026-64554.html * https://www.suse.com/security/cve/CVE-2026-64562.html * https://www.suse.com/security/cve/CVE-2026-64563.html * https://www.suse.com/security/cve/CVE-2026-64565.html * https://www.suse.com/security/cve/CVE-2026-64567.html * https://www.suse.com/security/cve/CVE-2026-64571.html * https://www.suse.com/security/cve/CVE-2026-64572.html * https://www.suse.com/security/cve/CVE-2026-64573.html * https://www.suse.com/security/cve/CVE-2026-64574.html * https://www.suse.com/security/cve/CVE-2026-64576.html * https://www.suse.com/security/cve/CVE-2026-64577.html * https://www.suse.com/security/cve/CVE-2026-64581.html * https://www.suse.com/security/cve/CVE-2026-64582.html * https://www.suse.com/security/cve/CVE-2026-64583.html * https://www.suse.com/security/cve/CVE-2026-64584.html * https://www.suse.com/security/cve/CVE-2026-64585.html * https://www.suse.com/security/cve/CVE-2026-64593.html * https://www.suse.com/security/cve/CVE-2026-64597.html * https://www.suse.com/security/cve/CVE-2026-64598.html * https://www.suse.com/security/cve/CVE-2026-64599.html * https://www.suse.com/security/cve/CVE-2026-64602.html * https://www.suse.com/security/cve/CVE-2026-64604.html * https://www.suse.com/security/cve/CVE-2026-68081.html * https://www.suse.com/security/cve/CVE-2026-68082.html * https://www.suse.com/security/cve/CVE-2026-68085.html * https://www.suse.com/security/cve/CVE-2026-68086.html * https://www.suse.com/security/cve/CVE-2026-68088.html * https://www.suse.com/security/cve/CVE-2026-68091.html * https://www.suse.com/security/cve/CVE-2026-68093.html * https://www.suse.com/security/cve/CVE-2026-68102.html * https://www.suse.com/security/cve/CVE-2026-68104.html * https://www.suse.com/security/cve/CVE-2026-68106.html * https://www.suse.com/security/cve/CVE-2026-68107.html * https://www.suse.com/security/cve/CVE-2026-68108.html * https://www.suse.com/security/cve/CVE-2026-68110.html * https://www.suse.com/security/cve/CVE-2026-68111.html * https://www.suse.com/security/cve/CVE-2026-68112.html * https://www.suse.com/security/cve/CVE-2026-68115.html * https://www.suse.com/security/cve/CVE-2026-68116.html * https://www.suse.com/security/cve/CVE-2026-68117.html * https://www.suse.com/security/cve/CVE-2026-68121.html * https://www.suse.com/security/cve/CVE-2026-68123.html * https://www.suse.com/security/cve/CVE-2026-68125.html * https://www.suse.com/security/cve/CVE-2026-68126.html * https://www.suse.com/security/cve/CVE-2026-68127.html * https://www.suse.com/security/cve/CVE-2026-68129.html * https://www.suse.com/security/cve/CVE-2026-68132.html * https://www.suse.com/security/cve/CVE-2026-68133.html * https://www.suse.com/security/cve/CVE-2026-68136.html * https://www.suse.com/security/cve/CVE-2026-68137.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://www.suse.com/security/cve/CVE-2026-68139.html * https://www.suse.com/security/cve/CVE-2026-68142.html * https://www.suse.com/security/cve/CVE-2026-68143.html * https://www.suse.com/security/cve/CVE-2026-68145.html * https://www.suse.com/security/cve/CVE-2026-68149.html * https://www.suse.com/security/cve/CVE-2026-68153.html * https://www.suse.com/security/cve/CVE-2026-68154.html * https://www.suse.com/security/cve/CVE-2026-68155.html * https://www.suse.com/security/cve/CVE-2026-68156.html * https://www.suse.com/security/cve/CVE-2026-68157.html * https://www.suse.com/security/cve/CVE-2026-68158.html * https://www.suse.com/security/cve/CVE-2026-68159.html * https://www.suse.com/security/cve/CVE-2026-68160.html * https://www.suse.com/security/cve/CVE-2026-68161.html * https://www.suse.com/security/cve/CVE-2026-68162.html * https://www.suse.com/security/cve/CVE-2026-68166.html * https://www.suse.com/security/cve/CVE-2026-68180.html * https://www.suse.com/security/cve/CVE-2026-68181.html * https://www.suse.com/security/cve/CVE-2026-68182.html * https://www.suse.com/security/cve/CVE-2026-68184.html * https://www.suse.com/security/cve/CVE-2026-68188.html * https://www.suse.com/security/cve/CVE-2026-68189.html * https://www.suse.com/security/cve/CVE-2026-68192.html * https://www.suse.com/security/cve/CVE-2026-68193.html * https://www.suse.com/security/cve/CVE-2026-68194.html * https://www.suse.com/security/cve/CVE-2026-68195.html * https://www.suse.com/security/cve/CVE-2026-68196.html * https://www.suse.com/security/cve/CVE-2026-68197.html * https://www.suse.com/security/cve/CVE-2026-68199.html * https://www.suse.com/security/cve/CVE-2026-68202.html * https://www.suse.com/security/cve/CVE-2026-68204.html * https://www.suse.com/security/cve/CVE-2026-68205.html * https://www.suse.com/security/cve/CVE-2026-68206.html * https://www.suse.com/security/cve/CVE-2026-68207.html * https://www.suse.com/security/cve/CVE-2026-68209.html * https://www.suse.com/security/cve/CVE-2026-68210.html * https://www.suse.com/security/cve/CVE-2026-68212.html * https://www.suse.com/security/cve/CVE-2026-68213.html * https://www.suse.com/security/cve/CVE-2026-68214.html * https://www.suse.com/security/cve/CVE-2026-68215.html * https://www.suse.com/security/cve/CVE-2026-68216.html * https://www.suse.com/security/cve/CVE-2026-68217.html * https://www.suse.com/security/cve/CVE-2026-68218.html * https://www.suse.com/security/cve/CVE-2026-68219.html * https://www.suse.com/security/cve/CVE-2026-68220.html * https://www.suse.com/security/cve/CVE-2026-68222.html * https://www.suse.com/security/cve/CVE-2026-68223.html * https://www.suse.com/security/cve/CVE-2026-68226.html * https://www.suse.com/security/cve/CVE-2026-68227.html * https://www.suse.com/security/cve/CVE-2026-68229.html * https://www.suse.com/security/cve/CVE-2026-68231.html * https://www.suse.com/security/cve/CVE-2026-68234.html * https://www.suse.com/security/cve/CVE-2026-68236.html * https://www.suse.com/security/cve/CVE-2026-68238.html * https://www.suse.com/security/cve/CVE-2026-68243.html * https://www.suse.com/security/cve/CVE-2026-68244.html * https://www.suse.com/security/cve/CVE-2026-68246.html * https://www.suse.com/security/cve/CVE-2026-68247.html * https://www.suse.com/security/cve/CVE-2026-68248.html * https://www.suse.com/security/cve/CVE-2026-68249.html * https://www.suse.com/security/cve/CVE-2026-68250.html * https://www.suse.com/security/cve/CVE-2026-68251.html * https://www.suse.com/security/cve/CVE-2026-68254.html * https://www.suse.com/security/cve/CVE-2026-68255.html * https://www.suse.com/security/cve/CVE-2026-68256.html * https://www.suse.com/security/cve/CVE-2026-68259.html * https://www.suse.com/security/cve/CVE-2026-68269.html * https://www.suse.com/security/cve/CVE-2026-68271.html * https://www.suse.com/security/cve/CVE-2026-68272.html * https://www.suse.com/security/cve/CVE-2026-68277.html * https://www.suse.com/security/cve/CVE-2026-68278.html * https://www.suse.com/security/cve/CVE-2026-68279.html * https://www.suse.com/security/cve/CVE-2026-68280.html * https://www.suse.com/security/cve/CVE-2026-68284.html * https://www.suse.com/security/cve/CVE-2026-68286.html * https://www.suse.com/security/cve/CVE-2026-68288.html * https://www.suse.com/security/cve/CVE-2026-68289.html * https://www.suse.com/security/cve/CVE-2026-68293.html * https://www.suse.com/security/cve/CVE-2026-68297.html * https://www.suse.com/security/cve/CVE-2026-68299.html * https://www.suse.com/security/cve/CVE-2026-68300.html * https://www.suse.com/security/cve/CVE-2026-68303.html * https://www.suse.com/security/cve/CVE-2026-68304.html * https://www.suse.com/security/cve/CVE-2026-68306.html * https://www.suse.com/security/cve/CVE-2026-68308.html * https://www.suse.com/security/cve/CVE-2026-68309.html * https://www.suse.com/security/cve/CVE-2026-68310.html * https://www.suse.com/security/cve/CVE-2026-68312.html * https://www.suse.com/security/cve/CVE-2026-68313.html * https://www.suse.com/security/cve/CVE-2026-68315.html * https://www.suse.com/security/cve/CVE-2026-68320.html * https://www.suse.com/security/cve/CVE-2026-68322.html * https://www.suse.com/security/cve/CVE-2026-68324.html * https://www.suse.com/security/cve/CVE-2026-68325.html * https://www.suse.com/security/cve/CVE-2026-68326.html * https://www.suse.com/security/cve/CVE-2026-68327.html * https://www.suse.com/security/cve/CVE-2026-68328.html * https://www.suse.com/security/cve/CVE-2026-68329.html * https://www.suse.com/security/cve/CVE-2026-68331.html * https://www.suse.com/security/cve/CVE-2026-68333.html * https://www.suse.com/security/cve/CVE-2026-68335.html * https://www.suse.com/security/cve/CVE-2026-68336.html * https://www.suse.com/security/cve/CVE-2026-68339.html * https://www.suse.com/security/cve/CVE-2026-68340.html * https://www.suse.com/security/cve/CVE-2026-68343.html * https://www.suse.com/security/cve/CVE-2026-68346.html * https://www.suse.com/security/cve/CVE-2026-68348.html * https://www.suse.com/security/cve/CVE-2026-68349.html * https://www.suse.com/security/cve/CVE-2026-68350.html * https://www.suse.com/security/cve/CVE-2026-68351.html * https://www.suse.com/security/cve/CVE-2026-68352.html * https://www.suse.com/security/cve/CVE-2026-68353.html * https://www.suse.com/security/cve/CVE-2026-68354.html * https://www.suse.com/security/cve/CVE-2026-68355.html * https://www.suse.com/security/cve/CVE-2026-68357.html * https://www.suse.com/security/cve/CVE-2026-68359.html * https://www.suse.com/security/cve/CVE-2026-68360.html * https://www.suse.com/security/cve/CVE-2026-68361.html * https://www.suse.com/security/cve/CVE-2026-68362.html * https://www.suse.com/security/cve/CVE-2026-68363.html * https://www.suse.com/security/cve/CVE-2026-68365.html * https://www.suse.com/security/cve/CVE-2026-68366.html * https://www.suse.com/security/cve/CVE-2026-68368.html * https://www.suse.com/security/cve/CVE-2026-68369.html * https://www.suse.com/security/cve/CVE-2026-68370.html * https://www.suse.com/security/cve/CVE-2026-68372.html * https://www.suse.com/security/cve/CVE-2026-68373.html * https://www.suse.com/security/cve/CVE-2026-68377.html * https://www.suse.com/security/cve/CVE-2026-68386.html * https://www.suse.com/security/cve/CVE-2026-68391.html * https://www.suse.com/security/cve/CVE-2026-68392.html * https://www.suse.com/security/cve/CVE-2026-68397.html * https://www.suse.com/security/cve/CVE-2026-68398.html * https://www.suse.com/security/cve/CVE-2026-68399.html * https://www.suse.com/security/cve/CVE-2026-68402.html * https://www.suse.com/security/cve/CVE-2026-68403.html * https://www.suse.com/security/cve/CVE-2026-68405.html * https://www.suse.com/security/cve/CVE-2026-68406.html * https://www.suse.com/security/cve/CVE-2026-68407.html * https://www.suse.com/security/cve/CVE-2026-68408.html * https://www.suse.com/security/cve/CVE-2026-68410.html * https://www.suse.com/security/cve/CVE-2026-68413.html * https://www.suse.com/security/cve/CVE-2026-68414.html * https://www.suse.com/security/cve/CVE-2026-68417.html * https://www.suse.com/security/cve/CVE-2026-68418.html * https://www.suse.com/security/cve/CVE-2026-68419.html * https://www.suse.com/security/cve/CVE-2026-68422.html * https://www.suse.com/security/cve/CVE-2026-68425.html * https://www.suse.com/security/cve/CVE-2026-68426.html * https://www.suse.com/security/cve/CVE-2026-68427.html * https://www.suse.com/security/cve/CVE-2026-68428.html * https://www.suse.com/security/cve/CVE-2026-68429.html * https://www.suse.com/security/cve/CVE-2026-68430.html * https://www.suse.com/security/cve/CVE-2026-68432.html * https://www.suse.com/security/cve/CVE-2026-68433.html * https://www.suse.com/security/cve/CVE-2026-68434.html * https://www.suse.com/security/cve/CVE-2026-68444.html * https://www.suse.com/security/cve/CVE-2026-68445.html * https://www.suse.com/security/cve/CVE-2026-68446.html * https://www.suse.com/security/cve/CVE-2026-68450.html * https://www.suse.com/security/cve/CVE-2026-68470.html * https://www.suse.com/security/cve/CVE-2026-68480.html * https://www.suse.com/security/cve/CVE-2026-72020.html * https://www.suse.com/security/cve/CVE-2026-72035.html * https://www.suse.com/security/cve/CVE-2026-72036.html * https://www.suse.com/security/cve/CVE-2026-72069.html * https://www.suse.com/security/cve/CVE-2026-72072.html * https://www.suse.com/security/cve/CVE-2026-72083.html * https://www.suse.com/security/cve/CVE-2026-72084.html * https://www.suse.com/security/cve/CVE-2026-72123.html * https://www.suse.com/security/cve/CVE-2026-72132.html * https://www.suse.com/security/cve/CVE-2026-72221.html * https://www.suse.com/security/cve/CVE-2026-72222.html * https://www.suse.com/security/cve/CVE-2026-72251.html * https://www.suse.com/security/cve/CVE-2026-72254.html * https://www.suse.com/security/cve/CVE-2026-72262.html * https://www.suse.com/security/cve/CVE-2026-72288.html * https://www.suse.com/security/cve/CVE-2026-72289.html * https://www.suse.com/security/cve/CVE-2026-72296.html * https://www.suse.com/security/cve/CVE-2026-72307.html * https://www.suse.com/security/cve/CVE-2026-72308.html * https://www.suse.com/security/cve/CVE-2026-72317.html * https://www.suse.com/security/cve/CVE-2026-72341.html * https://www.suse.com/security/cve/CVE-2026-72342.html * https://www.suse.com/security/cve/CVE-2026-72343.html * https://www.suse.com/security/cve/CVE-2026-72389.html * https://www.suse.com/security/cve/CVE-2026-72463.html * https://www.suse.com/security/cve/CVE-2026-72464.html * https://www.suse.com/security/cve/CVE-2026-72466.html * https://www.suse.com/security/cve/CVE-2026-72467.html * https://www.suse.com/security/cve/CVE-2026-72469.html * https://www.suse.com/security/cve/CVE-2026-72473.html * https://www.suse.com/security/cve/CVE-2026-72494.html * https://www.suse.com/security/cve/CVE-2026-72495.html * https://www.suse.com/security/cve/CVE-2026-72496.html * https://www.suse.com/security/cve/CVE-2026-72499.html * https://www.suse.com/security/cve/CVE-2026-72501.html * https://www.suse.com/security/cve/CVE-2026-72502.html * https://www.suse.com/security/cve/CVE-2026-74269.html * https://www.suse.com/security/cve/CVE-2026-74296.html * https://www.suse.com/security/cve/CVE-2026-74297.html * https://www.suse.com/security/cve/CVE-2026-74318.html * https://www.suse.com/security/cve/CVE-2026-74321.html * https://www.suse.com/security/cve/CVE-2026-74334.html * https://www.suse.com/security/cve/CVE-2026-74345.html * https://www.suse.com/security/cve/CVE-2026-74394.html * https://www.suse.com/security/cve/CVE-2026-74395.html * https://www.suse.com/security/cve/CVE-2026-74454.html * https://www.suse.com/security/cve/CVE-2026-74474.html * https://www.suse.com/security/cve/CVE-2026-74481.html * https://www.suse.com/security/cve/CVE-2026-74482.html * https://www.suse.com/security/cve/CVE-2026-74488.html * https://www.suse.com/security/cve/CVE-2026-74495.html * https://www.suse.com/security/cve/CVE-2026-74496.html * https://www.suse.com/security/cve/CVE-2026-74509.html * https://www.suse.com/security/cve/CVE-2026-74510.html * https://www.suse.com/security/cve/CVE-2026-74512.html * https://www.suse.com/security/cve/CVE-2026-74516.html * https://www.suse.com/security/cve/CVE-2026-74518.html * https://www.suse.com/security/cve/CVE-2026-74527.html * https://www.suse.com/security/cve/CVE-2026-74537.html * https://www.suse.com/security/cve/CVE-2026-74548.html * https://www.suse.com/security/cve/CVE-2026-74550.html * https://www.suse.com/security/cve/CVE-2026-74556.html * https://www.suse.com/security/cve/CVE-2026-74563.html * https://www.suse.com/security/cve/CVE-2026-74566.html * https://www.suse.com/security/cve/CVE-2026-74567.html * https://www.suse.com/security/cve/CVE-2026-74571.html * https://www.suse.com/security/cve/CVE-2026-74581.html * https://www.suse.com/security/cve/CVE-2026-74582.html * https://www.suse.com/security/cve/CVE-2026-74584.html * https://www.suse.com/security/cve/CVE-2026-74610.html * https://www.suse.com/security/cve/CVE-2026-74669.html * https://www.suse.com/security/cve/CVE-2026-74692.html * https://www.suse.com/security/cve/CVE-2026-74694.html * https://www.suse.com/security/cve/CVE-2026-74695.html * https://www.suse.com/security/cve/CVE-2026-74717.html * https://www.suse.com/security/cve/CVE-2026-74722.html * https://www.suse.com/security/cve/CVE-2026-80529.html * https://www.suse.com/security/cve/CVE-2026-80534.html * https://www.suse.com/security/cve/CVE-2026-80590.html * https://www.suse.com/security/cve/CVE-2026-80654.html * https://bugzilla.suse.com/show_bug.cgi?id=1230238 * https://bugzilla.suse.com/show_bug.cgi?id=1235944 * https://bugzilla.suse.com/show_bug.cgi?id=1247455 * https://bugzilla.suse.com/show_bug.cgi?id=1250748 * https://bugzilla.suse.com/show_bug.cgi?id=1251966 * https://bugzilla.suse.com/show_bug.cgi?id=1252682 * https://bugzilla.suse.com/show_bug.cgi?id=1254306 * https://bugzilla.suse.com/show_bug.cgi?id=1255225 * https://bugzilla.suse.com/show_bug.cgi?id=1255250 * https://bugzilla.suse.com/show_bug.cgi?id=1256629 * https://bugzilla.suse.com/show_bug.cgi?id=1256708 * https://bugzilla.suse.com/show_bug.cgi?id=1257154 * https://bugzilla.suse.com/show_bug.cgi?id=1258430 * https://bugzilla.suse.com/show_bug.cgi?id=1258517 * https://bugzilla.suse.com/show_bug.cgi?id=1260522 * https://bugzilla.suse.com/show_bug.cgi?id=1261780 * https://bugzilla.suse.com/show_bug.cgi?id=1261788 * https://bugzilla.suse.com/show_bug.cgi?id=1262073 * https://bugzilla.suse.com/show_bug.cgi?id=1263004 * https://bugzilla.suse.com/show_bug.cgi?id=1263061 * https://bugzilla.suse.com/show_bug.cgi?id=1263133 * https://bugzilla.suse.com/show_bug.cgi?id=1264335 * https://bugzilla.suse.com/show_bug.cgi?id=1264446 * https://bugzilla.suse.com/show_bug.cgi?id=1264541 * https://bugzilla.suse.com/show_bug.cgi?id=1264584 * https://bugzilla.suse.com/show_bug.cgi?id=1264587 * https://bugzilla.suse.com/show_bug.cgi?id=1264619 * https://bugzilla.suse.com/show_bug.cgi?id=1264788 * https://bugzilla.suse.com/show_bug.cgi?id=1265068 * https://bugzilla.suse.com/show_bug.cgi?id=1265121 * https://bugzilla.suse.com/show_bug.cgi?id=1265449 * https://bugzilla.suse.com/show_bug.cgi?id=1265928 * https://bugzilla.suse.com/show_bug.cgi?id=1266402 * https://bugzilla.suse.com/show_bug.cgi?id=1266860 * https://bugzilla.suse.com/show_bug.cgi?id=1266874 * https://bugzilla.suse.com/show_bug.cgi?id=1266897 * https://bugzilla.suse.com/show_bug.cgi?id=1267023 * https://bugzilla.suse.com/show_bug.cgi?id=1267238 * https://bugzilla.suse.com/show_bug.cgi?id=1267501 * https://bugzilla.suse.com/show_bug.cgi?id=1267612 * https://bugzilla.suse.com/show_bug.cgi?id=1268276 * https://bugzilla.suse.com/show_bug.cgi?id=1268972 * https://bugzilla.suse.com/show_bug.cgi?id=1268979 * https://bugzilla.suse.com/show_bug.cgi?id=1268987 * https://bugzilla.suse.com/show_bug.cgi?id=1269004 * https://bugzilla.suse.com/show_bug.cgi?id=1269013 * https://bugzilla.suse.com/show_bug.cgi?id=1269108 * https://bugzilla.suse.com/show_bug.cgi?id=1269113 * https://bugzilla.suse.com/show_bug.cgi?id=1269114 * https://bugzilla.suse.com/show_bug.cgi?id=1269126 * https://bugzilla.suse.com/show_bug.cgi?id=1269167 * https://bugzilla.suse.com/show_bug.cgi?id=1269234 * https://bugzilla.suse.com/show_bug.cgi?id=1269238 * https://bugzilla.suse.com/show_bug.cgi?id=1269242 * https://bugzilla.suse.com/show_bug.cgi?id=1269256 * https://bugzilla.suse.com/show_bug.cgi?id=1269301 * https://bugzilla.suse.com/show_bug.cgi?id=1269306 * https://bugzilla.suse.com/show_bug.cgi?id=1269381 * https://bugzilla.suse.com/show_bug.cgi?id=1269388 * https://bugzilla.suse.com/show_bug.cgi?id=1269412 * https://bugzilla.suse.com/show_bug.cgi?id=1269530 * https://bugzilla.suse.com/show_bug.cgi?id=1269579 * https://bugzilla.suse.com/show_bug.cgi?id=1269590 * https://bugzilla.suse.com/show_bug.cgi?id=1269635 * https://bugzilla.suse.com/show_bug.cgi?id=1269655 * https://bugzilla.suse.com/show_bug.cgi?id=1269665 * https://bugzilla.suse.com/show_bug.cgi?id=1269686 * https://bugzilla.suse.com/show_bug.cgi?id=1269695 * https://bugzilla.suse.com/show_bug.cgi?id=1269713 * https://bugzilla.suse.com/show_bug.cgi?id=1269731 * https://bugzilla.suse.com/show_bug.cgi?id=1269774 * https://bugzilla.suse.com/show_bug.cgi?id=1269783 * https://bugzilla.suse.com/show_bug.cgi?id=1269792 * https://bugzilla.suse.com/show_bug.cgi?id=1269815 * https://bugzilla.suse.com/show_bug.cgi?id=1269965 * https://bugzilla.suse.com/show_bug.cgi?id=1269969 * https://bugzilla.suse.com/show_bug.cgi?id=1269981 * https://bugzilla.suse.com/show_bug.cgi?id=1269985 * https://bugzilla.suse.com/show_bug.cgi?id=1270090 * https://bugzilla.suse.com/show_bug.cgi?id=1270108 * https://bugzilla.suse.com/show_bug.cgi?id=1270111 * https://bugzilla.suse.com/show_bug.cgi?id=1270251 * https://bugzilla.suse.com/show_bug.cgi?id=1271256 * https://bugzilla.suse.com/show_bug.cgi?id=1271365 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 * https://bugzilla.suse.com/show_bug.cgi?id=1271825 * https://bugzilla.suse.com/show_bug.cgi?id=1271830 * https://bugzilla.suse.com/show_bug.cgi?id=1272150 * https://bugzilla.suse.com/show_bug.cgi?id=1272175 * https://bugzilla.suse.com/show_bug.cgi?id=1272179 * https://bugzilla.suse.com/show_bug.cgi?id=1272182 * https://bugzilla.suse.com/show_bug.cgi?id=1272200 * https://bugzilla.suse.com/show_bug.cgi?id=1272210 * https://bugzilla.suse.com/show_bug.cgi?id=1272213 * https://bugzilla.suse.com/show_bug.cgi?id=1272230 * https://bugzilla.suse.com/show_bug.cgi?id=1272260 * https://bugzilla.suse.com/show_bug.cgi?id=1272261 * https://bugzilla.suse.com/show_bug.cgi?id=1272262 * https://bugzilla.suse.com/show_bug.cgi?id=1272297 * https://bugzilla.suse.com/show_bug.cgi?id=1272346 * https://bugzilla.suse.com/show_bug.cgi?id=1272381 * https://bugzilla.suse.com/show_bug.cgi?id=1272385 * https://bugzilla.suse.com/show_bug.cgi?id=1272390 * https://bugzilla.suse.com/show_bug.cgi?id=1272423 * https://bugzilla.suse.com/show_bug.cgi?id=1272429 * https://bugzilla.suse.com/show_bug.cgi?id=1272484 * https://bugzilla.suse.com/show_bug.cgi?id=1272486 * https://bugzilla.suse.com/show_bug.cgi?id=1272497 * https://bugzilla.suse.com/show_bug.cgi?id=1272516 * https://bugzilla.suse.com/show_bug.cgi?id=1272569 * https://bugzilla.suse.com/show_bug.cgi?id=1272571 * https://bugzilla.suse.com/show_bug.cgi?id=1272641 * https://bugzilla.suse.com/show_bug.cgi?id=1272643 * https://bugzilla.suse.com/show_bug.cgi?id=1272662 * https://bugzilla.suse.com/show_bug.cgi?id=1272673 * https://bugzilla.suse.com/show_bug.cgi?id=1272680 * https://bugzilla.suse.com/show_bug.cgi?id=1272682 * https://bugzilla.suse.com/show_bug.cgi?id=1272756 * https://bugzilla.suse.com/show_bug.cgi?id=1272786 * https://bugzilla.suse.com/show_bug.cgi?id=1272788 * https://bugzilla.suse.com/show_bug.cgi?id=1272798 * https://bugzilla.suse.com/show_bug.cgi?id=1272799 * https://bugzilla.suse.com/show_bug.cgi?id=1272868 * https://bugzilla.suse.com/show_bug.cgi?id=1272877 * https://bugzilla.suse.com/show_bug.cgi?id=1272891 * https://bugzilla.suse.com/show_bug.cgi?id=1272963 * https://bugzilla.suse.com/show_bug.cgi?id=1272983 * https://bugzilla.suse.com/show_bug.cgi?id=1273008 * https://bugzilla.suse.com/show_bug.cgi?id=1273019 * https://bugzilla.suse.com/show_bug.cgi?id=1273027 * https://bugzilla.suse.com/show_bug.cgi?id=1273028 * https://bugzilla.suse.com/show_bug.cgi?id=1273030 * https://bugzilla.suse.com/show_bug.cgi?id=1273038 * https://bugzilla.suse.com/show_bug.cgi?id=1273053 * https://bugzilla.suse.com/show_bug.cgi?id=1273054 * https://bugzilla.suse.com/show_bug.cgi?id=1273060 * https://bugzilla.suse.com/show_bug.cgi?id=1273105 * https://bugzilla.suse.com/show_bug.cgi?id=1273249 * https://bugzilla.suse.com/show_bug.cgi?id=1273250 * https://bugzilla.suse.com/show_bug.cgi?id=1273260 * https://bugzilla.suse.com/show_bug.cgi?id=1273273 * https://bugzilla.suse.com/show_bug.cgi?id=1273274 * https://bugzilla.suse.com/show_bug.cgi?id=1273276 * https://bugzilla.suse.com/show_bug.cgi?id=1273281 * https://bugzilla.suse.com/show_bug.cgi?id=1273284 * https://bugzilla.suse.com/show_bug.cgi?id=1273285 * https://bugzilla.suse.com/show_bug.cgi?id=1273289 * https://bugzilla.suse.com/show_bug.cgi?id=1273291 * https://bugzilla.suse.com/show_bug.cgi?id=1273294 * https://bugzilla.suse.com/show_bug.cgi?id=1273302 * https://bugzilla.suse.com/show_bug.cgi?id=1273303 * https://bugzilla.suse.com/show_bug.cgi?id=1273305 * https://bugzilla.suse.com/show_bug.cgi?id=1273310 * https://bugzilla.suse.com/show_bug.cgi?id=1273311 * https://bugzilla.suse.com/show_bug.cgi?id=1273316 * https://bugzilla.suse.com/show_bug.cgi?id=1273318 * https://bugzilla.suse.com/show_bug.cgi?id=1273319 * https://bugzilla.suse.com/show_bug.cgi?id=1273323 * https://bugzilla.suse.com/show_bug.cgi?id=1273325 * https://bugzilla.suse.com/show_bug.cgi?id=1273327 * https://bugzilla.suse.com/show_bug.cgi?id=1273334 * https://bugzilla.suse.com/show_bug.cgi?id=1273335 * https://bugzilla.suse.com/show_bug.cgi?id=1273336 * https://bugzilla.suse.com/show_bug.cgi?id=1273337 * https://bugzilla.suse.com/show_bug.cgi?id=1273338 * https://bugzilla.suse.com/show_bug.cgi?id=1273340 * https://bugzilla.suse.com/show_bug.cgi?id=1273341 * https://bugzilla.suse.com/show_bug.cgi?id=1273346 * https://bugzilla.suse.com/show_bug.cgi?id=1273422 * https://bugzilla.suse.com/show_bug.cgi?id=1273426 * https://bugzilla.suse.com/show_bug.cgi?id=1273443 * https://bugzilla.suse.com/show_bug.cgi?id=1273463 * https://bugzilla.suse.com/show_bug.cgi?id=1273468 * https://bugzilla.suse.com/show_bug.cgi?id=1273469 * https://bugzilla.suse.com/show_bug.cgi?id=1273471 * https://bugzilla.suse.com/show_bug.cgi?id=1273479 * https://bugzilla.suse.com/show_bug.cgi?id=1273480 * https://bugzilla.suse.com/show_bug.cgi?id=1273482 * https://bugzilla.suse.com/show_bug.cgi?id=1273484 * https://bugzilla.suse.com/show_bug.cgi?id=1273488 * https://bugzilla.suse.com/show_bug.cgi?id=1273490 * https://bugzilla.suse.com/show_bug.cgi?id=1273501 * https://bugzilla.suse.com/show_bug.cgi?id=1273503 * https://bugzilla.suse.com/show_bug.cgi?id=1273504 * https://bugzilla.suse.com/show_bug.cgi?id=1273506 * https://bugzilla.suse.com/show_bug.cgi?id=1273523 * https://bugzilla.suse.com/show_bug.cgi?id=1273525 * https://bugzilla.suse.com/show_bug.cgi?id=1273533 * https://bugzilla.suse.com/show_bug.cgi?id=1273536 * https://bugzilla.suse.com/show_bug.cgi?id=1273542 * https://bugzilla.suse.com/show_bug.cgi?id=1273555 * https://bugzilla.suse.com/show_bug.cgi?id=1273578 * https://bugzilla.suse.com/show_bug.cgi?id=1273579 * https://bugzilla.suse.com/show_bug.cgi?id=1273582 * https://bugzilla.suse.com/show_bug.cgi?id=1273596 * https://bugzilla.suse.com/show_bug.cgi?id=1273597 * https://bugzilla.suse.com/show_bug.cgi?id=1273598 * https://bugzilla.suse.com/show_bug.cgi?id=1273600 * https://bugzilla.suse.com/show_bug.cgi?id=1273601 * https://bugzilla.suse.com/show_bug.cgi?id=1273602 * https://bugzilla.suse.com/show_bug.cgi?id=1273603 * https://bugzilla.suse.com/show_bug.cgi?id=1273682 * https://bugzilla.suse.com/show_bug.cgi?id=1273734 * https://bugzilla.suse.com/show_bug.cgi?id=1273738 * https://bugzilla.suse.com/show_bug.cgi?id=1273739 * https://bugzilla.suse.com/show_bug.cgi?id=1273741 * https://bugzilla.suse.com/show_bug.cgi?id=1273742 * https://bugzilla.suse.com/show_bug.cgi?id=1273743 * https://bugzilla.suse.com/show_bug.cgi?id=1273745 * https://bugzilla.suse.com/show_bug.cgi?id=1273748 * https://bugzilla.suse.com/show_bug.cgi?id=1273749 * https://bugzilla.suse.com/show_bug.cgi?id=1273755 * https://bugzilla.suse.com/show_bug.cgi?id=1273762 * https://bugzilla.suse.com/show_bug.cgi?id=1273765 * https://bugzilla.suse.com/show_bug.cgi?id=1273766 * https://bugzilla.suse.com/show_bug.cgi?id=1273769 * https://bugzilla.suse.com/show_bug.cgi?id=1273774 * https://bugzilla.suse.com/show_bug.cgi?id=1273778 * https://bugzilla.suse.com/show_bug.cgi?id=1273780 * https://bugzilla.suse.com/show_bug.cgi?id=1273790 * https://bugzilla.suse.com/show_bug.cgi?id=1273796 * https://bugzilla.suse.com/show_bug.cgi?id=1273804 * https://bugzilla.suse.com/show_bug.cgi?id=1273810 * https://bugzilla.suse.com/show_bug.cgi?id=1273811 * https://bugzilla.suse.com/show_bug.cgi?id=1273813 * https://bugzilla.suse.com/show_bug.cgi?id=1273817 * https://bugzilla.suse.com/show_bug.cgi?id=1273822 * https://bugzilla.suse.com/show_bug.cgi?id=1273824 * https://bugzilla.suse.com/show_bug.cgi?id=1273831 * https://bugzilla.suse.com/show_bug.cgi?id=1273832 * https://bugzilla.suse.com/show_bug.cgi?id=1273834 * https://bugzilla.suse.com/show_bug.cgi?id=1273838 * https://bugzilla.suse.com/show_bug.cgi?id=1273844 * https://bugzilla.suse.com/show_bug.cgi?id=1273849 * https://bugzilla.suse.com/show_bug.cgi?id=1273860 * https://bugzilla.suse.com/show_bug.cgi?id=1273862 * https://bugzilla.suse.com/show_bug.cgi?id=1273867 * https://bugzilla.suse.com/show_bug.cgi?id=1273868 * https://bugzilla.suse.com/show_bug.cgi?id=1273869 * https://bugzilla.suse.com/show_bug.cgi?id=1273872 * https://bugzilla.suse.com/show_bug.cgi?id=1273876 * https://bugzilla.suse.com/show_bug.cgi?id=1273877 * https://bugzilla.suse.com/show_bug.cgi?id=1273880 * https://bugzilla.suse.com/show_bug.cgi?id=1273882 * https://bugzilla.suse.com/show_bug.cgi?id=1273890 * https://bugzilla.suse.com/show_bug.cgi?id=1273891 * https://bugzilla.suse.com/show_bug.cgi?id=1273892 * https://bugzilla.suse.com/show_bug.cgi?id=1273895 * https://bugzilla.suse.com/show_bug.cgi?id=1273896 * https://bugzilla.suse.com/show_bug.cgi?id=1273903 * https://bugzilla.suse.com/show_bug.cgi?id=1273905 * https://bugzilla.suse.com/show_bug.cgi?id=1273930 * https://bugzilla.suse.com/show_bug.cgi?id=1273933 * https://bugzilla.suse.com/show_bug.cgi?id=1273934 * https://bugzilla.suse.com/show_bug.cgi?id=1273935 * https://bugzilla.suse.com/show_bug.cgi?id=1273936 * https://bugzilla.suse.com/show_bug.cgi?id=1273939 * https://bugzilla.suse.com/show_bug.cgi?id=1273940 * https://bugzilla.suse.com/show_bug.cgi?id=1273941 * https://bugzilla.suse.com/show_bug.cgi?id=1273942 * https://bugzilla.suse.com/show_bug.cgi?id=1273944 * https://bugzilla.suse.com/show_bug.cgi?id=1273945 * https://bugzilla.suse.com/show_bug.cgi?id=1273946 * https://bugzilla.suse.com/show_bug.cgi?id=1273956 * https://bugzilla.suse.com/show_bug.cgi?id=1273957 * https://bugzilla.suse.com/show_bug.cgi?id=1273958 * https://bugzilla.suse.com/show_bug.cgi?id=1273966 * https://bugzilla.suse.com/show_bug.cgi?id=1273967 * https://bugzilla.suse.com/show_bug.cgi?id=1273968 * https://bugzilla.suse.com/show_bug.cgi?id=1273972 * https://bugzilla.suse.com/show_bug.cgi?id=1273974 * https://bugzilla.suse.com/show_bug.cgi?id=1273975 * https://bugzilla.suse.com/show_bug.cgi?id=1273977 * https://bugzilla.suse.com/show_bug.cgi?id=1273982 * https://bugzilla.suse.com/show_bug.cgi?id=1273988 * https://bugzilla.suse.com/show_bug.cgi?id=1273990 * https://bugzilla.suse.com/show_bug.cgi?id=1273991 * https://bugzilla.suse.com/show_bug.cgi?id=1273995 * https://bugzilla.suse.com/show_bug.cgi?id=1274001 * https://bugzilla.suse.com/show_bug.cgi?id=1274003 * https://bugzilla.suse.com/show_bug.cgi?id=1274006 * https://bugzilla.suse.com/show_bug.cgi?id=1274011 * https://bugzilla.suse.com/show_bug.cgi?id=1274012 * https://bugzilla.suse.com/show_bug.cgi?id=1274014 * https://bugzilla.suse.com/show_bug.cgi?id=1274017 * https://bugzilla.suse.com/show_bug.cgi?id=1274019 * https://bugzilla.suse.com/show_bug.cgi?id=1274020 * https://bugzilla.suse.com/show_bug.cgi?id=1274026 * https://bugzilla.suse.com/show_bug.cgi?id=1274028 * https://bugzilla.suse.com/show_bug.cgi?id=1274030 * https://bugzilla.suse.com/show_bug.cgi?id=1274031 * https://bugzilla.suse.com/show_bug.cgi?id=1274035 * https://bugzilla.suse.com/show_bug.cgi?id=1274040 * https://bugzilla.suse.com/show_bug.cgi?id=1274041 * https://bugzilla.suse.com/show_bug.cgi?id=1274057 * https://bugzilla.suse.com/show_bug.cgi?id=1274058 * https://bugzilla.suse.com/show_bug.cgi?id=1274061 * https://bugzilla.suse.com/show_bug.cgi?id=1274063 * https://bugzilla.suse.com/show_bug.cgi?id=1274065 * https://bugzilla.suse.com/show_bug.cgi?id=1274067 * https://bugzilla.suse.com/show_bug.cgi?id=1274075 * https://bugzilla.suse.com/show_bug.cgi?id=1274076 * https://bugzilla.suse.com/show_bug.cgi?id=1274077 * https://bugzilla.suse.com/show_bug.cgi?id=1274078 * https://bugzilla.suse.com/show_bug.cgi?id=1274208 * https://bugzilla.suse.com/show_bug.cgi?id=1274226 * https://bugzilla.suse.com/show_bug.cgi?id=1274239 * https://bugzilla.suse.com/show_bug.cgi?id=1274243 * https://bugzilla.suse.com/show_bug.cgi?id=1274258 * https://bugzilla.suse.com/show_bug.cgi?id=1274265 * https://bugzilla.suse.com/show_bug.cgi?id=1274274 * https://bugzilla.suse.com/show_bug.cgi?id=1274277 * https://bugzilla.suse.com/show_bug.cgi?id=1274278 * https://bugzilla.suse.com/show_bug.cgi?id=1274281 * https://bugzilla.suse.com/show_bug.cgi?id=1274283 * https://bugzilla.suse.com/show_bug.cgi?id=1274286 * https://bugzilla.suse.com/show_bug.cgi?id=1274290 * https://bugzilla.suse.com/show_bug.cgi?id=1274294 * https://bugzilla.suse.com/show_bug.cgi?id=1274296 * https://bugzilla.suse.com/show_bug.cgi?id=1274297 * https://bugzilla.suse.com/show_bug.cgi?id=1274298 * https://bugzilla.suse.com/show_bug.cgi?id=1274314 * https://bugzilla.suse.com/show_bug.cgi?id=1274321 * https://bugzilla.suse.com/show_bug.cgi?id=1274491 * https://bugzilla.suse.com/show_bug.cgi?id=1274497 * https://bugzilla.suse.com/show_bug.cgi?id=1274539 * https://bugzilla.suse.com/show_bug.cgi?id=1274541 * https://bugzilla.suse.com/show_bug.cgi?id=1274543 * https://bugzilla.suse.com/show_bug.cgi?id=1274545 * https://bugzilla.suse.com/show_bug.cgi?id=1274547 * https://bugzilla.suse.com/show_bug.cgi?id=1274550 * https://bugzilla.suse.com/show_bug.cgi?id=1274573 * https://bugzilla.suse.com/show_bug.cgi?id=1274578 * https://bugzilla.suse.com/show_bug.cgi?id=1274580 * https://bugzilla.suse.com/show_bug.cgi?id=1274581 * https://bugzilla.suse.com/show_bug.cgi?id=1274620 * https://bugzilla.suse.com/show_bug.cgi?id=1274622 * https://bugzilla.suse.com/show_bug.cgi?id=1274624 * https://bugzilla.suse.com/show_bug.cgi?id=1274629 * https://bugzilla.suse.com/show_bug.cgi?id=1274632 * https://bugzilla.suse.com/show_bug.cgi?id=1274636 * https://bugzilla.suse.com/show_bug.cgi?id=1274639 * https://bugzilla.suse.com/show_bug.cgi?id=1274640 * https://bugzilla.suse.com/show_bug.cgi?id=1274642 * https://bugzilla.suse.com/show_bug.cgi?id=1274644 * https://bugzilla.suse.com/show_bug.cgi?id=1274645 * https://bugzilla.suse.com/show_bug.cgi?id=1274646 * https://bugzilla.suse.com/show_bug.cgi?id=1274649 * https://bugzilla.suse.com/show_bug.cgi?id=1274650 * https://bugzilla.suse.com/show_bug.cgi?id=1274651 * https://bugzilla.suse.com/show_bug.cgi?id=1274656 * https://bugzilla.suse.com/show_bug.cgi?id=1274659 * https://bugzilla.suse.com/show_bug.cgi?id=1274662 * https://bugzilla.suse.com/show_bug.cgi?id=1274663 * https://bugzilla.suse.com/show_bug.cgi?id=1274665 * https://bugzilla.suse.com/show_bug.cgi?id=1274667 * https://bugzilla.suse.com/show_bug.cgi?id=1274670 * https://bugzilla.suse.com/show_bug.cgi?id=1274675 * https://bugzilla.suse.com/show_bug.cgi?id=1274677 * https://bugzilla.suse.com/show_bug.cgi?id=1274678 * https://bugzilla.suse.com/show_bug.cgi?id=1274679 * https://bugzilla.suse.com/show_bug.cgi?id=1274681 * https://bugzilla.suse.com/show_bug.cgi?id=1274682 * https://bugzilla.suse.com/show_bug.cgi?id=1274690 * https://bugzilla.suse.com/show_bug.cgi?id=1274694 * https://bugzilla.suse.com/show_bug.cgi?id=1274696 * https://bugzilla.suse.com/show_bug.cgi?id=1274698 * https://bugzilla.suse.com/show_bug.cgi?id=1274699 * https://bugzilla.suse.com/show_bug.cgi?id=1274700 * https://bugzilla.suse.com/show_bug.cgi?id=1274702 * https://bugzilla.suse.com/show_bug.cgi?id=1274703 * https://bugzilla.suse.com/show_bug.cgi?id=1274705 * https://bugzilla.suse.com/show_bug.cgi?id=1274706 * https://bugzilla.suse.com/show_bug.cgi?id=1274709 * https://bugzilla.suse.com/show_bug.cgi?id=1274710 * https://bugzilla.suse.com/show_bug.cgi?id=1274713 * https://bugzilla.suse.com/show_bug.cgi?id=1274716 * https://bugzilla.suse.com/show_bug.cgi?id=1274721 * https://bugzilla.suse.com/show_bug.cgi?id=1274725 * https://bugzilla.suse.com/show_bug.cgi?id=1274737 * https://bugzilla.suse.com/show_bug.cgi?id=1274738 * https://bugzilla.suse.com/show_bug.cgi?id=1274749 * https://bugzilla.suse.com/show_bug.cgi?id=1274752 * https://bugzilla.suse.com/show_bug.cgi?id=1274753 * https://bugzilla.suse.com/show_bug.cgi?id=1274754 * https://bugzilla.suse.com/show_bug.cgi?id=1274755 * https://bugzilla.suse.com/show_bug.cgi?id=1274756 * https://bugzilla.suse.com/show_bug.cgi?id=1274764 * https://bugzilla.suse.com/show_bug.cgi?id=1274768 * https://bugzilla.suse.com/show_bug.cgi?id=1274770 * https://bugzilla.suse.com/show_bug.cgi?id=1274787 * https://bugzilla.suse.com/show_bug.cgi?id=1274800 * https://bugzilla.suse.com/show_bug.cgi?id=1274801 * https://bugzilla.suse.com/show_bug.cgi?id=1274802 * https://bugzilla.suse.com/show_bug.cgi?id=1274804 * https://bugzilla.suse.com/show_bug.cgi?id=1274805 * https://bugzilla.suse.com/show_bug.cgi?id=1274807 * https://bugzilla.suse.com/show_bug.cgi?id=1274808 * https://bugzilla.suse.com/show_bug.cgi?id=1274811 * https://bugzilla.suse.com/show_bug.cgi?id=1274813 * https://bugzilla.suse.com/show_bug.cgi?id=1274814 * https://bugzilla.suse.com/show_bug.cgi?id=1274831 * https://bugzilla.suse.com/show_bug.cgi?id=1274834 * https://bugzilla.suse.com/show_bug.cgi?id=1274847 * https://bugzilla.suse.com/show_bug.cgi?id=1274853 * https://bugzilla.suse.com/show_bug.cgi?id=1274868 * https://bugzilla.suse.com/show_bug.cgi?id=1274869 * https://bugzilla.suse.com/show_bug.cgi?id=1274872 * https://bugzilla.suse.com/show_bug.cgi?id=1274873 * https://bugzilla.suse.com/show_bug.cgi?id=1274874 * https://bugzilla.suse.com/show_bug.cgi?id=1274876 * https://bugzilla.suse.com/show_bug.cgi?id=1274879 * https://bugzilla.suse.com/show_bug.cgi?id=1274881 * https://bugzilla.suse.com/show_bug.cgi?id=1274883 * https://bugzilla.suse.com/show_bug.cgi?id=1274886 * https://bugzilla.suse.com/show_bug.cgi?id=1274888 * https://bugzilla.suse.com/show_bug.cgi?id=1274891 * https://bugzilla.suse.com/show_bug.cgi?id=1274892 * https://bugzilla.suse.com/show_bug.cgi?id=1274893 * https://bugzilla.suse.com/show_bug.cgi?id=1274894 * https://bugzilla.suse.com/show_bug.cgi?id=1274896 * https://bugzilla.suse.com/show_bug.cgi?id=1274897 * https://bugzilla.suse.com/show_bug.cgi?id=1274898 * https://bugzilla.suse.com/show_bug.cgi?id=1274899 * https://bugzilla.suse.com/show_bug.cgi?id=1274901 * https://bugzilla.suse.com/show_bug.cgi?id=1274902 * https://bugzilla.suse.com/show_bug.cgi?id=1274905 * https://bugzilla.suse.com/show_bug.cgi?id=1274907 * https://bugzilla.suse.com/show_bug.cgi?id=1274908 * https://bugzilla.suse.com/show_bug.cgi?id=1274913 * https://bugzilla.suse.com/show_bug.cgi?id=1274914 * https://bugzilla.suse.com/show_bug.cgi?id=1274920 * https://bugzilla.suse.com/show_bug.cgi?id=1274921 * https://bugzilla.suse.com/show_bug.cgi?id=1274924 * https://bugzilla.suse.com/show_bug.cgi?id=1274925 * https://bugzilla.suse.com/show_bug.cgi?id=1274929 * https://bugzilla.suse.com/show_bug.cgi?id=1274930 * https://bugzilla.suse.com/show_bug.cgi?id=1274933 * https://bugzilla.suse.com/show_bug.cgi?id=1274934 * https://bugzilla.suse.com/show_bug.cgi?id=1274935 * https://bugzilla.suse.com/show_bug.cgi?id=1274941 * https://bugzilla.suse.com/show_bug.cgi?id=1274945 * https://bugzilla.suse.com/show_bug.cgi?id=1274947 * https://bugzilla.suse.com/show_bug.cgi?id=1274951 * https://bugzilla.suse.com/show_bug.cgi?id=1274953 * https://bugzilla.suse.com/show_bug.cgi?id=1274958 * https://bugzilla.suse.com/show_bug.cgi?id=1274968 * https://bugzilla.suse.com/show_bug.cgi?id=1274981 * https://bugzilla.suse.com/show_bug.cgi?id=1275040 * https://bugzilla.suse.com/show_bug.cgi?id=1275069 * https://bugzilla.suse.com/show_bug.cgi?id=1275071 * https://bugzilla.suse.com/show_bug.cgi?id=1275073 * https://bugzilla.suse.com/show_bug.cgi?id=1275076 * https://bugzilla.suse.com/show_bug.cgi?id=1275080 * https://bugzilla.suse.com/show_bug.cgi?id=1275083 * https://bugzilla.suse.com/show_bug.cgi?id=1275088 * https://bugzilla.suse.com/show_bug.cgi?id=1275091 * https://bugzilla.suse.com/show_bug.cgi?id=1275125 * https://bugzilla.suse.com/show_bug.cgi?id=1275126 * https://bugzilla.suse.com/show_bug.cgi?id=1275131 * https://bugzilla.suse.com/show_bug.cgi?id=1275132 * https://bugzilla.suse.com/show_bug.cgi?id=1275150 * https://bugzilla.suse.com/show_bug.cgi?id=1275152 * https://bugzilla.suse.com/show_bug.cgi?id=1275154 * https://bugzilla.suse.com/show_bug.cgi?id=1275155 * https://bugzilla.suse.com/show_bug.cgi?id=1275157 * https://bugzilla.suse.com/show_bug.cgi?id=1275158 * https://bugzilla.suse.com/show_bug.cgi?id=1275161 * https://bugzilla.suse.com/show_bug.cgi?id=1275163 * https://bugzilla.suse.com/show_bug.cgi?id=1275164 * https://bugzilla.suse.com/show_bug.cgi?id=1275169 * https://bugzilla.suse.com/show_bug.cgi?id=1275173 * https://bugzilla.suse.com/show_bug.cgi?id=1275176 * https://bugzilla.suse.com/show_bug.cgi?id=1275185 * https://bugzilla.suse.com/show_bug.cgi?id=1275190 * https://bugzilla.suse.com/show_bug.cgi?id=1275236 * https://bugzilla.suse.com/show_bug.cgi?id=1275237 * https://bugzilla.suse.com/show_bug.cgi?id=1275239 * https://bugzilla.suse.com/show_bug.cgi?id=1275294 * https://bugzilla.suse.com/show_bug.cgi?id=1275301 * https://bugzilla.suse.com/show_bug.cgi?id=1275303 * https://bugzilla.suse.com/show_bug.cgi?id=1275304 * https://bugzilla.suse.com/show_bug.cgi?id=1275305 * https://bugzilla.suse.com/show_bug.cgi?id=1275306 * https://bugzilla.suse.com/show_bug.cgi?id=1275307 * https://bugzilla.suse.com/show_bug.cgi?id=1275470 * https://bugzilla.suse.com/show_bug.cgi?id=1275472 * https://bugzilla.suse.com/show_bug.cgi?id=1275474 * https://bugzilla.suse.com/show_bug.cgi?id=1275479 * https://bugzilla.suse.com/show_bug.cgi?id=1275483 * https://bugzilla.suse.com/show_bug.cgi?id=1275486 * https://bugzilla.suse.com/show_bug.cgi?id=1275487 * https://bugzilla.suse.com/show_bug.cgi?id=1275506 * https://bugzilla.suse.com/show_bug.cgi?id=1275509 * https://bugzilla.suse.com/show_bug.cgi?id=1275511 * https://bugzilla.suse.com/show_bug.cgi?id=1275517 * https://bugzilla.suse.com/show_bug.cgi?id=1275528 * https://bugzilla.suse.com/show_bug.cgi?id=1275535 * https://bugzilla.suse.com/show_bug.cgi?id=1275540 * https://bugzilla.suse.com/show_bug.cgi?id=1275553 * https://bugzilla.suse.com/show_bug.cgi?id=1275555 * https://bugzilla.suse.com/show_bug.cgi?id=1275561 * https://bugzilla.suse.com/show_bug.cgi?id=1275566 * https://bugzilla.suse.com/show_bug.cgi?id=1275569 * https://bugzilla.suse.com/show_bug.cgi?id=1275574 * https://bugzilla.suse.com/show_bug.cgi?id=1275578 * https://bugzilla.suse.com/show_bug.cgi?id=1275582 * https://bugzilla.suse.com/show_bug.cgi?id=1275583 * https://bugzilla.suse.com/show_bug.cgi?id=1275584 * https://bugzilla.suse.com/show_bug.cgi?id=1275591 * https://bugzilla.suse.com/show_bug.cgi?id=1275595 * https://bugzilla.suse.com/show_bug.cgi?id=1275633 * https://bugzilla.suse.com/show_bug.cgi?id=1275636 * https://bugzilla.suse.com/show_bug.cgi?id=1275650 * https://bugzilla.suse.com/show_bug.cgi?id=1275659 * https://bugzilla.suse.com/show_bug.cgi?id=1275665 * https://bugzilla.suse.com/show_bug.cgi?id=1275669 * https://bugzilla.suse.com/show_bug.cgi?id=1275687 * https://bugzilla.suse.com/show_bug.cgi?id=1275688 * https://bugzilla.suse.com/show_bug.cgi?id=1275695 * https://bugzilla.suse.com/show_bug.cgi?id=1275696 * https://bugzilla.suse.com/show_bug.cgi?id=1275704 * https://bugzilla.suse.com/show_bug.cgi?id=1275782 * https://bugzilla.suse.com/show_bug.cgi?id=1275784 * https://bugzilla.suse.com/show_bug.cgi?id=1275787 * https://bugzilla.suse.com/show_bug.cgi?id=1275788 * https://bugzilla.suse.com/show_bug.cgi?id=1275790 * https://bugzilla.suse.com/show_bug.cgi?id=1275797 * https://bugzilla.suse.com/show_bug.cgi?id=1275798 * https://bugzilla.suse.com/show_bug.cgi?id=1275805 * https://bugzilla.suse.com/show_bug.cgi?id=1275817 * https://bugzilla.suse.com/show_bug.cgi?id=1275818 * https://bugzilla.suse.com/show_bug.cgi?id=1275819 * https://bugzilla.suse.com/show_bug.cgi?id=1275820 * https://bugzilla.suse.com/show_bug.cgi?id=1275821 * https://bugzilla.suse.com/show_bug.cgi?id=1275827 * https://bugzilla.suse.com/show_bug.cgi?id=1275864 * https://bugzilla.suse.com/show_bug.cgi?id=1275867 * https://bugzilla.suse.com/show_bug.cgi?id=1275869 * https://bugzilla.suse.com/show_bug.cgi?id=1275870 * https://bugzilla.suse.com/show_bug.cgi?id=1275871 * https://bugzilla.suse.com/show_bug.cgi?id=1275872 * https://bugzilla.suse.com/show_bug.cgi?id=1275886 * https://bugzilla.suse.com/show_bug.cgi?id=1275905 * https://bugzilla.suse.com/show_bug.cgi?id=1275923 * https://bugzilla.suse.com/show_bug.cgi?id=1275925 * https://bugzilla.suse.com/show_bug.cgi?id=1275946 * https://bugzilla.suse.com/show_bug.cgi?id=1275950 * https://bugzilla.suse.com/show_bug.cgi?id=1275954 * https://bugzilla.suse.com/show_bug.cgi?id=1275970 * https://bugzilla.suse.com/show_bug.cgi?id=1275973 * https://bugzilla.suse.com/show_bug.cgi?id=1275975 * https://bugzilla.suse.com/show_bug.cgi?id=1275976 * https://bugzilla.suse.com/show_bug.cgi?id=1276029 * https://bugzilla.suse.com/show_bug.cgi?id=1276257 * https://bugzilla.suse.com/show_bug.cgi?id=1276263 * https://bugzilla.suse.com/show_bug.cgi?id=1276270 * https://bugzilla.suse.com/show_bug.cgi?id=1276273 * https://bugzilla.suse.com/show_bug.cgi?id=1276277 * https://bugzilla.suse.com/show_bug.cgi?id=1276335 * https://bugzilla.suse.com/show_bug.cgi?id=1276346 * https://bugzilla.suse.com/show_bug.cgi?id=1276350 * https://bugzilla.suse.com/show_bug.cgi?id=1276355 * https://bugzilla.suse.com/show_bug.cgi?id=1276446 * https://bugzilla.suse.com/show_bug.cgi?id=1276452 * https://bugzilla.suse.com/show_bug.cgi?id=1276500 * https://bugzilla.suse.com/show_bug.cgi?id=1276507 * https://bugzilla.suse.com/show_bug.cgi?id=1276542 * https://bugzilla.suse.com/show_bug.cgi?id=1276546 * https://bugzilla.suse.com/show_bug.cgi?id=1276551 * https://bugzilla.suse.com/show_bug.cgi?id=1276561 * https://bugzilla.suse.com/show_bug.cgi?id=1276569 * https://bugzilla.suse.com/show_bug.cgi?id=1276665 * https://bugzilla.suse.com/show_bug.cgi?id=1276864 * https://bugzilla.suse.com/show_bug.cgi?id=1276927 * https://bugzilla.suse.com/show_bug.cgi?id=1276931 * https://bugzilla.suse.com/show_bug.cgi?id=1276937 * https://bugzilla.suse.com/show_bug.cgi?id=1276941 * https://bugzilla.suse.com/show_bug.cgi?id=1276943 * https://bugzilla.suse.com/show_bug.cgi?id=1276961 * https://bugzilla.suse.com/show_bug.cgi?id=1277022 * https://bugzilla.suse.com/show_bug.cgi?id=1277034 * https://bugzilla.suse.com/show_bug.cgi?id=1277037 * https://bugzilla.suse.com/show_bug.cgi?id=1277047 * https://bugzilla.suse.com/show_bug.cgi?id=1277054 * https://bugzilla.suse.com/show_bug.cgi?id=1277057 * https://bugzilla.suse.com/show_bug.cgi?id=1277059 * https://bugzilla.suse.com/show_bug.cgi?id=1277064 * https://bugzilla.suse.com/show_bug.cgi?id=1277066 * https://bugzilla.suse.com/show_bug.cgi?id=1277069 * https://bugzilla.suse.com/show_bug.cgi?id=1277073 * https://bugzilla.suse.com/show_bug.cgi?id=1277077 * https://bugzilla.suse.com/show_bug.cgi?id=1277095 * https://bugzilla.suse.com/show_bug.cgi?id=1277155 * https://bugzilla.suse.com/show_bug.cgi?id=1277159 * https://bugzilla.suse.com/show_bug.cgi?id=1277160 * https://bugzilla.suse.com/show_bug.cgi?id=1277202 * https://bugzilla.suse.com/show_bug.cgi?id=1277204 * https://bugzilla.suse.com/show_bug.cgi?id=1277275 * https://bugzilla.suse.com/show_bug.cgi?id=1277285 * https://bugzilla.suse.com/show_bug.cgi?id=1277391 * https://bugzilla.suse.com/show_bug.cgi?id=1277408 * https://bugzilla.suse.com/show_bug.cgi?id=1277516 * https://bugzilla.suse.com/show_bug.cgi?id=1277523 * https://bugzilla.suse.com/show_bug.cgi?id=1277551 * https://bugzilla.suse.com/show_bug.cgi?id=1277625 * https://bugzilla.suse.com/show_bug.cgi?id=1277660 * https://bugzilla.suse.com/show_bug.cgi?id=1277678 * https://bugzilla.suse.com/show_bug.cgi?id=1277688 * https://bugzilla.suse.com/show_bug.cgi?id=1277775 * https://bugzilla.suse.com/show_bug.cgi?id=1277776 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 17:07:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 17:07:32 -0000 Subject: SUSE-SU-2026:23528-1: important: Security update for the Linux Kernel Message-ID: <178914645256.7040.11219862104847732450@bab013902bd8> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:23528-1 Release Date: 2026-09-08T12:54:32Z Rating: important References: * bsc#1230238 * bsc#1235944 * bsc#1247455 * bsc#1250748 * bsc#1251966 * bsc#1252682 * bsc#1254306 * bsc#1255225 * bsc#1255250 * bsc#1256629 * bsc#1256708 * bsc#1257154 * bsc#1258430 * bsc#1258517 * bsc#1260522 * bsc#1261780 * bsc#1261788 * bsc#1262073 * bsc#1263004 * bsc#1263061 * bsc#1263133 * bsc#1264335 * bsc#1264446 * bsc#1264541 * bsc#1264584 * bsc#1264587 * bsc#1264619 * bsc#1264788 * bsc#1265068 * bsc#1265121 * bsc#1265449 * bsc#1265928 * bsc#1266402 * bsc#1266860 * bsc#1266874 * bsc#1266897 * bsc#1267023 * bsc#1267238 * bsc#1267501 * bsc#1267612 * bsc#1268276 * bsc#1268972 * bsc#1268979 * bsc#1268987 * bsc#1269004 * bsc#1269013 * bsc#1269108 * bsc#1269113 * bsc#1269114 * bsc#1269126 * bsc#1269167 * bsc#1269234 * bsc#1269238 * bsc#1269242 * bsc#1269256 * bsc#1269301 * bsc#1269306 * bsc#1269381 * bsc#1269388 * bsc#1269412 * bsc#1269530 * bsc#1269579 * bsc#1269590 * bsc#1269635 * bsc#1269655 * bsc#1269665 * bsc#1269686 * bsc#1269695 * bsc#1269713 * bsc#1269731 * bsc#1269774 * bsc#1269783 * bsc#1269792 * bsc#1269815 * bsc#1269965 * bsc#1269969 * bsc#1269981 * bsc#1269985 * bsc#1270090 * bsc#1270108 * bsc#1270111 * bsc#1270251 * bsc#1271256 * bsc#1271365 * bsc#1271366 * bsc#1271825 * bsc#1271830 * bsc#1272150 * bsc#1272175 * bsc#1272179 * bsc#1272182 * bsc#1272200 * bsc#1272210 * bsc#1272213 * bsc#1272230 * bsc#1272260 * bsc#1272261 * bsc#1272262 * bsc#1272297 * bsc#1272346 * bsc#1272381 * bsc#1272385 * bsc#1272390 * bsc#1272423 * bsc#1272429 * bsc#1272484 * bsc#1272486 * bsc#1272497 * bsc#1272516 * bsc#1272569 * bsc#1272571 * bsc#1272641 * bsc#1272643 * bsc#1272662 * bsc#1272673 * bsc#1272680 * bsc#1272682 * bsc#1272756 * bsc#1272786 * bsc#1272788 * bsc#1272798 * bsc#1272799 * bsc#1272868 * bsc#1272877 * bsc#1272891 * bsc#1272963 * bsc#1272983 * bsc#1273008 * bsc#1273019 * bsc#1273027 * bsc#1273028 * bsc#1273030 * bsc#1273038 * bsc#1273053 * bsc#1273054 * bsc#1273060 * bsc#1273105 * bsc#1273249 * bsc#1273250 * bsc#1273260 * bsc#1273273 * bsc#1273274 * bsc#1273276 * bsc#1273281 * bsc#1273284 * bsc#1273285 * bsc#1273289 * bsc#1273291 * bsc#1273294 * bsc#1273302 * bsc#1273303 * bsc#1273305 * bsc#1273310 * bsc#1273311 * bsc#1273316 * bsc#1273318 * bsc#1273319 * bsc#1273323 * bsc#1273325 * bsc#1273327 * bsc#1273334 * bsc#1273335 * bsc#1273336 * bsc#1273337 * bsc#1273338 * bsc#1273340 * bsc#1273341 * bsc#1273346 * bsc#1273422 * bsc#1273426 * bsc#1273443 * bsc#1273463 * bsc#1273468 * bsc#1273469 * bsc#1273471 * bsc#1273479 * bsc#1273480 * bsc#1273482 * bsc#1273484 * bsc#1273488 * bsc#1273490 * bsc#1273501 * bsc#1273503 * bsc#1273504 * bsc#1273506 * bsc#1273523 * bsc#1273525 * bsc#1273533 * bsc#1273536 * bsc#1273542 * bsc#1273555 * bsc#1273578 * bsc#1273579 * bsc#1273582 * bsc#1273596 * bsc#1273597 * bsc#1273598 * bsc#1273600 * bsc#1273601 * bsc#1273602 * bsc#1273603 * bsc#1273682 * bsc#1273734 * bsc#1273738 * bsc#1273739 * bsc#1273741 * bsc#1273742 * bsc#1273743 * bsc#1273745 * bsc#1273748 * bsc#1273749 * bsc#1273755 * bsc#1273762 * bsc#1273765 * bsc#1273766 * bsc#1273769 * bsc#1273774 * bsc#1273778 * bsc#1273780 * bsc#1273790 * bsc#1273796 * bsc#1273804 * bsc#1273810 * bsc#1273811 * bsc#1273813 * bsc#1273817 * bsc#1273822 * bsc#1273824 * bsc#1273831 * bsc#1273832 * bsc#1273834 * bsc#1273838 * bsc#1273844 * bsc#1273849 * bsc#1273860 * bsc#1273862 * bsc#1273867 * bsc#1273868 * bsc#1273869 * bsc#1273872 * bsc#1273876 * bsc#1273877 * bsc#1273880 * bsc#1273882 * bsc#1273890 * bsc#1273891 * bsc#1273892 * bsc#1273895 * bsc#1273896 * bsc#1273903 * bsc#1273905 * bsc#1273930 * bsc#1273933 * bsc#1273934 * bsc#1273935 * bsc#1273936 * bsc#1273939 * bsc#1273940 * bsc#1273941 * bsc#1273942 * bsc#1273944 * bsc#1273945 * bsc#1273946 * bsc#1273956 * bsc#1273957 * bsc#1273958 * bsc#1273966 * bsc#1273967 * bsc#1273968 * bsc#1273972 * bsc#1273974 * bsc#1273975 * bsc#1273977 * bsc#1273982 * bsc#1273988 * bsc#1273990 * bsc#1273991 * bsc#1273995 * bsc#1274001 * bsc#1274003 * bsc#1274006 * bsc#1274011 * bsc#1274012 * bsc#1274014 * bsc#1274017 * bsc#1274019 * bsc#1274020 * bsc#1274026 * bsc#1274028 * bsc#1274030 * bsc#1274031 * bsc#1274035 * bsc#1274040 * bsc#1274041 * bsc#1274057 * bsc#1274058 * bsc#1274061 * bsc#1274063 * bsc#1274065 * bsc#1274067 * bsc#1274075 * bsc#1274076 * bsc#1274077 * bsc#1274078 * bsc#1274208 * bsc#1274226 * bsc#1274239 * bsc#1274243 * bsc#1274258 * bsc#1274265 * bsc#1274274 * bsc#1274277 * bsc#1274278 * bsc#1274281 * bsc#1274283 * bsc#1274286 * bsc#1274290 * bsc#1274294 * bsc#1274296 * bsc#1274297 * bsc#1274298 * bsc#1274314 * bsc#1274321 * bsc#1274491 * bsc#1274497 * bsc#1274539 * bsc#1274541 * bsc#1274543 * bsc#1274545 * bsc#1274547 * bsc#1274550 * bsc#1274573 * bsc#1274578 * bsc#1274580 * bsc#1274581 * bsc#1274620 * bsc#1274622 * bsc#1274624 * bsc#1274629 * bsc#1274632 * bsc#1274636 * bsc#1274639 * bsc#1274640 * bsc#1274642 * bsc#1274644 * bsc#1274645 * bsc#1274646 * bsc#1274649 * bsc#1274650 * bsc#1274651 * bsc#1274656 * bsc#1274659 * bsc#1274662 * bsc#1274663 * bsc#1274665 * bsc#1274667 * bsc#1274670 * bsc#1274675 * bsc#1274677 * bsc#1274678 * bsc#1274679 * bsc#1274681 * bsc#1274682 * bsc#1274690 * bsc#1274694 * bsc#1274696 * bsc#1274698 * bsc#1274699 * bsc#1274700 * bsc#1274702 * bsc#1274703 * bsc#1274705 * bsc#1274706 * bsc#1274709 * bsc#1274710 * bsc#1274713 * bsc#1274716 * bsc#1274721 * bsc#1274725 * bsc#1274737 * bsc#1274738 * bsc#1274749 * bsc#1274752 * bsc#1274753 * bsc#1274754 * bsc#1274755 * bsc#1274756 * bsc#1274764 * bsc#1274768 * bsc#1274770 * bsc#1274787 * bsc#1274800 * bsc#1274801 * bsc#1274802 * bsc#1274804 * bsc#1274805 * bsc#1274807 * bsc#1274808 * bsc#1274811 * bsc#1274813 * bsc#1274814 * bsc#1274831 * bsc#1274834 * bsc#1274847 * bsc#1274853 * bsc#1274868 * bsc#1274869 * bsc#1274872 * bsc#1274873 * bsc#1274874 * bsc#1274876 * bsc#1274879 * bsc#1274881 * bsc#1274883 * bsc#1274886 * bsc#1274888 * bsc#1274891 * bsc#1274892 * bsc#1274893 * bsc#1274894 * bsc#1274896 * bsc#1274897 * bsc#1274898 * bsc#1274899 * bsc#1274901 * bsc#1274902 * bsc#1274905 * bsc#1274907 * bsc#1274908 * bsc#1274913 * bsc#1274914 * bsc#1274920 * bsc#1274921 * bsc#1274924 * bsc#1274925 * bsc#1274929 * bsc#1274930 * bsc#1274933 * bsc#1274934 * bsc#1274935 * bsc#1274941 * bsc#1274945 * bsc#1274947 * bsc#1274951 * bsc#1274953 * bsc#1274958 * bsc#1274968 * bsc#1274981 * bsc#1275040 * bsc#1275069 * bsc#1275071 * bsc#1275073 * bsc#1275076 * bsc#1275080 * bsc#1275083 * bsc#1275088 * bsc#1275091 * bsc#1275125 * bsc#1275126 * bsc#1275131 * bsc#1275132 * bsc#1275150 * bsc#1275152 * bsc#1275154 * bsc#1275155 * bsc#1275157 * bsc#1275158 * bsc#1275161 * bsc#1275163 * bsc#1275164 * bsc#1275169 * bsc#1275173 * bsc#1275176 * bsc#1275185 * bsc#1275190 * bsc#1275236 * bsc#1275237 * bsc#1275239 * bsc#1275294 * bsc#1275301 * bsc#1275303 * bsc#1275304 * bsc#1275305 * bsc#1275306 * bsc#1275307 * bsc#1275470 * bsc#1275472 * bsc#1275474 * bsc#1275479 * bsc#1275483 * bsc#1275486 * bsc#1275487 * bsc#1275506 * bsc#1275509 * bsc#1275511 * bsc#1275517 * bsc#1275528 * bsc#1275535 * bsc#1275540 * bsc#1275553 * bsc#1275555 * bsc#1275561 * bsc#1275566 * bsc#1275569 * bsc#1275574 * bsc#1275578 * bsc#1275582 * bsc#1275583 * bsc#1275584 * bsc#1275591 * bsc#1275595 * bsc#1275633 * bsc#1275636 * bsc#1275650 * bsc#1275659 * bsc#1275665 * bsc#1275669 * bsc#1275687 * bsc#1275688 * bsc#1275695 * bsc#1275696 * bsc#1275704 * bsc#1275782 * bsc#1275784 * bsc#1275787 * bsc#1275788 * bsc#1275790 * bsc#1275797 * bsc#1275798 * bsc#1275805 * bsc#1275817 * bsc#1275818 * bsc#1275819 * bsc#1275820 * bsc#1275821 * bsc#1275827 * bsc#1275864 * bsc#1275867 * bsc#1275869 * bsc#1275870 * bsc#1275871 * bsc#1275872 * bsc#1275886 * bsc#1275905 * bsc#1275923 * bsc#1275925 * bsc#1275946 * bsc#1275950 * bsc#1275954 * bsc#1275970 * bsc#1275973 * bsc#1275975 * bsc#1275976 * bsc#1276029 * bsc#1276257 * bsc#1276263 * bsc#1276270 * bsc#1276273 * bsc#1276277 * bsc#1276335 * bsc#1276346 * bsc#1276350 * bsc#1276355 * bsc#1276446 * bsc#1276452 * bsc#1276500 * bsc#1276507 * bsc#1276542 * bsc#1276546 * bsc#1276551 * bsc#1276561 * bsc#1276569 * bsc#1276665 * bsc#1276864 * bsc#1276927 * bsc#1276931 * bsc#1276937 * bsc#1276941 * bsc#1276943 * bsc#1276961 * bsc#1277022 * bsc#1277034 * bsc#1277037 * bsc#1277047 * bsc#1277054 * bsc#1277057 * bsc#1277059 * bsc#1277064 * bsc#1277066 * bsc#1277069 * bsc#1277073 * bsc#1277077 * bsc#1277095 * bsc#1277155 * bsc#1277159 * bsc#1277160 * bsc#1277202 * bsc#1277204 * bsc#1277275 * bsc#1277285 * bsc#1277391 * bsc#1277408 * bsc#1277516 * bsc#1277523 * bsc#1277551 * bsc#1277625 * bsc#1277660 * bsc#1277678 * bsc#1277688 * bsc#1277775 * bsc#1277776 Cross-References: * CVE-2024-44981 * CVE-2024-57841 * CVE-2025-38469 * CVE-2025-39964 * CVE-2025-40022 * CVE-2025-68179 * CVE-2025-68214 * CVE-2025-71075 * CVE-2025-71104 * CVE-2026-23210 * CVE-2026-23230 * CVE-2026-23454 * CVE-2026-31392 * CVE-2026-31418 * CVE-2026-31531 * CVE-2026-31557 * CVE-2026-31663 * CVE-2026-43116 * CVE-2026-43125 * CVE-2026-43163 * CVE-2026-43271 * CVE-2026-43273 * CVE-2026-43278 * CVE-2026-43319 * CVE-2026-43363 * CVE-2026-43416 * CVE-2026-45897 * CVE-2026-45968 * CVE-2026-46070 * CVE-2026-46091 * CVE-2026-46107 * CVE-2026-46115 * CVE-2026-46195 * CVE-2026-52920 * CVE-2026-52925 * CVE-2026-52929 * CVE-2026-52935 * CVE-2026-52939 * CVE-2026-52946 * CVE-2026-52975 * CVE-2026-52977 * CVE-2026-52990 * CVE-2026-52994 * CVE-2026-53001 * CVE-2026-53033 * CVE-2026-53059 * CVE-2026-53076 * CVE-2026-53077 * CVE-2026-53089 * CVE-2026-53091 * CVE-2026-53094 * CVE-2026-53096 * CVE-2026-53110 * CVE-2026-53111 * CVE-2026-53126 * CVE-2026-53154 * CVE-2026-53163 * CVE-2026-53207 * CVE-2026-53219 * CVE-2026-53220 * CVE-2026-53223 * CVE-2026-53228 * CVE-2026-53238 * CVE-2026-53260 * CVE-2026-53264 * CVE-2026-53269 * CVE-2026-53273 * CVE-2026-53309 * CVE-2026-53330 * CVE-2026-53336 * CVE-2026-53337 * CVE-2026-53353 * CVE-2026-53365 * CVE-2026-53366 * CVE-2026-53381 * CVE-2026-53388 * CVE-2026-63801 * CVE-2026-63808 * CVE-2026-63810 * CVE-2026-63823 * CVE-2026-63827 * CVE-2026-63828 * CVE-2026-63860 * CVE-2026-63865 * CVE-2026-63868 * CVE-2026-63879 * CVE-2026-63881 * CVE-2026-63886 * CVE-2026-63887 * CVE-2026-63888 * CVE-2026-63889 * CVE-2026-63891 * CVE-2026-63898 * CVE-2026-63920 * CVE-2026-63925 * CVE-2026-63926 * CVE-2026-63928 * CVE-2026-63944 * CVE-2026-63969 * CVE-2026-63970 * CVE-2026-63972 * CVE-2026-63973 * CVE-2026-63980 * CVE-2026-63985 * CVE-2026-63990 * CVE-2026-63992 * CVE-2026-63999 * CVE-2026-64000 * CVE-2026-64001 * CVE-2026-64002 * CVE-2026-64004 * CVE-2026-64005 * CVE-2026-64006 * CVE-2026-64007 * CVE-2026-64010 * CVE-2026-64011 * CVE-2026-64014 * CVE-2026-64015 * CVE-2026-64018 * CVE-2026-64029 * CVE-2026-64034 * CVE-2026-64039 * CVE-2026-64047 * CVE-2026-64048 * CVE-2026-64051 * CVE-2026-64052 * CVE-2026-64073 * CVE-2026-64083 * CVE-2026-64084 * CVE-2026-64085 * CVE-2026-64086 * CVE-2026-64087 * CVE-2026-64088 * CVE-2026-64097 * CVE-2026-64098 * CVE-2026-64102 * CVE-2026-64109 * CVE-2026-64112 * CVE-2026-64113 * CVE-2026-64114 * CVE-2026-64115 * CVE-2026-64118 * CVE-2026-64121 * CVE-2026-64125 * CVE-2026-64126 * CVE-2026-64128 * CVE-2026-64131 * CVE-2026-64133 * CVE-2026-64135 * CVE-2026-64137 * CVE-2026-64148 * CVE-2026-64155 * CVE-2026-64164 * CVE-2026-64166 * CVE-2026-64168 * CVE-2026-64178 * CVE-2026-64185 * CVE-2026-64188 * CVE-2026-64190 * CVE-2026-64192 * CVE-2026-64214 * CVE-2026-64217 * CVE-2026-64218 * CVE-2026-64219 * CVE-2026-64222 * CVE-2026-64225 * CVE-2026-64237 * CVE-2026-64243 * CVE-2026-64245 * CVE-2026-64246 * CVE-2026-64247 * CVE-2026-64249 * CVE-2026-64257 * CVE-2026-64266 * CVE-2026-64268 * CVE-2026-64271 * CVE-2026-64273 * CVE-2026-64274 * CVE-2026-64275 * CVE-2026-64276 * CVE-2026-64277 * CVE-2026-64286 * CVE-2026-64287 * CVE-2026-64294 * CVE-2026-64296 * CVE-2026-64303 * CVE-2026-64304 * CVE-2026-64305 * CVE-2026-64306 * CVE-2026-64312 * CVE-2026-64313 * CVE-2026-64315 * CVE-2026-64316 * CVE-2026-64317 * CVE-2026-64322 * CVE-2026-64323 * CVE-2026-64329 * CVE-2026-64331 * CVE-2026-64332 * CVE-2026-64333 * CVE-2026-64334 * CVE-2026-64335 * CVE-2026-64337 * CVE-2026-64338 * CVE-2026-64340 * CVE-2026-64341 * CVE-2026-64342 * CVE-2026-64343 * CVE-2026-64344 * CVE-2026-64346 * CVE-2026-64348 * CVE-2026-64350 * CVE-2026-64351 * CVE-2026-64355 * CVE-2026-64358 * CVE-2026-64362 * CVE-2026-64365 * CVE-2026-64375 * CVE-2026-64376 * CVE-2026-64378 * CVE-2026-64381 * CVE-2026-64382 * CVE-2026-64383 * CVE-2026-64384 * CVE-2026-64385 * CVE-2026-64386 * CVE-2026-64387 * CVE-2026-64388 * CVE-2026-64401 * CVE-2026-64403 * CVE-2026-64406 * CVE-2026-64408 * CVE-2026-64409 * CVE-2026-64411 * CVE-2026-64412 * CVE-2026-64420 * CVE-2026-64421 * CVE-2026-64423 * CVE-2026-64427 * CVE-2026-64429 * CVE-2026-64433 * CVE-2026-64434 * CVE-2026-64436 * CVE-2026-64440 * CVE-2026-64442 * CVE-2026-64443 * CVE-2026-64444 * CVE-2026-64445 * CVE-2026-64448 * CVE-2026-64450 * CVE-2026-64454 * CVE-2026-64455 * CVE-2026-64463 * CVE-2026-64470 * CVE-2026-64471 * CVE-2026-64472 * CVE-2026-64478 * CVE-2026-64479 * CVE-2026-64480 * CVE-2026-64481 * CVE-2026-64482 * CVE-2026-64483 * CVE-2026-64484 * CVE-2026-64486 * CVE-2026-64487 * CVE-2026-64489 * CVE-2026-64494 * CVE-2026-64495 * CVE-2026-64496 * CVE-2026-64497 * CVE-2026-64500 * CVE-2026-64503 * CVE-2026-64504 * CVE-2026-64505 * CVE-2026-64511 * CVE-2026-64512 * CVE-2026-64513 * CVE-2026-64524 * CVE-2026-64527 * CVE-2026-64536 * CVE-2026-64537 * CVE-2026-64538 * CVE-2026-64539 * CVE-2026-64540 * CVE-2026-64541 * CVE-2026-64543 * CVE-2026-64544 * CVE-2026-64545 * CVE-2026-64546 * CVE-2026-64547 * CVE-2026-64548 * CVE-2026-64549 * CVE-2026-64551 * CVE-2026-64552 * CVE-2026-64553 * CVE-2026-64554 * CVE-2026-64562 * CVE-2026-64563 * CVE-2026-64565 * CVE-2026-64567 * CVE-2026-64571 * CVE-2026-64572 * CVE-2026-64573 * CVE-2026-64574 * CVE-2026-64576 * CVE-2026-64577 * CVE-2026-64581 * CVE-2026-64582 * CVE-2026-64583 * CVE-2026-64584 * CVE-2026-64585 * CVE-2026-64593 * CVE-2026-64597 * CVE-2026-64598 * CVE-2026-64599 * CVE-2026-64602 * CVE-2026-64604 * CVE-2026-68081 * CVE-2026-68082 * CVE-2026-68085 * CVE-2026-68086 * CVE-2026-68088 * CVE-2026-68091 * CVE-2026-68093 * CVE-2026-68102 * CVE-2026-68104 * CVE-2026-68106 * CVE-2026-68107 * CVE-2026-68108 * CVE-2026-68110 * CVE-2026-68111 * CVE-2026-68112 * CVE-2026-68115 * CVE-2026-68116 * CVE-2026-68117 * CVE-2026-68121 * CVE-2026-68123 * CVE-2026-68125 * CVE-2026-68126 * CVE-2026-68127 * CVE-2026-68129 * CVE-2026-68132 * CVE-2026-68133 * CVE-2026-68136 * CVE-2026-68137 * CVE-2026-68138 * CVE-2026-68139 * CVE-2026-68142 * CVE-2026-68143 * CVE-2026-68145 * CVE-2026-68149 * CVE-2026-68153 * CVE-2026-68154 * CVE-2026-68155 * CVE-2026-68156 * CVE-2026-68157 * CVE-2026-68158 * CVE-2026-68159 * CVE-2026-68160 * CVE-2026-68161 * CVE-2026-68162 * CVE-2026-68166 * CVE-2026-68180 * CVE-2026-68181 * CVE-2026-68182 * CVE-2026-68184 * CVE-2026-68188 * CVE-2026-68189 * CVE-2026-68192 * CVE-2026-68193 * CVE-2026-68194 * CVE-2026-68195 * CVE-2026-68196 * CVE-2026-68197 * CVE-2026-68199 * CVE-2026-68202 * CVE-2026-68204 * CVE-2026-68205 * CVE-2026-68206 * CVE-2026-68207 * CVE-2026-68209 * CVE-2026-68210 * CVE-2026-68212 * CVE-2026-68213 * CVE-2026-68214 * CVE-2026-68215 * CVE-2026-68216 * CVE-2026-68217 * CVE-2026-68218 * CVE-2026-68219 * CVE-2026-68220 * CVE-2026-68222 * CVE-2026-68223 * CVE-2026-68226 * CVE-2026-68227 * CVE-2026-68229 * CVE-2026-68231 * CVE-2026-68234 * CVE-2026-68236 * CVE-2026-68238 * CVE-2026-68243 * CVE-2026-68244 * CVE-2026-68246 * CVE-2026-68247 * CVE-2026-68248 * CVE-2026-68249 * CVE-2026-68250 * CVE-2026-68251 * CVE-2026-68254 * CVE-2026-68255 * CVE-2026-68256 * CVE-2026-68259 * CVE-2026-68269 * CVE-2026-68271 * CVE-2026-68272 * CVE-2026-68277 * CVE-2026-68278 * CVE-2026-68279 * CVE-2026-68280 * CVE-2026-68284 * CVE-2026-68286 * CVE-2026-68288 * CVE-2026-68289 * CVE-2026-68293 * CVE-2026-68297 * CVE-2026-68299 * CVE-2026-68300 * CVE-2026-68303 * CVE-2026-68304 * CVE-2026-68306 * CVE-2026-68308 * CVE-2026-68309 * CVE-2026-68310 * CVE-2026-68312 * CVE-2026-68313 * CVE-2026-68315 * CVE-2026-68320 * CVE-2026-68322 * CVE-2026-68324 * CVE-2026-68325 * CVE-2026-68326 * CVE-2026-68327 * CVE-2026-68328 * CVE-2026-68329 * CVE-2026-68331 * CVE-2026-68333 * CVE-2026-68335 * CVE-2026-68336 * CVE-2026-68339 * CVE-2026-68340 * CVE-2026-68343 * CVE-2026-68346 * CVE-2026-68348 * CVE-2026-68349 * CVE-2026-68350 * CVE-2026-68351 * CVE-2026-68352 * CVE-2026-68353 * CVE-2026-68354 * CVE-2026-68355 * CVE-2026-68357 * CVE-2026-68359 * CVE-2026-68360 * CVE-2026-68361 * CVE-2026-68362 * CVE-2026-68363 * CVE-2026-68365 * CVE-2026-68366 * CVE-2026-68368 * CVE-2026-68369 * CVE-2026-68370 * CVE-2026-68372 * CVE-2026-68373 * CVE-2026-68377 * CVE-2026-68386 * CVE-2026-68391 * CVE-2026-68392 * CVE-2026-68397 * CVE-2026-68398 * CVE-2026-68399 * CVE-2026-68402 * CVE-2026-68403 * CVE-2026-68405 * CVE-2026-68406 * CVE-2026-68407 * CVE-2026-68408 * CVE-2026-68410 * CVE-2026-68413 * CVE-2026-68414 * CVE-2026-68417 * CVE-2026-68418 * CVE-2026-68419 * CVE-2026-68422 * CVE-2026-68425 * CVE-2026-68426 * CVE-2026-68427 * CVE-2026-68428 * CVE-2026-68429 * CVE-2026-68430 * CVE-2026-68432 * CVE-2026-68433 * CVE-2026-68434 * CVE-2026-68444 * CVE-2026-68445 * CVE-2026-68446 * CVE-2026-68450 * CVE-2026-68470 * CVE-2026-68480 * CVE-2026-72020 * CVE-2026-72035 * CVE-2026-72036 * CVE-2026-72069 * CVE-2026-72072 * CVE-2026-72083 * CVE-2026-72084 * CVE-2026-72123 * CVE-2026-72132 * CVE-2026-72221 * CVE-2026-72222 * CVE-2026-72251 * CVE-2026-72254 * CVE-2026-72262 * CVE-2026-72288 * CVE-2026-72289 * CVE-2026-72296 * CVE-2026-72307 * CVE-2026-72308 * CVE-2026-72317 * CVE-2026-72341 * CVE-2026-72342 * CVE-2026-72343 * CVE-2026-72389 * CVE-2026-72463 * CVE-2026-72464 * CVE-2026-72466 * CVE-2026-72467 * CVE-2026-72469 * CVE-2026-72473 * CVE-2026-72494 * CVE-2026-72495 * CVE-2026-72496 * CVE-2026-72499 * CVE-2026-72501 * CVE-2026-72502 * CVE-2026-74269 * CVE-2026-74296 * CVE-2026-74297 * CVE-2026-74318 * CVE-2026-74321 * CVE-2026-74334 * CVE-2026-74345 * CVE-2026-74394 * CVE-2026-74395 * CVE-2026-74454 * CVE-2026-74474 * CVE-2026-74481 * CVE-2026-74482 * CVE-2026-74488 * CVE-2026-74495 * CVE-2026-74496 * CVE-2026-74509 * CVE-2026-74510 * CVE-2026-74512 * CVE-2026-74516 * CVE-2026-74518 * CVE-2026-74527 * CVE-2026-74537 * CVE-2026-74548 * CVE-2026-74550 * CVE-2026-74556 * CVE-2026-74563 * CVE-2026-74566 * CVE-2026-74567 * CVE-2026-74571 * CVE-2026-74581 * CVE-2026-74582 * CVE-2026-74584 * CVE-2026-74610 * CVE-2026-74669 * CVE-2026-74692 * CVE-2026-74694 * CVE-2026-74695 * CVE-2026-74717 * CVE-2026-74722 * CVE-2026-80529 * CVE-2026-80534 * CVE-2026-80590 * CVE-2026-80654 CVSS scores: * CVE-2024-44981 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L * CVE-2024-44981 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2024-44981 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-57841 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-38469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39964 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-39964 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-39964 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-39964 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-40022 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-40022 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-68179 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68179 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68214 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71104 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2025-71104 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-71104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23210 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23230 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23230 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23230 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-23230 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23454 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23454 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23454 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31392 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-31392 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-31392 ( NVD ): 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L * CVE-2026-31418 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31418 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31531 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31557 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31663 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31663 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43116 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43163 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43271 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43271 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43271 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43319 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43319 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45897 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45897 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45897 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46070 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46070 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46091 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46091 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46091 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46107 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46107 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46107 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46115 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46115 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46195 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46195 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52920 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-52920 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-52925 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52925 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52925 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52939 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52939 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52977 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52977 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52990 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53033 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53059 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53059 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53059 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53076 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53076 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53077 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53077 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53077 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53089 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53089 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53091 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53091 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53091 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-53091 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53094 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53094 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53096 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53096 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53110 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53111 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53111 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53111 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53207 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53228 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53228 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53238 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53238 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53269 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53269 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53269 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53309 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53309 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53309 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53330 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53330 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53336 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53336 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53353 ( SUSE ): 0.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53353 ( SUSE ): 0.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N * CVE-2026-53353 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53365 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53365 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53365 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53381 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63801 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63801 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63801 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63808 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63808 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-63808 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63810 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63810 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63823 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63823 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63823 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63827 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63828 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63828 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63828 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-63860 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63860 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63860 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63865 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63865 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63865 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-63868 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63868 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63879 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63879 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63879 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63881 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63886 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63886 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63886 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63887 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63887 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63887 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63888 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63888 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63888 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63889 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63889 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63889 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63891 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63891 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63898 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63898 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63920 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63920 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63920 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63925 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63925 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63925 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-63926 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63926 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63926 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63928 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63928 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63944 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63944 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63969 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63969 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63970 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63970 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63972 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63972 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63972 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63973 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63973 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63980 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63985 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63985 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63985 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63990 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63990 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63992 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63992 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63992 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63999 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63999 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64000 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64000 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64000 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64001 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64001 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64002 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64002 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64002 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64004 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64004 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64005 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64005 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64005 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64006 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-64006 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-64007 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64007 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64007 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64010 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64011 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64014 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64014 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64015 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64015 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64018 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-64018 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-64018 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64029 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64029 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64029 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64034 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64039 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64039 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64039 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64047 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64047 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64048 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64048 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64048 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64051 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64051 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64051 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64052 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64052 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64052 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64073 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64073 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64073 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64083 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64083 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64083 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64084 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64084 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64084 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64085 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64085 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64085 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64086 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64086 ( SUSE ): 5.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64086 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64087 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64087 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64087 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64088 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64088 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64088 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64097 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64097 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64097 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64098 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64102 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-64102 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-64102 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64113 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64113 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64114 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64115 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64118 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64118 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64118 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64121 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64121 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64121 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64125 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64126 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64126 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L * CVE-2026-64126 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-64128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64128 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64135 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64137 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64137 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64137 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64148 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64148 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64148 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64155 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64164 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64166 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64178 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64178 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64185 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64185 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64188 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64188 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64188 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64190 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64190 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64190 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64217 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64217 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64217 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64218 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64219 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64222 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64222 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64222 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64225 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64225 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64225 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64237 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64237 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64245 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64246 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64246 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64246 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64247 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64247 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-64249 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64249 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64257 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64257 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-64257 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64266 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64266 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64268 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64271 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64271 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64271 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64273 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64275 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64275 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64277 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64286 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64286 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64287 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64303 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64303 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64303 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64304 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64305 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64305 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64306 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64313 ( SUSE ): 7.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-64313 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64313 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64315 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64316 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64316 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64317 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64317 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64317 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64322 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64322 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64322 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64323 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64323 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64329 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64329 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64329 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64331 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64331 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64333 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64333 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64334 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64334 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64334 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64335 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64335 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64335 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64337 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64337 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64338 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64340 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64340 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64340 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64341 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64342 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64343 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64344 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64346 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64348 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64348 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64348 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64350 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64350 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64350 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64351 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64351 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64351 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64355 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64355 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64358 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64358 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64365 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64375 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64375 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64376 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64376 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64376 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64381 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64381 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64382 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64382 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64383 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64383 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64384 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64385 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64386 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64387 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64388 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64388 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-64388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64401 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64401 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64403 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64403 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64403 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64406 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64408 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64409 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64409 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64411 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64411 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64411 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64412 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64412 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64412 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64420 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64421 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64421 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64427 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64427 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64434 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64436 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64436 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64440 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64440 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64440 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64442 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64442 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64443 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64443 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64444 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64444 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64444 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64445 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64448 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64448 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64450 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64454 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64471 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64478 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64478 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64479 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64480 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64481 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64481 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64482 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64482 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64483 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64484 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64484 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64486 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64487 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64489 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64497 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64500 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64503 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64504 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64505 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64511 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64511 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64512 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64513 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64527 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64537 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64537 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64538 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64540 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64540 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64540 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64541 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64541 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64541 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64544 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64544 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64545 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64547 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64547 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64547 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64548 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64548 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64549 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64551 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64551 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64552 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64552 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64552 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64553 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64562 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64562 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64563 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64563 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64565 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64565 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64567 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64567 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64567 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64571 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64571 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64572 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64572 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64573 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64573 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64574 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64576 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64576 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64576 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64577 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64577 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64577 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64581 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64581 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64581 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64582 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64583 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64583 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64584 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64585 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64593 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64593 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64598 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64598 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64599 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64599 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64602 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64604 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68081 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68081 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68082 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68082 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68082 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68085 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68085 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68085 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68086 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-68086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-68088 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68088 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68091 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68091 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68091 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68093 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-68093 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68102 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68102 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68104 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68106 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68106 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68106 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68107 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68107 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68107 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68108 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68108 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68108 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68110 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68110 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68111 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68111 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68115 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68115 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68116 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68116 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-68116 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68117 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68117 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68121 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68121 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68123 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68123 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68123 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68125 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68125 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68125 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68126 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68126 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68127 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68127 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68127 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68129 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68129 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68129 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68132 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68132 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68133 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68133 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68136 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68136 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68137 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68139 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68139 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68142 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68142 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-68142 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68143 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68143 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68143 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68145 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68145 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68145 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68149 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68149 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68149 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-68153 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68153 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68153 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68154 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68154 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68154 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68155 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68155 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68155 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68156 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68156 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68156 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68157 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68157 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68157 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68158 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68158 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68158 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68159 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68159 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68159 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68160 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68160 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68160 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68161 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68161 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68161 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68162 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68166 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68166 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68180 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68182 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68184 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68184 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68188 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68192 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68192 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68197 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68202 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68204 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68207 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68210 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68210 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68212 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68217 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68218 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68218 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68219 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68219 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68220 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68220 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68222 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68223 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68223 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68226 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68226 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68227 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68227 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68229 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68229 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-68229 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68231 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68231 ( SUSE ): 2.1 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68234 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68236 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68236 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68236 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68238 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68238 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68243 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68244 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68246 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68246 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68247 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68247 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68248 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68249 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68250 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68250 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68251 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68251 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68256 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68259 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68259 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68269 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68271 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68272 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68278 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68278 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68279 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68279 ( SUSE ): 2.4 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68280 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68280 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68284 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68284 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68286 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68286 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68288 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68288 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68289 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68293 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68293 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68299 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68308 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68309 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68310 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68312 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68313 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-68322 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68324 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68325 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68327 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68327 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68328 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68333 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68343 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68349 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68350 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68351 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68353 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68353 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68354 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68355 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68357 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68359 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68360 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68361 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68365 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68365 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-68366 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68368 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68369 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68370 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68372 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68377 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68377 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68386 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68391 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68391 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68392 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68392 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68402 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68402 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68403 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68405 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68406 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68407 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68408 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68410 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68413 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68414 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68414 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68422 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68425 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68425 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68426 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68426 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68427 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68427 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68427 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68428 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68430 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68430 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68433 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-68434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68444 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68445 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68445 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68445 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68446 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68446 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68470 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68470 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68470 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68480 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-72020 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72020 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72020 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72035 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72036 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72069 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72083 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72084 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72123 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72132 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72132 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72221 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72221 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72221 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72222 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72251 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72251 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72251 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72254 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72262 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72262 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72288 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72289 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72289 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72289 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72296 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72296 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72296 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-72307 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72307 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72308 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72308 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72317 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72317 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72317 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72341 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72342 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72342 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72343 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72343 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72389 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72463 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72463 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72464 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72464 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72467 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72473 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-72473 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72494 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72495 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72496 ( NVD ): 9.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H * CVE-2026-72499 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72499 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72501 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74269 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74269 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74318 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74345 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74345 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74345 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74394 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74395 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74395 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74454 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74454 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-74454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74474 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74474 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74481 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74482 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74482 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74488 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74488 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74495 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74495 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74509 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74509 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74516 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-74516 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74518 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74518 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74527 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-74527 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74537 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74537 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74550 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74550 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74556 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-74556 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74563 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74566 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-74567 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74567 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74571 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74581 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74581 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74582 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74584 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-74584 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-74584 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-74610 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-74610 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74610 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74692 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74694 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74694 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74695 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74695 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74717 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74717 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74722 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80534 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80534 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80590 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-80654 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80654 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves 588 vulnerabilities and has 23 fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 RT kernel was updated to fix various security issues: The following security issues were fixed: * CVE-2024-57841: net: fix memory leak in tcp_conn_request() (bsc#1235944) * CVE-2025-68214: timers: Fix NULL function pointer race in timer_shutdown_sync() (bsc#1255225). * CVE-2025-71075: scsi: aic94xx: fix use-after-free in device removal path (bsc#1256629). * CVE-2026-31392: smb: client: fix krb5 mount with username option (bsc#1261788). * CVE-2026-31418: netfilter: ipset: drop logically empty buckets in mtype_del (bsc#1262073). * CVE-2026-31531: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() (bsc#1263004). * CVE-2026-31557: nvmet: move async event work off nvmet-wq (bsc#1263061). * CVE-2026-31663: xfrm: hold device only for the asynchronous decryption (bsc#1263133). * CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack (bsc#1264619). * CVE-2026-43125: dlm: validate length in dlm_search_rsb_tree (bsc#1264541). * CVE-2026-43163: md/bitmap: fix GPF in write_page caused by resize race (bsc#1264335). * CVE-2026-43271: md-cluster: fix NULL pointer dereference in process_metadata_update (bsc#1264587). * CVE-2026-43273: ceph: supply snapshot context in ceph_zero_partial_object() (bsc#1264446). * CVE-2026-43278: dm: clear cloned request bio pointer when last clone bio completes (bsc#1264584). * CVE-2026-43319: spi: spidev: fix lock inversion between spi_lock and buf_lock (bsc#1264788). * CVE-2026-43363: x86/apic: Disable x2apic on resume if the kernel expects so (bsc#1265068). * CVE-2026-43416: powerpc, perf: Check that current->mm is alive before getting user callchain (bsc#1265121). * CVE-2026-45897: bpf: Fix UAF in sock clone early bailouts (bsc#1266897). * CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). * CVE-2026-46070: md/raid5: validate payload size before accessing journal metadata (bsc#1267501). * CVE-2026-46091: media: rc: igorplugusb: heed coherency rules (bsc#1267238). * CVE-2026-46107: dm-thin: fix metadata refcount underflow (bsc#1267612). * CVE-2026-46115: block: add pgmap check to biovec_phys_mergeable (bsc#1266874). * CVE-2026-46195: smb: client: validate dacloffset before building DACL pointers (bsc#1266860). * CVE-2026-52920: netfilter: xt_policy: fix strict mode inbound policy matching (bsc#1269013). * CVE-2026-52925: vrf: Fix a potential NPD when removing a port from a VRF (bsc#1268987). * CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). * CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send (bsc#1268979). * CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion (bsc#1268972). * CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (bsc#1269113). * CVE-2026-52975: bonding: 802.3ad replace MAC_ADDRESS_EQUAL with __agg_has_partner (bsc#1269234). * CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). * CVE-2026-52990: fsnotify: fix inode reference leak in fsnotify_recalc_mask() (bsc#1269108). * CVE-2026-52994: vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting (bsc#1269126). * CVE-2026-53001: netfilter: xtables: restrict several matches to inet family (bsc#1269114). * CVE-2026-53033: bpf, sockmap: Take state lock for af_unix iter (bsc#1269388). * CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). * CVE-2026-53076: bpf: Fix OOB in pcpu_init_value (bsc#1269695). * CVE-2026-53077: net/rds: Restrict use of RDS/IB to the initial network namespace (bsc#1269412). * CVE-2026-53089: bpf: Fix use-after-free in offloaded map/prog info fill (bsc#1269783). * CVE-2026-53091: net: account for encap headers in qdisc pkt len (bsc#1269530). * CVE-2026-53094: bpf: Fix stale offload->prog pointer after constant blinding (bsc#1269965). * CVE-2026-53096: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (bsc#1269969). * CVE-2026-53110: selftests/bpf: Add ASSERT_OK_FD macro (bsc#1269985). * CVE-2026-53111: bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap (bsc#1269167). * CVE-2026-53126: blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() (bsc#1269635). * CVE-2026-53154: mm/hugetlb: restore reservation on error in hugetlb folio copy paths (bsc#1269665). * CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). * CVE-2026-53207: mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison (bsc#1269590). * CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers (bsc#1269686). * CVE-2026-53220: netfilter: revalidate bridge ports (bsc#1269381). * CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs (bsc#1269301). * CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads (bsc#1269256). * CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths (bsc#1269774). * CVE-2026-53260: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req() (bsc#1269731). * CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). * CVE-2026-53269: netfilter: synproxy: add mutex to guard hook reference counting (bsc#1269579). * CVE-2026-53273: tee: optee: prevent use-after-free when the client exits before the supplicant (bsc#1269713). * CVE-2026-53309: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (bsc#1269815). * CVE-2026-53330: drm/amd/display: Fix out-of-bounds read in (bsc#1270090). * CVE-2026-53336: nvmem: layouts: onie-tlv: fix hang on unknown types (bsc#1270108). * CVE-2026-53337: net: bonding: fix NULL pointer dereference in bond_do_ioctl() (bsc#1270251). * CVE-2026-53353: hsr: Remove WARN_ONCE() in hsr_addr_is_self() (bsc#1270111). * CVE-2026-53365: vsock/virtio: fix zerocopy completion for multi-skb sends (bsc#1271365). * CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). * CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). * CVE-2026-63808: exfat: fix potential use-after-free in exfat_find_dir_entry() (bsc#1272260). * CVE-2026-63810: block: Avoid mounting the bdev pseudo-filesystem in userspace (bsc#1272297). * CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). * CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179). * CVE-2026-63828: apparmor: mediate the implicit connect of TCP fast open sendmsg (bsc#1272175). * CVE-2026-63860: RDMA/core: Prefer NLA_NUL_STRING (bsc#1272429). * CVE-2026-63865: bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (bsc#1272486). * CVE-2026-63868: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (bsc#1272497). * CVE-2026-63879: drm/amdgpu: fix amdgpu_hmm_range_get_pages (bsc#1272569). * CVE-2026-63881: drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger (bsc#1272571). * CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). * CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). * CVE-2026-63889: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (bsc#1272423). * CVE-2026-63891: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (bsc#1272641). * CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). * CVE-2026-63925: macsec: fix replay protection at XPN lower-PN wrap (bsc#1273008). * CVE-2026-63926: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (bsc#1273019). * CVE-2026-63944: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (bsc#1272662). * CVE-2026-63969: ipv6: fix possible infinite loop in rt6_fill_node() (bsc#1272484). * CVE-2026-63970: vsock/virtio: bind uarg before filling zerocopy skb (bsc#1272673). * CVE-2026-63980: net/handshake: Use spin_lock_bh for hn_lock (bsc#1273028). * CVE-2026-63985: ethtool: eeprom: add more safeties to EEPROM Netlink fallback (bsc#1272963). * CVE-2026-63990: bonding: refuse to enslave CAN devices (bsc#1273027). * CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). * CVE-2026-63999: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure (bsc#1273038). * CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273030). * CVE-2026-64001: ALSA: pcm: oss: Fix setup list UAF on proc write error (bsc#1273734). * CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). * CVE-2026-64004: net/iucv: fix locking in .getsockopt (bsc#1273804). * CVE-2026-64005: net/smc: Do not re-initialize smc hashtables (bsc#1273831). * CVE-2026-64006: netfilter: nf_tables: fix dst corruption in same register operation (bsc#1273834). * CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). * CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882). * CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891). * CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762). * CVE-2026-64029: ALSA: seq: Serialize UMP output teardown with event_input (bsc#1273766). * CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). * CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). * CVE-2026-64052: block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() (bsc#1272983). * CVE-2026-64073: irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT (bsc#1273490). * CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488). * CVE-2026-64102: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (bsc#1272516). * CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748). * CVE-2026-64112: rbd: eliminate a race in lock_dwork draining on unmap (bsc#1273741). * CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning (bsc#1272262). * CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). * CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). * CVE-2026-64118: qed: fix double free in qed_cxt_tables_alloc() (bsc#1273749). * CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273743). * CVE-2026-64125: net: bcmgenet: keep RBUF EEE/PM disabled (bsc#1272346). * CVE-2026-64131: mm/memory: fix spurious warning when unmapping device- private/exclusive pages (bsc#1274063). * CVE-2026-64148: pds_core: check health in devcmd wait (bsc#1273956). * CVE-2026-64164: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (bsc#1273957). * CVE-2026-64185: sysfs: don't remove existing directory on update failure (bsc#1272200). * CVE-2026-64188: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (bsc#1272150). * CVE-2026-64190: net: team: fix NULL pointer dereference in team_xmit during mode change (bsc#1272210). * CVE-2026-64192: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (bsc#1272213). * CVE-2026-64214: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() (bsc#1272799). * CVE-2026-64217: netfs: Fix overrun check in netfs_extract_user_iter() (bsc#1272798). * CVE-2026-64222: octeontx2-pf: avoid double free of pool->stack on AQ init failure (bsc#1272788). * CVE-2026-64225: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (bsc#1272786). * CVE-2026-64245: fbdev: modedb: fix a possible UAF in fb_find_mode() (bsc#1273905). * CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). * CVE-2026-64286: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (bsc#1274058). * CVE-2026-64287: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (bsc#1273325). * CVE-2026-64294: mm: do file ownership checks with the proper mount idmap (bsc#1273525). * CVE-2026-64296: exfat: bound uniname advance in exfat_find_dir_entry() (bsc#1273975). * CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944). * CVE-2026-64312: crypto: pcrypt - restore callback for non-parallel fallback (bsc#1273968). * CVE-2026-64315: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1274028). * CVE-2026-64316: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1273598). * CVE-2026-64317: isofs: bound Rock Ridge symlink components to the SL record (bsc#1273936). * CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count (bsc#1273958). * CVE-2026-64323: udf: validate VAT header length against the VAT inode size (bsc#1273305). * CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). * CVE-2026-64375: proc: protect ptrace_may_access() with exec_update_lock (FD links) (bsc#1273868). * CVE-2026-64378: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() (bsc#1273603). * CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard() (bsc#1273860). * CVE-2026-64382: smb: client: fix double-free in SMB2_open() replay (bsc#1273291). * CVE-2026-64383: smb: client: fix double-free in SMB2_flush() replay (bsc#1273426). * CVE-2026-64384: smb: client: fix change notify replay double-free (bsc#1274541). * CVE-2026-64385: smb: client: fix double-free in SMB2_ioctl() replay (bsc#1274539). * CVE-2026-64386: smb: client: fix query_info() replay double-free (bsc#1274543). * CVE-2026-64387: smb: client: fix query directory replay double-free (bsc#1274545). * CVE-2026-64388: smb/client: fix chown/chgrp with SMB3 POSIX Extensions (bsc#1274061). * CVE-2026-64411: netfilter: ebtables: terminate table name before find_table_lock() (bsc#1274077). * CVE-2026-64412: netfilter: ebtables: module names must be null-terminated (bsc#1273780). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). * CVE-2026-64434: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (bsc#1273880). * CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states (bsc#1274277). * CVE-2026-64448: smb: client: restrict implied bcc[0] exemption to responses without data area (bsc#1273982). * CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). * CVE-2026-64463: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres (bsc#1273273). * CVE-2026-64472: vfio/mlx5: Fix racy bitfields and tighten struct layout (bsc#1274075). * CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547). * CVE-2026-64537: bridge: cfm: reject invalid CCM interval at configuration time (bsc#1273289). * CVE-2026-64538: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change() (bsc#1273335). * CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). * CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). * CVE-2026-64545: net, bpf: check master for NULL in xdp_master_redirect() (bsc#1273318). * CVE-2026-64548: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (bsc#1273337). * CVE-2026-64551: sctp: validate STALE_COOKIE cause length before reading staleness (bsc#1273813). * CVE-2026-64552: virtio-net: fix len check in receive_big() (bsc#1273323). * CVE-2026-64553: net: psample: fix info leak in PSAMPLE_ATTR_DATA (bsc#1273336). * CVE-2026-64554: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (bsc#1273340). * CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930). * CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). * CVE-2026-64567: btrfs: reject free space cache with more entries than pages (bsc#1274006). * CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). * CVE-2026-64576: nexthop: initialize extack in nh_res_bucket_migrate() (bsc#1274030). * CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031). * CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). * CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (bsc#1274040). * CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497). * CVE-2026-64597: smb: client: fix double-free in SMB2_close() replay (bsc#1274297). * CVE-2026-64598: smb/client: Fix error code in smb2_aead_req_alloc() (bsc#1274298). * CVE-2026-68081: KVM: nVMX: Add helper to put (unmap) vmcs12 pages (bsc#1274580). * CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers() (bsc#1274581). * CVE-2026-68086: mm/khugepaged: write all dirty file folios when collapsing (bsc#1274713). * CVE-2026-68116: vxlan: mdb: Fix source list corruption on a failed replace (bsc#1274876). * CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (bsc#1274881). * CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). * CVE-2026-68123: openvswitch: fix GSO userspace truncation underflow (bsc#1275169). * CVE-2026-68127: ila: reload IPv6 header after pskb_may_pull in checksum adjust (bsc#1275237). * CVE-2026-68129: gve: fix Rx queue stall on alloc failure (bsc#1275517). * CVE-2026-68132: super: fix emergency thaw deadlock on frozen block devices (bsc#1275553). * CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). * CVE-2026-68139: net/mlx5e: Use sender devcom for MPV master-up (bsc#1275578). * CVE-2026-68142: geneve: require CAP_NET_ADMIN in the device netns for changelink (bsc#1275582). * CVE-2026-68143: net: slip: serialize receive against buffer reallocation (bsc#1275583). * CVE-2026-68145: iomap: fix out-of-bounds bitmap_set() with zero-length range (bsc#1275584). * CVE-2026-68149: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (bsc#1275294). * CVE-2026-68153: libceph: remove debugfs files before client teardown (bsc#1275301). * CVE-2026-68154: libceph: reject zero bucket types in crush_decode (bsc#1275303). * CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). * CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after authorizer update (bsc#1275305). * CVE-2026-68157: libceph: guard missing CRUSH type name lookup (bsc#1275306). * CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). * CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). * CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472). * CVE-2026-68161: sctp: close UDP tunnel sockets during netns teardown (bsc#1274892). * CVE-2026-68166: userfaultfd: prevent registration of special VMAs (bsc#1274930). * CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). * CVE-2026-68205: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (bsc#1274934). * CVE-2026-68238: drm/amdgpu: Release VFCT ACPI table reference (bsc#1275704). * CVE-2026-68247: drm/i915/bios: range check LFP Data Block panel_type2 (bsc#1275817). * CVE-2026-68254: drm/i915/vrr: require valid min/max vfreq for VRR (bsc#1275150). * CVE-2026-68284: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (bsc#1275970). * CVE-2026-68286: drop_monitor: perform u64_stats updates under IRQ-disabled section (bsc#1275973). * CVE-2026-68288: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (bsc#1275975). * CVE-2026-68289: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (bsc#1275976). * CVE-2026-68293: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (bsc#1275091). * CVE-2026-68297: tipc: fix u16 MTU truncation in media and bearer MTU validation (bsc#1275040). * CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (bsc#1275088). * CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL (bsc#1275083). * CVE-2026-68312: cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths (bsc#1274663). * CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit (bsc#1274665). * CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq() (bsc#1274662). * CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (bsc#1274659). * CVE-2026-68322: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (bsc#1274656). * CVE-2026-68324: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (bsc#1274649). * CVE-2026-68325: iommu/amd: Bound the early ACPI HID map (bsc#1274651). * CVE-2026-68328: nfp: Check resource mutex allocation (bsc#1274646). * CVE-2026-68329: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (bsc#1274645). * CVE-2026-68331: dpaa2-eth: put MAC endpoint device on disconnect (bsc#1274642). * CVE-2026-68333: dpaa2-switch: put MAC endpoint device on disconnect (bsc#1274644). * CVE-2026-68335: rds: drop incoming messages that cross network namespace boundaries (bsc#1274640). * CVE-2026-68336: bonding: fix devconf_all NULL dereference when IPv6 is disabled (bsc#1274639). * CVE-2026-68343: smb: client: validate DFS referral PathConsumed (bsc#1274629). * CVE-2026-68377: net/sched: act_tunnel_key: Defer dst_release to RCU callback (bsc#1274831). * CVE-2026-68386: bpf, sockmap: Reject unhashed UDP sockets on sockmap update (bsc#1274814). * CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). * CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). * CVE-2026-68408: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (bsc#1274709). * CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). * CVE-2026-68418: RDMA/irdma: Prevent user-triggered null deref on QP create (bsc#1274690). * CVE-2026-68419: RDMA/irdma: Prevent rereg_mr for non-mem regions (bsc#1274698). * CVE-2026-68422: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (bsc#1274706). * CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1274700). * CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). * CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink (bsc#1274800). * CVE-2026-68433: libceph: bound get_version reply decode to front len (bsc#1274801). * CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert (bsc#1274834). * CVE-2026-68470: wifi: cfg80211/mac80211: correctly parse S1G beacon optional elements (bsc#1276500). * CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). * CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). * CVE-2026-72035: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1276961). * CVE-2026-72036: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1277034). * CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). * CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155). * CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). * CVE-2026-72084: scsi: target: Bound PR-OUT TransportID parsing to the received buffer (bsc#1275540). * CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523). * CVE-2026-72132: NFS: Charge unstable writes by request size, not folio size (bsc#1277551). * CVE-2026-72221: sunrpc: wait for in-flight TLS handshake callback when cancel loses race (bsc#1275665). * CVE-2026-72222: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback (bsc#1275669). * CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). * CVE-2026-72254: netfilter: nft_fib: reject fib expression on the netdev egress hook (bsc#1277204). * CVE-2026-72262: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (bsc#1277678). * CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). * CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). * CVE-2026-72296: net: ife: require ETH_HLEN to be pullable in ife_decode() (bsc#1275923). * CVE-2026-72307: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (bsc#1277160). * CVE-2026-72308: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (bsc#1277159). * CVE-2026-72317: SUNRPC: pin upper rpc_clnt across the TLS connect_worker (bsc#1275925). * CVE-2026-72341: net/mlx5e: Fix publication race for priv->channel_stats[] (bsc#1277660). * CVE-2026-72342: net/mlx5e: Fix HV VHCA stats agent registration race (bsc#1277775). * CVE-2026-72343: net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation (bsc#1277776). * CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). * CVE-2026-72463: xfrm: Fix dev use-after-free in xfrm async resumption (bsc#1268276 bsc#1277064). * CVE-2026-72464: xprtrdma: Remove temp allocation of rpcrdma_rep objects (bsc#1277069). * CVE-2026-72466: xprtrdma: Fix bcall rep leak and unbounded peek (bsc#1277057). * CVE-2026-72467: xprtrdma: Check frwr_wp_create() during connect (bsc#1277059). * CVE-2026-72469: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE (bsc#1277047). * CVE-2026-72473: xprtrdma: Avoid 250 ms delay on backlog wakeup (bsc#1277037). * CVE-2026-72494: RDMA/irdma: Replace waitqueue and flag with completion (bsc#1276941). * CVE-2026-72495: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages (bsc#1276937). * CVE-2026-72496: RDMA/bnxt_re: Proper rollback if the ioremap fails (bsc#1276943). * CVE-2026-72499: RDMA/bnxt_re: Free CQ toggle page after firmware teardown (bsc#1276551). * CVE-2026-72501: RDMA/bnxt_re: Initialize dpi variable to zero (bsc#1276546). * CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (bsc#1276542). * CVE-2026-74269: bnxt: fix head underflow on XDP head-grow (bsc#1276507). * CVE-2026-74296: RDMA/mlx5: Release the HW-provided UAR index rather than the SW one (bsc#1276452). * CVE-2026-74297: RDMA/mlx5: Fix undefined shift of user RQ WQE size (bsc#1276446). * CVE-2026-74318: btrfs: fix deadlock cloning inline extent when using flushoncommit (bsc#1276864). * CVE-2026-74321: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (bsc#1277202). * CVE-2026-74334: RDMA/nldev: Fix locking when accessing mr->pd (bsc#1277095). * CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). * CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). * CVE-2026-74395: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (bsc#1277077). * CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073). * CVE-2026-74474: vxlan: use pskb_network_may_pull() for transmit path header pulls (bsc#1276335). * CVE-2026-74481: mm/page_reporting: use system_freezable_wq to fix UAF during suspend (bsc#1276355). * CVE-2026-74482: mm/huge_memory: unlock i_mmap_rwsem before releasing after- split folios (bsc#1276346). * CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350). * CVE-2026-74495: igbvf: Fix leak in TX DMA error cleanup (bsc#1275864). * CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). * CVE-2026-74509: Bluetooth: hci_sync: Fix advertising data UAFs (bsc#1275946). * CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation (bsc#1275950). * CVE-2026-74512: audit: fix potential use-after-free in audit_del_rule() (bsc#1275954). * CVE-2026-74516: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (bsc#1275797). * CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). * CVE-2026-74527: octeontx2-af: Block VFs from clobbering special CGX PKIND state (bsc#1275805). * CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). * CVE-2026-74548: forcedeth: fix UAF of txrx_stats in nv_remove (bsc#1275695). * CVE-2026-74550: net: do not send ICMP/NDISC Redirects when peer allocation fails (bsc#1275688). * CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). * CVE-2026-74563: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() (bsc#1275574). * CVE-2026-74566: keys: make keyring key-chunk byte order agree with keyring_diff_objects() (bsc#1275566). * CVE-2026-74567: keys: fix out-of-bounds read in keyring_get_key_chunk() (bsc#1275569). * CVE-2026-74571: btrfs: skip global block reserve accounting for rescue mounts (bsc#1275561). * CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782). * CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). * CVE-2026-74584: RDMA/bnxt_re: zero shared page before exposing to userspace (bsc#1277066). * CVE-2026-74610: tls: don't leave a full plaintext sk_msg ring unpushed (bsc#1277054). * CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). * CVE-2026-74692: net/smc: fix TOCTOU race between smc_listen_out() and listener close (bsc#1276927). * CVE-2026-74694: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (bsc#1277625). * CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). * CVE-2026-74717: net/mlx5: fw_tracer, return NULL on create error (bsc#1276569). * CVE-2026-74722: btrfs: fix memory leak in btrfs_do_encoded_write() (bsc#1276561). * CVE-2026-80529: xfs: don't swallow dquot recovery verification errors (bsc#1277688). * CVE-2026-80534: xfs: fix ilock leak on error in xfs_dq_get_next_id (bsc#1277022). * CVE-2026-80590: inet: frags: strip GSO state from fragments before reassembly (bsc#1277275). * CVE-2026-80654: soc: xilinx: Shutdown and free rx mailbox channel (bsc#1277516). The following non security issues were fixed: * accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() (git-fixes). * accessibility: speakup: unregister tty ldisc on later init failures (git- fixes). * ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer (git-fixes). * ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root (git- fixes). * ACPI: pfr_update: fix stack buffer overflow in query_capability() (git- fixes). * ACPI: processor: idle: Expand _LPI package sanity checks (git-fixes). * ACPI: processor: validate MADT IOAPIC entry bounds (git-fixes). * ACPI: scan: fix bus ID cleanup on device_add() failures (git-fixes). * ACPI: video: Release PCI device reference after lookup (git-fixes). * add my missing Reviewed-by: tag. * ALSA: 6fire: bound the MIDI event length from the device (git-fixes). * ALSA: 6fire: Fix UAF at error handling during probe (stable-fixes). * ALSA: bcd2000: clear the URB pointers on disconnect (git-fixes). * ALSA: core: Fix use-after-free in snd_card_do_free() (git-fixes). * ALSA: dummy: Check card index validity at probe (stable-fixes). * ALSA: hda/ext: preserve PPLCCTL bits when clearing reset (git-fixes). * ALSA: hda: Fix connection list comparison in proc output (git-fixes). * ALSA: hpi: Check transport errors during HPI6000 adapter initialization (git-fixes). * ALSA: pcxhr: initialize mutexes before requesting threaded IRQ (git-fixes). * ALSA: seq: midi: Optimize event_input locking with RCU (git-fixes). * ALSA: seq: midi: Serialize input teardown with event_input (git-fixes). * ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion (git-fixes). * ALSA: usb-audio: Complete cleanup after system-resume errors (git-fixes). * ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (git-fixes). * ALSA: usb-audio: fix OOB write on Type II inbound URBs (git-fixes). * ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (git-fixes). * ALSA: usx2y: bound the hwdep mmap fault offset (git-fixes). * ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() (git- fixes). * apparmor: advertise the tcp fast open fix is applied (git-fixes). * ASoC: adau1761: sort the register default table (git-fixes). * ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC (git-fixes). * ASoC: apple: mca: increase SERDES reset delay (git-fixes). * ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (git-fixes). * ASoC: cs35l33: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l34: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l41: sort the register default table (git-fixes). * ASoC: cs35l45: sort the register default table (git-fixes). * ASoC: cs4265: sort the register default table (git-fixes). * ASoC: cx2072x: sort the register default table (git-fixes). * ASoC: dapm: Fix off-by-one check on the second enum channel (git-fixes). * ASoC: fix unmet dependencies on PPC_BESTCOMM and SND_SOC_AC97_BUS (git- fixes). * ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready (git- fixes). * ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure (git-fixes). * ASoC: fsl_audmix: rework runtime PM handling in probe (git-fixes). * ASoC: fsl_easrc: sort the register default table (git-fixes). * AsoC: intel: sst: fix PCI device reference leak on probe failure (git- fixes). * ASoC: max9860: sort the register default table (git-fixes). * ASoC: meson: Keep link pointers valid on realloc failure (git-fixes). * ASoC: ml26124: sort the register default table (git-fixes). * ASoC: pcm512x: sort the register default table (git-fixes). * ASoC: pxa: Use devm_clk_get_optional() for extclk clock (git-fixes). * ASoC: qcom: q6apm: keep the graph start count in sync with the DSP (git- fixes). * ASoC: rt274: sort the register default table (git-fixes). * ASoC: rt286: sort the register default table (git-fixes). * ASoC: rt298: sort the register default table (git-fixes). * ASoC: rt700-sdw: always drain jack work on remove (git-fixes). * ASoC: rt700: drop duplicate reg_default entry (git-fixes). * ASoC: rt700: sort the register default table (git-fixes). * ASoC: rt711-sdca: sort the register default tables (git-fixes). * ASoC: rt711: sort the register default table (git-fixes). * ASoC: rt712-sdca-dmic: sort the register default table (git-fixes). * ASoC: rt715-sdca: drop duplicate reg_default entries (git-fixes). * ASoC: rt715-sdca: sort the register default tables (git-fixes). * ASoC: rt715: sort the register default table (git-fixes). * ASoC: rt1316-sdw: sort the register default table (git-fixes). * ASoC: rt1318-sdw: sort the register default table (git-fixes). * ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get (git-fixes). * ASoC: sgtl5000: sort the register default table (git-fixes). * ASoC: SOF: pcm: Move period/buffer configuration print after platform open (stable-fixes). * ASoC: sof: pcm: use snd_pcm_direction_name() (stable-fixes). * ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() (git- fixes). * ASoC: SOF: validate topology volume range before allocation (git-fixes). * ASoC: sti-sas: sort the register default table (git-fixes). * ASoC: tas2552: sort the register default table (git-fixes). * ASoC: tas2764: sort the register default table (git-fixes). * ASoC: tas2780: sort the register default table (git-fixes). * ASoC: tegra210_i2s: sort the register default table (git-fixes). * ASoC: tegra210_mixer: sort the register default table (git-fixes). * ASoC: tegra: Fix the MIXER enable default value (git-fixes). * ASoC: tegra: Sort MBDRC register defaults (git-fixes). * ASoC: xilinx: formatter_pcm: fix stream_data leak on open error (git-fixes). * ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (git-fixes). * batman-adv: bla: fix freeing of claims on meshif deletion (git-fixes). * batman-adv: bla: prevent CRC corruptions after claim flush (git-fixes). * batman-adv: dat: avoid unaligned fault in IP extraction (git-fixes). * batman-adv: fix stale receive device on merged fragments (git-fixes). * Bluetooth: btintel: Fix diagnostics event detection (git-fixes). * Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path (git-fixes). * Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX (git- fixes). * Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event (git- fixes). * Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() (git- fixes). * Bluetooth: do not leak an hci_conn when a second LE connect is rejected (git-fixes). * Bluetooth: eir: Fix OOB read in eir_get_service_data() (git-fixes). * Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (git-fixes). * Bluetooth: hci_conn: re-enable advertising only for peripheral role (git- fixes). * Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection (git- fixes). * Bluetooth: hci_event: fix LE list UAF on reset (git-fixes). * Bluetooth: hci_event: validate LE Set CIG Parameters response (git-fixes). * Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths (git-fixes). * Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (stable-fixes). * Bluetooth: hci_uart: Fix false success return in hci_uart_setup() (git- fixes). * Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready (git-fixes). * Bluetooth: MGMT: free the mesh send cancel command when it is cancelled (git-fixes). * Bluetooth: MSFT: validate evt_prefix_len against the response length (git- fixes). * Bluetooth: RFCOMM: serialize security confirmation handling (git-fixes). * Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (git- fixes). * Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop (git-fixes). * Bluetooth: virtio_bt: avoid OOB read of build info string (git-fixes). * bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation (git-fixes). * bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET (git-fixes). * bus: ti-sysc: Fix /chosen node reference leak (git-fixes). * cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64) (git-fixes). * can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (stable-fixes). * crypto: aspeed - Propagate platform_get_irq() errors (git-fixes). * crypto: atmel-sha204a - fix heap info leak on I2C transfer failure (git- fixes). * crypto: atmel-tdes - use scatterlist length before DMA mapping (git-fixes). * crypto: ccm - Set rfc4309 maxauthsize from child (git-fixes). * crypto: ccp - Fix memory leak in SEV INIT_EX path (git-fixes). * crypto: ccp - Fix possible deadlock in SEV init failure path (git-fixes). * crypto: doc - Remove extra parenthesis (git-fixes). * crypto: hisilicon/sec2 - fix CCM algorithm long packet failure (git-fixes). * crypto: keembay - Initialize completion before requesting IRQ (git-fixes). * crypto: keembay - publish OF module alias for OCS AES/SM4 (git-fixes). * crypto: mxs-dcp - fix source scatterlist length access (git-fixes). * crypto: qat - cancel work on re-enable SR-IOV timeout (git-fixes). * crypto: qat - clear AES key schedule from stack (git-fixes). * crypto: qce - fix CCM AAD buffer underallocation (git-fixes). * crypto: qce - fix error path in devm_qce_register_algs (git-fixes). * crypto: rk3288 - fail ahash requests on HASH idle timeout (git-fixes). * crypto: sa2ul - stop probe if context pool creation fails (git-fixes). * crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping (git- fixes). * device property: fix infinite loop in fwnode_for_each_child_node() (git- fixes). * dmaengine: dw-edma: Clear stale requests on termination (git-fixes). * dmaengine: dw-edma: Complete descriptors before pausing (git-fixes). * dmaengine: dw-edma: Initialize IRQ data before requesting IRQs (git-fixes). * dmaengine: dw-edma: Serialize abort state updates (git-fixes). * dmaengine: dw-edma: Serialize channel state checks (git-fixes). * dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe (git-fixes). * dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure (git-fixes). * dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal (git-fixes). * dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers (git-fixes). * dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout (git-fixes). * driver core: soc: Unregister bus on early device registration failure (git- fixes). * drm/amd/display: avoid divide-by-zero in __is_lut_linear() (git-fixes). * drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read (git- fixes). * drm/amdgpu/gfx6: Fixup emit_cntxcntl() (git-fixes). * drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets (git-fixes). * drm/amdgpu/gfx6: Use PFP on the compute queues too (git-fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup (git- fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup (git- fixes). * drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check (git- fixes). * drm/amdgpu: cap GTT size to physical RAM on APUs (stable-fixes). * drm/amdgpu: check ASPM on the dGPU host link (git-fixes). * drm/amdgpu: disallow multiple FENCE chunks in one submit (git-fixes). * drm/amdgpu: fix aperture iounmap skipped on device removal (git-fixes). * drm/amdgpu: fix autosuspend cleanup during removal (git-fixes). * drm/amdgpu: Fix UVD decode image min size calculation (stable-fixes). * drm/amdgpu: Fix UVD dpb min size calculation for H264 (stable-fixes). * drm/amdgpu: Fix UVD min buffer sizes (stable-fixes). * drm/amdgpu: Fix VCE 3 ring align_mask (git-fixes). * drm/amdgpu: Implement insert_end for VCE 3 (git-fixes). * drm/amdgpu: Reject UVD message with dimensions above 4096 (stable-fixes). * drm/amdgpu: Reject UVD message with invalid number of h265 refs (stable- fixes). * drm/amdgpu: restore UMD profile pstate after runtime resume (stable-fixes). * drm/amdgpu: validate GEM_CREATE domain combinations (stable-fixes). * drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (stable-fixes). * drm/amdkfd: fix QID bit leak in pqm_create_queue() (stable-fixes). * drm/amdkfd: Handle invalid event type in CRIU event restore (stable-fixes). * drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure (git-fixes). * drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure (git-fixes). * drm/bridge: ps8640: propagate AUX transfer register errors (git-fixes). * drm/bridge: tc358767: clamp the reported AUX read size to the request (git- fixes). * drm/connector: Fix epoch_counter docs to reflect reality (git-fixes). * drm/hibmc: Fix list of formats on the primary plane (git-fixes). * drm/hibmc: Use drm_atomic_helper_check_plane_state() (git-fixes). * drm/i915/fbc: Extract intel_fbc_has_fences() (stable-fixes). * drm/lima: call drm_mm_init() with a valid allocation range (git-fixes). * drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: Drop dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value (git- fixes). * drm/panel-edp: fix i2c adapter leak on probe failure (git-fixes). * drm/panel: samsung-s6d16d0: Power off on prepare failure (git-fixes). * drm/radeon: fix autosuspend cleanup during teardown (git-fixes). * drm/radeon: restore hardware polling in fence_is_signaled to fix performance regression (git-fixes). * drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format (git-fixes). * drm/ssd130x: fix column and row end address in partial updates for ssd132x (git-fixes). * drm/sun4i: crtc: Propagate layer initialization error (git-fixes). * drm/sun4i: Drop node references while building component list (git-fixes). * drm/sun4i: dw-hdmi: Drop TCON TOP port reference (git-fixes). * drm/sun4i: fix refcount leak in sun4i_backend_init_sat() (git-fixes). * drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz (git-fixes). * drm/sun4i: tcon: Drop remote endpoint reference (git-fixes). * drm/sun4i: tcon: Drop TCON TOP device reference (git-fixes). * drm/sun4i: tcon: Set output mux for DSI and LVDS (git-fixes). * drm/sun4i: vi scaler: Fix coefficient selection (git-fixes). * drm/tegra: dsi: Re-add clear enable register if DSI was powered by bootloader (git-fixes). * drm/tve200: add OF module alias for autoloading (git-fixes). * drm: fix race between partial drm_dev_register() failure and ioctl (git- fixes). * drm: lcdif: Wait for vblank before disabling DMA (git-fixes). * drm: Remove unused header in drm_dumb_buffers.c (git-fixes). * ethtool: rss: fix hkey leak when indir_size is 0 (git-fixes). * fbdev: bitblit: bound-check glyph index in bit_cursor() (git-fixes). * fbdev: core: Fix pointer desynchronization in fb_io_read() (git-fixes). * fbdev: kyro: Validate overlay viewport coordinates (git-fixes). * fbdev: omapfb: panel-dsi-cm: initialize lock before registering display (git-fixes). * fbdev: ssd1307fb: defer I2C transfers from damage callbacks (git-fixes). * fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() (git-fixes). * fbdev: uvesafb: unregister connector callback on init failure (git-fixes). * firmware: arm_scmi: Avoid IDR updates while cleaning channels (git-fixes). * firmware: arm_scmi: Drop handle on protocol bind failures (git-fixes). * firmware: arm_scmi: Fix requested device removal race (git-fixes). * firmware: arm_scmi: Free transport channel on IDR failure (git-fixes). * firmware: arm_scmi: Protect device request lookup with RCU (git-fixes). * firmware: arm_scmi: Reject out of range DT protocol IDs (git-fixes). * firmware: arm_scmi: Unregister device notifier before IDR teardown (git- fixes). * firmware: arm_scmi: Use channel ID for transport teardown (git-fixes). * firmware_loader: do not queue completed sysfs fallback requests (git-fixes). * fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write (git- fixes). * fpga: dfl: fme: add error handling (git-fixes). * fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration (git- fixes). * gpu: host1x: Avoid stack over-read in debug output helpers (git-fixes). * gpu: host1x: Fix offset calculation in trace_write_gather (git-fixes). * HID: core: fix number/pointer type confusion on long items (git-fixes). * HID: core: fix OOB read of field->usage in hid_set_field() (git-fixes). * HID: hyperv: validate initial device info bounds (git-fixes). * HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure (git-fixes). * HID: lg4ff: validate report length before fixed offsets (git-fixes). * HID: logitech-dj: Fix maxfield check in DJ short report validation (git- fixes). * HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (git- fixes). * HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (stable-fixes). * HID: logitech-dj: Standardise hid_report_enum variable nomenclature (stable- fixes). * HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID (stable-fixes). * HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (git- fixes). * HID: mcp2221: validate report size in mcp2221_raw_event() (git-fixes). * HID: nintendo: Fix imu_timestamp_us double increment per report (git-fixes). * HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() (git- fixes). * HID: picolcd: clamp eeprom debugfs read to bytes actually received (git- fixes). * HID: roccat: bound device-supplied profile index (git-fixes). * HID: roccat: free buffered reports when destroying device (git-fixes). * HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature (git- fixes). * HID: sensor: custom: Fix field sysfs group cleanup on failure (git-fixes). * HID: sensor: custom: Fix use-after-free in enable_sensor (git-fixes). * HID: tmff: Use 64-bit arithmetic for force feedback scaling (git-fixes). * hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (git-fixes). * hwmon: (lm25066) Use i2c_get_match_data() (stable-fixes). * hwmon: (max6621) fix negative temperature offset and crit readings (git- fixes). * hwmon: (max6621) fix temperature clamp range (git-fixes). * hwmon: (nzxt-smart2) Check return value of init_device() in probe (git- fixes). * hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (git-fixes). * hwrng: ks-sa - Fix runtime PM cleanup on registration failure (git-fixes). * hwrng: omap - Fix probe error path cleanup (git-fixes). * hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() (git- fixes). * i2c: bcm-iproc: remove printout on handled timeouts (stable-fixes). * i2c: iproc: reset bus after timeout if START_BUSY is stuck (git-fixes). * i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure (git-fixes). * i2c: mux: Fix channel node leak on adapter add failure (git-fixes). * i2c: ocores: Disable clock on failed resume (git-fixes). * i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices (git-fixes). * i3c: master: Fix device_register() error path (git-fixes). * i3c: master: Fix info leak and UAF in device unregister path (git-fixes). * i3c: master: svc: bound IBI payload to the requested max_payload_len (git- fixes). * ibmvnic: Only record tx completed bytes once per handler (bsc#1274620). * iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE (git-fixes). * iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable (git-fixes). * iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF (git-fixes). * iio: chemical: sgp30: Handle IAQ thread creation failure (git-fixes). * iio: dac: m62332: Fix regulator reference count imbalance (git-fixes). * iio: gyro: mpu3050: fix sign of raw angular velocity readings (git-fixes). * iio: light: cm32181: return zero after writing calibscale (git-fixes). * iio: light: gp2ap002: Disable regulators on resume failure (git-fixes). * iio: light: gp2ap002: re-enable irq if runtime suspend fails (git-fixes). * iio: light: isl29028: return zero in write_raw() on success (git-fixes). * iio: light: tsl2583: return zero in write_raw() on success (git-fixes). * iio: light: tsl2772: fix ALS calibscale readback (git-fixes). * iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure (git-fixes). * iio: pressure: dps310: fix NULL pointer dereference on ACPI probe (git- fixes). * iio: pressure: mpl115: Fix runtime PM cleanup (git-fixes). * iio: srf04: fix pm_runtime handling on probe error path (git-fixes). * iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() (git-fixes). * Input: atkbd - skip deactivate for HONOR ZQC-P (git-fixes). * Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (stable-fixes). * Input: evdev - fix information leak in evdev_pass_values() (stable-fixes). * Input: evdev - sanitize event type index when fetching event masks (stable- fixes). * Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (git-fixes). * Input: focaltech - use signed coordinates to prevent underflow (git-fixes). * Input: hynitron_cstxxx - validate touch count and finger IDs (git-fixes). * Input: iforce - validate input packet lengths (stable-fixes). * Input: iqs5xx - validate firmware record destination span (git-fixes). * Input: mms114 - fix Y-resolution configuration (git-fixes). * Input: psxpad-spi - set driver data before use (git-fixes). * Input: sur40 - fix input device registration ordering (stable-fixes). * Input: sur40 - fix V4L error path cleanup (stable-fixes). * Input: synaptics-rmi4 - block s_input when F54 queue is busy (git-fixes). * Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (git-fixes). * Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (git- fixes). * Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (git- fixes). * Input: synaptics-rmi4 - zero report size on F54 work error (git-fixes). * Input: xpad - add support for ZENAIM LEVERLESS (stable-fixes). * interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (git-fixes). * ipmi: ipmb: validate write message length (git-fixes). * ipmi: si: Fix NULL pointer dereference after failed registration (git- fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (git-fixes). * leds: pca9532: Fix inverted GPIO output polarity (git-fixes). * leds: pca9532: Fix phantom device registration on missing hardware (git- fixes). * lib/string: fix memchr_inv() for large ranges (git-fixes). * lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() (git-fixes). * mailbox: qcom-ipcc: fix duplicate channel allocation across holes (git- fixes). * mailbox: rockchip: disable pclk on probe failure and unbind (git-fixes). * maple_tree: fix argument name in header (git-fixes). * md/raid1: create serial pool adding rdev to array with serialize_policy=1 (bsc#1272261). * media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref (git-fixes). * media: cec-pin: Fix event FIFO ordering (git-fixes). * media: cec: disable delayed work before freeing an interrupted transmit (git-fixes). * media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash (git-fixes). * media: cec: Serialize exclusive follower delivery (git-fixes). * media: cec: stm32: prevent out-of-bounds write on RX overflow (git-fixes). * media: cedrus: fix memory leak in cedrus_init_ctrls() (git-fixes). * media: cobalt: Avoid freeing ALSA private data twice (git-fixes). * media: cx231xx: reject geometry changes while the VBI queue is busy (git- fixes). * media: cx23885: cancel NetUP CI work before teardown (git-fixes). * media: em28xx: defer audio-only extension registration (git-fixes). * media: em28xx: fix use-after-free of dev_next->devlist on disconnect (git- fixes). * media: go7007: defer the ALSA v4l2 put until card release (git-fixes). * media: i2c: ov02a10: fix endpoint parsing use-after-free (git-fixes). * media: i2c: ov7740: fix use-after-destroy in remove (git-fixes). * media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define (git- fixes). * media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define (git-fixes). * media: mc-entity: Add missing kerneldoc (git-fixes). * media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common (git- fixes). * media: nxp: imx8-isi: Correct color map between V4L2 and ISI (git-fixes). * media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing (git-fixes). * media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks (git-fixes). * media: rc: sunxi-cir: Unregister rc device on probe failure (git-fixes). * media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure (git-fixes). * media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak (git-fixes). * media: s2255: bound JPEG frame size before copying into the buffer (git- fixes). * media: s2255: check firmware size before reading trailing marker (git- fixes). * media: saa7164: fix cleanup on resource allocation failure (git-fixes). * media: tda18250: fix possible integer overflow (git-fixes). * media: usbtv: keep device alive while ALSA card exists (git-fixes). * media: v4l2-ctrls: Allow unknown HDR10 white point and luminance (git- fixes). * media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link (git-fixes). * media: venus: fix payload size calculation in parse_raw_formats() (git- fixes). * media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() (git-fixes). * media: vicodec: fix out-of-bounds write in FWHT encoder (git-fixes). * media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure (git-fixes). * media: vimc: fix pixel format lookup in enum_framesizes (git-fixes). * media: zoran: Avoid freeing a registered video_device twice (git-fixes). * mei: pull kvfree out of spinlock (git-fixes). * mfd: iqs62x: Reject zero-length firmware records (git-fixes). * mfd: rave-sp: validate received frame payload lengths (git-fixes). * misc: bcm-vk: Use acquire/release for msgq_inited (git-fixes). * misc: fastrpc: fix channel ctx ref leak when session alloc fails (git- fixes). * misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (git-fixes). * misc: fastrpc: Remove buffer from list prior to unmap operation (git-fixes). * misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke (git- fixes). * misc: rtsx: add missing write register handling (git-fixes). * misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() (git- fixes). * mkspec-dtb: Move DTS prefix into package list. * mkspec-dtb: Move provides-obsoletes to package list. * mkspec-dtb: Put per-architecture package lists into a hash. * mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (git- fixes). * mmc: sdhci: unmap the bounce buffer before device release (git-fixes). * mmc: via-sdmmc: stop card-detect handling on probe failure (git-fixes). * mtd: afs: validate v2 image info bounds (git-fixes). * mtd: mtdoops: free page bitmap when the backing MTD is removed (git-fixes). * mtd: mtdswap: Avoid freeing registered blktrans device twice (git-fixes). * mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() (git-fixes). * mtd: rawnand: validate ONFI extended parameter page sections (git-fixes). * net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes). * net: mana: Add handler for sriov configure (bsc#1272756). * net: mana: Cap MSI-X vectors to the device MSI-X table size (git-fixes). * net: mana: Extend RX CQE coalescing up to 8 packets (git-fixes). * net: mana: Fall back to scattered pages for GDMA queues (git-fixes). * net: mana: force full-page RX buffers via ethtool private flag (bsc#1269792). * net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792). * net: mana: Route ring-buffer access through offset-based helpers (git- fixes). * net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). * net: thunderbolt: Count delivered packets in rx_packets and rx_bytes (git- fixes). * net: thunderbolt: Mark the connection down when bringing it up fails (git- fixes). * net: thunderbolt: Release the Rx HopID that was handed out on mismatch (git- fixes). * net: thunderbolt: Tear down DMA paths before stopping the rings (git-fixes). * net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (git-fixes). * net: usb: ipheth: fix carrier_work UAF on disconnect (git-fixes). * nfc: digital: clamp SENSF_RES length to the destination buffer (git-fixes). * nfc: digital: Do not dump a NULL response in command completion (git-fixes). * nfc: fdp: bound the device-reported read length and fix an skb leak (git- fixes). * nfc: llcp: avoid userspace overflow on invalid optlen (git-fixes). * nfc: llcp: bound SNL TLV parsing to the skb and add length checks (git- fixes). * nfc: llcp: bound the connect_sn TLV walk to the skb (git-fixes). * nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (git-fixes). * nfc: llcp: read llcp_sock->local under the socket lock in getsockopt (git- fixes). * nfc: llcp: reject PDUs shorter than the LLCP header (git-fixes). * nfc: microread: validate target discovery payload lengths (git-fixes). * nfc: nci: fix double completion race in nci_data_exchange_complete (git- fixes). * nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (git- fixes). * nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (git- fixes). * nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing (git- fixes). * nfc: nci: free destination parameters when closing a connection (git-fixes). * nfc: pn533: hold a reference to the request skb during send_frame (git- fixes). * nfc: pn533: purge fragmented skbs during cleanup (git-fixes). * nfc: st21nfca: validate ATR_REQ length against the received frame (git- fixes). * nouveau/gem: reserve the bo in the info ioctl around the vma lookup (git- fixes). * PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] (git-fixes). * PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk (git- fixes). * PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git- fixes). * PCI: j721e: Fix incorrect max_lanes for J7200 (git-fixes). * PCI: meson: Fix GPIO state while requesting PERST# (git-fixes). * phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs (git- fixes). * phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend (git-fixes). * phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table (git- fixes). * phy: sunplus: fix error handling in sp_uphy_init() (git-fixes). * pinctrl: bcm2835: Don't remove an unregistered GPIO chip (git-fixes). * pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip (git-fixes). * pinctrl: rockchip: Reset the pin count when recalculating SoC data (git- fixes). * platform/chrome: cros_ec_debugfs: Clean up console log on probe failure (git-fixes). * platform/chrome: cros_ec_debugfs: Unregister panic notifier (git-fixes). * platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count (git- fixes). * platform/chrome: sensorhub: Bound the EC-reported sensor number (git-fixes). * platform/chrome: sensorhub: Fix dropped timestamp events and log spam (git- fixes). * platform/chrome: sensorhub: Fix memory overread in ring handler (git-fixes). * platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL (git- fixes). * platform/surface: acpi-notify: Check ACPI companion before use (git-fixes). * platform/x86: dell-privacy: Fix race condition (git-fixes). * platform/x86: dell-wmi-base: Fix resource leak on module load failure (git- fixes). * platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (git-fixes). * platform/x86: dell-wmi-sysman: Fix instance ID bounds (git-fixes). * platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path (git-fixes). * platform/x86: ISST: Just allow 2 bits for SST feature enable (git-fixes). * platform/x86: ISST: Validate level in perf mask ioctls (git-fixes). * platform/x86: ISST: Validate logical CPU id and clos id (git-fixes). * platform/x86: ISST: Validate socket ID in clos_assoc ioctl (git-fixes). * PM: sleep: Fix off-by-one in wakelocks number limit check (git-fixes). * power: supply: bd99954: Drop bad register fields (git-fixes). * power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq27520g4: fix REG_TTES address (git-fixes). * power: supply: bq256xx: drain usb_work before freeing the charger (git- fixes). * power: supply: bq24257: fix use-after-free on remove (git-fixes). * power: supply: bq25890: Fix power_supply reference leak (git-fixes). * power: supply: cros_usbpd-charger: bound the EC-reported port count (git- fixes). * power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS (git- fixes). * power: supply: isp1704_charger: cancel work on remove (git-fixes). * power: supply: lp8727: fix use-after-free in lp8727_release_irq() (git- fixes). * power: supply: max17040: drop incorrect I2C functionality check (git-fixes). * power: supply: max17040: synchronize work cancellation on suspend (git- fixes). * power: supply: qcom_battmgr: terminate the strings from firmware (git- fixes). * power: supply: rt9455: quiesce delayed work before teardown (git-fixes). * power: supply: sbs-battery: Use a per-device serial number buffer (git- fixes). * power: supply: twl4030_charger: cancel workers via devm (git-fixes). * power: supply: ucs1002: fix use-after-free on remove (git-fixes). * powercap: intel_rapl_tpmi: Handle PMU registration failure during probe (git-fixes). * powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash (bsc#1271256). * powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). * powerpc/pseries: pci - logic bug (bsc#1274749 ltc#221282 bsc#1274755 ltc#221284 bsc#1274756 ltc#221283). * ppdev: prevent overflow when setting port timeout (git-fixes). * qede: fix out-of-bounds check for cqe->len_list (git-fixes). * rapidio: clear mport->net when rio_add_net() fails (git-fixes). * rapidio: mport_cdev: fix use-after-free in dma_req_free() (git-fixes). * RDMA/irdma: Remove redundant legacy_mode checks (git-fixes). * RDMA/mana_ib: drain QP references after partial table insertion (git-fixes). * RDMA/mana_ib: unify QP lookup table (git-fixes). * RDMA/mlx5: Fix integer overflow of user QP buffer size (git-fixes). * regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (git-fixes). * regulator: core: use system_freezable_wq for init complete work (git-fixes). * regulator: devres: add API for reference voltage supplies (stable-fixes). * regulator: devres: fix devm_regulator_get_enable_read_voltage() return (git- fixes). * regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata (git-fixes). * regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling (git-fixes). * remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev (git-fixes). * remoteproc: qcom_q6v5_adsp: Fix reference leak for device node (git-fixes). * remoteproc: scp: Fix device reference leak on failed lookup (git-fixes). * Revert "drm/amdgpu: fix aperture mapping leak" (git-fixes). * Revert "media: v4l2-dev: fix error handling in __video_register_device()" (git-fixes). * Revert "thermal/drivers/hwmon: Cleanup coding style a bit" (stable-fixes). * rpmsg: core: Fix incorrect return value documentation (git-fixes). * rpmsg: glink: smem: order FIFO read after availability check (git-fixes). * rtc: gamecube: check return value of devm_rtc_register_device() (git-fixes). * rtc: pcf8563: fix clock provider leak on unbind (git-fixes). * rtc: pcf85363: Add error checking to regmap calls in probe() (git-fixes). * rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers (git-fixes). * rtc: rzn1: Fix weekday underflow when alarm crosses month boundary (git- fixes). * rtc: zynqmp: Return optional clock lookup errors (git-fixes). * scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes). * sctp: avoid auth_enable sysctl UAF during netns teardown (git-fixes). * serial: 8250_dma: Clear stale RX state on shutdown (git-fixes). * serial: amba-pl011: unprepare console clock on unregister (git-fixes). * serial: core: clear freed pointers on uart_register_driver() failure (git- fixes). * serial: qcom-geni: fix TX DMA buffer flush (git-fixes). * serial: sc16is7xx: fix copy-paste errors in EFR_SWFLOWx_BIT constants (stable-fixes). * smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). * smb: client: reject overlapping data areas in SMB2 responses (git-fixes). * smb: client: require net admin for CIFS SWN netlink (bsc#1273966). * smb: client: resolve SWN tcon from live registrations (bsc#1273872). * soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() (git- fixes). * soc: qcom: rpmh-rsc: manage PM notifiers with devres (git-fixes). * soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() (git-fixes). * software node: Fix software_node_get_reference_args() with index -1 (git- fixes). * soundwire: qcom: Fix port exhaustion check in stream_alloc_ports (git- fixes). * speakup: keyhelp: guard letter_offsets possible out-of-range indexing (git- fixes). * spi: img-spfi: don't disable runtime PM on DMA deferred probe (git-fixes). * spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (stable-fixes). * spi: sprd-adi: Fix probe succeeding without registering the controller (git- fixes). * staging: fbtft: Use sysfs_emit_at() to print to sysfs file (git-fixes). * staging: media: tegra-video: vi: fix probe failure on skipped last port (git-fixes). * staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown (git- fixes). * staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() (git-fixes). * staging: rtl8723bs: fix missing shared-key auth challenge length check (git- fixes). * staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (git-fixes). * staging: rtl8723bs: fix OOB read in WMM_param_handler() (git-fixes). * staging: rtl8723bs: use kfree_sensitive() for key material (git-fixes). * staging: rtl8723bs: validate monitor transmit frame lengths (git-fixes). * staging: sm750fb: gate dualview dataflow using g_dualview (git-fixes). * thermal/drivers/imx: Disable clock on runtime resume failure (git-fixes). * thermal/drivers/qoriq: Disable clock on resume failure (git-fixes). * thermal: intel: int3400: clean up ODVP on probe failures (git-fixes). * thunderbolt: Bound the DROM dual link port number before indexing sw->ports (git-fixes). * thunderbolt: icm: Preserve USB4 proxy data-valid bit (git-fixes). * tlclk: if sscanf() fails, fall back to 0, not random value (git-fixes). * tpm: st33zp24: Return zero on status read failure (git-fixes). * tpm: st33zp24: Validate locality read result (git-fixes). * tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (git-fixes). * tty: clear cdev pointer after cdev_add() failure (git-fixes). * tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 (git-fixes). * tty: skip cdev_del() when no cdev is registered (git-fixes). * uio: Fix stale info pointer in failed registration path (git-fixes). * usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (git-fixes). * usb: atm: usbatm: fix invalid ci_range initialization (git-fixes). * USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (git-fixes). * usb: cdnsp: fix incorrect endian conversions for APB timeout register (git- fixes). * usb: dwc2: add missing @remotewakeup kernel-doc parameter (git-fixes). * usb: dwc2: gadget: Exit partial power down state when changing USB pull-up (git-fixes). * usb: gadget: configfs: fix out-of-bounds read of qw_sign (git-fixes). * usb: gadget: f_fs: Prevent deadlock during ep0 read loop (git-fixes). * usb: gadget: f_ncm: Use unsigned int for ndp_index (git-fixes). * usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() (git-fixes). * usb: gadget: f_uac1_legacy: remove broken string configfs attributes (git- fixes). * usb: gadget: pch_udc: remove excess kernel-doc member for registered (git- fixes). * usb: gadget: r8a66597: avoid double free of ep0_req in probe error path (git-fixes). * usb: gadget: snps_udc_plat: clean up PHY on probe deferral (git-fixes). * usb: gadget: u_audio: Fix use-after-free on sound card disconnect (git- fixes). * usb: gadget: uac: validate rate list length before storing (git-fixes). * usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() (git-fixes). * usb: mtu3: allow system suspend during active gadget connection (git-fixes). * usb: musb: omap2430: clean up probe error handling (stable-fixes). * USB: phy: fsl-usb: fix missing static keywords (git-fixes). * usb: renesas_usbhs: Fix power-off ordering on unbind (git-fixes). * USB: serial: digi_acceleport: fix port registration order (git-fixes). * USB: serial: ftdi_sio: add support for E+H FXA291 (stable-fixes). * USB: serial: option: add TDTECH MT5710-CN (stable-fixes). * USB: serial: option: fix slab OOB read in interrupt URB callback (git- fixes). * USB: serial: spcp8x5: drop broken carrier detect support (git-fixes). * USB: storage: add NO_ATA_1X quirk for Longmai USB Key (stable-fixes). * usb: typec: ucsi: unregister debugfs entries on teardown (git-fixes). * usb: usbfs: fix use-after-free of usb_device in usbdev_release() (git- fixes). * usb: xhci: Handle USB3 port events when there is one roothub (git-fixes). * vt: add permission check for KDSKBMETA ioctl (stable-fixes). * vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (stable- fixes). * w1: ds28e17: reject an oversize length on an I2C block read (git-fixes). * w1: ds2482: Fix signedness bug in ds2482_w1_triplet() (git-fixes). * wifi: ath6kl: avoid buffer overreads in WMI event handlers (git-fixes). * wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (git-fixes). * wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump (git-fixes). * wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() (git-fixes). * wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate (git- fixes). * wifi: ath11k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() (git-fixes). * wifi: ath12k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (git-fixes). * wifi: brcmfmac: fix P2P action frame handling without device vif (git- fixes). * wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs (git-fixes). * wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments (git-fixes). * wifi: iwlwifi: mei: pass correct argument to function (git-fixes). * wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser (git-fixes). * wifi: mac80211: send TWT teardown to peer after setup TX failure (git- fixes). * wifi: mac80211: skip default WMM setup for AP_VLAN links (git-fixes). * wifi: mac80211: skip unused probe response countdown offsets (git-fixes). * wifi: mt76: fix 4th chain ACK RSSI bitmask in sta_poll (git-fixes). * wifi: mt76: fix ER-SU 106-tone RU check in RX rate decode (git-fixes). * wifi: mt76: fix HE DCM max-RU capability encoding (git-fixes). * wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length (git- fixes). * wifi: mt76: mt792x: Fix memory leak in SDIO TX path (git-fixes). * wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (git- fixes). * wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss (git- fixes). * wifi: mt76: mt7915: fix double hif2 init on the non-WED path (git-fixes). * wifi: mt76: mt7915: fix ext PHY use-after-free on register error path (git- fixes). * wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 (git- fixes). * wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie (git-fixes). * wifi: mt76: mt7915: release hif2 reference on probe IRQ failure (git-fixes). * wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement (git- fixes). * wifi: mt76: mt7915: unwind state on add_interface failure (git-fixes). * wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields (git- fixes). * wifi: mt76: mt7915: write RX header translation bit to the correct register (git-fixes). * wifi: mt76: mt7921: validate CLC firmware records (git-fixes). * wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (git- fixes). * wifi: mt76: mt7925: fix msg len mismatch between driver and firmware (git- fixes). * wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config (git- fixes). * wifi: mt76: mt7996: don't report a zero TX bitrate (git-fixes). * wifi: mt76: mt7996: fix reg addr remap when addr is 0 (git-fixes). * wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV (git- fixes). * wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset (git-fixes). * wifi: mt76: mt7996: validate RX band_idx before dereferencing phys (git- fixes). * wifi: mt76: report data NSS for STBC frames in RX rate decode (git-fixes). * wifi: mwifiex: Detach sync cmd buffer on interrupted wait (git-fixes). * wifi: rtlwifi: pci: fix error path in rtl_pci_probe() (git-fixes). * wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (git-fixes). * wifi: rtw89: fix HE extended capability length check (git-fixes). * wifi: zd1211rw: reject secondary interfaces to prevent conflicts (git- fixes). * x86/bugs: Clarify that syscall hardening isn't a BHI mitigation (git-fixes). * xhci: dbgtty: Fix unregister on tty_alloc_driver() failure (git-fixes). * xhci: dbgtty: Fix unregister on tty_register_driver() failure (git-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-603=1 ## Package List: * SUSE Linux Micro 6.1 (noarch) * kernel-devel-rt-6.4.0-52.1 * kernel-source-rt-6.4.0-52.1 * SUSE Linux Micro 6.1 (aarch64 nosrc x86_64) * kernel-rt-6.4.0-52.1 * SUSE Linux Micro 6.1 (aarch64 x86_64) * kernel-rt-devel-6.4.0-52.1 * kernel-rt-debuginfo-6.4.0-52.1 * kernel-rt-debugsource-6.4.0-52.1 * SUSE Linux Micro 6.1 (x86_64) * kernel-rt-livepatch-6.4.0-52.1 * kernel-rt-devel-debuginfo-6.4.0-52.1 ## References: * https://www.suse.com/security/cve/CVE-2024-44981.html * https://www.suse.com/security/cve/CVE-2024-57841.html * https://www.suse.com/security/cve/CVE-2025-38469.html * https://www.suse.com/security/cve/CVE-2025-39964.html * https://www.suse.com/security/cve/CVE-2025-40022.html * https://www.suse.com/security/cve/CVE-2025-68179.html * https://www.suse.com/security/cve/CVE-2025-68214.html * https://www.suse.com/security/cve/CVE-2025-71075.html * https://www.suse.com/security/cve/CVE-2025-71104.html * https://www.suse.com/security/cve/CVE-2026-23210.html * https://www.suse.com/security/cve/CVE-2026-23230.html * https://www.suse.com/security/cve/CVE-2026-23454.html * https://www.suse.com/security/cve/CVE-2026-31392.html * https://www.suse.com/security/cve/CVE-2026-31418.html * https://www.suse.com/security/cve/CVE-2026-31531.html * https://www.suse.com/security/cve/CVE-2026-31557.html * https://www.suse.com/security/cve/CVE-2026-31663.html * https://www.suse.com/security/cve/CVE-2026-43116.html * https://www.suse.com/security/cve/CVE-2026-43125.html * https://www.suse.com/security/cve/CVE-2026-43163.html * https://www.suse.com/security/cve/CVE-2026-43271.html * https://www.suse.com/security/cve/CVE-2026-43273.html * https://www.suse.com/security/cve/CVE-2026-43278.html * https://www.suse.com/security/cve/CVE-2026-43319.html * https://www.suse.com/security/cve/CVE-2026-43363.html * https://www.suse.com/security/cve/CVE-2026-43416.html * https://www.suse.com/security/cve/CVE-2026-45897.html * https://www.suse.com/security/cve/CVE-2026-45968.html * https://www.suse.com/security/cve/CVE-2026-46070.html * https://www.suse.com/security/cve/CVE-2026-46091.html * https://www.suse.com/security/cve/CVE-2026-46107.html * https://www.suse.com/security/cve/CVE-2026-46115.html * https://www.suse.com/security/cve/CVE-2026-46195.html * https://www.suse.com/security/cve/CVE-2026-52920.html * https://www.suse.com/security/cve/CVE-2026-52925.html * https://www.suse.com/security/cve/CVE-2026-52929.html * https://www.suse.com/security/cve/CVE-2026-52935.html * https://www.suse.com/security/cve/CVE-2026-52939.html * https://www.suse.com/security/cve/CVE-2026-52946.html * https://www.suse.com/security/cve/CVE-2026-52975.html * https://www.suse.com/security/cve/CVE-2026-52977.html * https://www.suse.com/security/cve/CVE-2026-52990.html * https://www.suse.com/security/cve/CVE-2026-52994.html * https://www.suse.com/security/cve/CVE-2026-53001.html * https://www.suse.com/security/cve/CVE-2026-53033.html * https://www.suse.com/security/cve/CVE-2026-53059.html * https://www.suse.com/security/cve/CVE-2026-53076.html * https://www.suse.com/security/cve/CVE-2026-53077.html * https://www.suse.com/security/cve/CVE-2026-53089.html * https://www.suse.com/security/cve/CVE-2026-53091.html * https://www.suse.com/security/cve/CVE-2026-53094.html * https://www.suse.com/security/cve/CVE-2026-53096.html * https://www.suse.com/security/cve/CVE-2026-53110.html * https://www.suse.com/security/cve/CVE-2026-53111.html * https://www.suse.com/security/cve/CVE-2026-53126.html * https://www.suse.com/security/cve/CVE-2026-53154.html * https://www.suse.com/security/cve/CVE-2026-53163.html * https://www.suse.com/security/cve/CVE-2026-53207.html * https://www.suse.com/security/cve/CVE-2026-53219.html * https://www.suse.com/security/cve/CVE-2026-53220.html * https://www.suse.com/security/cve/CVE-2026-53223.html * https://www.suse.com/security/cve/CVE-2026-53228.html * https://www.suse.com/security/cve/CVE-2026-53238.html * https://www.suse.com/security/cve/CVE-2026-53260.html * https://www.suse.com/security/cve/CVE-2026-53264.html * https://www.suse.com/security/cve/CVE-2026-53269.html * https://www.suse.com/security/cve/CVE-2026-53273.html * https://www.suse.com/security/cve/CVE-2026-53309.html * https://www.suse.com/security/cve/CVE-2026-53330.html * https://www.suse.com/security/cve/CVE-2026-53336.html * https://www.suse.com/security/cve/CVE-2026-53337.html * https://www.suse.com/security/cve/CVE-2026-53353.html * https://www.suse.com/security/cve/CVE-2026-53365.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://www.suse.com/security/cve/CVE-2026-53381.html * https://www.suse.com/security/cve/CVE-2026-53388.html * https://www.suse.com/security/cve/CVE-2026-63801.html * https://www.suse.com/security/cve/CVE-2026-63808.html * https://www.suse.com/security/cve/CVE-2026-63810.html * https://www.suse.com/security/cve/CVE-2026-63823.html * https://www.suse.com/security/cve/CVE-2026-63827.html * https://www.suse.com/security/cve/CVE-2026-63828.html * https://www.suse.com/security/cve/CVE-2026-63860.html * https://www.suse.com/security/cve/CVE-2026-63865.html * https://www.suse.com/security/cve/CVE-2026-63868.html * https://www.suse.com/security/cve/CVE-2026-63879.html * https://www.suse.com/security/cve/CVE-2026-63881.html * https://www.suse.com/security/cve/CVE-2026-63886.html * https://www.suse.com/security/cve/CVE-2026-63887.html * https://www.suse.com/security/cve/CVE-2026-63888.html * https://www.suse.com/security/cve/CVE-2026-63889.html * https://www.suse.com/security/cve/CVE-2026-63891.html * https://www.suse.com/security/cve/CVE-2026-63898.html * https://www.suse.com/security/cve/CVE-2026-63920.html * https://www.suse.com/security/cve/CVE-2026-63925.html * https://www.suse.com/security/cve/CVE-2026-63926.html * https://www.suse.com/security/cve/CVE-2026-63928.html * https://www.suse.com/security/cve/CVE-2026-63944.html * https://www.suse.com/security/cve/CVE-2026-63969.html * https://www.suse.com/security/cve/CVE-2026-63970.html * https://www.suse.com/security/cve/CVE-2026-63972.html * https://www.suse.com/security/cve/CVE-2026-63973.html * https://www.suse.com/security/cve/CVE-2026-63980.html * https://www.suse.com/security/cve/CVE-2026-63985.html * https://www.suse.com/security/cve/CVE-2026-63990.html * https://www.suse.com/security/cve/CVE-2026-63992.html * https://www.suse.com/security/cve/CVE-2026-63999.html * https://www.suse.com/security/cve/CVE-2026-64000.html * https://www.suse.com/security/cve/CVE-2026-64001.html * https://www.suse.com/security/cve/CVE-2026-64002.html * https://www.suse.com/security/cve/CVE-2026-64004.html * https://www.suse.com/security/cve/CVE-2026-64005.html * https://www.suse.com/security/cve/CVE-2026-64006.html * https://www.suse.com/security/cve/CVE-2026-64007.html * https://www.suse.com/security/cve/CVE-2026-64010.html * https://www.suse.com/security/cve/CVE-2026-64011.html * https://www.suse.com/security/cve/CVE-2026-64014.html * https://www.suse.com/security/cve/CVE-2026-64015.html * https://www.suse.com/security/cve/CVE-2026-64018.html * https://www.suse.com/security/cve/CVE-2026-64029.html * https://www.suse.com/security/cve/CVE-2026-64034.html * https://www.suse.com/security/cve/CVE-2026-64039.html * https://www.suse.com/security/cve/CVE-2026-64047.html * https://www.suse.com/security/cve/CVE-2026-64048.html * https://www.suse.com/security/cve/CVE-2026-64051.html * https://www.suse.com/security/cve/CVE-2026-64052.html * https://www.suse.com/security/cve/CVE-2026-64073.html * https://www.suse.com/security/cve/CVE-2026-64083.html * https://www.suse.com/security/cve/CVE-2026-64084.html * https://www.suse.com/security/cve/CVE-2026-64085.html * https://www.suse.com/security/cve/CVE-2026-64086.html * https://www.suse.com/security/cve/CVE-2026-64087.html * https://www.suse.com/security/cve/CVE-2026-64088.html * https://www.suse.com/security/cve/CVE-2026-64097.html * https://www.suse.com/security/cve/CVE-2026-64098.html * https://www.suse.com/security/cve/CVE-2026-64102.html * https://www.suse.com/security/cve/CVE-2026-64109.html * https://www.suse.com/security/cve/CVE-2026-64112.html * https://www.suse.com/security/cve/CVE-2026-64113.html * https://www.suse.com/security/cve/CVE-2026-64114.html * https://www.suse.com/security/cve/CVE-2026-64115.html * https://www.suse.com/security/cve/CVE-2026-64118.html * https://www.suse.com/security/cve/CVE-2026-64121.html * https://www.suse.com/security/cve/CVE-2026-64125.html * https://www.suse.com/security/cve/CVE-2026-64126.html * https://www.suse.com/security/cve/CVE-2026-64128.html * https://www.suse.com/security/cve/CVE-2026-64131.html * https://www.suse.com/security/cve/CVE-2026-64133.html * https://www.suse.com/security/cve/CVE-2026-64135.html * https://www.suse.com/security/cve/CVE-2026-64137.html * https://www.suse.com/security/cve/CVE-2026-64148.html * https://www.suse.com/security/cve/CVE-2026-64155.html * https://www.suse.com/security/cve/CVE-2026-64164.html * https://www.suse.com/security/cve/CVE-2026-64166.html * https://www.suse.com/security/cve/CVE-2026-64168.html * https://www.suse.com/security/cve/CVE-2026-64178.html * https://www.suse.com/security/cve/CVE-2026-64185.html * https://www.suse.com/security/cve/CVE-2026-64188.html * https://www.suse.com/security/cve/CVE-2026-64190.html * https://www.suse.com/security/cve/CVE-2026-64192.html * https://www.suse.com/security/cve/CVE-2026-64214.html * https://www.suse.com/security/cve/CVE-2026-64217.html * https://www.suse.com/security/cve/CVE-2026-64218.html * https://www.suse.com/security/cve/CVE-2026-64219.html * https://www.suse.com/security/cve/CVE-2026-64222.html * https://www.suse.com/security/cve/CVE-2026-64225.html * https://www.suse.com/security/cve/CVE-2026-64237.html * https://www.suse.com/security/cve/CVE-2026-64243.html * https://www.suse.com/security/cve/CVE-2026-64245.html * https://www.suse.com/security/cve/CVE-2026-64246.html * https://www.suse.com/security/cve/CVE-2026-64247.html * https://www.suse.com/security/cve/CVE-2026-64249.html * https://www.suse.com/security/cve/CVE-2026-64257.html * https://www.suse.com/security/cve/CVE-2026-64266.html * https://www.suse.com/security/cve/CVE-2026-64268.html * https://www.suse.com/security/cve/CVE-2026-64271.html * https://www.suse.com/security/cve/CVE-2026-64273.html * https://www.suse.com/security/cve/CVE-2026-64274.html * https://www.suse.com/security/cve/CVE-2026-64275.html * https://www.suse.com/security/cve/CVE-2026-64276.html * https://www.suse.com/security/cve/CVE-2026-64277.html * https://www.suse.com/security/cve/CVE-2026-64286.html * https://www.suse.com/security/cve/CVE-2026-64287.html * https://www.suse.com/security/cve/CVE-2026-64294.html * https://www.suse.com/security/cve/CVE-2026-64296.html * https://www.suse.com/security/cve/CVE-2026-64303.html * https://www.suse.com/security/cve/CVE-2026-64304.html * https://www.suse.com/security/cve/CVE-2026-64305.html * https://www.suse.com/security/cve/CVE-2026-64306.html * https://www.suse.com/security/cve/CVE-2026-64312.html * https://www.suse.com/security/cve/CVE-2026-64313.html * https://www.suse.com/security/cve/CVE-2026-64315.html * https://www.suse.com/security/cve/CVE-2026-64316.html * https://www.suse.com/security/cve/CVE-2026-64317.html * https://www.suse.com/security/cve/CVE-2026-64322.html * https://www.suse.com/security/cve/CVE-2026-64323.html * https://www.suse.com/security/cve/CVE-2026-64329.html * https://www.suse.com/security/cve/CVE-2026-64331.html * https://www.suse.com/security/cve/CVE-2026-64332.html * https://www.suse.com/security/cve/CVE-2026-64333.html * https://www.suse.com/security/cve/CVE-2026-64334.html * https://www.suse.com/security/cve/CVE-2026-64335.html * https://www.suse.com/security/cve/CVE-2026-64337.html * https://www.suse.com/security/cve/CVE-2026-64338.html * https://www.suse.com/security/cve/CVE-2026-64340.html * https://www.suse.com/security/cve/CVE-2026-64341.html * https://www.suse.com/security/cve/CVE-2026-64342.html * https://www.suse.com/security/cve/CVE-2026-64343.html * https://www.suse.com/security/cve/CVE-2026-64344.html * https://www.suse.com/security/cve/CVE-2026-64346.html * https://www.suse.com/security/cve/CVE-2026-64348.html * https://www.suse.com/security/cve/CVE-2026-64350.html * https://www.suse.com/security/cve/CVE-2026-64351.html * https://www.suse.com/security/cve/CVE-2026-64355.html * https://www.suse.com/security/cve/CVE-2026-64358.html * https://www.suse.com/security/cve/CVE-2026-64362.html * https://www.suse.com/security/cve/CVE-2026-64365.html * https://www.suse.com/security/cve/CVE-2026-64375.html * https://www.suse.com/security/cve/CVE-2026-64376.html * https://www.suse.com/security/cve/CVE-2026-64378.html * https://www.suse.com/security/cve/CVE-2026-64381.html * https://www.suse.com/security/cve/CVE-2026-64382.html * https://www.suse.com/security/cve/CVE-2026-64383.html * https://www.suse.com/security/cve/CVE-2026-64384.html * https://www.suse.com/security/cve/CVE-2026-64385.html * https://www.suse.com/security/cve/CVE-2026-64386.html * https://www.suse.com/security/cve/CVE-2026-64387.html * https://www.suse.com/security/cve/CVE-2026-64388.html * https://www.suse.com/security/cve/CVE-2026-64401.html * https://www.suse.com/security/cve/CVE-2026-64403.html * https://www.suse.com/security/cve/CVE-2026-64406.html * https://www.suse.com/security/cve/CVE-2026-64408.html * https://www.suse.com/security/cve/CVE-2026-64409.html * https://www.suse.com/security/cve/CVE-2026-64411.html * https://www.suse.com/security/cve/CVE-2026-64412.html * https://www.suse.com/security/cve/CVE-2026-64420.html * https://www.suse.com/security/cve/CVE-2026-64421.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64427.html * https://www.suse.com/security/cve/CVE-2026-64429.html * https://www.suse.com/security/cve/CVE-2026-64433.html * https://www.suse.com/security/cve/CVE-2026-64434.html * https://www.suse.com/security/cve/CVE-2026-64436.html * https://www.suse.com/security/cve/CVE-2026-64440.html * https://www.suse.com/security/cve/CVE-2026-64442.html * https://www.suse.com/security/cve/CVE-2026-64443.html * https://www.suse.com/security/cve/CVE-2026-64444.html * https://www.suse.com/security/cve/CVE-2026-64445.html * https://www.suse.com/security/cve/CVE-2026-64448.html * https://www.suse.com/security/cve/CVE-2026-64450.html * https://www.suse.com/security/cve/CVE-2026-64454.html * https://www.suse.com/security/cve/CVE-2026-64455.html * https://www.suse.com/security/cve/CVE-2026-64463.html * https://www.suse.com/security/cve/CVE-2026-64470.html * https://www.suse.com/security/cve/CVE-2026-64471.html * https://www.suse.com/security/cve/CVE-2026-64472.html * https://www.suse.com/security/cve/CVE-2026-64478.html * https://www.suse.com/security/cve/CVE-2026-64479.html * https://www.suse.com/security/cve/CVE-2026-64480.html * https://www.suse.com/security/cve/CVE-2026-64481.html * https://www.suse.com/security/cve/CVE-2026-64482.html * https://www.suse.com/security/cve/CVE-2026-64483.html * https://www.suse.com/security/cve/CVE-2026-64484.html * https://www.suse.com/security/cve/CVE-2026-64486.html * https://www.suse.com/security/cve/CVE-2026-64487.html * https://www.suse.com/security/cve/CVE-2026-64489.html * https://www.suse.com/security/cve/CVE-2026-64494.html * https://www.suse.com/security/cve/CVE-2026-64495.html * https://www.suse.com/security/cve/CVE-2026-64496.html * https://www.suse.com/security/cve/CVE-2026-64497.html * https://www.suse.com/security/cve/CVE-2026-64500.html * https://www.suse.com/security/cve/CVE-2026-64503.html * https://www.suse.com/security/cve/CVE-2026-64504.html * https://www.suse.com/security/cve/CVE-2026-64505.html * https://www.suse.com/security/cve/CVE-2026-64511.html * https://www.suse.com/security/cve/CVE-2026-64512.html * https://www.suse.com/security/cve/CVE-2026-64513.html * https://www.suse.com/security/cve/CVE-2026-64524.html * https://www.suse.com/security/cve/CVE-2026-64527.html * https://www.suse.com/security/cve/CVE-2026-64536.html * https://www.suse.com/security/cve/CVE-2026-64537.html * https://www.suse.com/security/cve/CVE-2026-64538.html * https://www.suse.com/security/cve/CVE-2026-64539.html * https://www.suse.com/security/cve/CVE-2026-64540.html * https://www.suse.com/security/cve/CVE-2026-64541.html * https://www.suse.com/security/cve/CVE-2026-64543.html * https://www.suse.com/security/cve/CVE-2026-64544.html * https://www.suse.com/security/cve/CVE-2026-64545.html * https://www.suse.com/security/cve/CVE-2026-64546.html * https://www.suse.com/security/cve/CVE-2026-64547.html * https://www.suse.com/security/cve/CVE-2026-64548.html * https://www.suse.com/security/cve/CVE-2026-64549.html * https://www.suse.com/security/cve/CVE-2026-64551.html * https://www.suse.com/security/cve/CVE-2026-64552.html * https://www.suse.com/security/cve/CVE-2026-64553.html * https://www.suse.com/security/cve/CVE-2026-64554.html * https://www.suse.com/security/cve/CVE-2026-64562.html * https://www.suse.com/security/cve/CVE-2026-64563.html * https://www.suse.com/security/cve/CVE-2026-64565.html * https://www.suse.com/security/cve/CVE-2026-64567.html * https://www.suse.com/security/cve/CVE-2026-64571.html * https://www.suse.com/security/cve/CVE-2026-64572.html * https://www.suse.com/security/cve/CVE-2026-64573.html * https://www.suse.com/security/cve/CVE-2026-64574.html * https://www.suse.com/security/cve/CVE-2026-64576.html * https://www.suse.com/security/cve/CVE-2026-64577.html * https://www.suse.com/security/cve/CVE-2026-64581.html * https://www.suse.com/security/cve/CVE-2026-64582.html * https://www.suse.com/security/cve/CVE-2026-64583.html * https://www.suse.com/security/cve/CVE-2026-64584.html * https://www.suse.com/security/cve/CVE-2026-64585.html * https://www.suse.com/security/cve/CVE-2026-64593.html * https://www.suse.com/security/cve/CVE-2026-64597.html * https://www.suse.com/security/cve/CVE-2026-64598.html * https://www.suse.com/security/cve/CVE-2026-64599.html * https://www.suse.com/security/cve/CVE-2026-64602.html * https://www.suse.com/security/cve/CVE-2026-64604.html * https://www.suse.com/security/cve/CVE-2026-68081.html * https://www.suse.com/security/cve/CVE-2026-68082.html * https://www.suse.com/security/cve/CVE-2026-68085.html * https://www.suse.com/security/cve/CVE-2026-68086.html * https://www.suse.com/security/cve/CVE-2026-68088.html * https://www.suse.com/security/cve/CVE-2026-68091.html * https://www.suse.com/security/cve/CVE-2026-68093.html * https://www.suse.com/security/cve/CVE-2026-68102.html * https://www.suse.com/security/cve/CVE-2026-68104.html * https://www.suse.com/security/cve/CVE-2026-68106.html * https://www.suse.com/security/cve/CVE-2026-68107.html * https://www.suse.com/security/cve/CVE-2026-68108.html * https://www.suse.com/security/cve/CVE-2026-68110.html * https://www.suse.com/security/cve/CVE-2026-68111.html * https://www.suse.com/security/cve/CVE-2026-68112.html * https://www.suse.com/security/cve/CVE-2026-68115.html * https://www.suse.com/security/cve/CVE-2026-68116.html * https://www.suse.com/security/cve/CVE-2026-68117.html * https://www.suse.com/security/cve/CVE-2026-68121.html * https://www.suse.com/security/cve/CVE-2026-68123.html * https://www.suse.com/security/cve/CVE-2026-68125.html * https://www.suse.com/security/cve/CVE-2026-68126.html * https://www.suse.com/security/cve/CVE-2026-68127.html * https://www.suse.com/security/cve/CVE-2026-68129.html * https://www.suse.com/security/cve/CVE-2026-68132.html * https://www.suse.com/security/cve/CVE-2026-68133.html * https://www.suse.com/security/cve/CVE-2026-68136.html * https://www.suse.com/security/cve/CVE-2026-68137.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://www.suse.com/security/cve/CVE-2026-68139.html * https://www.suse.com/security/cve/CVE-2026-68142.html * https://www.suse.com/security/cve/CVE-2026-68143.html * https://www.suse.com/security/cve/CVE-2026-68145.html * https://www.suse.com/security/cve/CVE-2026-68149.html * https://www.suse.com/security/cve/CVE-2026-68153.html * https://www.suse.com/security/cve/CVE-2026-68154.html * https://www.suse.com/security/cve/CVE-2026-68155.html * https://www.suse.com/security/cve/CVE-2026-68156.html * https://www.suse.com/security/cve/CVE-2026-68157.html * https://www.suse.com/security/cve/CVE-2026-68158.html * https://www.suse.com/security/cve/CVE-2026-68159.html * https://www.suse.com/security/cve/CVE-2026-68160.html * https://www.suse.com/security/cve/CVE-2026-68161.html * https://www.suse.com/security/cve/CVE-2026-68162.html * https://www.suse.com/security/cve/CVE-2026-68166.html * https://www.suse.com/security/cve/CVE-2026-68180.html * https://www.suse.com/security/cve/CVE-2026-68181.html * https://www.suse.com/security/cve/CVE-2026-68182.html * https://www.suse.com/security/cve/CVE-2026-68184.html * https://www.suse.com/security/cve/CVE-2026-68188.html * https://www.suse.com/security/cve/CVE-2026-68189.html * https://www.suse.com/security/cve/CVE-2026-68192.html * https://www.suse.com/security/cve/CVE-2026-68193.html * https://www.suse.com/security/cve/CVE-2026-68194.html * https://www.suse.com/security/cve/CVE-2026-68195.html * https://www.suse.com/security/cve/CVE-2026-68196.html * https://www.suse.com/security/cve/CVE-2026-68197.html * https://www.suse.com/security/cve/CVE-2026-68199.html * https://www.suse.com/security/cve/CVE-2026-68202.html * https://www.suse.com/security/cve/CVE-2026-68204.html * https://www.suse.com/security/cve/CVE-2026-68205.html * https://www.suse.com/security/cve/CVE-2026-68206.html * https://www.suse.com/security/cve/CVE-2026-68207.html * https://www.suse.com/security/cve/CVE-2026-68209.html * https://www.suse.com/security/cve/CVE-2026-68210.html * https://www.suse.com/security/cve/CVE-2026-68212.html * https://www.suse.com/security/cve/CVE-2026-68213.html * https://www.suse.com/security/cve/CVE-2026-68214.html * https://www.suse.com/security/cve/CVE-2026-68215.html * https://www.suse.com/security/cve/CVE-2026-68216.html * https://www.suse.com/security/cve/CVE-2026-68217.html * https://www.suse.com/security/cve/CVE-2026-68218.html * https://www.suse.com/security/cve/CVE-2026-68219.html * https://www.suse.com/security/cve/CVE-2026-68220.html * https://www.suse.com/security/cve/CVE-2026-68222.html * https://www.suse.com/security/cve/CVE-2026-68223.html * https://www.suse.com/security/cve/CVE-2026-68226.html * https://www.suse.com/security/cve/CVE-2026-68227.html * https://www.suse.com/security/cve/CVE-2026-68229.html * https://www.suse.com/security/cve/CVE-2026-68231.html * https://www.suse.com/security/cve/CVE-2026-68234.html * https://www.suse.com/security/cve/CVE-2026-68236.html * https://www.suse.com/security/cve/CVE-2026-68238.html * https://www.suse.com/security/cve/CVE-2026-68243.html * https://www.suse.com/security/cve/CVE-2026-68244.html * https://www.suse.com/security/cve/CVE-2026-68246.html * https://www.suse.com/security/cve/CVE-2026-68247.html * https://www.suse.com/security/cve/CVE-2026-68248.html * https://www.suse.com/security/cve/CVE-2026-68249.html * https://www.suse.com/security/cve/CVE-2026-68250.html * https://www.suse.com/security/cve/CVE-2026-68251.html * https://www.suse.com/security/cve/CVE-2026-68254.html * https://www.suse.com/security/cve/CVE-2026-68255.html * https://www.suse.com/security/cve/CVE-2026-68256.html * https://www.suse.com/security/cve/CVE-2026-68259.html * https://www.suse.com/security/cve/CVE-2026-68269.html * https://www.suse.com/security/cve/CVE-2026-68271.html * https://www.suse.com/security/cve/CVE-2026-68272.html * https://www.suse.com/security/cve/CVE-2026-68277.html * https://www.suse.com/security/cve/CVE-2026-68278.html * https://www.suse.com/security/cve/CVE-2026-68279.html * https://www.suse.com/security/cve/CVE-2026-68280.html * https://www.suse.com/security/cve/CVE-2026-68284.html * https://www.suse.com/security/cve/CVE-2026-68286.html * https://www.suse.com/security/cve/CVE-2026-68288.html * https://www.suse.com/security/cve/CVE-2026-68289.html * https://www.suse.com/security/cve/CVE-2026-68293.html * https://www.suse.com/security/cve/CVE-2026-68297.html * https://www.suse.com/security/cve/CVE-2026-68299.html * https://www.suse.com/security/cve/CVE-2026-68300.html * https://www.suse.com/security/cve/CVE-2026-68303.html * https://www.suse.com/security/cve/CVE-2026-68304.html * https://www.suse.com/security/cve/CVE-2026-68306.html * https://www.suse.com/security/cve/CVE-2026-68308.html * https://www.suse.com/security/cve/CVE-2026-68309.html * https://www.suse.com/security/cve/CVE-2026-68310.html * https://www.suse.com/security/cve/CVE-2026-68312.html * https://www.suse.com/security/cve/CVE-2026-68313.html * https://www.suse.com/security/cve/CVE-2026-68315.html * https://www.suse.com/security/cve/CVE-2026-68320.html * https://www.suse.com/security/cve/CVE-2026-68322.html * https://www.suse.com/security/cve/CVE-2026-68324.html * https://www.suse.com/security/cve/CVE-2026-68325.html * https://www.suse.com/security/cve/CVE-2026-68326.html * https://www.suse.com/security/cve/CVE-2026-68327.html * https://www.suse.com/security/cve/CVE-2026-68328.html * https://www.suse.com/security/cve/CVE-2026-68329.html * https://www.suse.com/security/cve/CVE-2026-68331.html * https://www.suse.com/security/cve/CVE-2026-68333.html * https://www.suse.com/security/cve/CVE-2026-68335.html * https://www.suse.com/security/cve/CVE-2026-68336.html * https://www.suse.com/security/cve/CVE-2026-68339.html * https://www.suse.com/security/cve/CVE-2026-68340.html * https://www.suse.com/security/cve/CVE-2026-68343.html * https://www.suse.com/security/cve/CVE-2026-68346.html * https://www.suse.com/security/cve/CVE-2026-68348.html * https://www.suse.com/security/cve/CVE-2026-68349.html * https://www.suse.com/security/cve/CVE-2026-68350.html * https://www.suse.com/security/cve/CVE-2026-68351.html * https://www.suse.com/security/cve/CVE-2026-68352.html * https://www.suse.com/security/cve/CVE-2026-68353.html * https://www.suse.com/security/cve/CVE-2026-68354.html * https://www.suse.com/security/cve/CVE-2026-68355.html * https://www.suse.com/security/cve/CVE-2026-68357.html * https://www.suse.com/security/cve/CVE-2026-68359.html * https://www.suse.com/security/cve/CVE-2026-68360.html * https://www.suse.com/security/cve/CVE-2026-68361.html * https://www.suse.com/security/cve/CVE-2026-68362.html * https://www.suse.com/security/cve/CVE-2026-68363.html * https://www.suse.com/security/cve/CVE-2026-68365.html * https://www.suse.com/security/cve/CVE-2026-68366.html * https://www.suse.com/security/cve/CVE-2026-68368.html * https://www.suse.com/security/cve/CVE-2026-68369.html * https://www.suse.com/security/cve/CVE-2026-68370.html * https://www.suse.com/security/cve/CVE-2026-68372.html * https://www.suse.com/security/cve/CVE-2026-68373.html * https://www.suse.com/security/cve/CVE-2026-68377.html * https://www.suse.com/security/cve/CVE-2026-68386.html * https://www.suse.com/security/cve/CVE-2026-68391.html * https://www.suse.com/security/cve/CVE-2026-68392.html * https://www.suse.com/security/cve/CVE-2026-68397.html * https://www.suse.com/security/cve/CVE-2026-68398.html * https://www.suse.com/security/cve/CVE-2026-68399.html * https://www.suse.com/security/cve/CVE-2026-68402.html * https://www.suse.com/security/cve/CVE-2026-68403.html * https://www.suse.com/security/cve/CVE-2026-68405.html * https://www.suse.com/security/cve/CVE-2026-68406.html * https://www.suse.com/security/cve/CVE-2026-68407.html * https://www.suse.com/security/cve/CVE-2026-68408.html * https://www.suse.com/security/cve/CVE-2026-68410.html * https://www.suse.com/security/cve/CVE-2026-68413.html * https://www.suse.com/security/cve/CVE-2026-68414.html * https://www.suse.com/security/cve/CVE-2026-68417.html * https://www.suse.com/security/cve/CVE-2026-68418.html * https://www.suse.com/security/cve/CVE-2026-68419.html * https://www.suse.com/security/cve/CVE-2026-68422.html * https://www.suse.com/security/cve/CVE-2026-68425.html * https://www.suse.com/security/cve/CVE-2026-68426.html * https://www.suse.com/security/cve/CVE-2026-68427.html * https://www.suse.com/security/cve/CVE-2026-68428.html * https://www.suse.com/security/cve/CVE-2026-68429.html * https://www.suse.com/security/cve/CVE-2026-68430.html * https://www.suse.com/security/cve/CVE-2026-68432.html * https://www.suse.com/security/cve/CVE-2026-68433.html * https://www.suse.com/security/cve/CVE-2026-68434.html * https://www.suse.com/security/cve/CVE-2026-68444.html * https://www.suse.com/security/cve/CVE-2026-68445.html * https://www.suse.com/security/cve/CVE-2026-68446.html * https://www.suse.com/security/cve/CVE-2026-68450.html * https://www.suse.com/security/cve/CVE-2026-68470.html * https://www.suse.com/security/cve/CVE-2026-68480.html * https://www.suse.com/security/cve/CVE-2026-72020.html * https://www.suse.com/security/cve/CVE-2026-72035.html * https://www.suse.com/security/cve/CVE-2026-72036.html * https://www.suse.com/security/cve/CVE-2026-72069.html * https://www.suse.com/security/cve/CVE-2026-72072.html * https://www.suse.com/security/cve/CVE-2026-72083.html * https://www.suse.com/security/cve/CVE-2026-72084.html * https://www.suse.com/security/cve/CVE-2026-72123.html * https://www.suse.com/security/cve/CVE-2026-72132.html * https://www.suse.com/security/cve/CVE-2026-72221.html * https://www.suse.com/security/cve/CVE-2026-72222.html * https://www.suse.com/security/cve/CVE-2026-72251.html * https://www.suse.com/security/cve/CVE-2026-72254.html * https://www.suse.com/security/cve/CVE-2026-72262.html * https://www.suse.com/security/cve/CVE-2026-72288.html * https://www.suse.com/security/cve/CVE-2026-72289.html * https://www.suse.com/security/cve/CVE-2026-72296.html * https://www.suse.com/security/cve/CVE-2026-72307.html * https://www.suse.com/security/cve/CVE-2026-72308.html * https://www.suse.com/security/cve/CVE-2026-72317.html * https://www.suse.com/security/cve/CVE-2026-72341.html * https://www.suse.com/security/cve/CVE-2026-72342.html * https://www.suse.com/security/cve/CVE-2026-72343.html * https://www.suse.com/security/cve/CVE-2026-72389.html * https://www.suse.com/security/cve/CVE-2026-72463.html * https://www.suse.com/security/cve/CVE-2026-72464.html * https://www.suse.com/security/cve/CVE-2026-72466.html * https://www.suse.com/security/cve/CVE-2026-72467.html * https://www.suse.com/security/cve/CVE-2026-72469.html * https://www.suse.com/security/cve/CVE-2026-72473.html * https://www.suse.com/security/cve/CVE-2026-72494.html * https://www.suse.com/security/cve/CVE-2026-72495.html * https://www.suse.com/security/cve/CVE-2026-72496.html * https://www.suse.com/security/cve/CVE-2026-72499.html * https://www.suse.com/security/cve/CVE-2026-72501.html * https://www.suse.com/security/cve/CVE-2026-72502.html * https://www.suse.com/security/cve/CVE-2026-74269.html * https://www.suse.com/security/cve/CVE-2026-74296.html * https://www.suse.com/security/cve/CVE-2026-74297.html * https://www.suse.com/security/cve/CVE-2026-74318.html * https://www.suse.com/security/cve/CVE-2026-74321.html * https://www.suse.com/security/cve/CVE-2026-74334.html * https://www.suse.com/security/cve/CVE-2026-74345.html * https://www.suse.com/security/cve/CVE-2026-74394.html * https://www.suse.com/security/cve/CVE-2026-74395.html * https://www.suse.com/security/cve/CVE-2026-74454.html * https://www.suse.com/security/cve/CVE-2026-74474.html * https://www.suse.com/security/cve/CVE-2026-74481.html * https://www.suse.com/security/cve/CVE-2026-74482.html * https://www.suse.com/security/cve/CVE-2026-74488.html * https://www.suse.com/security/cve/CVE-2026-74495.html * https://www.suse.com/security/cve/CVE-2026-74496.html * https://www.suse.com/security/cve/CVE-2026-74509.html * https://www.suse.com/security/cve/CVE-2026-74510.html * https://www.suse.com/security/cve/CVE-2026-74512.html * https://www.suse.com/security/cve/CVE-2026-74516.html * https://www.suse.com/security/cve/CVE-2026-74518.html * https://www.suse.com/security/cve/CVE-2026-74527.html * https://www.suse.com/security/cve/CVE-2026-74537.html * https://www.suse.com/security/cve/CVE-2026-74548.html * https://www.suse.com/security/cve/CVE-2026-74550.html * https://www.suse.com/security/cve/CVE-2026-74556.html * https://www.suse.com/security/cve/CVE-2026-74563.html * https://www.suse.com/security/cve/CVE-2026-74566.html * https://www.suse.com/security/cve/CVE-2026-74567.html * https://www.suse.com/security/cve/CVE-2026-74571.html * https://www.suse.com/security/cve/CVE-2026-74581.html * https://www.suse.com/security/cve/CVE-2026-74582.html * https://www.suse.com/security/cve/CVE-2026-74584.html * https://www.suse.com/security/cve/CVE-2026-74610.html * https://www.suse.com/security/cve/CVE-2026-74669.html * https://www.suse.com/security/cve/CVE-2026-74692.html * https://www.suse.com/security/cve/CVE-2026-74694.html * https://www.suse.com/security/cve/CVE-2026-74695.html * https://www.suse.com/security/cve/CVE-2026-74717.html * https://www.suse.com/security/cve/CVE-2026-74722.html * https://www.suse.com/security/cve/CVE-2026-80529.html * https://www.suse.com/security/cve/CVE-2026-80534.html * https://www.suse.com/security/cve/CVE-2026-80590.html * https://www.suse.com/security/cve/CVE-2026-80654.html * https://bugzilla.suse.com/show_bug.cgi?id=1230238 * https://bugzilla.suse.com/show_bug.cgi?id=1235944 * https://bugzilla.suse.com/show_bug.cgi?id=1247455 * https://bugzilla.suse.com/show_bug.cgi?id=1250748 * https://bugzilla.suse.com/show_bug.cgi?id=1251966 * https://bugzilla.suse.com/show_bug.cgi?id=1252682 * https://bugzilla.suse.com/show_bug.cgi?id=1254306 * https://bugzilla.suse.com/show_bug.cgi?id=1255225 * https://bugzilla.suse.com/show_bug.cgi?id=1255250 * https://bugzilla.suse.com/show_bug.cgi?id=1256629 * https://bugzilla.suse.com/show_bug.cgi?id=1256708 * https://bugzilla.suse.com/show_bug.cgi?id=1257154 * https://bugzilla.suse.com/show_bug.cgi?id=1258430 * https://bugzilla.suse.com/show_bug.cgi?id=1258517 * https://bugzilla.suse.com/show_bug.cgi?id=1260522 * https://bugzilla.suse.com/show_bug.cgi?id=1261780 * https://bugzilla.suse.com/show_bug.cgi?id=1261788 * https://bugzilla.suse.com/show_bug.cgi?id=1262073 * https://bugzilla.suse.com/show_bug.cgi?id=1263004 * https://bugzilla.suse.com/show_bug.cgi?id=1263061 * https://bugzilla.suse.com/show_bug.cgi?id=1263133 * https://bugzilla.suse.com/show_bug.cgi?id=1264335 * https://bugzilla.suse.com/show_bug.cgi?id=1264446 * https://bugzilla.suse.com/show_bug.cgi?id=1264541 * https://bugzilla.suse.com/show_bug.cgi?id=1264584 * https://bugzilla.suse.com/show_bug.cgi?id=1264587 * https://bugzilla.suse.com/show_bug.cgi?id=1264619 * https://bugzilla.suse.com/show_bug.cgi?id=1264788 * https://bugzilla.suse.com/show_bug.cgi?id=1265068 * https://bugzilla.suse.com/show_bug.cgi?id=1265121 * https://bugzilla.suse.com/show_bug.cgi?id=1265449 * https://bugzilla.suse.com/show_bug.cgi?id=1265928 * https://bugzilla.suse.com/show_bug.cgi?id=1266402 * https://bugzilla.suse.com/show_bug.cgi?id=1266860 * https://bugzilla.suse.com/show_bug.cgi?id=1266874 * https://bugzilla.suse.com/show_bug.cgi?id=1266897 * https://bugzilla.suse.com/show_bug.cgi?id=1267023 * https://bugzilla.suse.com/show_bug.cgi?id=1267238 * https://bugzilla.suse.com/show_bug.cgi?id=1267501 * https://bugzilla.suse.com/show_bug.cgi?id=1267612 * https://bugzilla.suse.com/show_bug.cgi?id=1268276 * https://bugzilla.suse.com/show_bug.cgi?id=1268972 * https://bugzilla.suse.com/show_bug.cgi?id=1268979 * https://bugzilla.suse.com/show_bug.cgi?id=1268987 * https://bugzilla.suse.com/show_bug.cgi?id=1269004 * https://bugzilla.suse.com/show_bug.cgi?id=1269013 * https://bugzilla.suse.com/show_bug.cgi?id=1269108 * https://bugzilla.suse.com/show_bug.cgi?id=1269113 * https://bugzilla.suse.com/show_bug.cgi?id=1269114 * https://bugzilla.suse.com/show_bug.cgi?id=1269126 * https://bugzilla.suse.com/show_bug.cgi?id=1269167 * https://bugzilla.suse.com/show_bug.cgi?id=1269234 * https://bugzilla.suse.com/show_bug.cgi?id=1269238 * https://bugzilla.suse.com/show_bug.cgi?id=1269242 * https://bugzilla.suse.com/show_bug.cgi?id=1269256 * https://bugzilla.suse.com/show_bug.cgi?id=1269301 * https://bugzilla.suse.com/show_bug.cgi?id=1269306 * https://bugzilla.suse.com/show_bug.cgi?id=1269381 * https://bugzilla.suse.com/show_bug.cgi?id=1269388 * https://bugzilla.suse.com/show_bug.cgi?id=1269412 * https://bugzilla.suse.com/show_bug.cgi?id=1269530 * https://bugzilla.suse.com/show_bug.cgi?id=1269579 * https://bugzilla.suse.com/show_bug.cgi?id=1269590 * https://bugzilla.suse.com/show_bug.cgi?id=1269635 * https://bugzilla.suse.com/show_bug.cgi?id=1269655 * https://bugzilla.suse.com/show_bug.cgi?id=1269665 * https://bugzilla.suse.com/show_bug.cgi?id=1269686 * https://bugzilla.suse.com/show_bug.cgi?id=1269695 * https://bugzilla.suse.com/show_bug.cgi?id=1269713 * https://bugzilla.suse.com/show_bug.cgi?id=1269731 * https://bugzilla.suse.com/show_bug.cgi?id=1269774 * https://bugzilla.suse.com/show_bug.cgi?id=1269783 * https://bugzilla.suse.com/show_bug.cgi?id=1269792 * https://bugzilla.suse.com/show_bug.cgi?id=1269815 * https://bugzilla.suse.com/show_bug.cgi?id=1269965 * https://bugzilla.suse.com/show_bug.cgi?id=1269969 * https://bugzilla.suse.com/show_bug.cgi?id=1269981 * https://bugzilla.suse.com/show_bug.cgi?id=1269985 * https://bugzilla.suse.com/show_bug.cgi?id=1270090 * https://bugzilla.suse.com/show_bug.cgi?id=1270108 * https://bugzilla.suse.com/show_bug.cgi?id=1270111 * https://bugzilla.suse.com/show_bug.cgi?id=1270251 * https://bugzilla.suse.com/show_bug.cgi?id=1271256 * https://bugzilla.suse.com/show_bug.cgi?id=1271365 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 * https://bugzilla.suse.com/show_bug.cgi?id=1271825 * https://bugzilla.suse.com/show_bug.cgi?id=1271830 * https://bugzilla.suse.com/show_bug.cgi?id=1272150 * https://bugzilla.suse.com/show_bug.cgi?id=1272175 * https://bugzilla.suse.com/show_bug.cgi?id=1272179 * https://bugzilla.suse.com/show_bug.cgi?id=1272182 * https://bugzilla.suse.com/show_bug.cgi?id=1272200 * https://bugzilla.suse.com/show_bug.cgi?id=1272210 * https://bugzilla.suse.com/show_bug.cgi?id=1272213 * https://bugzilla.suse.com/show_bug.cgi?id=1272230 * https://bugzilla.suse.com/show_bug.cgi?id=1272260 * https://bugzilla.suse.com/show_bug.cgi?id=1272261 * https://bugzilla.suse.com/show_bug.cgi?id=1272262 * https://bugzilla.suse.com/show_bug.cgi?id=1272297 * https://bugzilla.suse.com/show_bug.cgi?id=1272346 * https://bugzilla.suse.com/show_bug.cgi?id=1272381 * https://bugzilla.suse.com/show_bug.cgi?id=1272385 * https://bugzilla.suse.com/show_bug.cgi?id=1272390 * https://bugzilla.suse.com/show_bug.cgi?id=1272423 * https://bugzilla.suse.com/show_bug.cgi?id=1272429 * https://bugzilla.suse.com/show_bug.cgi?id=1272484 * https://bugzilla.suse.com/show_bug.cgi?id=1272486 * https://bugzilla.suse.com/show_bug.cgi?id=1272497 * https://bugzilla.suse.com/show_bug.cgi?id=1272516 * https://bugzilla.suse.com/show_bug.cgi?id=1272569 * https://bugzilla.suse.com/show_bug.cgi?id=1272571 * https://bugzilla.suse.com/show_bug.cgi?id=1272641 * https://bugzilla.suse.com/show_bug.cgi?id=1272643 * https://bugzilla.suse.com/show_bug.cgi?id=1272662 * https://bugzilla.suse.com/show_bug.cgi?id=1272673 * https://bugzilla.suse.com/show_bug.cgi?id=1272680 * https://bugzilla.suse.com/show_bug.cgi?id=1272682 * https://bugzilla.suse.com/show_bug.cgi?id=1272756 * https://bugzilla.suse.com/show_bug.cgi?id=1272786 * https://bugzilla.suse.com/show_bug.cgi?id=1272788 * https://bugzilla.suse.com/show_bug.cgi?id=1272798 * https://bugzilla.suse.com/show_bug.cgi?id=1272799 * https://bugzilla.suse.com/show_bug.cgi?id=1272868 * https://bugzilla.suse.com/show_bug.cgi?id=1272877 * https://bugzilla.suse.com/show_bug.cgi?id=1272891 * https://bugzilla.suse.com/show_bug.cgi?id=1272963 * https://bugzilla.suse.com/show_bug.cgi?id=1272983 * https://bugzilla.suse.com/show_bug.cgi?id=1273008 * https://bugzilla.suse.com/show_bug.cgi?id=1273019 * https://bugzilla.suse.com/show_bug.cgi?id=1273027 * https://bugzilla.suse.com/show_bug.cgi?id=1273028 * https://bugzilla.suse.com/show_bug.cgi?id=1273030 * https://bugzilla.suse.com/show_bug.cgi?id=1273038 * https://bugzilla.suse.com/show_bug.cgi?id=1273053 * https://bugzilla.suse.com/show_bug.cgi?id=1273054 * https://bugzilla.suse.com/show_bug.cgi?id=1273060 * https://bugzilla.suse.com/show_bug.cgi?id=1273105 * https://bugzilla.suse.com/show_bug.cgi?id=1273249 * https://bugzilla.suse.com/show_bug.cgi?id=1273250 * https://bugzilla.suse.com/show_bug.cgi?id=1273260 * https://bugzilla.suse.com/show_bug.cgi?id=1273273 * https://bugzilla.suse.com/show_bug.cgi?id=1273274 * https://bugzilla.suse.com/show_bug.cgi?id=1273276 * https://bugzilla.suse.com/show_bug.cgi?id=1273281 * https://bugzilla.suse.com/show_bug.cgi?id=1273284 * https://bugzilla.suse.com/show_bug.cgi?id=1273285 * https://bugzilla.suse.com/show_bug.cgi?id=1273289 * https://bugzilla.suse.com/show_bug.cgi?id=1273291 * https://bugzilla.suse.com/show_bug.cgi?id=1273294 * https://bugzilla.suse.com/show_bug.cgi?id=1273302 * https://bugzilla.suse.com/show_bug.cgi?id=1273303 * https://bugzilla.suse.com/show_bug.cgi?id=1273305 * https://bugzilla.suse.com/show_bug.cgi?id=1273310 * https://bugzilla.suse.com/show_bug.cgi?id=1273311 * https://bugzilla.suse.com/show_bug.cgi?id=1273316 * https://bugzilla.suse.com/show_bug.cgi?id=1273318 * https://bugzilla.suse.com/show_bug.cgi?id=1273319 * https://bugzilla.suse.com/show_bug.cgi?id=1273323 * https://bugzilla.suse.com/show_bug.cgi?id=1273325 * https://bugzilla.suse.com/show_bug.cgi?id=1273327 * https://bugzilla.suse.com/show_bug.cgi?id=1273334 * https://bugzilla.suse.com/show_bug.cgi?id=1273335 * https://bugzilla.suse.com/show_bug.cgi?id=1273336 * https://bugzilla.suse.com/show_bug.cgi?id=1273337 * https://bugzilla.suse.com/show_bug.cgi?id=1273338 * https://bugzilla.suse.com/show_bug.cgi?id=1273340 * https://bugzilla.suse.com/show_bug.cgi?id=1273341 * https://bugzilla.suse.com/show_bug.cgi?id=1273346 * https://bugzilla.suse.com/show_bug.cgi?id=1273422 * https://bugzilla.suse.com/show_bug.cgi?id=1273426 * https://bugzilla.suse.com/show_bug.cgi?id=1273443 * https://bugzilla.suse.com/show_bug.cgi?id=1273463 * https://bugzilla.suse.com/show_bug.cgi?id=1273468 * https://bugzilla.suse.com/show_bug.cgi?id=1273469 * https://bugzilla.suse.com/show_bug.cgi?id=1273471 * https://bugzilla.suse.com/show_bug.cgi?id=1273479 * https://bugzilla.suse.com/show_bug.cgi?id=1273480 * https://bugzilla.suse.com/show_bug.cgi?id=1273482 * https://bugzilla.suse.com/show_bug.cgi?id=1273484 * https://bugzilla.suse.com/show_bug.cgi?id=1273488 * https://bugzilla.suse.com/show_bug.cgi?id=1273490 * https://bugzilla.suse.com/show_bug.cgi?id=1273501 * https://bugzilla.suse.com/show_bug.cgi?id=1273503 * https://bugzilla.suse.com/show_bug.cgi?id=1273504 * https://bugzilla.suse.com/show_bug.cgi?id=1273506 * https://bugzilla.suse.com/show_bug.cgi?id=1273523 * https://bugzilla.suse.com/show_bug.cgi?id=1273525 * https://bugzilla.suse.com/show_bug.cgi?id=1273533 * https://bugzilla.suse.com/show_bug.cgi?id=1273536 * https://bugzilla.suse.com/show_bug.cgi?id=1273542 * https://bugzilla.suse.com/show_bug.cgi?id=1273555 * https://bugzilla.suse.com/show_bug.cgi?id=1273578 * https://bugzilla.suse.com/show_bug.cgi?id=1273579 * https://bugzilla.suse.com/show_bug.cgi?id=1273582 * https://bugzilla.suse.com/show_bug.cgi?id=1273596 * https://bugzilla.suse.com/show_bug.cgi?id=1273597 * https://bugzilla.suse.com/show_bug.cgi?id=1273598 * https://bugzilla.suse.com/show_bug.cgi?id=1273600 * https://bugzilla.suse.com/show_bug.cgi?id=1273601 * https://bugzilla.suse.com/show_bug.cgi?id=1273602 * https://bugzilla.suse.com/show_bug.cgi?id=1273603 * https://bugzilla.suse.com/show_bug.cgi?id=1273682 * https://bugzilla.suse.com/show_bug.cgi?id=1273734 * https://bugzilla.suse.com/show_bug.cgi?id=1273738 * https://bugzilla.suse.com/show_bug.cgi?id=1273739 * https://bugzilla.suse.com/show_bug.cgi?id=1273741 * https://bugzilla.suse.com/show_bug.cgi?id=1273742 * https://bugzilla.suse.com/show_bug.cgi?id=1273743 * https://bugzilla.suse.com/show_bug.cgi?id=1273745 * https://bugzilla.suse.com/show_bug.cgi?id=1273748 * https://bugzilla.suse.com/show_bug.cgi?id=1273749 * https://bugzilla.suse.com/show_bug.cgi?id=1273755 * https://bugzilla.suse.com/show_bug.cgi?id=1273762 * https://bugzilla.suse.com/show_bug.cgi?id=1273765 * https://bugzilla.suse.com/show_bug.cgi?id=1273766 * https://bugzilla.suse.com/show_bug.cgi?id=1273769 * https://bugzilla.suse.com/show_bug.cgi?id=1273774 * https://bugzilla.suse.com/show_bug.cgi?id=1273778 * https://bugzilla.suse.com/show_bug.cgi?id=1273780 * https://bugzilla.suse.com/show_bug.cgi?id=1273790 * https://bugzilla.suse.com/show_bug.cgi?id=1273796 * https://bugzilla.suse.com/show_bug.cgi?id=1273804 * https://bugzilla.suse.com/show_bug.cgi?id=1273810 * https://bugzilla.suse.com/show_bug.cgi?id=1273811 * https://bugzilla.suse.com/show_bug.cgi?id=1273813 * https://bugzilla.suse.com/show_bug.cgi?id=1273817 * https://bugzilla.suse.com/show_bug.cgi?id=1273822 * https://bugzilla.suse.com/show_bug.cgi?id=1273824 * https://bugzilla.suse.com/show_bug.cgi?id=1273831 * https://bugzilla.suse.com/show_bug.cgi?id=1273832 * https://bugzilla.suse.com/show_bug.cgi?id=1273834 * https://bugzilla.suse.com/show_bug.cgi?id=1273838 * https://bugzilla.suse.com/show_bug.cgi?id=1273844 * https://bugzilla.suse.com/show_bug.cgi?id=1273849 * https://bugzilla.suse.com/show_bug.cgi?id=1273860 * https://bugzilla.suse.com/show_bug.cgi?id=1273862 * https://bugzilla.suse.com/show_bug.cgi?id=1273867 * https://bugzilla.suse.com/show_bug.cgi?id=1273868 * https://bugzilla.suse.com/show_bug.cgi?id=1273869 * https://bugzilla.suse.com/show_bug.cgi?id=1273872 * https://bugzilla.suse.com/show_bug.cgi?id=1273876 * https://bugzilla.suse.com/show_bug.cgi?id=1273877 * https://bugzilla.suse.com/show_bug.cgi?id=1273880 * https://bugzilla.suse.com/show_bug.cgi?id=1273882 * https://bugzilla.suse.com/show_bug.cgi?id=1273890 * https://bugzilla.suse.com/show_bug.cgi?id=1273891 * https://bugzilla.suse.com/show_bug.cgi?id=1273892 * https://bugzilla.suse.com/show_bug.cgi?id=1273895 * https://bugzilla.suse.com/show_bug.cgi?id=1273896 * https://bugzilla.suse.com/show_bug.cgi?id=1273903 * https://bugzilla.suse.com/show_bug.cgi?id=1273905 * https://bugzilla.suse.com/show_bug.cgi?id=1273930 * https://bugzilla.suse.com/show_bug.cgi?id=1273933 * https://bugzilla.suse.com/show_bug.cgi?id=1273934 * https://bugzilla.suse.com/show_bug.cgi?id=1273935 * https://bugzilla.suse.com/show_bug.cgi?id=1273936 * https://bugzilla.suse.com/show_bug.cgi?id=1273939 * https://bugzilla.suse.com/show_bug.cgi?id=1273940 * https://bugzilla.suse.com/show_bug.cgi?id=1273941 * https://bugzilla.suse.com/show_bug.cgi?id=1273942 * https://bugzilla.suse.com/show_bug.cgi?id=1273944 * https://bugzilla.suse.com/show_bug.cgi?id=1273945 * https://bugzilla.suse.com/show_bug.cgi?id=1273946 * https://bugzilla.suse.com/show_bug.cgi?id=1273956 * https://bugzilla.suse.com/show_bug.cgi?id=1273957 * https://bugzilla.suse.com/show_bug.cgi?id=1273958 * https://bugzilla.suse.com/show_bug.cgi?id=1273966 * https://bugzilla.suse.com/show_bug.cgi?id=1273967 * https://bugzilla.suse.com/show_bug.cgi?id=1273968 * https://bugzilla.suse.com/show_bug.cgi?id=1273972 * https://bugzilla.suse.com/show_bug.cgi?id=1273974 * https://bugzilla.suse.com/show_bug.cgi?id=1273975 * https://bugzilla.suse.com/show_bug.cgi?id=1273977 * https://bugzilla.suse.com/show_bug.cgi?id=1273982 * https://bugzilla.suse.com/show_bug.cgi?id=1273988 * https://bugzilla.suse.com/show_bug.cgi?id=1273990 * https://bugzilla.suse.com/show_bug.cgi?id=1273991 * https://bugzilla.suse.com/show_bug.cgi?id=1273995 * https://bugzilla.suse.com/show_bug.cgi?id=1274001 * https://bugzilla.suse.com/show_bug.cgi?id=1274003 * https://bugzilla.suse.com/show_bug.cgi?id=1274006 * https://bugzilla.suse.com/show_bug.cgi?id=1274011 * https://bugzilla.suse.com/show_bug.cgi?id=1274012 * https://bugzilla.suse.com/show_bug.cgi?id=1274014 * https://bugzilla.suse.com/show_bug.cgi?id=1274017 * https://bugzilla.suse.com/show_bug.cgi?id=1274019 * https://bugzilla.suse.com/show_bug.cgi?id=1274020 * https://bugzilla.suse.com/show_bug.cgi?id=1274026 * https://bugzilla.suse.com/show_bug.cgi?id=1274028 * https://bugzilla.suse.com/show_bug.cgi?id=1274030 * https://bugzilla.suse.com/show_bug.cgi?id=1274031 * https://bugzilla.suse.com/show_bug.cgi?id=1274035 * https://bugzilla.suse.com/show_bug.cgi?id=1274040 * https://bugzilla.suse.com/show_bug.cgi?id=1274041 * https://bugzilla.suse.com/show_bug.cgi?id=1274057 * https://bugzilla.suse.com/show_bug.cgi?id=1274058 * https://bugzilla.suse.com/show_bug.cgi?id=1274061 * https://bugzilla.suse.com/show_bug.cgi?id=1274063 * https://bugzilla.suse.com/show_bug.cgi?id=1274065 * https://bugzilla.suse.com/show_bug.cgi?id=1274067 * https://bugzilla.suse.com/show_bug.cgi?id=1274075 * https://bugzilla.suse.com/show_bug.cgi?id=1274076 * https://bugzilla.suse.com/show_bug.cgi?id=1274077 * https://bugzilla.suse.com/show_bug.cgi?id=1274078 * https://bugzilla.suse.com/show_bug.cgi?id=1274208 * https://bugzilla.suse.com/show_bug.cgi?id=1274226 * https://bugzilla.suse.com/show_bug.cgi?id=1274239 * https://bugzilla.suse.com/show_bug.cgi?id=1274243 * https://bugzilla.suse.com/show_bug.cgi?id=1274258 * https://bugzilla.suse.com/show_bug.cgi?id=1274265 * https://bugzilla.suse.com/show_bug.cgi?id=1274274 * https://bugzilla.suse.com/show_bug.cgi?id=1274277 * https://bugzilla.suse.com/show_bug.cgi?id=1274278 * https://bugzilla.suse.com/show_bug.cgi?id=1274281 * https://bugzilla.suse.com/show_bug.cgi?id=1274283 * https://bugzilla.suse.com/show_bug.cgi?id=1274286 * https://bugzilla.suse.com/show_bug.cgi?id=1274290 * https://bugzilla.suse.com/show_bug.cgi?id=1274294 * https://bugzilla.suse.com/show_bug.cgi?id=1274296 * https://bugzilla.suse.com/show_bug.cgi?id=1274297 * https://bugzilla.suse.com/show_bug.cgi?id=1274298 * https://bugzilla.suse.com/show_bug.cgi?id=1274314 * https://bugzilla.suse.com/show_bug.cgi?id=1274321 * https://bugzilla.suse.com/show_bug.cgi?id=1274491 * https://bugzilla.suse.com/show_bug.cgi?id=1274497 * https://bugzilla.suse.com/show_bug.cgi?id=1274539 * https://bugzilla.suse.com/show_bug.cgi?id=1274541 * https://bugzilla.suse.com/show_bug.cgi?id=1274543 * https://bugzilla.suse.com/show_bug.cgi?id=1274545 * https://bugzilla.suse.com/show_bug.cgi?id=1274547 * https://bugzilla.suse.com/show_bug.cgi?id=1274550 * https://bugzilla.suse.com/show_bug.cgi?id=1274573 * https://bugzilla.suse.com/show_bug.cgi?id=1274578 * https://bugzilla.suse.com/show_bug.cgi?id=1274580 * https://bugzilla.suse.com/show_bug.cgi?id=1274581 * https://bugzilla.suse.com/show_bug.cgi?id=1274620 * https://bugzilla.suse.com/show_bug.cgi?id=1274622 * https://bugzilla.suse.com/show_bug.cgi?id=1274624 * https://bugzilla.suse.com/show_bug.cgi?id=1274629 * https://bugzilla.suse.com/show_bug.cgi?id=1274632 * https://bugzilla.suse.com/show_bug.cgi?id=1274636 * https://bugzilla.suse.com/show_bug.cgi?id=1274639 * https://bugzilla.suse.com/show_bug.cgi?id=1274640 * https://bugzilla.suse.com/show_bug.cgi?id=1274642 * https://bugzilla.suse.com/show_bug.cgi?id=1274644 * https://bugzilla.suse.com/show_bug.cgi?id=1274645 * https://bugzilla.suse.com/show_bug.cgi?id=1274646 * https://bugzilla.suse.com/show_bug.cgi?id=1274649 * https://bugzilla.suse.com/show_bug.cgi?id=1274650 * https://bugzilla.suse.com/show_bug.cgi?id=1274651 * https://bugzilla.suse.com/show_bug.cgi?id=1274656 * https://bugzilla.suse.com/show_bug.cgi?id=1274659 * https://bugzilla.suse.com/show_bug.cgi?id=1274662 * https://bugzilla.suse.com/show_bug.cgi?id=1274663 * https://bugzilla.suse.com/show_bug.cgi?id=1274665 * https://bugzilla.suse.com/show_bug.cgi?id=1274667 * https://bugzilla.suse.com/show_bug.cgi?id=1274670 * https://bugzilla.suse.com/show_bug.cgi?id=1274675 * https://bugzilla.suse.com/show_bug.cgi?id=1274677 * https://bugzilla.suse.com/show_bug.cgi?id=1274678 * https://bugzilla.suse.com/show_bug.cgi?id=1274679 * https://bugzilla.suse.com/show_bug.cgi?id=1274681 * https://bugzilla.suse.com/show_bug.cgi?id=1274682 * https://bugzilla.suse.com/show_bug.cgi?id=1274690 * https://bugzilla.suse.com/show_bug.cgi?id=1274694 * https://bugzilla.suse.com/show_bug.cgi?id=1274696 * https://bugzilla.suse.com/show_bug.cgi?id=1274698 * https://bugzilla.suse.com/show_bug.cgi?id=1274699 * https://bugzilla.suse.com/show_bug.cgi?id=1274700 * https://bugzilla.suse.com/show_bug.cgi?id=1274702 * https://bugzilla.suse.com/show_bug.cgi?id=1274703 * https://bugzilla.suse.com/show_bug.cgi?id=1274705 * https://bugzilla.suse.com/show_bug.cgi?id=1274706 * https://bugzilla.suse.com/show_bug.cgi?id=1274709 * https://bugzilla.suse.com/show_bug.cgi?id=1274710 * https://bugzilla.suse.com/show_bug.cgi?id=1274713 * https://bugzilla.suse.com/show_bug.cgi?id=1274716 * https://bugzilla.suse.com/show_bug.cgi?id=1274721 * https://bugzilla.suse.com/show_bug.cgi?id=1274725 * https://bugzilla.suse.com/show_bug.cgi?id=1274737 * https://bugzilla.suse.com/show_bug.cgi?id=1274738 * https://bugzilla.suse.com/show_bug.cgi?id=1274749 * https://bugzilla.suse.com/show_bug.cgi?id=1274752 * https://bugzilla.suse.com/show_bug.cgi?id=1274753 * https://bugzilla.suse.com/show_bug.cgi?id=1274754 * https://bugzilla.suse.com/show_bug.cgi?id=1274755 * https://bugzilla.suse.com/show_bug.cgi?id=1274756 * https://bugzilla.suse.com/show_bug.cgi?id=1274764 * https://bugzilla.suse.com/show_bug.cgi?id=1274768 * https://bugzilla.suse.com/show_bug.cgi?id=1274770 * https://bugzilla.suse.com/show_bug.cgi?id=1274787 * https://bugzilla.suse.com/show_bug.cgi?id=1274800 * https://bugzilla.suse.com/show_bug.cgi?id=1274801 * https://bugzilla.suse.com/show_bug.cgi?id=1274802 * https://bugzilla.suse.com/show_bug.cgi?id=1274804 * https://bugzilla.suse.com/show_bug.cgi?id=1274805 * https://bugzilla.suse.com/show_bug.cgi?id=1274807 * https://bugzilla.suse.com/show_bug.cgi?id=1274808 * https://bugzilla.suse.com/show_bug.cgi?id=1274811 * https://bugzilla.suse.com/show_bug.cgi?id=1274813 * https://bugzilla.suse.com/show_bug.cgi?id=1274814 * https://bugzilla.suse.com/show_bug.cgi?id=1274831 * https://bugzilla.suse.com/show_bug.cgi?id=1274834 * https://bugzilla.suse.com/show_bug.cgi?id=1274847 * https://bugzilla.suse.com/show_bug.cgi?id=1274853 * https://bugzilla.suse.com/show_bug.cgi?id=1274868 * https://bugzilla.suse.com/show_bug.cgi?id=1274869 * https://bugzilla.suse.com/show_bug.cgi?id=1274872 * https://bugzilla.suse.com/show_bug.cgi?id=1274873 * https://bugzilla.suse.com/show_bug.cgi?id=1274874 * https://bugzilla.suse.com/show_bug.cgi?id=1274876 * https://bugzilla.suse.com/show_bug.cgi?id=1274879 * https://bugzilla.suse.com/show_bug.cgi?id=1274881 * https://bugzilla.suse.com/show_bug.cgi?id=1274883 * https://bugzilla.suse.com/show_bug.cgi?id=1274886 * https://bugzilla.suse.com/show_bug.cgi?id=1274888 * https://bugzilla.suse.com/show_bug.cgi?id=1274891 * https://bugzilla.suse.com/show_bug.cgi?id=1274892 * https://bugzilla.suse.com/show_bug.cgi?id=1274893 * https://bugzilla.suse.com/show_bug.cgi?id=1274894 * https://bugzilla.suse.com/show_bug.cgi?id=1274896 * https://bugzilla.suse.com/show_bug.cgi?id=1274897 * https://bugzilla.suse.com/show_bug.cgi?id=1274898 * https://bugzilla.suse.com/show_bug.cgi?id=1274899 * https://bugzilla.suse.com/show_bug.cgi?id=1274901 * https://bugzilla.suse.com/show_bug.cgi?id=1274902 * https://bugzilla.suse.com/show_bug.cgi?id=1274905 * https://bugzilla.suse.com/show_bug.cgi?id=1274907 * https://bugzilla.suse.com/show_bug.cgi?id=1274908 * https://bugzilla.suse.com/show_bug.cgi?id=1274913 * https://bugzilla.suse.com/show_bug.cgi?id=1274914 * https://bugzilla.suse.com/show_bug.cgi?id=1274920 * https://bugzilla.suse.com/show_bug.cgi?id=1274921 * https://bugzilla.suse.com/show_bug.cgi?id=1274924 * https://bugzilla.suse.com/show_bug.cgi?id=1274925 * https://bugzilla.suse.com/show_bug.cgi?id=1274929 * https://bugzilla.suse.com/show_bug.cgi?id=1274930 * https://bugzilla.suse.com/show_bug.cgi?id=1274933 * https://bugzilla.suse.com/show_bug.cgi?id=1274934 * https://bugzilla.suse.com/show_bug.cgi?id=1274935 * https://bugzilla.suse.com/show_bug.cgi?id=1274941 * https://bugzilla.suse.com/show_bug.cgi?id=1274945 * https://bugzilla.suse.com/show_bug.cgi?id=1274947 * https://bugzilla.suse.com/show_bug.cgi?id=1274951 * https://bugzilla.suse.com/show_bug.cgi?id=1274953 * https://bugzilla.suse.com/show_bug.cgi?id=1274958 * https://bugzilla.suse.com/show_bug.cgi?id=1274968 * https://bugzilla.suse.com/show_bug.cgi?id=1274981 * https://bugzilla.suse.com/show_bug.cgi?id=1275040 * https://bugzilla.suse.com/show_bug.cgi?id=1275069 * https://bugzilla.suse.com/show_bug.cgi?id=1275071 * https://bugzilla.suse.com/show_bug.cgi?id=1275073 * https://bugzilla.suse.com/show_bug.cgi?id=1275076 * https://bugzilla.suse.com/show_bug.cgi?id=1275080 * https://bugzilla.suse.com/show_bug.cgi?id=1275083 * https://bugzilla.suse.com/show_bug.cgi?id=1275088 * https://bugzilla.suse.com/show_bug.cgi?id=1275091 * https://bugzilla.suse.com/show_bug.cgi?id=1275125 * https://bugzilla.suse.com/show_bug.cgi?id=1275126 * https://bugzilla.suse.com/show_bug.cgi?id=1275131 * https://bugzilla.suse.com/show_bug.cgi?id=1275132 * https://bugzilla.suse.com/show_bug.cgi?id=1275150 * https://bugzilla.suse.com/show_bug.cgi?id=1275152 * https://bugzilla.suse.com/show_bug.cgi?id=1275154 * https://bugzilla.suse.com/show_bug.cgi?id=1275155 * https://bugzilla.suse.com/show_bug.cgi?id=1275157 * https://bugzilla.suse.com/show_bug.cgi?id=1275158 * https://bugzilla.suse.com/show_bug.cgi?id=1275161 * https://bugzilla.suse.com/show_bug.cgi?id=1275163 * https://bugzilla.suse.com/show_bug.cgi?id=1275164 * https://bugzilla.suse.com/show_bug.cgi?id=1275169 * https://bugzilla.suse.com/show_bug.cgi?id=1275173 * https://bugzilla.suse.com/show_bug.cgi?id=1275176 * https://bugzilla.suse.com/show_bug.cgi?id=1275185 * https://bugzilla.suse.com/show_bug.cgi?id=1275190 * https://bugzilla.suse.com/show_bug.cgi?id=1275236 * https://bugzilla.suse.com/show_bug.cgi?id=1275237 * https://bugzilla.suse.com/show_bug.cgi?id=1275239 * https://bugzilla.suse.com/show_bug.cgi?id=1275294 * https://bugzilla.suse.com/show_bug.cgi?id=1275301 * https://bugzilla.suse.com/show_bug.cgi?id=1275303 * https://bugzilla.suse.com/show_bug.cgi?id=1275304 * https://bugzilla.suse.com/show_bug.cgi?id=1275305 * https://bugzilla.suse.com/show_bug.cgi?id=1275306 * https://bugzilla.suse.com/show_bug.cgi?id=1275307 * https://bugzilla.suse.com/show_bug.cgi?id=1275470 * https://bugzilla.suse.com/show_bug.cgi?id=1275472 * https://bugzilla.suse.com/show_bug.cgi?id=1275474 * https://bugzilla.suse.com/show_bug.cgi?id=1275479 * https://bugzilla.suse.com/show_bug.cgi?id=1275483 * https://bugzilla.suse.com/show_bug.cgi?id=1275486 * https://bugzilla.suse.com/show_bug.cgi?id=1275487 * https://bugzilla.suse.com/show_bug.cgi?id=1275506 * https://bugzilla.suse.com/show_bug.cgi?id=1275509 * https://bugzilla.suse.com/show_bug.cgi?id=1275511 * https://bugzilla.suse.com/show_bug.cgi?id=1275517 * https://bugzilla.suse.com/show_bug.cgi?id=1275528 * https://bugzilla.suse.com/show_bug.cgi?id=1275535 * https://bugzilla.suse.com/show_bug.cgi?id=1275540 * https://bugzilla.suse.com/show_bug.cgi?id=1275553 * https://bugzilla.suse.com/show_bug.cgi?id=1275555 * https://bugzilla.suse.com/show_bug.cgi?id=1275561 * https://bugzilla.suse.com/show_bug.cgi?id=1275566 * https://bugzilla.suse.com/show_bug.cgi?id=1275569 * https://bugzilla.suse.com/show_bug.cgi?id=1275574 * https://bugzilla.suse.com/show_bug.cgi?id=1275578 * https://bugzilla.suse.com/show_bug.cgi?id=1275582 * https://bugzilla.suse.com/show_bug.cgi?id=1275583 * https://bugzilla.suse.com/show_bug.cgi?id=1275584 * https://bugzilla.suse.com/show_bug.cgi?id=1275591 * https://bugzilla.suse.com/show_bug.cgi?id=1275595 * https://bugzilla.suse.com/show_bug.cgi?id=1275633 * https://bugzilla.suse.com/show_bug.cgi?id=1275636 * https://bugzilla.suse.com/show_bug.cgi?id=1275650 * https://bugzilla.suse.com/show_bug.cgi?id=1275659 * https://bugzilla.suse.com/show_bug.cgi?id=1275665 * https://bugzilla.suse.com/show_bug.cgi?id=1275669 * https://bugzilla.suse.com/show_bug.cgi?id=1275687 * https://bugzilla.suse.com/show_bug.cgi?id=1275688 * https://bugzilla.suse.com/show_bug.cgi?id=1275695 * https://bugzilla.suse.com/show_bug.cgi?id=1275696 * https://bugzilla.suse.com/show_bug.cgi?id=1275704 * https://bugzilla.suse.com/show_bug.cgi?id=1275782 * https://bugzilla.suse.com/show_bug.cgi?id=1275784 * https://bugzilla.suse.com/show_bug.cgi?id=1275787 * https://bugzilla.suse.com/show_bug.cgi?id=1275788 * https://bugzilla.suse.com/show_bug.cgi?id=1275790 * https://bugzilla.suse.com/show_bug.cgi?id=1275797 * https://bugzilla.suse.com/show_bug.cgi?id=1275798 * https://bugzilla.suse.com/show_bug.cgi?id=1275805 * https://bugzilla.suse.com/show_bug.cgi?id=1275817 * https://bugzilla.suse.com/show_bug.cgi?id=1275818 * https://bugzilla.suse.com/show_bug.cgi?id=1275819 * https://bugzilla.suse.com/show_bug.cgi?id=1275820 * https://bugzilla.suse.com/show_bug.cgi?id=1275821 * https://bugzilla.suse.com/show_bug.cgi?id=1275827 * https://bugzilla.suse.com/show_bug.cgi?id=1275864 * https://bugzilla.suse.com/show_bug.cgi?id=1275867 * https://bugzilla.suse.com/show_bug.cgi?id=1275869 * https://bugzilla.suse.com/show_bug.cgi?id=1275870 * https://bugzilla.suse.com/show_bug.cgi?id=1275871 * https://bugzilla.suse.com/show_bug.cgi?id=1275872 * https://bugzilla.suse.com/show_bug.cgi?id=1275886 * https://bugzilla.suse.com/show_bug.cgi?id=1275905 * https://bugzilla.suse.com/show_bug.cgi?id=1275923 * https://bugzilla.suse.com/show_bug.cgi?id=1275925 * https://bugzilla.suse.com/show_bug.cgi?id=1275946 * https://bugzilla.suse.com/show_bug.cgi?id=1275950 * https://bugzilla.suse.com/show_bug.cgi?id=1275954 * https://bugzilla.suse.com/show_bug.cgi?id=1275970 * https://bugzilla.suse.com/show_bug.cgi?id=1275973 * https://bugzilla.suse.com/show_bug.cgi?id=1275975 * https://bugzilla.suse.com/show_bug.cgi?id=1275976 * https://bugzilla.suse.com/show_bug.cgi?id=1276029 * https://bugzilla.suse.com/show_bug.cgi?id=1276257 * https://bugzilla.suse.com/show_bug.cgi?id=1276263 * https://bugzilla.suse.com/show_bug.cgi?id=1276270 * https://bugzilla.suse.com/show_bug.cgi?id=1276273 * https://bugzilla.suse.com/show_bug.cgi?id=1276277 * https://bugzilla.suse.com/show_bug.cgi?id=1276335 * https://bugzilla.suse.com/show_bug.cgi?id=1276346 * https://bugzilla.suse.com/show_bug.cgi?id=1276350 * https://bugzilla.suse.com/show_bug.cgi?id=1276355 * https://bugzilla.suse.com/show_bug.cgi?id=1276446 * https://bugzilla.suse.com/show_bug.cgi?id=1276452 * https://bugzilla.suse.com/show_bug.cgi?id=1276500 * https://bugzilla.suse.com/show_bug.cgi?id=1276507 * https://bugzilla.suse.com/show_bug.cgi?id=1276542 * https://bugzilla.suse.com/show_bug.cgi?id=1276546 * https://bugzilla.suse.com/show_bug.cgi?id=1276551 * https://bugzilla.suse.com/show_bug.cgi?id=1276561 * https://bugzilla.suse.com/show_bug.cgi?id=1276569 * https://bugzilla.suse.com/show_bug.cgi?id=1276665 * https://bugzilla.suse.com/show_bug.cgi?id=1276864 * https://bugzilla.suse.com/show_bug.cgi?id=1276927 * https://bugzilla.suse.com/show_bug.cgi?id=1276931 * https://bugzilla.suse.com/show_bug.cgi?id=1276937 * https://bugzilla.suse.com/show_bug.cgi?id=1276941 * https://bugzilla.suse.com/show_bug.cgi?id=1276943 * https://bugzilla.suse.com/show_bug.cgi?id=1276961 * https://bugzilla.suse.com/show_bug.cgi?id=1277022 * https://bugzilla.suse.com/show_bug.cgi?id=1277034 * https://bugzilla.suse.com/show_bug.cgi?id=1277037 * https://bugzilla.suse.com/show_bug.cgi?id=1277047 * https://bugzilla.suse.com/show_bug.cgi?id=1277054 * https://bugzilla.suse.com/show_bug.cgi?id=1277057 * https://bugzilla.suse.com/show_bug.cgi?id=1277059 * https://bugzilla.suse.com/show_bug.cgi?id=1277064 * https://bugzilla.suse.com/show_bug.cgi?id=1277066 * https://bugzilla.suse.com/show_bug.cgi?id=1277069 * https://bugzilla.suse.com/show_bug.cgi?id=1277073 * https://bugzilla.suse.com/show_bug.cgi?id=1277077 * https://bugzilla.suse.com/show_bug.cgi?id=1277095 * https://bugzilla.suse.com/show_bug.cgi?id=1277155 * https://bugzilla.suse.com/show_bug.cgi?id=1277159 * https://bugzilla.suse.com/show_bug.cgi?id=1277160 * https://bugzilla.suse.com/show_bug.cgi?id=1277202 * https://bugzilla.suse.com/show_bug.cgi?id=1277204 * https://bugzilla.suse.com/show_bug.cgi?id=1277275 * https://bugzilla.suse.com/show_bug.cgi?id=1277285 * https://bugzilla.suse.com/show_bug.cgi?id=1277391 * https://bugzilla.suse.com/show_bug.cgi?id=1277408 * https://bugzilla.suse.com/show_bug.cgi?id=1277516 * https://bugzilla.suse.com/show_bug.cgi?id=1277523 * https://bugzilla.suse.com/show_bug.cgi?id=1277551 * https://bugzilla.suse.com/show_bug.cgi?id=1277625 * https://bugzilla.suse.com/show_bug.cgi?id=1277660 * https://bugzilla.suse.com/show_bug.cgi?id=1277678 * https://bugzilla.suse.com/show_bug.cgi?id=1277688 * https://bugzilla.suse.com/show_bug.cgi?id=1277775 * https://bugzilla.suse.com/show_bug.cgi?id=1277776 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 17:08:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 17:08:12 -0000 Subject: SUSE-SU-2026:23527-1: moderate: Security update for opensc Message-ID: <178914649205.7040.2256127516314927941@bab013902bd8> # Security update for opensc Announcement ID: SUSE-SU-2026:23527-1 Release Date: 2026-09-08T09:21:17Z Rating: moderate References: * bsc#1266964 Cross-References: * CVE-2026-40510 CVSS scores: * CVE-2026-40510 ( SUSE ): 4.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-40510 ( SUSE ): 5.7 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-40510 ( NVD ): 1.0 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40510 ( NVD ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-40510 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for opensc fixes the following issue: * CVE-2026-40510: stack buffer overflow in `piv_process_history()` allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device (bsc#1266964). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-715=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * opensc-debuginfo-0.24.0-slfo.1.1_5.1 * opensc-0.24.0-slfo.1.1_5.1 * opensc-debugsource-0.24.0-slfo.1.1_5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40510.html * https://bugzilla.suse.com/show_bug.cgi?id=1266964 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 17:08:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 17:08:58 -0000 Subject: SUSE-SU-2026:23526-1: moderate: Security update for multipath-tools Message-ID: <178914653840.7040.14535324762766936065@bab013902bd8> # Security update for multipath-tools Announcement ID: SUSE-SU-2026:23526-1 Release Date: 2026-09-08T09:21:17Z Rating: moderate References: * bsc#1277199 * bsc#1277203 * bsc#1277205 * bsc#1277208 * bsc#1277209 * bsc#1277210 * bsc#1277212 Affected Products: * SUSE Linux Micro 6.1 An update that has seven fixes can now be installed. ## Description: This update for multipath-tools fixes the following issues: * Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205). * Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210). * SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212). * Local Denial of Service via Blocking IPC Send Operations (bsc#1277199). * Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209). * DoS on multipathd socket by exhausting connections (bsc#1277203). * Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208). Changes for multipath-tools: * Update to version 0.10.8+212+suse.3dc4ecc. * Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-714=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libmpath0-debuginfo-0.10.8+212+suse.3dc4ecc-slfo.1.1_1.1 * multipath-tools-debugsource-0.10.8+212+suse.3dc4ecc-slfo.1.1_1.1 * multipath-tools-debuginfo-0.10.8+212+suse.3dc4ecc-slfo.1.1_1.1 * kpartx-0.10.8+212+suse.3dc4ecc-slfo.1.1_1.1 * multipath-tools-0.10.8+212+suse.3dc4ecc-slfo.1.1_1.1 * kpartx-debuginfo-0.10.8+212+suse.3dc4ecc-slfo.1.1_1.1 * libmpath0-0.10.8+212+suse.3dc4ecc-slfo.1.1_1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1277199 * https://bugzilla.suse.com/show_bug.cgi?id=1277203 * https://bugzilla.suse.com/show_bug.cgi?id=1277205 * https://bugzilla.suse.com/show_bug.cgi?id=1277208 * https://bugzilla.suse.com/show_bug.cgi?id=1277209 * https://bugzilla.suse.com/show_bug.cgi?id=1277210 * https://bugzilla.suse.com/show_bug.cgi?id=1277212 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 17:09:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 17:09:38 -0000 Subject: SUSE-SU-2026:23525-1: important: Security update for NetworkManager Message-ID: <178914657853.7040.188695545021230895@bab013902bd8> # Security update for NetworkManager Announcement ID: SUSE-SU-2026:23525-1 Release Date: 2026-09-08T09:21:17Z Rating: important References: * bsc#1267696 * bsc#1276764 Cross-References: * CVE-2026-10805 * CVE-2026-19685 CVSS scores: * CVE-2026-10805 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-10805 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19685 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-19685 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-19685 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19685 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for NetworkManager fixes the following issues: * CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). * CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-713=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * NetworkManager-debuginfo-1.42.6-slfo.1.1_5.1 * NetworkManager-bluetooth-1.42.6-slfo.1.1_5.1 * NetworkManager-cloud-setup-1.42.6-slfo.1.1_5.1 * NetworkManager-tui-1.42.6-slfo.1.1_5.1 * NetworkManager-wwan-debuginfo-1.42.6-slfo.1.1_5.1 * libnm0-1.42.6-slfo.1.1_5.1 * NetworkManager-pppoe-1.42.6-slfo.1.1_5.1 * NetworkManager-1.42.6-slfo.1.1_5.1 * NetworkManager-bluetooth-debuginfo-1.42.6-slfo.1.1_5.1 * NetworkManager-cloud-setup-debuginfo-1.42.6-slfo.1.1_5.1 * typelib-1_0-NM-1_0-1.42.6-slfo.1.1_5.1 * libnm0-debuginfo-1.42.6-slfo.1.1_5.1 * NetworkManager-tui-debuginfo-1.42.6-slfo.1.1_5.1 * NetworkManager-wwan-1.42.6-slfo.1.1_5.1 * NetworkManager-pppoe-debuginfo-1.42.6-slfo.1.1_5.1 * NetworkManager-debugsource-1.42.6-slfo.1.1_5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10805.html * https://www.suse.com/security/cve/CVE-2026-19685.html * https://bugzilla.suse.com/show_bug.cgi?id=1267696 * https://bugzilla.suse.com/show_bug.cgi?id=1276764 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 17:10:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 17:10:40 -0000 Subject: SUSE-SU-2026:23523-1: important: Security update for python-tornado6 Message-ID: <178914664052.7040.4156370453192457108@bab013902bd8> # Security update for python-tornado6 Announcement ID: SUSE-SU-2026:23523-1 Release Date: 2026-09-07T08:48:49Z Rating: important References: * bsc#1277725 Cross-References: * CVE-2026-82397 CVSS scores: * CVE-2026-82397 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-82397 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for python-tornado6 fixes the following issue: * CVE-2026-82397: an unauthenticated request body containing millions of separator-delimited fields can synchronously stall the single-threaded event loop and delay every connection (bsc#1277725). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-711=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * python311-tornado6-debuginfo-6.4-slfo.1.1_7.1 * python-tornado6-debugsource-6.4-slfo.1.1_7.1 * python311-tornado6-6.4-slfo.1.1_7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-82397.html * https://bugzilla.suse.com/show_bug.cgi?id=1277725 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 17:11:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 17:11:25 -0000 Subject: SUSE-SU-2026:23522-1: moderate: Security update for helm Message-ID: <178914668556.7040.8194441570035287864@bab013902bd8> # Security update for helm Announcement ID: SUSE-SU-2026:23522-1 Release Date: 2026-09-04T09:07:47Z Rating: moderate References: * bsc#1270127 * bsc#1271660 * bsc#1272402 * bsc#1276510 * bsc#1276514 * bsc#1277949 Cross-References: * CVE-2026-37236 * CVE-2026-41178 * CVE-2026-48978 * CVE-2026-50151 * CVE-2026-63308 CVSS scores: * CVE-2026-37236 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-37236 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-37236 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48978 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48978 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48978 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-50151 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-50151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-63308 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-63308 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-63308 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-63308 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for helm fixes the following issues: * CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST request through the X-HTTP-Method- Override header and bypass established access control (bsc#1277949). * CVE-2026-41178: go.opentelemetry.io/otel/baggage,go.opentelemetry.io/otel/propagation: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276510). * CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). * CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271660). * CVE-2026-63308: processing zero-length byte slices in template chart files can trigger an index out-of-range panic (bsc#1272402). * gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation (bsc#1276514). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-709=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * helm-3.21.3-slfo.1.1_2.1 * helm-debuginfo-3.21.3-slfo.1.1_2.1 * SUSE Linux Micro 6.1 (noarch) * helm-bash-completion-3.21.3-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-37236.html * https://www.suse.com/security/cve/CVE-2026-41178.html * https://www.suse.com/security/cve/CVE-2026-48978.html * https://www.suse.com/security/cve/CVE-2026-50151.html * https://www.suse.com/security/cve/CVE-2026-63308.html * https://bugzilla.suse.com/show_bug.cgi?id=1270127 * https://bugzilla.suse.com/show_bug.cgi?id=1271660 * https://bugzilla.suse.com/show_bug.cgi?id=1272402 * https://bugzilla.suse.com/show_bug.cgi?id=1276510 * https://bugzilla.suse.com/show_bug.cgi?id=1276514 * https://bugzilla.suse.com/show_bug.cgi?id=1277949 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 17:12:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 17:12:06 -0000 Subject: SUSE-SU-2026:23521-1: low: Security update for curl Message-ID: <178914672652.7040.7215188394568381374@bab013902bd8> # Security update for curl Announcement ID: SUSE-SU-2026:23521-1 Release Date: 2026-09-04T09:07:47Z Rating: low References: * bsc#1277476 * bsc#1277479 * bsc#1277480 Cross-References: * CVE-2026-13608 * CVE-2026-80229 * CVE-2026-80230 CVSS scores: * CVE-2026-13608 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-13608 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-13608 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-80229 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-80229 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-80229 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80230 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-80230 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-80230 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves three vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues: * CVE-2026-13608: flow in OpenLDAP SASL negotiation can cause an authentication bypass (bsc#1277476). * CVE-2026-80229: premature free can lead to OpenSSL provider use-after-free (bsc#1277479). * CVE-2026-80230: OpenSSL pinning bypass can allow unauthenticated connections to succeed (bsc#1277480). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-708=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libcurl4-debuginfo-8.14.1-slfo.1.1_10.1 * curl-debuginfo-8.14.1-slfo.1.1_10.1 * curl-debugsource-8.14.1-slfo.1.1_10.1 * curl-8.14.1-slfo.1.1_10.1 * libcurl4-8.14.1-slfo.1.1_10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13608.html * https://www.suse.com/security/cve/CVE-2026-80229.html * https://www.suse.com/security/cve/CVE-2026-80230.html * https://bugzilla.suse.com/show_bug.cgi?id=1277476 * https://bugzilla.suse.com/show_bug.cgi?id=1277479 * https://bugzilla.suse.com/show_bug.cgi?id=1277480 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 17:12:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 17:12:45 -0000 Subject: SUSE-SU-2026:23520-1: moderate: Security update for wget Message-ID: <178914676535.7040.17546098312004330718@bab013902bd8> # Security update for wget Announcement ID: SUSE-SU-2026:23520-1 Release Date: 2026-09-04T09:07:47Z Rating: moderate References: * bsc#1276962 Cross-References: * CVE-2026-16599 CVSS scores: * CVE-2026-16599 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-16599 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-16599 ( NVD ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for wget fixes the following issue: * CVE-2026-16599: server-controlled unbounded MD5 loop in FTP OPIE (bsc#1276962). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-707=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * wget-1.24.5-slfo.1.1_6.1 * wget-debuginfo-1.24.5-slfo.1.1_6.1 * wget-debugsource-1.24.5-slfo.1.1_6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16599.html * https://bugzilla.suse.com/show_bug.cgi?id=1276962 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 17:13:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 17:13:25 -0000 Subject: SUSE-SU-2026:23519-1: moderate: Security update for libusb-1_0 Message-ID: <178914680556.7040.2817838348720559581@bab013902bd8> # Security update for libusb-1_0 Announcement ID: SUSE-SU-2026:23519-1 Release Date: 2026-09-03T08:49:13Z Rating: moderate References: * bsc#1266664 * bsc#1266667 Cross-References: * CVE-2026-23679 * CVE-2026-47104 CVSS scores: * CVE-2026-23679 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23679 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23679 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23679 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23679 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-47104 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47104 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47104 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47104 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for libusb-1_0 fixes the following issues: * CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). * CVE-2026-47104: one-byte out-of-bounds read in `parse_iad_array()` allows attackers to trigger a denial of service via a malformed USB descriptor (bsc#1266667). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-705=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libusb-1_0-0-1.0.27-slfo.1.1_2.1 * libusb-1_0-0-debuginfo-1.0.27-slfo.1.1_2.1 * libusb-1_0-debugsource-1.0.27-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23679.html * https://www.suse.com/security/cve/CVE-2026-47104.html * https://bugzilla.suse.com/show_bug.cgi?id=1266664 * https://bugzilla.suse.com/show_bug.cgi?id=1266667 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 17:14:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 17:14:04 -0000 Subject: SUSE-SU-2026:23518-1: moderate: Security update for rpcbind Message-ID: <178914684433.7040.3673361233392629443@bab013902bd8> # Security update for rpcbind Announcement ID: SUSE-SU-2026:23518-1 Release Date: 2026-09-03T08:48:19Z Rating: moderate References: * bsc#1272340 Cross-References: * CVE-2026-16461 CVSS scores: * CVE-2026-16461 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-16461 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for rpcbind fixes the following issue: * CVE-2026-16461: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting (bsc#1272340). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-706=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * rpcbind-debuginfo-1.2.9-slfo.1.1_2.1 * rpcbind-debugsource-1.2.9-slfo.1.1_2.1 * rpcbind-1.2.9-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16461.html * https://bugzilla.suse.com/show_bug.cgi?id=1272340 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 17:15:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 17:15:38 -0000 Subject: SUSE-SU-2026:23515-1: important: Security update for libvirt Message-ID: <178914693897.7040.4021865329375155704@bab013902bd8> # Security update for libvirt Announcement ID: SUSE-SU-2026:23515-1 Release Date: 2026-09-02T09:21:08Z Rating: important References: * bsc#1274576 * bsc#1274946 * bsc#1275264 * bsc#1275265 * bsc#1275863 Cross-References: * CVE-2026-18917 * CVE-2026-61477 * CVE-2026-63622 * CVE-2026-63623 * CVE-2026-77159 CVSS scores: * CVE-2026-18917 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-18917 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-61477 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-61477 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61477 ( NVD ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-63622 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63622 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63622 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63623 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-63623 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-63623 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-77159 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-77159 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-77159 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for libvirt fixes the following issues: * CVE-2026-18917: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow (bsc#1275863). * CVE-2026-61477: newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection (bsc#1274576). * CVE-2026-63622: `swtpm` privilege escalation via symlink following (bsc#1275264). * CVE-2026-63623: information disclosure via world-readable storage volume images during clone/convert (bsc#1275265). * CVE-2026-77159: root `chown()` on `swtpm` logfile follows symlinks (bsc#1274946). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-700=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libvirt-daemon-lock-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-nwfilter-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-daemon-plugin-lockd-10.0.0-slfo.1.1_3.1 * libvirt-daemon-10.0.0-slfo.1.1_3.1 * libvirt-daemon-hooks-10.0.0-slfo.1.1_3.1 * libvirt-daemon-log-10.0.0-slfo.1.1_3.1 * libvirt-libs-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-nss-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-libs-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-nodedev-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-nss-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-secret-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-client-qemu-10.0.0-slfo.1.1_3.1 * libvirt-daemon-log-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-daemon-common-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-nodedev-10.0.0-slfo.1.1_3.1 * libvirt-daemon-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-debugsource-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-network-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-qemu-10.0.0-slfo.1.1_3.1 * libvirt-daemon-common-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-storage-core-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-storage-logical-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-client-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-daemon-config-network-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-storage-scsi-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-qemu-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-storage-logical-10.0.0-slfo.1.1_3.1 * libvirt-daemon-proxy-10.0.0-slfo.1.1_3.1 * libvirt-daemon-lock-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-storage-iscsi-direct-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-storage-mpath-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-daemon-proxy-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-storage-mpath-10.0.0-slfo.1.1_3.1 * libvirt-daemon-plugin-lockd-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-storage-core-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-storage-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-secret-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-storage-iscsi-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-storage-scsi-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-network-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-nwfilter-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-storage-disk-10.0.0-slfo.1.1_3.1 * libvirt-daemon-qemu-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-10.0.0-slfo.1.1_3.1 * libvirt-client-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-storage-disk-debuginfo-10.0.0-slfo.1.1_3.1 * SUSE Linux Micro 6.1 (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-10.0.0-slfo.1.1_3.1 * libvirt-daemon-driver-storage-rbd-debuginfo-10.0.0-slfo.1.1_3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-18917.html * https://www.suse.com/security/cve/CVE-2026-61477.html * https://www.suse.com/security/cve/CVE-2026-63622.html * https://www.suse.com/security/cve/CVE-2026-63623.html * https://www.suse.com/security/cve/CVE-2026-77159.html * https://bugzilla.suse.com/show_bug.cgi?id=1274576 * https://bugzilla.suse.com/show_bug.cgi?id=1274946 * https://bugzilla.suse.com/show_bug.cgi?id=1275264 * https://bugzilla.suse.com/show_bug.cgi?id=1275265 * https://bugzilla.suse.com/show_bug.cgi?id=1275863 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 17:16:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 17:16:16 -0000 Subject: SUSE-SU-2026:23514-1: important: Security update for libpng16 Message-ID: <178914697651.7040.9392216618438293194@bab013902bd8> # Security update for libpng16 Announcement ID: SUSE-SU-2026:23514-1 Release Date: 2026-09-02T09:15:54Z Rating: important References: * jsc#PED-16190 Cross-References: * CVE-2025-28162 * CVE-2025-64505 * CVE-2025-64506 * CVE-2025-64720 * CVE-2025-65018 * CVE-2025-66293 * CVE-2026-22695 * CVE-2026-22801 * CVE-2026-25646 * CVE-2026-33416 * CVE-2026-33636 * CVE-2026-34757 CVSS scores: * CVE-2025-28162 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-28162 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2025-28162 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-64505 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-64505 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2025-64505 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2025-64506 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-64506 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2025-64506 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2025-64720 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-64720 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2025-64720 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2025-65018 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-65018 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2025-65018 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2025-66293 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-66293 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2025-66293 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-22695 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-22695 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-22695 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-22695 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-22801 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-22801 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-22801 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-22801 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-25646 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-25646 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-25646 ( NVD ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25646 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-25646 ( NVD ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-33416 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-33416 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-33416 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-33636 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-33636 ( SUSE ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-33636 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-34757 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-34757 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34757 ( NVD ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-34757 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves 12 vulnerabilities and contains one feature can now be installed. ## Description: This update for libpng16 fixes the following issues: Changes for libpng16: * Version update to 1.6.58 (jsc#PED-16190). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-702=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libpng16-debugsource-1.6.58-slfo.1.1_1.1 * libpng16-16-debuginfo-1.6.58-slfo.1.1_1.1 * libpng16-16-1.6.58-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-28162.html * https://www.suse.com/security/cve/CVE-2025-64505.html * https://www.suse.com/security/cve/CVE-2025-64506.html * https://www.suse.com/security/cve/CVE-2025-64720.html * https://www.suse.com/security/cve/CVE-2025-65018.html * https://www.suse.com/security/cve/CVE-2025-66293.html * https://www.suse.com/security/cve/CVE-2026-22695.html * https://www.suse.com/security/cve/CVE-2026-22801.html * https://www.suse.com/security/cve/CVE-2026-25646.html * https://www.suse.com/security/cve/CVE-2026-33416.html * https://www.suse.com/security/cve/CVE-2026-33636.html * https://www.suse.com/security/cve/CVE-2026-34757.html * https://jira.suse.com/browse/PED-16190 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 17:16:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 17:16:56 -0000 Subject: SUSE-SU-2026:23513-1: important: Security update for dracut Message-ID: <178914701664.7040.5187327264739036417@bab013902bd8> # Security update for dracut Announcement ID: SUSE-SU-2026:23513-1 Release Date: 2026-09-02T09:14:10Z Rating: important References: * bsc#1268322 * bsc#1273580 Cross-References: * CVE-2026-16445 * CVE-2026-6893 CVSS scores: * CVE-2026-16445 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16445 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for dracut fixes the following issues: * CVE-2026-6893: Root code execution via DHCP options command injection (bsc#1268322). * CVE-2026-16445: Root code execution via DHCP options command injection in NetworkManager initrd module (bsc#1273580). Changes for dracut: * Update to version 059+suse.649.g0274006: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset * fix(network-manager): ensure safe content of /tmp/dhclient."$ifname".dhcpopts ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-703=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * dracut-debugsource-059+suse.649.g0274006-slfo.1.1_1.1 * dracut-fips-059+suse.649.g0274006-slfo.1.1_1.1 * dracut-debuginfo-059+suse.649.g0274006-slfo.1.1_1.1 * dracut-059+suse.649.g0274006-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16445.html * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 * https://bugzilla.suse.com/show_bug.cgi?id=1273580 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 17:17:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 17:17:41 -0000 Subject: SUSE-SU-2026:23512-1: important: Security update for openssl-3 Message-ID: <178914706195.7040.3249234854250060481@bab013902bd8> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:23512-1 Release Date: 2026-09-02T09:11:40Z Rating: important References: * bsc#1274774 * bsc#1274788 * bsc#1274790 * bsc#1274795 * bsc#1274797 * bsc#1275837 Cross-References: * CVE-2026-54874 * CVE-2026-63072 * CVE-2026-63074 * CVE-2026-63076 * CVE-2026-75803 CVSS scores: * CVE-2026-54874 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-54874 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63074 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63074 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-75803 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-75803 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities and has one fix can now be installed. ## Description: This update for openssl-3 fixes the following issues: August 2026 release. * CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). * CVE-2026-54874: excessive memory use when buffering DTLS records for a future epoch (bsc#1274795). * CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). * CVE-2026-63074: unbounded growth of `extraCerts` cache in the CMP server (bsc#1274797). * CVE-2026-63076: invalid pointer dereference in the CMP server via crafted `protectionAlg` (bsc#1274790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-701=1 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libopenssl-3-fips-provider-debuginfo-3.1.4-slfo.1.1_13.1 * openssl-3-debuginfo-3.1.4-slfo.1.1_13.1 * libopenssl3-debuginfo-3.1.4-slfo.1.1_13.1 * openssl-3-3.1.4-slfo.1.1_13.1 * libopenssl3-3.1.4-slfo.1.1_13.1 * libopenssl-3-devel-3.1.4-slfo.1.1_13.1 * libopenssl-3-fips-provider-3.1.4-slfo.1.1_13.1 * openssl-3-debugsource-3.1.4-slfo.1.1_13.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54874.html * https://www.suse.com/security/cve/CVE-2026-63072.html * https://www.suse.com/security/cve/CVE-2026-63074.html * https://www.suse.com/security/cve/CVE-2026-63076.html * https://www.suse.com/security/cve/CVE-2026-75803.html * https://bugzilla.suse.com/show_bug.cgi?id=1274774 * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1274790 * https://bugzilla.suse.com/show_bug.cgi?id=1274795 * https://bugzilla.suse.com/show_bug.cgi?id=1274797 * https://bugzilla.suse.com/show_bug.cgi?id=1275837 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 17:31:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 17:31:38 -0000 Subject: SUSE-SU-2026:23510-1: important: Security update for the Linux Kernel Message-ID: <178914789866.7040.7451343553319531175@bab013902bd8> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:23510-1 Release Date: 2026-09-08T13:00:49Z Rating: important References: * bsc#1230238 * bsc#1235944 * bsc#1247455 * bsc#1250748 * bsc#1251966 * bsc#1252682 * bsc#1254306 * bsc#1255225 * bsc#1255250 * bsc#1256629 * bsc#1256708 * bsc#1257154 * bsc#1258430 * bsc#1258517 * bsc#1260522 * bsc#1261780 * bsc#1261788 * bsc#1262073 * bsc#1263004 * bsc#1263061 * bsc#1263133 * bsc#1264335 * bsc#1264446 * bsc#1264541 * bsc#1264584 * bsc#1264587 * bsc#1264619 * bsc#1264788 * bsc#1265068 * bsc#1265121 * bsc#1265449 * bsc#1265928 * bsc#1266402 * bsc#1266860 * bsc#1266874 * bsc#1266897 * bsc#1267023 * bsc#1267238 * bsc#1267501 * bsc#1267612 * bsc#1268276 * bsc#1268972 * bsc#1268979 * bsc#1268987 * bsc#1269004 * bsc#1269013 * bsc#1269108 * bsc#1269113 * bsc#1269114 * bsc#1269126 * bsc#1269167 * bsc#1269234 * bsc#1269238 * bsc#1269242 * bsc#1269256 * bsc#1269301 * bsc#1269306 * bsc#1269381 * bsc#1269388 * bsc#1269412 * bsc#1269530 * bsc#1269579 * bsc#1269590 * bsc#1269635 * bsc#1269655 * bsc#1269665 * bsc#1269686 * bsc#1269695 * bsc#1269713 * bsc#1269731 * bsc#1269774 * bsc#1269783 * bsc#1269792 * bsc#1269815 * bsc#1269965 * bsc#1269969 * bsc#1269981 * bsc#1269985 * bsc#1270090 * bsc#1270108 * bsc#1270111 * bsc#1270251 * bsc#1271256 * bsc#1271365 * bsc#1271366 * bsc#1271825 * bsc#1271830 * bsc#1272150 * bsc#1272175 * bsc#1272179 * bsc#1272182 * bsc#1272200 * bsc#1272210 * bsc#1272213 * bsc#1272230 * bsc#1272260 * bsc#1272261 * bsc#1272262 * bsc#1272297 * bsc#1272346 * bsc#1272381 * bsc#1272385 * bsc#1272390 * bsc#1272423 * bsc#1272429 * bsc#1272484 * bsc#1272486 * bsc#1272497 * bsc#1272516 * bsc#1272569 * bsc#1272571 * bsc#1272641 * bsc#1272643 * bsc#1272662 * bsc#1272673 * bsc#1272680 * bsc#1272682 * bsc#1272756 * bsc#1272786 * bsc#1272788 * bsc#1272798 * bsc#1272799 * bsc#1272868 * bsc#1272877 * bsc#1272891 * bsc#1272963 * bsc#1272983 * bsc#1273008 * bsc#1273019 * bsc#1273027 * bsc#1273028 * bsc#1273030 * bsc#1273038 * bsc#1273053 * bsc#1273054 * bsc#1273060 * bsc#1273105 * bsc#1273249 * bsc#1273250 * bsc#1273260 * bsc#1273273 * bsc#1273274 * bsc#1273276 * bsc#1273281 * bsc#1273284 * bsc#1273285 * bsc#1273289 * bsc#1273291 * bsc#1273294 * bsc#1273302 * bsc#1273303 * bsc#1273305 * bsc#1273310 * bsc#1273311 * bsc#1273316 * bsc#1273318 * bsc#1273319 * bsc#1273323 * bsc#1273325 * bsc#1273327 * bsc#1273334 * bsc#1273335 * bsc#1273336 * bsc#1273337 * bsc#1273338 * bsc#1273340 * bsc#1273341 * bsc#1273346 * bsc#1273422 * bsc#1273426 * bsc#1273443 * bsc#1273463 * bsc#1273468 * bsc#1273469 * bsc#1273471 * bsc#1273479 * bsc#1273480 * bsc#1273482 * bsc#1273484 * bsc#1273488 * bsc#1273490 * bsc#1273501 * bsc#1273503 * bsc#1273504 * bsc#1273506 * bsc#1273523 * bsc#1273525 * bsc#1273533 * bsc#1273536 * bsc#1273542 * bsc#1273555 * bsc#1273578 * bsc#1273579 * bsc#1273582 * bsc#1273596 * bsc#1273597 * bsc#1273598 * bsc#1273600 * bsc#1273601 * bsc#1273602 * bsc#1273603 * bsc#1273682 * bsc#1273734 * bsc#1273738 * bsc#1273739 * bsc#1273741 * bsc#1273742 * bsc#1273743 * bsc#1273745 * bsc#1273748 * bsc#1273749 * bsc#1273755 * bsc#1273762 * bsc#1273765 * bsc#1273766 * bsc#1273769 * bsc#1273774 * bsc#1273778 * bsc#1273780 * bsc#1273790 * bsc#1273796 * bsc#1273804 * bsc#1273810 * bsc#1273811 * bsc#1273813 * bsc#1273817 * bsc#1273822 * bsc#1273824 * bsc#1273831 * bsc#1273832 * bsc#1273834 * bsc#1273838 * bsc#1273844 * bsc#1273849 * bsc#1273860 * bsc#1273862 * bsc#1273867 * bsc#1273868 * bsc#1273869 * bsc#1273872 * bsc#1273876 * bsc#1273877 * bsc#1273880 * bsc#1273882 * bsc#1273890 * bsc#1273891 * bsc#1273892 * bsc#1273895 * bsc#1273896 * bsc#1273903 * bsc#1273905 * bsc#1273930 * bsc#1273933 * bsc#1273934 * bsc#1273935 * bsc#1273936 * bsc#1273939 * bsc#1273940 * bsc#1273941 * bsc#1273942 * bsc#1273944 * bsc#1273945 * bsc#1273946 * bsc#1273956 * bsc#1273957 * bsc#1273958 * bsc#1273966 * bsc#1273967 * bsc#1273968 * bsc#1273972 * bsc#1273974 * bsc#1273975 * bsc#1273977 * bsc#1273982 * bsc#1273988 * bsc#1273990 * bsc#1273991 * bsc#1273995 * bsc#1274001 * bsc#1274003 * bsc#1274006 * bsc#1274011 * bsc#1274012 * bsc#1274014 * bsc#1274017 * bsc#1274019 * bsc#1274020 * bsc#1274026 * bsc#1274028 * bsc#1274030 * bsc#1274031 * bsc#1274035 * bsc#1274040 * bsc#1274041 * bsc#1274057 * bsc#1274058 * bsc#1274061 * bsc#1274063 * bsc#1274065 * bsc#1274067 * bsc#1274075 * bsc#1274076 * bsc#1274077 * bsc#1274078 * bsc#1274208 * bsc#1274226 * bsc#1274239 * bsc#1274243 * bsc#1274258 * bsc#1274265 * bsc#1274274 * bsc#1274277 * bsc#1274278 * bsc#1274281 * bsc#1274283 * bsc#1274286 * bsc#1274290 * bsc#1274294 * bsc#1274296 * bsc#1274297 * bsc#1274298 * bsc#1274314 * bsc#1274321 * bsc#1274491 * bsc#1274497 * bsc#1274539 * bsc#1274541 * bsc#1274543 * bsc#1274545 * bsc#1274547 * bsc#1274550 * bsc#1274573 * bsc#1274578 * bsc#1274580 * bsc#1274581 * bsc#1274620 * bsc#1274622 * bsc#1274624 * bsc#1274629 * bsc#1274632 * bsc#1274636 * bsc#1274639 * bsc#1274640 * bsc#1274642 * bsc#1274644 * bsc#1274645 * bsc#1274646 * bsc#1274649 * bsc#1274650 * bsc#1274651 * bsc#1274656 * bsc#1274659 * bsc#1274662 * bsc#1274663 * bsc#1274665 * bsc#1274667 * bsc#1274670 * bsc#1274675 * bsc#1274677 * bsc#1274678 * bsc#1274679 * bsc#1274681 * bsc#1274682 * bsc#1274690 * bsc#1274694 * bsc#1274696 * bsc#1274698 * bsc#1274699 * bsc#1274700 * bsc#1274702 * bsc#1274703 * bsc#1274705 * bsc#1274706 * bsc#1274709 * bsc#1274710 * bsc#1274713 * bsc#1274716 * bsc#1274721 * bsc#1274725 * bsc#1274737 * bsc#1274738 * bsc#1274749 * bsc#1274752 * bsc#1274753 * bsc#1274754 * bsc#1274755 * bsc#1274756 * bsc#1274764 * bsc#1274768 * bsc#1274770 * bsc#1274787 * bsc#1274800 * bsc#1274801 * bsc#1274802 * bsc#1274804 * bsc#1274805 * bsc#1274807 * bsc#1274808 * bsc#1274811 * bsc#1274813 * bsc#1274814 * bsc#1274831 * bsc#1274834 * bsc#1274847 * bsc#1274853 * bsc#1274868 * bsc#1274869 * bsc#1274872 * bsc#1274873 * bsc#1274874 * bsc#1274876 * bsc#1274879 * bsc#1274881 * bsc#1274883 * bsc#1274886 * bsc#1274888 * bsc#1274891 * bsc#1274892 * bsc#1274893 * bsc#1274894 * bsc#1274896 * bsc#1274897 * bsc#1274898 * bsc#1274899 * bsc#1274901 * bsc#1274902 * bsc#1274905 * bsc#1274907 * bsc#1274908 * bsc#1274913 * bsc#1274914 * bsc#1274920 * bsc#1274921 * bsc#1274924 * bsc#1274925 * bsc#1274929 * bsc#1274930 * bsc#1274933 * bsc#1274934 * bsc#1274935 * bsc#1274941 * bsc#1274945 * bsc#1274947 * bsc#1274951 * bsc#1274953 * bsc#1274958 * bsc#1274968 * bsc#1274981 * bsc#1275040 * bsc#1275069 * bsc#1275071 * bsc#1275073 * bsc#1275076 * bsc#1275080 * bsc#1275083 * bsc#1275088 * bsc#1275091 * bsc#1275125 * bsc#1275126 * bsc#1275131 * bsc#1275132 * bsc#1275150 * bsc#1275152 * bsc#1275154 * bsc#1275155 * bsc#1275157 * bsc#1275158 * bsc#1275161 * bsc#1275163 * bsc#1275164 * bsc#1275169 * bsc#1275173 * bsc#1275176 * bsc#1275185 * bsc#1275190 * bsc#1275236 * bsc#1275237 * bsc#1275239 * bsc#1275294 * bsc#1275301 * bsc#1275303 * bsc#1275304 * bsc#1275305 * bsc#1275306 * bsc#1275307 * bsc#1275470 * bsc#1275472 * bsc#1275474 * bsc#1275479 * bsc#1275483 * bsc#1275486 * bsc#1275487 * bsc#1275506 * bsc#1275509 * bsc#1275511 * bsc#1275517 * bsc#1275528 * bsc#1275535 * bsc#1275540 * bsc#1275553 * bsc#1275555 * bsc#1275561 * bsc#1275566 * bsc#1275569 * bsc#1275574 * bsc#1275578 * bsc#1275582 * bsc#1275583 * bsc#1275584 * bsc#1275591 * bsc#1275595 * bsc#1275633 * bsc#1275636 * bsc#1275650 * bsc#1275659 * bsc#1275665 * bsc#1275669 * bsc#1275687 * bsc#1275688 * bsc#1275695 * bsc#1275696 * bsc#1275704 * bsc#1275782 * bsc#1275784 * bsc#1275787 * bsc#1275788 * bsc#1275790 * bsc#1275797 * bsc#1275798 * bsc#1275805 * bsc#1275817 * bsc#1275818 * bsc#1275819 * bsc#1275820 * bsc#1275821 * bsc#1275827 * bsc#1275864 * bsc#1275867 * bsc#1275869 * bsc#1275870 * bsc#1275871 * bsc#1275872 * bsc#1275886 * bsc#1275905 * bsc#1275923 * bsc#1275925 * bsc#1275946 * bsc#1275950 * bsc#1275954 * bsc#1275970 * bsc#1275973 * bsc#1275975 * bsc#1275976 * bsc#1276029 * bsc#1276257 * bsc#1276263 * bsc#1276270 * bsc#1276273 * bsc#1276277 * bsc#1276335 * bsc#1276346 * bsc#1276350 * bsc#1276355 * bsc#1276446 * bsc#1276452 * bsc#1276500 * bsc#1276507 * bsc#1276542 * bsc#1276546 * bsc#1276551 * bsc#1276561 * bsc#1276569 * bsc#1276665 * bsc#1276864 * bsc#1276927 * bsc#1276931 * bsc#1276937 * bsc#1276941 * bsc#1276943 * bsc#1276961 * bsc#1277022 * bsc#1277034 * bsc#1277037 * bsc#1277047 * bsc#1277054 * bsc#1277057 * bsc#1277059 * bsc#1277064 * bsc#1277066 * bsc#1277069 * bsc#1277073 * bsc#1277077 * bsc#1277095 * bsc#1277155 * bsc#1277159 * bsc#1277160 * bsc#1277202 * bsc#1277204 * bsc#1277275 * bsc#1277285 * bsc#1277391 * bsc#1277408 * bsc#1277516 * bsc#1277523 * bsc#1277551 * bsc#1277625 * bsc#1277660 * bsc#1277678 * bsc#1277688 * bsc#1277775 * bsc#1277776 Cross-References: * CVE-2024-44981 * CVE-2024-57841 * CVE-2025-38469 * CVE-2025-39964 * CVE-2025-40022 * CVE-2025-68179 * CVE-2025-68214 * CVE-2025-71075 * CVE-2025-71104 * CVE-2026-23210 * CVE-2026-23230 * CVE-2026-23454 * CVE-2026-31392 * CVE-2026-31418 * CVE-2026-31531 * CVE-2026-31557 * CVE-2026-31663 * CVE-2026-43116 * CVE-2026-43125 * CVE-2026-43163 * CVE-2026-43271 * CVE-2026-43273 * CVE-2026-43278 * CVE-2026-43319 * CVE-2026-43363 * CVE-2026-43416 * CVE-2026-45897 * CVE-2026-45968 * CVE-2026-46070 * CVE-2026-46091 * CVE-2026-46107 * CVE-2026-46115 * CVE-2026-46195 * CVE-2026-52920 * CVE-2026-52925 * CVE-2026-52929 * CVE-2026-52935 * CVE-2026-52939 * CVE-2026-52946 * CVE-2026-52975 * CVE-2026-52977 * CVE-2026-52990 * CVE-2026-52994 * CVE-2026-53001 * CVE-2026-53033 * CVE-2026-53059 * CVE-2026-53076 * CVE-2026-53077 * CVE-2026-53089 * CVE-2026-53091 * CVE-2026-53094 * CVE-2026-53096 * CVE-2026-53110 * CVE-2026-53111 * CVE-2026-53126 * CVE-2026-53154 * CVE-2026-53163 * CVE-2026-53207 * CVE-2026-53219 * CVE-2026-53220 * CVE-2026-53223 * CVE-2026-53228 * CVE-2026-53238 * CVE-2026-53260 * CVE-2026-53264 * CVE-2026-53269 * CVE-2026-53273 * CVE-2026-53309 * CVE-2026-53330 * CVE-2026-53336 * CVE-2026-53337 * CVE-2026-53353 * CVE-2026-53365 * CVE-2026-53366 * CVE-2026-53381 * CVE-2026-53388 * CVE-2026-63801 * CVE-2026-63808 * CVE-2026-63810 * CVE-2026-63823 * CVE-2026-63827 * CVE-2026-63828 * CVE-2026-63860 * CVE-2026-63865 * CVE-2026-63868 * CVE-2026-63879 * CVE-2026-63881 * CVE-2026-63886 * CVE-2026-63887 * CVE-2026-63888 * CVE-2026-63889 * CVE-2026-63891 * CVE-2026-63898 * CVE-2026-63920 * CVE-2026-63925 * CVE-2026-63926 * CVE-2026-63928 * CVE-2026-63944 * CVE-2026-63969 * CVE-2026-63970 * CVE-2026-63972 * CVE-2026-63973 * CVE-2026-63980 * CVE-2026-63985 * CVE-2026-63990 * CVE-2026-63992 * CVE-2026-63999 * CVE-2026-64000 * CVE-2026-64001 * CVE-2026-64002 * CVE-2026-64004 * CVE-2026-64005 * CVE-2026-64006 * CVE-2026-64007 * CVE-2026-64010 * CVE-2026-64011 * CVE-2026-64014 * CVE-2026-64015 * CVE-2026-64018 * CVE-2026-64029 * CVE-2026-64034 * CVE-2026-64039 * CVE-2026-64047 * CVE-2026-64048 * CVE-2026-64051 * CVE-2026-64052 * CVE-2026-64073 * CVE-2026-64083 * CVE-2026-64084 * CVE-2026-64085 * CVE-2026-64086 * CVE-2026-64087 * CVE-2026-64088 * CVE-2026-64097 * CVE-2026-64098 * CVE-2026-64102 * CVE-2026-64109 * CVE-2026-64112 * CVE-2026-64113 * CVE-2026-64114 * CVE-2026-64115 * CVE-2026-64118 * CVE-2026-64121 * CVE-2026-64125 * CVE-2026-64126 * CVE-2026-64128 * CVE-2026-64131 * CVE-2026-64133 * CVE-2026-64135 * CVE-2026-64137 * CVE-2026-64148 * CVE-2026-64155 * CVE-2026-64164 * CVE-2026-64166 * CVE-2026-64168 * CVE-2026-64178 * CVE-2026-64185 * CVE-2026-64188 * CVE-2026-64190 * CVE-2026-64192 * CVE-2026-64214 * CVE-2026-64217 * CVE-2026-64218 * CVE-2026-64219 * CVE-2026-64222 * CVE-2026-64225 * CVE-2026-64237 * CVE-2026-64243 * CVE-2026-64245 * CVE-2026-64246 * CVE-2026-64247 * CVE-2026-64249 * CVE-2026-64257 * CVE-2026-64266 * CVE-2026-64268 * CVE-2026-64271 * CVE-2026-64273 * CVE-2026-64274 * CVE-2026-64275 * CVE-2026-64276 * CVE-2026-64277 * CVE-2026-64286 * CVE-2026-64287 * CVE-2026-64294 * CVE-2026-64296 * CVE-2026-64303 * CVE-2026-64304 * CVE-2026-64305 * CVE-2026-64306 * CVE-2026-64312 * CVE-2026-64313 * CVE-2026-64315 * CVE-2026-64316 * CVE-2026-64317 * CVE-2026-64322 * CVE-2026-64323 * CVE-2026-64329 * CVE-2026-64331 * CVE-2026-64332 * CVE-2026-64333 * CVE-2026-64334 * CVE-2026-64335 * CVE-2026-64337 * CVE-2026-64338 * CVE-2026-64340 * CVE-2026-64341 * CVE-2026-64342 * CVE-2026-64343 * CVE-2026-64344 * CVE-2026-64346 * CVE-2026-64348 * CVE-2026-64350 * CVE-2026-64351 * CVE-2026-64355 * CVE-2026-64358 * CVE-2026-64362 * CVE-2026-64365 * CVE-2026-64375 * CVE-2026-64376 * CVE-2026-64378 * CVE-2026-64381 * CVE-2026-64382 * CVE-2026-64383 * CVE-2026-64384 * CVE-2026-64385 * CVE-2026-64386 * CVE-2026-64387 * CVE-2026-64388 * CVE-2026-64401 * CVE-2026-64403 * CVE-2026-64406 * CVE-2026-64408 * CVE-2026-64409 * CVE-2026-64411 * CVE-2026-64412 * CVE-2026-64420 * CVE-2026-64421 * CVE-2026-64423 * CVE-2026-64427 * CVE-2026-64429 * CVE-2026-64433 * CVE-2026-64434 * CVE-2026-64436 * CVE-2026-64440 * CVE-2026-64442 * CVE-2026-64443 * CVE-2026-64444 * CVE-2026-64445 * CVE-2026-64448 * CVE-2026-64450 * CVE-2026-64454 * CVE-2026-64455 * CVE-2026-64463 * CVE-2026-64470 * CVE-2026-64471 * CVE-2026-64472 * CVE-2026-64478 * CVE-2026-64479 * CVE-2026-64480 * CVE-2026-64481 * CVE-2026-64482 * CVE-2026-64483 * CVE-2026-64484 * CVE-2026-64486 * CVE-2026-64487 * CVE-2026-64489 * CVE-2026-64494 * CVE-2026-64495 * CVE-2026-64496 * CVE-2026-64497 * CVE-2026-64500 * CVE-2026-64503 * CVE-2026-64504 * CVE-2026-64505 * CVE-2026-64511 * CVE-2026-64512 * CVE-2026-64513 * CVE-2026-64524 * CVE-2026-64527 * CVE-2026-64536 * CVE-2026-64537 * CVE-2026-64538 * CVE-2026-64539 * CVE-2026-64540 * CVE-2026-64541 * CVE-2026-64543 * CVE-2026-64544 * CVE-2026-64545 * CVE-2026-64546 * CVE-2026-64547 * CVE-2026-64548 * CVE-2026-64549 * CVE-2026-64551 * CVE-2026-64552 * CVE-2026-64553 * CVE-2026-64554 * CVE-2026-64562 * CVE-2026-64563 * CVE-2026-64565 * CVE-2026-64567 * CVE-2026-64571 * CVE-2026-64572 * CVE-2026-64573 * CVE-2026-64574 * CVE-2026-64576 * CVE-2026-64577 * CVE-2026-64581 * CVE-2026-64582 * CVE-2026-64583 * CVE-2026-64584 * CVE-2026-64585 * CVE-2026-64593 * CVE-2026-64597 * CVE-2026-64598 * CVE-2026-64599 * CVE-2026-64602 * CVE-2026-64604 * CVE-2026-68081 * CVE-2026-68082 * CVE-2026-68085 * CVE-2026-68086 * CVE-2026-68088 * CVE-2026-68091 * CVE-2026-68093 * CVE-2026-68102 * CVE-2026-68104 * CVE-2026-68106 * CVE-2026-68107 * CVE-2026-68108 * CVE-2026-68110 * CVE-2026-68111 * CVE-2026-68112 * CVE-2026-68115 * CVE-2026-68116 * CVE-2026-68117 * CVE-2026-68121 * CVE-2026-68123 * CVE-2026-68125 * CVE-2026-68126 * CVE-2026-68127 * CVE-2026-68129 * CVE-2026-68132 * CVE-2026-68133 * CVE-2026-68136 * CVE-2026-68137 * CVE-2026-68138 * CVE-2026-68139 * CVE-2026-68142 * CVE-2026-68143 * CVE-2026-68145 * CVE-2026-68149 * CVE-2026-68153 * CVE-2026-68154 * CVE-2026-68155 * CVE-2026-68156 * CVE-2026-68157 * CVE-2026-68158 * CVE-2026-68159 * CVE-2026-68160 * CVE-2026-68161 * CVE-2026-68162 * CVE-2026-68166 * CVE-2026-68180 * CVE-2026-68181 * CVE-2026-68182 * CVE-2026-68184 * CVE-2026-68188 * CVE-2026-68189 * CVE-2026-68192 * CVE-2026-68193 * CVE-2026-68194 * CVE-2026-68195 * CVE-2026-68196 * CVE-2026-68197 * CVE-2026-68199 * CVE-2026-68202 * CVE-2026-68204 * CVE-2026-68205 * CVE-2026-68206 * CVE-2026-68207 * CVE-2026-68209 * CVE-2026-68210 * CVE-2026-68212 * CVE-2026-68213 * CVE-2026-68214 * CVE-2026-68215 * CVE-2026-68216 * CVE-2026-68217 * CVE-2026-68218 * CVE-2026-68219 * CVE-2026-68220 * CVE-2026-68222 * CVE-2026-68223 * CVE-2026-68226 * CVE-2026-68227 * CVE-2026-68229 * CVE-2026-68231 * CVE-2026-68234 * CVE-2026-68236 * CVE-2026-68238 * CVE-2026-68243 * CVE-2026-68244 * CVE-2026-68246 * CVE-2026-68247 * CVE-2026-68248 * CVE-2026-68249 * CVE-2026-68250 * CVE-2026-68251 * CVE-2026-68254 * CVE-2026-68255 * CVE-2026-68256 * CVE-2026-68259 * CVE-2026-68269 * CVE-2026-68271 * CVE-2026-68272 * CVE-2026-68277 * CVE-2026-68278 * CVE-2026-68279 * CVE-2026-68280 * CVE-2026-68284 * CVE-2026-68286 * CVE-2026-68288 * CVE-2026-68289 * CVE-2026-68293 * CVE-2026-68297 * CVE-2026-68299 * CVE-2026-68300 * CVE-2026-68303 * CVE-2026-68304 * CVE-2026-68306 * CVE-2026-68308 * CVE-2026-68309 * CVE-2026-68310 * CVE-2026-68312 * CVE-2026-68313 * CVE-2026-68315 * CVE-2026-68320 * CVE-2026-68322 * CVE-2026-68324 * CVE-2026-68325 * CVE-2026-68326 * CVE-2026-68327 * CVE-2026-68328 * CVE-2026-68329 * CVE-2026-68331 * CVE-2026-68333 * CVE-2026-68335 * CVE-2026-68336 * CVE-2026-68339 * CVE-2026-68340 * CVE-2026-68343 * CVE-2026-68346 * CVE-2026-68348 * CVE-2026-68349 * CVE-2026-68350 * CVE-2026-68351 * CVE-2026-68352 * CVE-2026-68353 * CVE-2026-68354 * CVE-2026-68355 * CVE-2026-68357 * CVE-2026-68359 * CVE-2026-68360 * CVE-2026-68361 * CVE-2026-68362 * CVE-2026-68363 * CVE-2026-68365 * CVE-2026-68366 * CVE-2026-68368 * CVE-2026-68369 * CVE-2026-68370 * CVE-2026-68372 * CVE-2026-68373 * CVE-2026-68377 * CVE-2026-68386 * CVE-2026-68391 * CVE-2026-68392 * CVE-2026-68397 * CVE-2026-68398 * CVE-2026-68399 * CVE-2026-68402 * CVE-2026-68403 * CVE-2026-68405 * CVE-2026-68406 * CVE-2026-68407 * CVE-2026-68408 * CVE-2026-68410 * CVE-2026-68413 * CVE-2026-68414 * CVE-2026-68417 * CVE-2026-68418 * CVE-2026-68419 * CVE-2026-68422 * CVE-2026-68425 * CVE-2026-68426 * CVE-2026-68427 * CVE-2026-68428 * CVE-2026-68429 * CVE-2026-68430 * CVE-2026-68432 * CVE-2026-68433 * CVE-2026-68434 * CVE-2026-68444 * CVE-2026-68445 * CVE-2026-68446 * CVE-2026-68450 * CVE-2026-68470 * CVE-2026-68480 * CVE-2026-72020 * CVE-2026-72035 * CVE-2026-72036 * CVE-2026-72069 * CVE-2026-72072 * CVE-2026-72083 * CVE-2026-72084 * CVE-2026-72123 * CVE-2026-72132 * CVE-2026-72221 * CVE-2026-72222 * CVE-2026-72251 * CVE-2026-72254 * CVE-2026-72262 * CVE-2026-72288 * CVE-2026-72289 * CVE-2026-72296 * CVE-2026-72307 * CVE-2026-72308 * CVE-2026-72317 * CVE-2026-72341 * CVE-2026-72342 * CVE-2026-72343 * CVE-2026-72389 * CVE-2026-72463 * CVE-2026-72464 * CVE-2026-72466 * CVE-2026-72467 * CVE-2026-72469 * CVE-2026-72473 * CVE-2026-72494 * CVE-2026-72495 * CVE-2026-72496 * CVE-2026-72499 * CVE-2026-72501 * CVE-2026-72502 * CVE-2026-74269 * CVE-2026-74296 * CVE-2026-74297 * CVE-2026-74318 * CVE-2026-74321 * CVE-2026-74334 * CVE-2026-74345 * CVE-2026-74394 * CVE-2026-74395 * CVE-2026-74454 * CVE-2026-74474 * CVE-2026-74481 * CVE-2026-74482 * CVE-2026-74488 * CVE-2026-74495 * CVE-2026-74496 * CVE-2026-74509 * CVE-2026-74510 * CVE-2026-74512 * CVE-2026-74516 * CVE-2026-74518 * CVE-2026-74527 * CVE-2026-74537 * CVE-2026-74548 * CVE-2026-74550 * CVE-2026-74556 * CVE-2026-74563 * CVE-2026-74566 * CVE-2026-74567 * CVE-2026-74571 * CVE-2026-74581 * CVE-2026-74582 * CVE-2026-74584 * CVE-2026-74610 * CVE-2026-74669 * CVE-2026-74692 * CVE-2026-74694 * CVE-2026-74695 * CVE-2026-74717 * CVE-2026-74722 * CVE-2026-80529 * CVE-2026-80534 * CVE-2026-80590 * CVE-2026-80654 CVSS scores: * CVE-2024-44981 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L * CVE-2024-44981 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2024-44981 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-57841 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-38469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39964 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-39964 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-39964 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-39964 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40022 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-40022 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-68179 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68179 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68214 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71104 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2025-71104 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-71104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23210 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23230 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23230 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23230 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23230 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-23454 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23454 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23454 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31392 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-31392 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-31392 ( NVD ): 8.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:L * CVE-2026-31418 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31418 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31531 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31557 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31663 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31663 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43116 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43125 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43163 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43271 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43271 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43271 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43278 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43319 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43319 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45897 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45897 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45897 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46070 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46070 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46091 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46091 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46091 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46107 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46107 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46107 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46115 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46115 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46195 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46195 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52920 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-52920 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-52925 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52925 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52925 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52939 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52939 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52977 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52977 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52990 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53033 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53059 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53059 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53059 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53076 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53076 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53077 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53077 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53077 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53089 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53089 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53091 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53091 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53091 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53091 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-53094 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53094 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53096 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53096 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53110 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53111 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53111 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53111 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53207 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53228 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53228 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53238 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53238 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53269 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53269 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53269 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53309 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53309 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53309 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53330 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53330 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53336 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53336 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53353 ( SUSE ): 0.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53353 ( SUSE ): 0.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N * CVE-2026-53353 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53365 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53365 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53365 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53381 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63801 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63801 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63801 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63808 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63808 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-63808 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63810 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63810 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63823 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63823 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63823 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63827 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63828 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63828 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63828 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-63860 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63860 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63860 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63865 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63865 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63865 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-63868 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63868 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63879 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63879 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63879 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63881 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63886 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63886 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63886 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63887 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63887 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63887 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63888 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63888 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63888 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63889 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63889 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63889 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63891 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63891 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63898 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63898 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63920 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63920 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63920 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63925 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63925 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63925 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-63926 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63926 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63926 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63928 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63928 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63944 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63944 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63969 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63969 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63970 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63970 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63972 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63972 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63972 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63973 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63973 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63980 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63985 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63985 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63985 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63990 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63990 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63992 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63992 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63992 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63999 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63999 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64000 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64000 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64000 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64001 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64001 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64002 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64002 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64002 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64004 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64004 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64005 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64005 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64005 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64006 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-64006 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-64007 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64007 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64007 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64010 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64011 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64014 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64014 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64015 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64015 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64018 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-64018 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-64018 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64029 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64029 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64029 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64034 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64039 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64039 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64039 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64047 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64047 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64048 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64048 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64048 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64051 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64051 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64051 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64052 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64052 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64052 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64073 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64073 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64073 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64083 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64083 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64083 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64084 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64084 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64084 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64085 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64085 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64085 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64086 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64086 ( SUSE ): 5.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64086 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64087 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64087 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64087 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64088 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64088 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64088 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64097 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64097 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64097 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64098 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64102 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-64102 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-64102 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64113 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64113 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64114 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64115 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64118 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64118 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64118 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64121 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64121 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64121 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64125 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64126 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64126 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L * CVE-2026-64126 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-64128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64128 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64135 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64137 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64137 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64137 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64148 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64148 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64148 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64155 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64164 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64166 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64178 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64178 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64185 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64185 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64188 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64188 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64188 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64190 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64190 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64190 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64217 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64217 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64217 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64218 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64219 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64222 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64222 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64222 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64225 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64225 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64225 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64237 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64237 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64245 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64246 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64246 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64246 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64247 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64247 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-64249 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64249 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64257 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64257 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-64257 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64266 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64266 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64268 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64271 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64271 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64271 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64273 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64275 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64275 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64277 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64286 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64286 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64287 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64303 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64303 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64303 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64304 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64305 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64305 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64306 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64313 ( SUSE ): 7.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-64313 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64313 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64315 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64316 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64316 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64317 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64317 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64317 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64322 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64322 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64322 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64323 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64323 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64329 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64329 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64329 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64331 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64331 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64333 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64333 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64334 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64334 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64334 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64335 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64335 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64335 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64337 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64337 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64338 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64340 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64340 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64340 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64341 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64342 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64343 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64344 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64346 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64348 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64348 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64348 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64350 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64350 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64350 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64351 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64351 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64351 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64355 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64355 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64358 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64358 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64365 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64375 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64375 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64376 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64376 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64376 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64381 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64381 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64382 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64382 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64383 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64383 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64384 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64385 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64386 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64387 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64388 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64388 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-64388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64401 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64401 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64403 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64403 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64403 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64406 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64408 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64409 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64409 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64411 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64411 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64411 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64412 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64412 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64412 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64420 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64421 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64421 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64427 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64427 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64434 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64436 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64436 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64440 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64440 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64440 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64442 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64442 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64443 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64443 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64444 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64444 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64444 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64445 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64448 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64448 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64450 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64454 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64471 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64478 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64478 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64479 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64480 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64481 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64481 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64482 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64482 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64483 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64484 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64484 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64486 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64487 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64489 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64497 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64500 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64503 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64504 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64505 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64511 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64511 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64512 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64513 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64527 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64537 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64537 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64538 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64540 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64540 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64540 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64541 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64541 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64541 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64544 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64544 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64545 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64547 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64547 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64547 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64548 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64548 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64549 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64551 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64551 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64552 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64552 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64552 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64553 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64562 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64562 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64563 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64563 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64565 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64565 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64567 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64567 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64567 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64571 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64571 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64572 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64572 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64573 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64573 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64574 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64576 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64576 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64576 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64577 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64577 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64577 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64581 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64581 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64581 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64582 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64583 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64583 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64584 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64585 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64593 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64593 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64598 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64598 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64599 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64599 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64602 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64604 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68081 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68081 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68082 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68082 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68082 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68085 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68085 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68085 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68086 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-68086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-68088 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68088 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68091 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68091 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68091 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68093 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-68093 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68102 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68102 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68104 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68106 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68106 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68106 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68107 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68107 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68107 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68108 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68108 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68108 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68110 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68110 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68111 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68111 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68115 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68115 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68116 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68116 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-68116 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68117 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68117 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68121 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68121 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68123 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68123 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68123 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68125 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68125 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68125 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68126 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68126 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68127 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68127 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68127 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68129 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68129 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68129 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68132 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68132 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68133 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68133 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68136 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68136 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68137 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68139 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68139 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68142 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68142 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-68142 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68143 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68143 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68143 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68145 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68145 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68145 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68149 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68149 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68149 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-68153 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68153 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68153 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68154 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68154 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68154 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68155 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68155 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68155 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68156 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68156 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68156 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68157 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68157 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68157 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68158 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68158 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68158 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68159 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68159 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68159 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68160 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68160 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68160 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68161 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68161 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68161 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68162 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68166 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68166 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68180 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68182 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68184 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68184 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68188 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68192 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68192 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68197 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68202 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68204 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68207 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68210 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68210 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68212 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68217 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68218 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68218 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68219 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68219 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68220 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68220 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68222 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68223 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68223 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68226 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68226 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68227 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68227 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68229 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68229 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-68229 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68231 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68231 ( SUSE ): 2.1 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68234 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68236 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68236 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68236 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68238 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68238 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68243 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68244 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68246 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68246 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68247 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68247 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68248 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68249 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68250 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68250 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68251 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68251 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68256 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68259 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68259 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68269 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68271 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68272 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68278 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68278 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68279 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68279 ( SUSE ): 2.4 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68280 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68280 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68284 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68284 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68286 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68286 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68288 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68288 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68289 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68293 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68293 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68299 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68308 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68309 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68310 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68312 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68313 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-68322 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68324 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68325 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68327 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68327 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68328 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68333 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68343 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68349 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68350 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68351 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68353 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68353 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68354 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68355 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68357 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68359 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68360 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68361 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68365 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68365 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-68366 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68368 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68369 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68370 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68372 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68377 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68377 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68386 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68391 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68391 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68392 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68392 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68402 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68402 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68403 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68405 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68406 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68407 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68408 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68410 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68413 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68414 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68414 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68422 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68425 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68425 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68426 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68426 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68427 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68427 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68427 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68428 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68430 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68430 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68433 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-68434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68444 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68445 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68445 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68445 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68446 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68446 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68470 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68470 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68470 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68480 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-72020 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72020 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72020 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72035 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72036 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72069 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72083 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72084 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72123 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72132 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72132 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72221 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72221 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72221 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72222 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72251 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72251 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72251 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72254 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72262 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72262 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72288 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72289 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72289 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72289 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72296 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72296 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72296 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-72307 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72307 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72308 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72308 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72317 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72317 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72317 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72341 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72342 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72342 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72343 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72343 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72389 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72463 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72463 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72464 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72464 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72467 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72473 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-72473 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72494 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72495 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72496 ( NVD ): 9.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H * CVE-2026-72499 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72499 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72501 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74269 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74269 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74318 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74345 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74345 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74345 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74394 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74395 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74395 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74454 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74454 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-74454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74474 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74474 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74481 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74482 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74482 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74488 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74488 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74495 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74495 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74509 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74509 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74516 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-74516 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74518 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74518 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74527 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-74527 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74537 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74537 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74550 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74550 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74556 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-74556 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74563 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74566 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-74567 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74567 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74571 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74581 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74581 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74582 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74584 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-74584 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-74584 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-74610 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-74610 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74610 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74692 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74694 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74694 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74695 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74695 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74717 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74717 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74722 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80534 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80534 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80590 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-80654 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80654 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 * SUSE Linux Micro Extras 6.1 An update that solves 588 vulnerabilities and has 23 fixes can now be installed. ## Description: The SUSE Linux Enterprise Micro 6.0 and Micro 6.1 kernel was updated to fix various security issues: The following security issues were fixed: * CVE-2024-57841: net: fix memory leak in tcp_conn_request() (bsc#1269731). * CVE-2025-68214: timers: Fix NULL function pointer race in timer_shutdown_sync() (bsc#1255225). * CVE-2025-71075: scsi: aic94xx: fix use-after-free in device removal path (bsc#1256629). * CVE-2026-31392: smb: client: fix krb5 mount with username option (bsc#1261788). * CVE-2026-31418: netfilter: ipset: drop logically empty buckets in mtype_del (bsc#1262073). * CVE-2026-31531: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() (bsc#1263004). * CVE-2026-31557: nvmet: move async event work off nvmet-wq (bsc#1263061). * CVE-2026-31663: xfrm: hold device only for the asynchronous decryption (bsc#1263133). * CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack (bsc#1264619). * CVE-2026-43125: dlm: validate length in dlm_search_rsb_tree (bsc#1264541). * CVE-2026-43163: md/bitmap: fix GPF in write_page caused by resize race (bsc#1264335). * CVE-2026-43271: md-cluster: fix NULL pointer dereference in process_metadata_update (bsc#1264587). * CVE-2026-43273: ceph: supply snapshot context in ceph_zero_partial_object() (bsc#1264446). * CVE-2026-43278: dm: clear cloned request bio pointer when last clone bio completes (bsc#1264584). * CVE-2026-43319: spi: spidev: fix lock inversion between spi_lock and buf_lock (bsc#1264788). * CVE-2026-43363: x86/apic: Disable x2apic on resume if the kernel expects so (bsc#1265068). * CVE-2026-43416: powerpc, perf: Check that current->mm is alive before getting user callchain (bsc#1265121). * CVE-2026-45897: bpf: Fix UAF in sock clone early bailouts (bsc#1266897). * CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). * CVE-2026-46070: md/raid5: validate payload size before accessing journal metadata (bsc#1267501). * CVE-2026-46091: media: rc: igorplugusb: heed coherency rules (bsc#1267238). * CVE-2026-46107: dm-thin: fix metadata refcount underflow (bsc#1267612). * CVE-2026-46115: block: add pgmap check to biovec_phys_mergeable (bsc#1266874). * CVE-2026-46195: smb: client: validate dacloffset before building DACL pointers (bsc#1266860). * CVE-2026-52920: netfilter: xt_policy: fix strict mode inbound policy matching (bsc#1269013). * CVE-2026-52925: vrf: Fix a potential NPD when removing a port from a VRF (bsc#1268987). * CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). * CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send (bsc#1268979). * CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion (bsc#1268972). * CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (bsc#1269113). * CVE-2026-52975: bonding: 802.3ad replace MAC_ADDRESS_EQUAL with __agg_has_partner (bsc#1269234). * CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). * CVE-2026-52990: fsnotify: fix inode reference leak in fsnotify_recalc_mask() (bsc#1269108). * CVE-2026-52994: vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting (bsc#1269126). * CVE-2026-53001: netfilter: xtables: restrict several matches to inet family (bsc#1269114). * CVE-2026-53033: bpf, sockmap: Take state lock for af_unix iter (bsc#1269388). * CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). * CVE-2026-53076: bpf: Fix OOB in pcpu_init_value (bsc#1269695). * CVE-2026-53077: net/rds: Restrict use of RDS/IB to the initial network namespace (bsc#1269412). * CVE-2026-53089: bpf: Fix use-after-free in offloaded map/prog info fill (bsc#1269783). * CVE-2026-53091: net: account for encap headers in qdisc pkt len (bsc#1269530). * CVE-2026-53094: bpf: Fix stale offload->prog pointer after constant blinding (bsc#1269965). * CVE-2026-53096: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (bsc#1269969). * CVE-2026-53110: selftests/bpf: Add ASSERT_OK_FD macro (bsc#1269985). * CVE-2026-53111: bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap (bsc#1269167). * CVE-2026-53126: blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() (bsc#1269635). * CVE-2026-53154: mm/hugetlb: restore reservation on error in hugetlb folio copy paths (bsc#1269665). * CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). * CVE-2026-53207: mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison (bsc#1269590). * CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers (bsc#1269686). * CVE-2026-53220: netfilter: revalidate bridge ports (bsc#1269381). * CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs (bsc#1269301). * CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads (bsc#1269256). * CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths (bsc#1269774). * CVE-2026-53260: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req() (bsc#1269731) * CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). * CVE-2026-53269: netfilter: synproxy: add mutex to guard hook reference counting (bsc#1269579). * CVE-2026-53273: tee: optee: prevent use-after-free when the client exits before the supplicant (bsc#1269713). * CVE-2026-53309: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (bsc#1269815). * CVE-2026-53330: drm/amd/display: Fix out-of-bounds read in (bsc#1270090). * CVE-2026-53336: nvmem: layouts: onie-tlv: fix hang on unknown types (bsc#1270108). * CVE-2026-53337: net: bonding: fix NULL pointer dereference in bond_do_ioctl() (bsc#1270251). * CVE-2026-53353: hsr: Remove WARN_ONCE() in hsr_addr_is_self() (bsc#1270111). * CVE-2026-53365: vsock/virtio: fix zerocopy completion for multi-skb sends (bsc#1271365). * CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). * CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). * CVE-2026-63808: exfat: fix potential use-after-free in exfat_find_dir_entry() (bsc#1272260). * CVE-2026-63810: block: Avoid mounting the bdev pseudo-filesystem in userspace (bsc#1272297). * CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). * CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179). * CVE-2026-63828: apparmor: mediate the implicit connect of TCP fast open sendmsg (bsc#1272175). * CVE-2026-63860: RDMA/core: Prefer NLA_NUL_STRING (bsc#1272429). * CVE-2026-63865: bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (bsc#1272486). * CVE-2026-63868: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (bsc#1272497). * CVE-2026-63879: drm/amdgpu: fix amdgpu_hmm_range_get_pages (bsc#1272569). * CVE-2026-63881: drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger (bsc#1272571). * CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). * CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). * CVE-2026-63889: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (bsc#1272423). * CVE-2026-63891: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (bsc#1272641). * CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). * CVE-2026-63925: macsec: fix replay protection at XPN lower-PN wrap (bsc#1273008). * CVE-2026-63926: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (bsc#1273019). * CVE-2026-63944: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (bsc#1272662). * CVE-2026-63969: ipv6: fix possible infinite loop in rt6_fill_node() (bsc#1272484). * CVE-2026-63970: vsock/virtio: bind uarg before filling zerocopy skb (bsc#1272673). * CVE-2026-63980: net/handshake: Use spin_lock_bh for hn_lock (bsc#1273028). * CVE-2026-63985: ethtool: eeprom: add more safeties to EEPROM Netlink fallback (bsc#1272963). * CVE-2026-63990: bonding: refuse to enslave CAN devices (bsc#1273027). * CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). * CVE-2026-63999: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure (bsc#1273038). * CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273030). * CVE-2026-64001: ALSA: pcm: oss: Fix setup list UAF on proc write error (bsc#1273734). * CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). * CVE-2026-64004: net/iucv: fix locking in .getsockopt (bsc#1273804). * CVE-2026-64005: net/smc: Do not re-initialize smc hashtables (bsc#1273831). * CVE-2026-64006: netfilter: nf_tables: fix dst corruption in same register operation (bsc#1273834). * CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). * CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882). * CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891). * CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762). * CVE-2026-64029: ALSA: seq: Serialize UMP output teardown with event_input (bsc#1273766). * CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). * CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). * CVE-2026-64052: block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() (bsc#1272983). * CVE-2026-64073: irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT (bsc#1273490). * CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488). * CVE-2026-64102: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (bsc#1272516). * CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748). * CVE-2026-64112: rbd: eliminate a race in lock_dwork draining on unmap (bsc#1273741). * CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning (bsc#1272262). * CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). * CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). * CVE-2026-64118: qed: fix double free in qed_cxt_tables_alloc() (bsc#1273749). * CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273743). * CVE-2026-64125: net: bcmgenet: keep RBUF EEE/PM disabled (bsc#1272346). * CVE-2026-64131: mm/memory: fix spurious warning when unmapping device- private/exclusive pages (bsc#1274063). * CVE-2026-64148: pds_core: check health in devcmd wait (bsc#1273956). * CVE-2026-64164: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (bsc#1273957). * CVE-2026-64185: sysfs: don't remove existing directory on update failure (bsc#1272200). * CVE-2026-64188: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (bsc#1272150). * CVE-2026-64190: net: team: fix NULL pointer dereference in team_xmit during mode change (bsc#1272210). * CVE-2026-64192: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (bsc#1272213). * CVE-2026-64214: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() (bsc#1272799). * CVE-2026-64217: netfs: Fix overrun check in netfs_extract_user_iter() (bsc#1272798). * CVE-2026-64222: octeontx2-pf: avoid double free of pool->stack on AQ init failure (bsc#1272788). * CVE-2026-64225: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (bsc#1272786). * CVE-2026-64245: fbdev: modedb: fix a possible UAF in fb_find_mode() (bsc#1273905). * CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). * CVE-2026-64286: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (bsc#1274058). * CVE-2026-64287: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (bsc#1273325). * CVE-2026-64294: mm: do file ownership checks with the proper mount idmap (bsc#1273525). * CVE-2026-64296: exfat: bound uniname advance in exfat_find_dir_entry() (bsc#1273975). * CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944). * CVE-2026-64312: crypto: pcrypt - restore callback for non-parallel fallback (bsc#1273968). * CVE-2026-64315: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1274028). * CVE-2026-64316: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1273598). * CVE-2026-64317: isofs: bound Rock Ridge symlink components to the SL record (bsc#1273936). * CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count (bsc#1273958). * CVE-2026-64323: udf: validate VAT header length against the VAT inode size (bsc#1273305). * CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). * CVE-2026-64375: proc: protect ptrace_may_access() with exec_update_lock (FD links) (bsc#1273868). * CVE-2026-64378: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() (bsc#1273603). * CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard() (bsc#1273860). * CVE-2026-64382: smb: client: fix double-free in SMB2_open() replay (bsc#1273291). * CVE-2026-64383: smb: client: fix double-free in SMB2_flush() replay (bsc#1273426). * CVE-2026-64384: smb: client: fix change notify replay double-free (bsc#1274541). * CVE-2026-64385: smb: client: fix double-free in SMB2_ioctl() replay (bsc#1274539). * CVE-2026-64386: smb: client: fix query_info() replay double-free (bsc#1274543). * CVE-2026-64387: smb: client: fix query directory replay double-free (bsc#1274545). * CVE-2026-64388: smb/client: fix chown/chgrp with SMB3 POSIX Extensions (bsc#1274061). * CVE-2026-64411: netfilter: ebtables: terminate table name before find_table_lock() (bsc#1274077). * CVE-2026-64412: netfilter: ebtables: module names must be null-terminated (bsc#1273780). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). * CVE-2026-64434: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (bsc#1273880). * CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states (bsc#1274277). * CVE-2026-64448: smb: client: restrict implied bcc[0] exemption to responses without data area (bsc#1273982). * CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). * CVE-2026-64463: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres (bsc#1273273). * CVE-2026-64472: vfio/mlx5: Fix racy bitfields and tighten struct layout (bsc#1274075). * CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547). * CVE-2026-64537: bridge: cfm: reject invalid CCM interval at configuration time (bsc#1273289). * CVE-2026-64538: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change() (bsc#1273335). * CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). * CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). * CVE-2026-64545: net, bpf: check master for NULL in xdp_master_redirect() (bsc#1273318). * CVE-2026-64548: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (bsc#1273337). * CVE-2026-64551: sctp: validate STALE_COOKIE cause length before reading staleness (bsc#1273813). * CVE-2026-64552: virtio-net: fix len check in receive_big() (bsc#1273323). * CVE-2026-64553: net: psample: fix info leak in PSAMPLE_ATTR_DATA (bsc#1273336). * CVE-2026-64554: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (bsc#1273340). * CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930). * CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). * CVE-2026-64567: btrfs: reject free space cache with more entries than pages (bsc#1274006). * CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). * CVE-2026-64576: nexthop: initialize extack in nh_res_bucket_migrate() (bsc#1274030). * CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031). * CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). * CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (bsc#1274040). * CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497). * CVE-2026-64597: smb: client: fix double-free in SMB2_close() replay (bsc#1274297). * CVE-2026-64598: smb/client: Fix error code in smb2_aead_req_alloc() (bsc#1274298). * CVE-2026-68081: KVM: nVMX: Add helper to put (unmap) vmcs12 pages (bsc#1274580). * CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers() (bsc#1274581). * CVE-2026-68086: mm/khugepaged: write all dirty file folios when collapsing (bsc#1274713). * CVE-2026-68116: vxlan: mdb: Fix source list corruption on a failed replace (bsc#1274876). * CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (bsc#1274881). * CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). * CVE-2026-68123: openvswitch: fix GSO userspace truncation underflow (bsc#1275169). * CVE-2026-68127: ila: reload IPv6 header after pskb_may_pull in checksum adjust (bsc#1275237). * CVE-2026-68129: gve: fix Rx queue stall on alloc failure (bsc#1275517). * CVE-2026-68132: super: fix emergency thaw deadlock on frozen block devices (bsc#1275553). * CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). * CVE-2026-68139: net/mlx5e: Use sender devcom for MPV master-up (bsc#1275578). * CVE-2026-68142: geneve: require CAP_NET_ADMIN in the device netns for changelink (bsc#1275582). * CVE-2026-68143: net: slip: serialize receive against buffer reallocation (bsc#1275583). * CVE-2026-68145: iomap: fix out-of-bounds bitmap_set() with zero-length range (bsc#1275584). * CVE-2026-68149: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (bsc#1275294). * CVE-2026-68153: libceph: remove debugfs files before client teardown (bsc#1275301). * CVE-2026-68154: libceph: reject zero bucket types in crush_decode (bsc#1275303). * CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). * CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after authorizer update (bsc#1275305). * CVE-2026-68157: libceph: guard missing CRUSH type name lookup (bsc#1275306). * CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). * CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). * CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472). * CVE-2026-68161: sctp: close UDP tunnel sockets during netns teardown (bsc#1274892). * CVE-2026-68166: userfaultfd: prevent registration of special VMAs (bsc#1274930). * CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). * CVE-2026-68205: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (bsc#1274934). * CVE-2026-68238: drm/amdgpu: Release VFCT ACPI table reference (bsc#1275704). * CVE-2026-68247: drm/i915/bios: range check LFP Data Block panel_type2 (bsc#1275817). * CVE-2026-68254: drm/i915/vrr: require valid min/max vfreq for VRR (bsc#1275150). * CVE-2026-68284: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (bsc#1275970). * CVE-2026-68286: drop_monitor: perform u64_stats updates under IRQ-disabled section (bsc#1275973). * CVE-2026-68288: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (bsc#1275975). * CVE-2026-68289: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (bsc#1275976). * CVE-2026-68293: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (bsc#1275091). * CVE-2026-68297: tipc: fix u16 MTU truncation in media and bearer MTU validation (bsc#1275040). * CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (bsc#1275088). * CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL (bsc#1275083). * CVE-2026-68312: cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths (bsc#1274663). * CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit (bsc#1274665). * CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq() (bsc#1274662). * CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (bsc#1274659). * CVE-2026-68322: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (bsc#1274656). * CVE-2026-68324: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (bsc#1274649). * CVE-2026-68325: iommu/amd: Bound the early ACPI HID map (bsc#1274651). * CVE-2026-68328: nfp: Check resource mutex allocation (bsc#1274646). * CVE-2026-68329: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (bsc#1274645). * CVE-2026-68331: dpaa2-eth: put MAC endpoint device on disconnect (bsc#1274642). * CVE-2026-68333: dpaa2-switch: put MAC endpoint device on disconnect (bsc#1274644). * CVE-2026-68335: rds: drop incoming messages that cross network namespace boundaries (bsc#1274640). * CVE-2026-68336: bonding: fix devconf_all NULL dereference when IPv6 is disabled (bsc#1274639). * CVE-2026-68343: smb: client: validate DFS referral PathConsumed (bsc#1274629). * CVE-2026-68377: net/sched: act_tunnel_key: Defer dst_release to RCU callback (bsc#1274831). * CVE-2026-68386: bpf, sockmap: Reject unhashed UDP sockets on sockmap update (bsc#1274814). * CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). * CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). * CVE-2026-68408: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (bsc#1274709). * CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). * CVE-2026-68418: RDMA/irdma: Prevent user-triggered null deref on QP create (bsc#1274690). * CVE-2026-68419: RDMA/irdma: Prevent rereg_mr for non-mem regions (bsc#1274698). * CVE-2026-68422: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (bsc#1274706). * CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1274700). * CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). * CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink (bsc#1274800). * CVE-2026-68433: libceph: bound get_version reply decode to front len (bsc#1274801). * CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert (bsc#1274834). * CVE-2026-68470: wifi: cfg80211/mac80211: correctly parse S1G beacon optional elements (bsc#1276500). * CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). * CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). * CVE-2026-72035: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1276961). * CVE-2026-72036: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1277034). * CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). * CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155). * CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). * CVE-2026-72084: scsi: target: Bound PR-OUT TransportID parsing to the received buffer (bsc#1275540). * CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523). * CVE-2026-72132: NFS: Charge unstable writes by request size, not folio size (bsc#1277551). * CVE-2026-72221: sunrpc: wait for in-flight TLS handshake callback when cancel loses race (bsc#1275665). * CVE-2026-72222: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback (bsc#1275669). * CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). * CVE-2026-72254: netfilter: nft_fib: reject fib expression on the netdev egress hook (bsc#1277204). * CVE-2026-72262: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (bsc#1277678). * CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). * CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). * CVE-2026-72296: net: ife: require ETH_HLEN to be pullable in ife_decode() (bsc#1275923). * CVE-2026-72307: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (bsc#1277160). * CVE-2026-72308: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (bsc#1277159). * CVE-2026-72317: SUNRPC: pin upper rpc_clnt across the TLS connect_worker (bsc#1275925). * CVE-2026-72341: net/mlx5e: Fix publication race for priv->channel_stats[] (bsc#1277660). * CVE-2026-72342: net/mlx5e: Fix HV VHCA stats agent registration race (bsc#1277775). * CVE-2026-72343: net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation (bsc#1277776). * CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). * CVE-2026-72463: xfrm: Fix dev use-after-free in xfrm async resumption (bsc#1268276 bsc#1277064). * CVE-2026-72464: xprtrdma: Remove temp allocation of rpcrdma_rep objects (bsc#1277069). * CVE-2026-72466: xprtrdma: Fix bcall rep leak and unbounded peek (bsc#1277057). * CVE-2026-72467: xprtrdma: Check frwr_wp_create() during connect (bsc#1277059). * CVE-2026-72469: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE (bsc#1277047). * CVE-2026-72473: xprtrdma: Avoid 250 ms delay on backlog wakeup (bsc#1277037). * CVE-2026-72494: RDMA/irdma: Replace waitqueue and flag with completion (bsc#1276941). * CVE-2026-72495: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages (bsc#1276937). * CVE-2026-72496: RDMA/bnxt_re: Proper rollback if the ioremap fails (bsc#1276943). * CVE-2026-72499: RDMA/bnxt_re: Free CQ toggle page after firmware teardown (bsc#1276551). * CVE-2026-72501: RDMA/bnxt_re: Initialize dpi variable to zero (bsc#1276546). * CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (bsc#1276542). * CVE-2026-74269: bnxt: fix head underflow on XDP head-grow (bsc#1276507). * CVE-2026-74296: RDMA/mlx5: Release the HW-provided UAR index rather than the SW one (bsc#1276452). * CVE-2026-74297: RDMA/mlx5: Fix undefined shift of user RQ WQE size (bsc#1276446). * CVE-2026-74318: btrfs: fix deadlock cloning inline extent when using flushoncommit (bsc#1276864). * CVE-2026-74321: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (bsc#1277202). * CVE-2026-74334: RDMA/nldev: Fix locking when accessing mr->pd (bsc#1277095). * CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). * CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). * CVE-2026-74395: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (bsc#1277077). * CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073). * CVE-2026-74474: vxlan: use pskb_network_may_pull() for transmit path header pulls (bsc#1276335). * CVE-2026-74481: mm/page_reporting: use system_freezable_wq to fix UAF during suspend (bsc#1276355). * CVE-2026-74482: mm/huge_memory: unlock i_mmap_rwsem before releasing after- split folios (bsc#1276346). * CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350). * CVE-2026-74495: igbvf: Fix leak in TX DMA error cleanup (bsc#1275864). * CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). * CVE-2026-74509: Bluetooth: hci_sync: Fix advertising data UAFs (bsc#1275946). * CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation (bsc#1275950). * CVE-2026-74512: audit: fix potential use-after-free in audit_del_rule() (bsc#1275954). * CVE-2026-74516: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (bsc#1275797). * CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). * CVE-2026-74527: octeontx2-af: Block VFs from clobbering special CGX PKIND state (bsc#1275805). * CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). * CVE-2026-74548: forcedeth: fix UAF of txrx_stats in nv_remove (bsc#1275695). * CVE-2026-74550: net: do not send ICMP/NDISC Redirects when peer allocation fails (bsc#1275688). * CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). * CVE-2026-74563: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() (bsc#1275574). * CVE-2026-74566: keys: make keyring key-chunk byte order agree with keyring_diff_objects() (bsc#1275566). * CVE-2026-74567: keys: fix out-of-bounds read in keyring_get_key_chunk() (bsc#1275569). * CVE-2026-74571: btrfs: skip global block reserve accounting for rescue mounts (bsc#1275561). * CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782). * CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). * CVE-2026-74584: RDMA/bnxt_re: zero shared page before exposing to userspace (bsc#1277066). * CVE-2026-74610: tls: don't leave a full plaintext sk_msg ring unpushed (bsc#1277054). * CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). * CVE-2026-74692: net/smc: fix TOCTOU race between smc_listen_out() and listener close (bsc#1276927). * CVE-2026-74694: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (bsc#1277625). * CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). * CVE-2026-74717: net/mlx5: fw_tracer, return NULL on create error (bsc#1276569). * CVE-2026-74722: btrfs: fix memory leak in btrfs_do_encoded_write() (bsc#1276561). * CVE-2026-80529: xfs: don't swallow dquot recovery verification errors (bsc#1277688). * CVE-2026-80534: xfs: fix ilock leak on error in xfs_dq_get_next_id (bsc#1277022). * CVE-2026-80590: inet: frags: strip GSO state from fragments before reassembly (bsc#1277275). * CVE-2026-80654: soc: xilinx: Shutdown and free rx mailbox channel (bsc#1277516). The following non security issues were fixed: * accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() (git-fixes). * accessibility: speakup: unregister tty ldisc on later init failures (git- fixes). * ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer (git-fixes). * ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root (git- fixes). * ACPI: pfr_update: fix stack buffer overflow in query_capability() (git- fixes). * ACPI: processor: idle: Expand _LPI package sanity checks (git-fixes). * ACPI: processor: validate MADT IOAPIC entry bounds (git-fixes). * ACPI: scan: fix bus ID cleanup on device_add() failures (git-fixes). * ACPI: video: Release PCI device reference after lookup (git-fixes). * add my missing Reviewed-by: tag. * ALSA: 6fire: bound the MIDI event length from the device (git-fixes). * ALSA: 6fire: Fix UAF at error handling during probe (stable-fixes). * ALSA: bcd2000: clear the URB pointers on disconnect (git-fixes). * ALSA: core: Fix use-after-free in snd_card_do_free() (git-fixes). * ALSA: dummy: Check card index validity at probe (stable-fixes). * ALSA: hda/ext: preserve PPLCCTL bits when clearing reset (git-fixes). * ALSA: hda: Fix connection list comparison in proc output (git-fixes). * ALSA: hpi: Check transport errors during HPI6000 adapter initialization (git-fixes). * ALSA: pcxhr: initialize mutexes before requesting threaded IRQ (git-fixes). * ALSA: seq: midi: Optimize event_input locking with RCU (git-fixes). * ALSA: seq: midi: Serialize input teardown with event_input (git-fixes). * ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion (git-fixes). * ALSA: usb-audio: Complete cleanup after system-resume errors (git-fixes). * ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (git-fixes). * ALSA: usb-audio: fix OOB write on Type II inbound URBs (git-fixes). * ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (git-fixes). * ALSA: usx2y: bound the hwdep mmap fault offset (git-fixes). * ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() (git- fixes). * apparmor: advertise the tcp fast open fix is applied (git-fixes). * ASoC: adau1761: sort the register default table (git-fixes). * ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC (git-fixes). * ASoC: apple: mca: increase SERDES reset delay (git-fixes). * ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (git-fixes). * ASoC: cs35l33: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l34: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l41: sort the register default table (git-fixes). * ASoC: cs35l45: sort the register default table (git-fixes). * ASoC: cs4265: sort the register default table (git-fixes). * ASoC: cx2072x: sort the register default table (git-fixes). * ASoC: dapm: Fix off-by-one check on the second enum channel (git-fixes). * ASoC: fix unmet dependencies on PPC_BESTCOMM and SND_SOC_AC97_BUS (git- fixes). * ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready (git- fixes). * ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure (git-fixes). * ASoC: fsl_audmix: rework runtime PM handling in probe (git-fixes). * ASoC: fsl_easrc: sort the register default table (git-fixes). * AsoC: intel: sst: fix PCI device reference leak on probe failure (git- fixes). * ASoC: max9860: sort the register default table (git-fixes). * ASoC: meson: Keep link pointers valid on realloc failure (git-fixes). * ASoC: ml26124: sort the register default table (git-fixes). * ASoC: pcm512x: sort the register default table (git-fixes). * ASoC: pxa: Use devm_clk_get_optional() for extclk clock (git-fixes). * ASoC: qcom: q6apm: keep the graph start count in sync with the DSP (git- fixes). * ASoC: rt274: sort the register default table (git-fixes). * ASoC: rt286: sort the register default table (git-fixes). * ASoC: rt298: sort the register default table (git-fixes). * ASoC: rt700-sdw: always drain jack work on remove (git-fixes). * ASoC: rt700: drop duplicate reg_default entry (git-fixes). * ASoC: rt700: sort the register default table (git-fixes). * ASoC: rt711-sdca: sort the register default tables (git-fixes). * ASoC: rt711: sort the register default table (git-fixes). * ASoC: rt712-sdca-dmic: sort the register default table (git-fixes). * ASoC: rt715-sdca: drop duplicate reg_default entries (git-fixes). * ASoC: rt715-sdca: sort the register default tables (git-fixes). * ASoC: rt715: sort the register default table (git-fixes). * ASoC: rt1316-sdw: sort the register default table (git-fixes). * ASoC: rt1318-sdw: sort the register default table (git-fixes). * ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get (git-fixes). * ASoC: sgtl5000: sort the register default table (git-fixes). * ASoC: SOF: pcm: Move period/buffer configuration print after platform open (stable-fixes). * ASoC: sof: pcm: use snd_pcm_direction_name() (stable-fixes). * ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() (git- fixes). * ASoC: SOF: validate topology volume range before allocation (git-fixes). * ASoC: sti-sas: sort the register default table (git-fixes). * ASoC: tas2552: sort the register default table (git-fixes). * ASoC: tas2764: sort the register default table (git-fixes). * ASoC: tas2780: sort the register default table (git-fixes). * ASoC: tegra210_i2s: sort the register default table (git-fixes). * ASoC: tegra210_mixer: sort the register default table (git-fixes). * ASoC: tegra: Fix the MIXER enable default value (git-fixes). * ASoC: tegra: Sort MBDRC register defaults (git-fixes). * ASoC: xilinx: formatter_pcm: fix stream_data leak on open error (git-fixes). * ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (git-fixes). * batman-adv: bla: fix freeing of claims on meshif deletion (git-fixes). * batman-adv: bla: prevent CRC corruptions after claim flush (git-fixes). * batman-adv: dat: avoid unaligned fault in IP extraction (git-fixes). * batman-adv: fix stale receive device on merged fragments (git-fixes). * Bluetooth: btintel: Fix diagnostics event detection (git-fixes). * Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path (git-fixes). * Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX (git- fixes). * Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event (git- fixes). * Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() (git- fixes). * Bluetooth: do not leak an hci_conn when a second LE connect is rejected (git-fixes). * Bluetooth: eir: Fix OOB read in eir_get_service_data() (git-fixes). * Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (git-fixes). * Bluetooth: hci_conn: re-enable advertising only for peripheral role (git- fixes). * Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection (git- fixes). * Bluetooth: hci_event: fix LE list UAF on reset (git-fixes). * Bluetooth: hci_event: validate LE Set CIG Parameters response (git-fixes). * Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths (git-fixes). * Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (stable-fixes). * Bluetooth: hci_uart: Fix false success return in hci_uart_setup() (git- fixes). * Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready (git-fixes). * Bluetooth: MGMT: free the mesh send cancel command when it is cancelled (git-fixes). * Bluetooth: MSFT: validate evt_prefix_len against the response length (git- fixes). * Bluetooth: RFCOMM: serialize security confirmation handling (git-fixes). * Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (git- fixes). * Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop (git-fixes). * Bluetooth: virtio_bt: avoid OOB read of build info string (git-fixes). * bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation (git-fixes). * bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET (git-fixes). * bus: ti-sysc: Fix /chosen node reference leak (git-fixes). * cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64) (git-fixes). * can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (stable-fixes). * crypto: aspeed - Propagate platform_get_irq() errors (git-fixes). * crypto: atmel-sha204a - fix heap info leak on I2C transfer failure (git- fixes). * crypto: atmel-tdes - use scatterlist length before DMA mapping (git-fixes). * crypto: ccm - Set rfc4309 maxauthsize from child (git-fixes). * crypto: ccp - Fix memory leak in SEV INIT_EX path (git-fixes). * crypto: ccp - Fix possible deadlock in SEV init failure path (git-fixes). * crypto: doc - Remove extra parenthesis (git-fixes). * crypto: hisilicon/sec2 - fix CCM algorithm long packet failure (git-fixes). * crypto: keembay - Initialize completion before requesting IRQ (git-fixes). * crypto: keembay - publish OF module alias for OCS AES/SM4 (git-fixes). * crypto: mxs-dcp - fix source scatterlist length access (git-fixes). * crypto: qat - cancel work on re-enable SR-IOV timeout (git-fixes). * crypto: qat - clear AES key schedule from stack (git-fixes). * crypto: qce - fix CCM AAD buffer underallocation (git-fixes). * crypto: qce - fix error path in devm_qce_register_algs (git-fixes). * crypto: rk3288 - fail ahash requests on HASH idle timeout (git-fixes). * crypto: sa2ul - stop probe if context pool creation fails (git-fixes). * crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping (git- fixes). * device property: fix infinite loop in fwnode_for_each_child_node() (git- fixes). * dmaengine: dw-edma: Clear stale requests on termination (git-fixes). * dmaengine: dw-edma: Complete descriptors before pausing (git-fixes). * dmaengine: dw-edma: Initialize IRQ data before requesting IRQs (git-fixes). * dmaengine: dw-edma: Serialize abort state updates (git-fixes). * dmaengine: dw-edma: Serialize channel state checks (git-fixes). * dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe (git-fixes). * dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure (git-fixes). * dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal (git-fixes). * dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers (git-fixes). * dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout (git-fixes). * driver core: soc: Unregister bus on early device registration failure (git- fixes). * drm/amd/display: avoid divide-by-zero in __is_lut_linear() (git-fixes). * drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read (git- fixes). * drm/amdgpu/gfx6: Fixup emit_cntxcntl() (git-fixes). * drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets (git-fixes). * drm/amdgpu/gfx6: Use PFP on the compute queues too (git-fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup (git- fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup (git- fixes). * drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check (git- fixes). * drm/amdgpu: cap GTT size to physical RAM on APUs (stable-fixes). * drm/amdgpu: check ASPM on the dGPU host link (git-fixes). * drm/amdgpu: disallow multiple FENCE chunks in one submit (git-fixes). * drm/amdgpu: fix aperture iounmap skipped on device removal (git-fixes). * drm/amdgpu: fix autosuspend cleanup during removal (git-fixes). * drm/amdgpu: Fix UVD decode image min size calculation (stable-fixes). * drm/amdgpu: Fix UVD dpb min size calculation for H264 (stable-fixes). * drm/amdgpu: Fix UVD min buffer sizes (stable-fixes). * drm/amdgpu: Fix VCE 3 ring align_mask (git-fixes). * drm/amdgpu: Implement insert_end for VCE 3 (git-fixes). * drm/amdgpu: Reject UVD message with dimensions above 4096 (stable-fixes). * drm/amdgpu: Reject UVD message with invalid number of h265 refs (stable- fixes). * drm/amdgpu: restore UMD profile pstate after runtime resume (stable-fixes). * drm/amdgpu: validate GEM_CREATE domain combinations (stable-fixes). * drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (stable-fixes). * drm/amdkfd: fix QID bit leak in pqm_create_queue() (stable-fixes). * drm/amdkfd: Handle invalid event type in CRIU event restore (stable-fixes). * drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure (git-fixes). * drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure (git-fixes). * drm/bridge: ps8640: propagate AUX transfer register errors (git-fixes). * drm/bridge: tc358767: clamp the reported AUX read size to the request (git- fixes). * drm/connector: Fix epoch_counter docs to reflect reality (git-fixes). * drm/hibmc: Fix list of formats on the primary plane (git-fixes). * drm/hibmc: Use drm_atomic_helper_check_plane_state() (git-fixes). * drm/i915/fbc: Extract intel_fbc_has_fences() (stable-fixes). * drm/lima: call drm_mm_init() with a valid allocation range (git-fixes). * drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: Drop dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value (git- fixes). * drm/panel-edp: fix i2c adapter leak on probe failure (git-fixes). * drm/panel: samsung-s6d16d0: Power off on prepare failure (git-fixes). * drm/radeon: fix autosuspend cleanup during teardown (git-fixes). * drm/radeon: restore hardware polling in fence_is_signaled to fix performance regression (git-fixes). * drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format (git-fixes). * drm/ssd130x: fix column and row end address in partial updates for ssd132x (git-fixes). * drm/sun4i: crtc: Propagate layer initialization error (git-fixes). * drm/sun4i: Drop node references while building component list (git-fixes). * drm/sun4i: dw-hdmi: Drop TCON TOP port reference (git-fixes). * drm/sun4i: fix refcount leak in sun4i_backend_init_sat() (git-fixes). * drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz (git-fixes). * drm/sun4i: tcon: Drop remote endpoint reference (git-fixes). * drm/sun4i: tcon: Drop TCON TOP device reference (git-fixes). * drm/sun4i: tcon: Set output mux for DSI and LVDS (git-fixes). * drm/sun4i: vi scaler: Fix coefficient selection (git-fixes). * drm/tegra: dsi: Re-add clear enable register if DSI was powered by bootloader (git-fixes). * drm/tve200: add OF module alias for autoloading (git-fixes). * drm: fix race between partial drm_dev_register() failure and ioctl (git- fixes). * drm: lcdif: Wait for vblank before disabling DMA (git-fixes). * drm: Remove unused header in drm_dumb_buffers.c (git-fixes). * ethtool: rss: fix hkey leak when indir_size is 0 (git-fixes). * fbdev: bitblit: bound-check glyph index in bit_cursor() (git-fixes). * fbdev: core: Fix pointer desynchronization in fb_io_read() (git-fixes). * fbdev: kyro: Validate overlay viewport coordinates (git-fixes). * fbdev: omapfb: panel-dsi-cm: initialize lock before registering display (git-fixes). * fbdev: ssd1307fb: defer I2C transfers from damage callbacks (git-fixes). * fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() (git-fixes). * fbdev: uvesafb: unregister connector callback on init failure (git-fixes). * firmware: arm_scmi: Avoid IDR updates while cleaning channels (git-fixes). * firmware: arm_scmi: Drop handle on protocol bind failures (git-fixes). * firmware: arm_scmi: Fix requested device removal race (git-fixes). * firmware: arm_scmi: Free transport channel on IDR failure (git-fixes). * firmware: arm_scmi: Protect device request lookup with RCU (git-fixes). * firmware: arm_scmi: Reject out of range DT protocol IDs (git-fixes). * firmware: arm_scmi: Unregister device notifier before IDR teardown (git- fixes). * firmware: arm_scmi: Use channel ID for transport teardown (git-fixes). * firmware_loader: do not queue completed sysfs fallback requests (git-fixes). * fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write (git- fixes). * fpga: dfl: fme: add error handling (git-fixes). * fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration (git- fixes). * gpu: host1x: Avoid stack over-read in debug output helpers (git-fixes). * gpu: host1x: Fix offset calculation in trace_write_gather (git-fixes). * HID: core: fix number/pointer type confusion on long items (git-fixes). * HID: core: fix OOB read of field->usage in hid_set_field() (git-fixes). * HID: hyperv: validate initial device info bounds (git-fixes). * HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure (git-fixes). * HID: lg4ff: validate report length before fixed offsets (git-fixes). * HID: logitech-dj: Fix maxfield check in DJ short report validation (git- fixes). * HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (git- fixes). * HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (stable-fixes). * HID: logitech-dj: Standardise hid_report_enum variable nomenclature (stable- fixes). * HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID (stable-fixes). * HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (git- fixes). * HID: mcp2221: validate report size in mcp2221_raw_event() (git-fixes). * HID: nintendo: Fix imu_timestamp_us double increment per report (git-fixes). * HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() (git- fixes). * HID: picolcd: clamp eeprom debugfs read to bytes actually received (git- fixes). * HID: roccat: bound device-supplied profile index (git-fixes). * HID: roccat: free buffered reports when destroying device (git-fixes). * HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature (git- fixes). * HID: sensor: custom: Fix field sysfs group cleanup on failure (git-fixes). * HID: sensor: custom: Fix use-after-free in enable_sensor (git-fixes). * HID: tmff: Use 64-bit arithmetic for force feedback scaling (git-fixes). * hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (git-fixes). * hwmon: (lm25066) Use i2c_get_match_data() (stable-fixes). * hwmon: (max6621) fix negative temperature offset and crit readings (git- fixes). * hwmon: (max6621) fix temperature clamp range (git-fixes). * hwmon: (nzxt-smart2) Check return value of init_device() in probe (git- fixes). * hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (git-fixes). * hwrng: ks-sa - Fix runtime PM cleanup on registration failure (git-fixes). * hwrng: omap - Fix probe error path cleanup (git-fixes). * hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() (git- fixes). * i2c: bcm-iproc: remove printout on handled timeouts (stable-fixes). * i2c: iproc: reset bus after timeout if START_BUSY is stuck (git-fixes). * i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure (git-fixes). * i2c: mux: Fix channel node leak on adapter add failure (git-fixes). * i2c: ocores: Disable clock on failed resume (git-fixes). * i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices (git-fixes). * i3c: master: Fix device_register() error path (git-fixes). * i3c: master: Fix info leak and UAF in device unregister path (git-fixes). * i3c: master: svc: bound IBI payload to the requested max_payload_len (git- fixes). * ibmvnic: Only record tx completed bytes once per handler (bsc#1274620). * iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE (git-fixes). * iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable (git-fixes). * iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF (git-fixes). * iio: chemical: sgp30: Handle IAQ thread creation failure (git-fixes). * iio: dac: m62332: Fix regulator reference count imbalance (git-fixes). * iio: gyro: mpu3050: fix sign of raw angular velocity readings (git-fixes). * iio: light: cm32181: return zero after writing calibscale (git-fixes). * iio: light: gp2ap002: Disable regulators on resume failure (git-fixes). * iio: light: gp2ap002: re-enable irq if runtime suspend fails (git-fixes). * iio: light: isl29028: return zero in write_raw() on success (git-fixes). * iio: light: tsl2583: return zero in write_raw() on success (git-fixes). * iio: light: tsl2772: fix ALS calibscale readback (git-fixes). * iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure (git-fixes). * iio: pressure: dps310: fix NULL pointer dereference on ACPI probe (git- fixes). * iio: pressure: mpl115: Fix runtime PM cleanup (git-fixes). * iio: srf04: fix pm_runtime handling on probe error path (git-fixes). * iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() (git-fixes). * Input: atkbd - skip deactivate for HONOR ZQC-P (git-fixes). * Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (stable-fixes). * Input: evdev - fix information leak in evdev_pass_values() (stable-fixes). * Input: evdev - sanitize event type index when fetching event masks (stable- fixes). * Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (git-fixes). * Input: focaltech - use signed coordinates to prevent underflow (git-fixes). * Input: hynitron_cstxxx - validate touch count and finger IDs (git-fixes). * Input: iforce - validate input packet lengths (stable-fixes). * Input: iqs5xx - validate firmware record destination span (git-fixes). * Input: mms114 - fix Y-resolution configuration (git-fixes). * Input: psxpad-spi - set driver data before use (git-fixes). * Input: sur40 - fix input device registration ordering (stable-fixes). * Input: sur40 - fix V4L error path cleanup (stable-fixes). * Input: synaptics-rmi4 - block s_input when F54 queue is busy (git-fixes). * Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (git-fixes). * Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (git- fixes). * Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (git- fixes). * Input: synaptics-rmi4 - zero report size on F54 work error (git-fixes). * Input: xpad - add support for ZENAIM LEVERLESS (stable-fixes). * interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (git-fixes). * ipmi: ipmb: validate write message length (git-fixes). * ipmi: si: Fix NULL pointer dereference after failed registration (git- fixes). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (git-fixes). * leds: pca9532: Fix inverted GPIO output polarity (git-fixes). * leds: pca9532: Fix phantom device registration on missing hardware (git- fixes). * lib/string: fix memchr_inv() for large ranges (git-fixes). * lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() (git-fixes). * mailbox: qcom-ipcc: fix duplicate channel allocation across holes (git- fixes). * mailbox: rockchip: disable pclk on probe failure and unbind (git-fixes). * maple_tree: fix argument name in header (git-fixes). * md/raid1: create serial pool adding rdev to array with serialize_policy=1 (bsc#1272261). * media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref (git-fixes). * media: cec-pin: Fix event FIFO ordering (git-fixes). * media: cec: disable delayed work before freeing an interrupted transmit (git-fixes). * media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash (git-fixes). * media: cec: Serialize exclusive follower delivery (git-fixes). * media: cec: stm32: prevent out-of-bounds write on RX overflow (git-fixes). * media: cedrus: fix memory leak in cedrus_init_ctrls() (git-fixes). * media: cobalt: Avoid freeing ALSA private data twice (git-fixes). * media: cx231xx: reject geometry changes while the VBI queue is busy (git- fixes). * media: cx23885: cancel NetUP CI work before teardown (git-fixes). * media: em28xx: defer audio-only extension registration (git-fixes). * media: em28xx: fix use-after-free of dev_next->devlist on disconnect (git- fixes). * media: go7007: defer the ALSA v4l2 put until card release (git-fixes). * media: i2c: ov02a10: fix endpoint parsing use-after-free (git-fixes). * media: i2c: ov7740: fix use-after-destroy in remove (git-fixes). * media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define (git- fixes). * media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define (git-fixes). * media: mc-entity: Add missing kerneldoc (git-fixes). * media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common (git- fixes). * media: nxp: imx8-isi: Correct color map between V4L2 and ISI (git-fixes). * media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing (git-fixes). * media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks (git-fixes). * media: rc: sunxi-cir: Unregister rc device on probe failure (git-fixes). * media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure (git-fixes). * media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak (git-fixes). * media: s2255: bound JPEG frame size before copying into the buffer (git- fixes). * media: s2255: check firmware size before reading trailing marker (git- fixes). * media: saa7164: fix cleanup on resource allocation failure (git-fixes). * media: tda18250: fix possible integer overflow (git-fixes). * media: usbtv: keep device alive while ALSA card exists (git-fixes). * media: v4l2-ctrls: Allow unknown HDR10 white point and luminance (git- fixes). * media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link (git-fixes). * media: venus: fix payload size calculation in parse_raw_formats() (git- fixes). * media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() (git-fixes). * media: vicodec: fix out-of-bounds write in FWHT encoder (git-fixes). * media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure (git-fixes). * media: vimc: fix pixel format lookup in enum_framesizes (git-fixes). * media: zoran: Avoid freeing a registered video_device twice (git-fixes). * mei: pull kvfree out of spinlock (git-fixes). * mfd: iqs62x: Reject zero-length firmware records (git-fixes). * mfd: rave-sp: validate received frame payload lengths (git-fixes). * misc: bcm-vk: Use acquire/release for msgq_inited (git-fixes). * misc: fastrpc: fix channel ctx ref leak when session alloc fails (git- fixes). * misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (git-fixes). * misc: fastrpc: Remove buffer from list prior to unmap operation (git-fixes). * misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke (git- fixes). * misc: rtsx: add missing write register handling (git-fixes). * misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() (git- fixes). * mkspec-dtb: Move DTS prefix into package list. * mkspec-dtb: Move provides-obsoletes to package list. * mkspec-dtb: Put per-architecture package lists into a hash. * mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (git- fixes). * mmc: sdhci: unmap the bounce buffer before device release (git-fixes). * mmc: via-sdmmc: stop card-detect handling on probe failure (git-fixes). * mtd: afs: validate v2 image info bounds (git-fixes). * mtd: mtdoops: free page bitmap when the backing MTD is removed (git-fixes). * mtd: mtdswap: Avoid freeing registered blktrans device twice (git-fixes). * mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() (git-fixes). * mtd: rawnand: validate ONFI extended parameter page sections (git-fixes). * net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes). * net: mana: Add handler for sriov configure (bsc#1272756). * net: mana: Cap MSI-X vectors to the device MSI-X table size (git-fixes). * net: mana: Extend RX CQE coalescing up to 8 packets (git-fixes). * net: mana: Fall back to scattered pages for GDMA queues (git-fixes). * net: mana: force full-page RX buffers via ethtool private flag (bsc#1269792). * net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792). * net: mana: Route ring-buffer access through offset-based helpers (git- fixes). * net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). * net: thunderbolt: Count delivered packets in rx_packets and rx_bytes (git- fixes). * net: thunderbolt: Mark the connection down when bringing it up fails (git- fixes). * net: thunderbolt: Release the Rx HopID that was handed out on mismatch (git- fixes). * net: thunderbolt: Tear down DMA paths before stopping the rings (git-fixes). * net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (git-fixes). * net: usb: ipheth: fix carrier_work UAF on disconnect (git-fixes). * nfc: digital: clamp SENSF_RES length to the destination buffer (git-fixes). * nfc: digital: Do not dump a NULL response in command completion (git-fixes). * nfc: fdp: bound the device-reported read length and fix an skb leak (git- fixes). * nfc: llcp: avoid userspace overflow on invalid optlen (git-fixes). * nfc: llcp: bound SNL TLV parsing to the skb and add length checks (git- fixes). * nfc: llcp: bound the connect_sn TLV walk to the skb (git-fixes). * nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (git-fixes). * nfc: llcp: read llcp_sock->local under the socket lock in getsockopt (git- fixes). * nfc: llcp: reject PDUs shorter than the LLCP header (git-fixes). * nfc: microread: validate target discovery payload lengths (git-fixes). * nfc: nci: fix double completion race in nci_data_exchange_complete (git- fixes). * nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (git- fixes). * nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (git- fixes). * nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing (git- fixes). * nfc: nci: free destination parameters when closing a connection (git-fixes). * nfc: pn533: hold a reference to the request skb during send_frame (git- fixes). * nfc: pn533: purge fragmented skbs during cleanup (git-fixes). * nfc: st21nfca: validate ATR_REQ length against the received frame (git- fixes). * nouveau/gem: reserve the bo in the info ioctl around the vma lookup (git- fixes). * PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] (git-fixes). * PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk (git- fixes). * PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git- fixes). * PCI: j721e: Fix incorrect max_lanes for J7200 (git-fixes). * PCI: meson: Fix GPIO state while requesting PERST# (git-fixes). * phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs (git- fixes). * phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend (git-fixes). * phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table (git- fixes). * phy: sunplus: fix error handling in sp_uphy_init() (git-fixes). * pinctrl: bcm2835: Don't remove an unregistered GPIO chip (git-fixes). * pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip (git-fixes). * pinctrl: rockchip: Reset the pin count when recalculating SoC data (git- fixes). * platform/chrome: cros_ec_debugfs: Clean up console log on probe failure (git-fixes). * platform/chrome: cros_ec_debugfs: Unregister panic notifier (git-fixes). * platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count (git- fixes). * platform/chrome: sensorhub: Bound the EC-reported sensor number (git-fixes). * platform/chrome: sensorhub: Fix dropped timestamp events and log spam (git- fixes). * platform/chrome: sensorhub: Fix memory overread in ring handler (git-fixes). * platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL (git- fixes). * platform/surface: acpi-notify: Check ACPI companion before use (git-fixes). * platform/x86: dell-privacy: Fix race condition (git-fixes). * platform/x86: dell-wmi-base: Fix resource leak on module load failure (git- fixes). * platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (git-fixes). * platform/x86: dell-wmi-sysman: Fix instance ID bounds (git-fixes). * platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path (git-fixes). * platform/x86: ISST: Just allow 2 bits for SST feature enable (git-fixes). * platform/x86: ISST: Validate level in perf mask ioctls (git-fixes). * platform/x86: ISST: Validate logical CPU id and clos id (git-fixes). * platform/x86: ISST: Validate socket ID in clos_assoc ioctl (git-fixes). * PM: sleep: Fix off-by-one in wakelocks number limit check (git-fixes). * power: supply: bd99954: Drop bad register fields (git-fixes). * power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq27520g4: fix REG_TTES address (git-fixes). * power: supply: bq256xx: drain usb_work before freeing the charger (git- fixes). * power: supply: bq24257: fix use-after-free on remove (git-fixes). * power: supply: bq25890: Fix power_supply reference leak (git-fixes). * power: supply: cros_usbpd-charger: bound the EC-reported port count (git- fixes). * power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS (git- fixes). * power: supply: isp1704_charger: cancel work on remove (git-fixes). * power: supply: lp8727: fix use-after-free in lp8727_release_irq() (git- fixes). * power: supply: max17040: drop incorrect I2C functionality check (git-fixes). * power: supply: max17040: synchronize work cancellation on suspend (git- fixes). * power: supply: qcom_battmgr: terminate the strings from firmware (git- fixes). * power: supply: rt9455: quiesce delayed work before teardown (git-fixes). * power: supply: sbs-battery: Use a per-device serial number buffer (git- fixes). * power: supply: twl4030_charger: cancel workers via devm (git-fixes). * power: supply: ucs1002: fix use-after-free on remove (git-fixes). * powercap: intel_rapl_tpmi: Handle PMU registration failure during probe (git-fixes). * powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash (bsc#1271256). * powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). * powerpc/pseries: pci - logic bug (bsc#1274749 ltc#221282 bsc#1274755 ltc#221284 bsc#1274756 ltc#221283). * ppdev: prevent overflow when setting port timeout (git-fixes). * qede: fix out-of-bounds check for cqe->len_list (git-fixes). * rapidio: clear mport->net when rio_add_net() fails (git-fixes). * rapidio: mport_cdev: fix use-after-free in dma_req_free() (git-fixes). * RDMA/irdma: Remove redundant legacy_mode checks (git-fixes). * RDMA/mana_ib: drain QP references after partial table insertion (git-fixes). * RDMA/mana_ib: unify QP lookup table (git-fixes). * RDMA/mlx5: Fix integer overflow of user QP buffer size (git-fixes). * regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (git-fixes). * regulator: core: use system_freezable_wq for init complete work (git-fixes). * regulator: devres: add API for reference voltage supplies (stable-fixes). * regulator: devres: fix devm_regulator_get_enable_read_voltage() return (git- fixes). * regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata (git-fixes). * regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling (git-fixes). * remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev (git-fixes). * remoteproc: qcom_q6v5_adsp: Fix reference leak for device node (git-fixes). * remoteproc: scp: Fix device reference leak on failed lookup (git-fixes). * Revert "drm/amdgpu: fix aperture mapping leak" (git-fixes). * Revert "media: v4l2-dev: fix error handling in __video_register_device()" (git-fixes). * Revert "thermal/drivers/hwmon: Cleanup coding style a bit" (stable-fixes). * rpmsg: core: Fix incorrect return value documentation (git-fixes). * rpmsg: glink: smem: order FIFO read after availability check (git-fixes). * rtc: gamecube: check return value of devm_rtc_register_device() (git-fixes). * rtc: pcf8563: fix clock provider leak on unbind (git-fixes). * rtc: pcf85363: Add error checking to regmap calls in probe() (git-fixes). * rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers (git-fixes). * rtc: rzn1: Fix weekday underflow when alarm crosses month boundary (git- fixes). * rtc: zynqmp: Return optional clock lookup errors (git-fixes). * scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes). * sctp: avoid auth_enable sysctl UAF during netns teardown (git-fixes). * serial: 8250_dma: Clear stale RX state on shutdown (git-fixes). * serial: amba-pl011: unprepare console clock on unregister (git-fixes). * serial: core: clear freed pointers on uart_register_driver() failure (git- fixes). * serial: qcom-geni: fix TX DMA buffer flush (git-fixes). * serial: sc16is7xx: fix copy-paste errors in EFR_SWFLOWx_BIT constants (stable-fixes). * smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). * smb: client: reject overlapping data areas in SMB2 responses (git-fixes). * smb: client: require net admin for CIFS SWN netlink (bsc#1273966). * smb: client: resolve SWN tcon from live registrations (bsc#1273872). * soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() (git- fixes). * soc: qcom: rpmh-rsc: manage PM notifiers with devres (git-fixes). * soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() (git-fixes). * software node: Fix software_node_get_reference_args() with index -1 (git- fixes). * soundwire: qcom: Fix port exhaustion check in stream_alloc_ports (git- fixes). * speakup: keyhelp: guard letter_offsets possible out-of-range indexing (git- fixes). * spi: img-spfi: don't disable runtime PM on DMA deferred probe (git-fixes). * spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (stable-fixes). * spi: sprd-adi: Fix probe succeeding without registering the controller (git- fixes). * staging: fbtft: Use sysfs_emit_at() to print to sysfs file (git-fixes). * staging: media: tegra-video: vi: fix probe failure on skipped last port (git-fixes). * staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown (git- fixes). * staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() (git-fixes). * staging: rtl8723bs: fix missing shared-key auth challenge length check (git- fixes). * staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (git-fixes). * staging: rtl8723bs: fix OOB read in WMM_param_handler() (git-fixes). * staging: rtl8723bs: use kfree_sensitive() for key material (git-fixes). * staging: rtl8723bs: validate monitor transmit frame lengths (git-fixes). * staging: sm750fb: gate dualview dataflow using g_dualview (git-fixes). * thermal/drivers/imx: Disable clock on runtime resume failure (git-fixes). * thermal/drivers/qoriq: Disable clock on resume failure (git-fixes). * thermal: intel: int3400: clean up ODVP on probe failures (git-fixes). * thunderbolt: Bound the DROM dual link port number before indexing sw->ports (git-fixes). * thunderbolt: icm: Preserve USB4 proxy data-valid bit (git-fixes). * tlclk: if sscanf() fails, fall back to 0, not random value (git-fixes). * tpm: st33zp24: Return zero on status read failure (git-fixes). * tpm: st33zp24: Validate locality read result (git-fixes). * tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (git-fixes). * tty: clear cdev pointer after cdev_add() failure (git-fixes). * tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 (git-fixes). * tty: skip cdev_del() when no cdev is registered (git-fixes). * uio: Fix stale info pointer in failed registration path (git-fixes). * usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (git-fixes). * usb: atm: usbatm: fix invalid ci_range initialization (git-fixes). * USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (git-fixes). * usb: cdnsp: fix incorrect endian conversions for APB timeout register (git- fixes). * usb: dwc2: add missing @remotewakeup kernel-doc parameter (git-fixes). * usb: dwc2: gadget: Exit partial power down state when changing USB pull-up (git-fixes). * usb: gadget: configfs: fix out-of-bounds read of qw_sign (git-fixes). * usb: gadget: f_fs: Prevent deadlock during ep0 read loop (git-fixes). * usb: gadget: f_ncm: Use unsigned int for ndp_index (git-fixes). * usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() (git-fixes). * usb: gadget: f_uac1_legacy: remove broken string configfs attributes (git- fixes). * usb: gadget: pch_udc: remove excess kernel-doc member for registered (git- fixes). * usb: gadget: r8a66597: avoid double free of ep0_req in probe error path (git-fixes). * usb: gadget: snps_udc_plat: clean up PHY on probe deferral (git-fixes). * usb: gadget: u_audio: Fix use-after-free on sound card disconnect (git- fixes). * usb: gadget: uac: validate rate list length before storing (git-fixes). * usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() (git-fixes). * usb: mtu3: allow system suspend during active gadget connection (git-fixes). * usb: musb: omap2430: clean up probe error handling (stable-fixes). * USB: phy: fsl-usb: fix missing static keywords (git-fixes). * usb: renesas_usbhs: Fix power-off ordering on unbind (git-fixes). * USB: serial: digi_acceleport: fix port registration order (git-fixes). * USB: serial: ftdi_sio: add support for E+H FXA291 (stable-fixes). * USB: serial: option: add TDTECH MT5710-CN (stable-fixes). * USB: serial: option: fix slab OOB read in interrupt URB callback (git- fixes). * USB: serial: spcp8x5: drop broken carrier detect support (git-fixes). * USB: storage: add NO_ATA_1X quirk for Longmai USB Key (stable-fixes). * usb: typec: ucsi: unregister debugfs entries on teardown (git-fixes). * usb: usbfs: fix use-after-free of usb_device in usbdev_release() (git- fixes). * usb: xhci: Handle USB3 port events when there is one roothub (git-fixes). * vt: add permission check for KDSKBMETA ioctl (stable-fixes). * vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (stable- fixes). * w1: ds28e17: reject an oversize length on an I2C block read (git-fixes). * w1: ds2482: Fix signedness bug in ds2482_w1_triplet() (git-fixes). * wifi: ath6kl: avoid buffer overreads in WMI event handlers (git-fixes). * wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (git-fixes). * wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump (git-fixes). * wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() (git-fixes). * wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate (git- fixes). * wifi: ath11k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() (git-fixes). * wifi: ath12k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (git-fixes). * wifi: brcmfmac: fix P2P action frame handling without device vif (git- fixes). * wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs (git-fixes). * wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments (git-fixes). * wifi: iwlwifi: mei: pass correct argument to function (git-fixes). * wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser (git-fixes). * wifi: mac80211: send TWT teardown to peer after setup TX failure (git- fixes). * wifi: mac80211: skip default WMM setup for AP_VLAN links (git-fixes). * wifi: mac80211: skip unused probe response countdown offsets (git-fixes). * wifi: mt76: fix 4th chain ACK RSSI bitmask in sta_poll (git-fixes). * wifi: mt76: fix ER-SU 106-tone RU check in RX rate decode (git-fixes). * wifi: mt76: fix HE DCM max-RU capability encoding (git-fixes). * wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length (git- fixes). * wifi: mt76: mt792x: Fix memory leak in SDIO TX path (git-fixes). * wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (git- fixes). * wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss (git- fixes). * wifi: mt76: mt7915: fix double hif2 init on the non-WED path (git-fixes). * wifi: mt76: mt7915: fix ext PHY use-after-free on register error path (git- fixes). * wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 (git- fixes). * wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie (git-fixes). * wifi: mt76: mt7915: release hif2 reference on probe IRQ failure (git-fixes). * wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement (git- fixes). * wifi: mt76: mt7915: unwind state on add_interface failure (git-fixes). * wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields (git- fixes). * wifi: mt76: mt7915: write RX header translation bit to the correct register (git-fixes). * wifi: mt76: mt7921: validate CLC firmware records (git-fixes). * wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (git- fixes). * wifi: mt76: mt7925: fix msg len mismatch between driver and firmware (git- fixes). * wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config (git- fixes). * wifi: mt76: mt7996: don't report a zero TX bitrate (git-fixes). * wifi: mt76: mt7996: fix reg addr remap when addr is 0 (git-fixes). * wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV (git- fixes). * wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset (git-fixes). * wifi: mt76: mt7996: validate RX band_idx before dereferencing phys (git- fixes). * wifi: mt76: report data NSS for STBC frames in RX rate decode (git-fixes). * wifi: mwifiex: Detach sync cmd buffer on interrupted wait (git-fixes). * wifi: rtlwifi: pci: fix error path in rtl_pci_probe() (git-fixes). * wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (git-fixes). * wifi: rtw89: fix HE extended capability length check (git-fixes). * wifi: zd1211rw: reject secondary interfaces to prevent conflicts (git- fixes). * x86/bugs: Clarify that syscall hardening isn't a BHI mitigation (git-fixes). * xhci: dbgtty: Fix unregister on tty_alloc_driver() failure (git-fixes). * xhci: dbgtty: Fix unregister on tty_register_driver() failure (git-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.1 zypper in -t patch SUSE-SLE-Micro-Extras-6.1-kernel-601=1 ## Package List: * SUSE Linux Micro Extras 6.1 (nosrc) * kernel-64kb-6.4.0-52.1 * SUSE Linux Micro Extras 6.1 (aarch64) * kernel-64kb-devel-6.4.0-52.1 * kernel-64kb-debugsource-6.4.0-52.1 * SUSE Linux Micro Extras 6.1 (aarch64 ppc64le s390x x86_64) * kernel-obs-build-debugsource-6.4.0-52.1 * kernel-obs-build-6.4.0-52.1 * kernel-syms-6.4.0-52.1 ## References: * https://www.suse.com/security/cve/CVE-2024-44981.html * https://www.suse.com/security/cve/CVE-2024-57841.html * https://www.suse.com/security/cve/CVE-2025-38469.html * https://www.suse.com/security/cve/CVE-2025-39964.html * https://www.suse.com/security/cve/CVE-2025-40022.html * https://www.suse.com/security/cve/CVE-2025-68179.html * https://www.suse.com/security/cve/CVE-2025-68214.html * https://www.suse.com/security/cve/CVE-2025-71075.html * https://www.suse.com/security/cve/CVE-2025-71104.html * https://www.suse.com/security/cve/CVE-2026-23210.html * https://www.suse.com/security/cve/CVE-2026-23230.html * https://www.suse.com/security/cve/CVE-2026-23454.html * https://www.suse.com/security/cve/CVE-2026-31392.html * https://www.suse.com/security/cve/CVE-2026-31418.html * https://www.suse.com/security/cve/CVE-2026-31531.html * https://www.suse.com/security/cve/CVE-2026-31557.html * https://www.suse.com/security/cve/CVE-2026-31663.html * https://www.suse.com/security/cve/CVE-2026-43116.html * https://www.suse.com/security/cve/CVE-2026-43125.html * https://www.suse.com/security/cve/CVE-2026-43163.html * https://www.suse.com/security/cve/CVE-2026-43271.html * https://www.suse.com/security/cve/CVE-2026-43273.html * https://www.suse.com/security/cve/CVE-2026-43278.html * https://www.suse.com/security/cve/CVE-2026-43319.html * https://www.suse.com/security/cve/CVE-2026-43363.html * https://www.suse.com/security/cve/CVE-2026-43416.html * https://www.suse.com/security/cve/CVE-2026-45897.html * https://www.suse.com/security/cve/CVE-2026-45968.html * https://www.suse.com/security/cve/CVE-2026-46070.html * https://www.suse.com/security/cve/CVE-2026-46091.html * https://www.suse.com/security/cve/CVE-2026-46107.html * https://www.suse.com/security/cve/CVE-2026-46115.html * https://www.suse.com/security/cve/CVE-2026-46195.html * https://www.suse.com/security/cve/CVE-2026-52920.html * https://www.suse.com/security/cve/CVE-2026-52925.html * https://www.suse.com/security/cve/CVE-2026-52929.html * https://www.suse.com/security/cve/CVE-2026-52935.html * https://www.suse.com/security/cve/CVE-2026-52939.html * https://www.suse.com/security/cve/CVE-2026-52946.html * https://www.suse.com/security/cve/CVE-2026-52975.html * https://www.suse.com/security/cve/CVE-2026-52977.html * https://www.suse.com/security/cve/CVE-2026-52990.html * https://www.suse.com/security/cve/CVE-2026-52994.html * https://www.suse.com/security/cve/CVE-2026-53001.html * https://www.suse.com/security/cve/CVE-2026-53033.html * https://www.suse.com/security/cve/CVE-2026-53059.html * https://www.suse.com/security/cve/CVE-2026-53076.html * https://www.suse.com/security/cve/CVE-2026-53077.html * https://www.suse.com/security/cve/CVE-2026-53089.html * https://www.suse.com/security/cve/CVE-2026-53091.html * https://www.suse.com/security/cve/CVE-2026-53094.html * https://www.suse.com/security/cve/CVE-2026-53096.html * https://www.suse.com/security/cve/CVE-2026-53110.html * https://www.suse.com/security/cve/CVE-2026-53111.html * https://www.suse.com/security/cve/CVE-2026-53126.html * https://www.suse.com/security/cve/CVE-2026-53154.html * https://www.suse.com/security/cve/CVE-2026-53163.html * https://www.suse.com/security/cve/CVE-2026-53207.html * https://www.suse.com/security/cve/CVE-2026-53219.html * https://www.suse.com/security/cve/CVE-2026-53220.html * https://www.suse.com/security/cve/CVE-2026-53223.html * https://www.suse.com/security/cve/CVE-2026-53228.html * https://www.suse.com/security/cve/CVE-2026-53238.html * https://www.suse.com/security/cve/CVE-2026-53260.html * https://www.suse.com/security/cve/CVE-2026-53264.html * https://www.suse.com/security/cve/CVE-2026-53269.html * https://www.suse.com/security/cve/CVE-2026-53273.html * https://www.suse.com/security/cve/CVE-2026-53309.html * https://www.suse.com/security/cve/CVE-2026-53330.html * https://www.suse.com/security/cve/CVE-2026-53336.html * https://www.suse.com/security/cve/CVE-2026-53337.html * https://www.suse.com/security/cve/CVE-2026-53353.html * https://www.suse.com/security/cve/CVE-2026-53365.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://www.suse.com/security/cve/CVE-2026-53381.html * https://www.suse.com/security/cve/CVE-2026-53388.html * https://www.suse.com/security/cve/CVE-2026-63801.html * https://www.suse.com/security/cve/CVE-2026-63808.html * https://www.suse.com/security/cve/CVE-2026-63810.html * https://www.suse.com/security/cve/CVE-2026-63823.html * https://www.suse.com/security/cve/CVE-2026-63827.html * https://www.suse.com/security/cve/CVE-2026-63828.html * https://www.suse.com/security/cve/CVE-2026-63860.html * https://www.suse.com/security/cve/CVE-2026-63865.html * https://www.suse.com/security/cve/CVE-2026-63868.html * https://www.suse.com/security/cve/CVE-2026-63879.html * https://www.suse.com/security/cve/CVE-2026-63881.html * https://www.suse.com/security/cve/CVE-2026-63886.html * https://www.suse.com/security/cve/CVE-2026-63887.html * https://www.suse.com/security/cve/CVE-2026-63888.html * https://www.suse.com/security/cve/CVE-2026-63889.html * https://www.suse.com/security/cve/CVE-2026-63891.html * https://www.suse.com/security/cve/CVE-2026-63898.html * https://www.suse.com/security/cve/CVE-2026-63920.html * https://www.suse.com/security/cve/CVE-2026-63925.html * https://www.suse.com/security/cve/CVE-2026-63926.html * https://www.suse.com/security/cve/CVE-2026-63928.html * https://www.suse.com/security/cve/CVE-2026-63944.html * https://www.suse.com/security/cve/CVE-2026-63969.html * https://www.suse.com/security/cve/CVE-2026-63970.html * https://www.suse.com/security/cve/CVE-2026-63972.html * https://www.suse.com/security/cve/CVE-2026-63973.html * https://www.suse.com/security/cve/CVE-2026-63980.html * https://www.suse.com/security/cve/CVE-2026-63985.html * https://www.suse.com/security/cve/CVE-2026-63990.html * https://www.suse.com/security/cve/CVE-2026-63992.html * https://www.suse.com/security/cve/CVE-2026-63999.html * https://www.suse.com/security/cve/CVE-2026-64000.html * https://www.suse.com/security/cve/CVE-2026-64001.html * https://www.suse.com/security/cve/CVE-2026-64002.html * https://www.suse.com/security/cve/CVE-2026-64004.html * https://www.suse.com/security/cve/CVE-2026-64005.html * https://www.suse.com/security/cve/CVE-2026-64006.html * https://www.suse.com/security/cve/CVE-2026-64007.html * https://www.suse.com/security/cve/CVE-2026-64010.html * https://www.suse.com/security/cve/CVE-2026-64011.html * https://www.suse.com/security/cve/CVE-2026-64014.html * https://www.suse.com/security/cve/CVE-2026-64015.html * https://www.suse.com/security/cve/CVE-2026-64018.html * https://www.suse.com/security/cve/CVE-2026-64029.html * https://www.suse.com/security/cve/CVE-2026-64034.html * https://www.suse.com/security/cve/CVE-2026-64039.html * https://www.suse.com/security/cve/CVE-2026-64047.html * https://www.suse.com/security/cve/CVE-2026-64048.html * https://www.suse.com/security/cve/CVE-2026-64051.html * https://www.suse.com/security/cve/CVE-2026-64052.html * https://www.suse.com/security/cve/CVE-2026-64073.html * https://www.suse.com/security/cve/CVE-2026-64083.html * https://www.suse.com/security/cve/CVE-2026-64084.html * https://www.suse.com/security/cve/CVE-2026-64085.html * https://www.suse.com/security/cve/CVE-2026-64086.html * https://www.suse.com/security/cve/CVE-2026-64087.html * https://www.suse.com/security/cve/CVE-2026-64088.html * https://www.suse.com/security/cve/CVE-2026-64097.html * https://www.suse.com/security/cve/CVE-2026-64098.html * https://www.suse.com/security/cve/CVE-2026-64102.html * https://www.suse.com/security/cve/CVE-2026-64109.html * https://www.suse.com/security/cve/CVE-2026-64112.html * https://www.suse.com/security/cve/CVE-2026-64113.html * https://www.suse.com/security/cve/CVE-2026-64114.html * https://www.suse.com/security/cve/CVE-2026-64115.html * https://www.suse.com/security/cve/CVE-2026-64118.html * https://www.suse.com/security/cve/CVE-2026-64121.html * https://www.suse.com/security/cve/CVE-2026-64125.html * https://www.suse.com/security/cve/CVE-2026-64126.html * https://www.suse.com/security/cve/CVE-2026-64128.html * https://www.suse.com/security/cve/CVE-2026-64131.html * https://www.suse.com/security/cve/CVE-2026-64133.html * https://www.suse.com/security/cve/CVE-2026-64135.html * https://www.suse.com/security/cve/CVE-2026-64137.html * https://www.suse.com/security/cve/CVE-2026-64148.html * https://www.suse.com/security/cve/CVE-2026-64155.html * https://www.suse.com/security/cve/CVE-2026-64164.html * https://www.suse.com/security/cve/CVE-2026-64166.html * https://www.suse.com/security/cve/CVE-2026-64168.html * https://www.suse.com/security/cve/CVE-2026-64178.html * https://www.suse.com/security/cve/CVE-2026-64185.html * https://www.suse.com/security/cve/CVE-2026-64188.html * https://www.suse.com/security/cve/CVE-2026-64190.html * https://www.suse.com/security/cve/CVE-2026-64192.html * https://www.suse.com/security/cve/CVE-2026-64214.html * https://www.suse.com/security/cve/CVE-2026-64217.html * https://www.suse.com/security/cve/CVE-2026-64218.html * https://www.suse.com/security/cve/CVE-2026-64219.html * https://www.suse.com/security/cve/CVE-2026-64222.html * https://www.suse.com/security/cve/CVE-2026-64225.html * https://www.suse.com/security/cve/CVE-2026-64237.html * https://www.suse.com/security/cve/CVE-2026-64243.html * https://www.suse.com/security/cve/CVE-2026-64245.html * https://www.suse.com/security/cve/CVE-2026-64246.html * https://www.suse.com/security/cve/CVE-2026-64247.html * https://www.suse.com/security/cve/CVE-2026-64249.html * https://www.suse.com/security/cve/CVE-2026-64257.html * https://www.suse.com/security/cve/CVE-2026-64266.html * https://www.suse.com/security/cve/CVE-2026-64268.html * https://www.suse.com/security/cve/CVE-2026-64271.html * https://www.suse.com/security/cve/CVE-2026-64273.html * https://www.suse.com/security/cve/CVE-2026-64274.html * https://www.suse.com/security/cve/CVE-2026-64275.html * https://www.suse.com/security/cve/CVE-2026-64276.html * https://www.suse.com/security/cve/CVE-2026-64277.html * https://www.suse.com/security/cve/CVE-2026-64286.html * https://www.suse.com/security/cve/CVE-2026-64287.html * https://www.suse.com/security/cve/CVE-2026-64294.html * https://www.suse.com/security/cve/CVE-2026-64296.html * https://www.suse.com/security/cve/CVE-2026-64303.html * https://www.suse.com/security/cve/CVE-2026-64304.html * https://www.suse.com/security/cve/CVE-2026-64305.html * https://www.suse.com/security/cve/CVE-2026-64306.html * https://www.suse.com/security/cve/CVE-2026-64312.html * https://www.suse.com/security/cve/CVE-2026-64313.html * https://www.suse.com/security/cve/CVE-2026-64315.html * https://www.suse.com/security/cve/CVE-2026-64316.html * https://www.suse.com/security/cve/CVE-2026-64317.html * https://www.suse.com/security/cve/CVE-2026-64322.html * https://www.suse.com/security/cve/CVE-2026-64323.html * https://www.suse.com/security/cve/CVE-2026-64329.html * https://www.suse.com/security/cve/CVE-2026-64331.html * https://www.suse.com/security/cve/CVE-2026-64332.html * https://www.suse.com/security/cve/CVE-2026-64333.html * https://www.suse.com/security/cve/CVE-2026-64334.html * https://www.suse.com/security/cve/CVE-2026-64335.html * https://www.suse.com/security/cve/CVE-2026-64337.html * https://www.suse.com/security/cve/CVE-2026-64338.html * https://www.suse.com/security/cve/CVE-2026-64340.html * https://www.suse.com/security/cve/CVE-2026-64341.html * https://www.suse.com/security/cve/CVE-2026-64342.html * https://www.suse.com/security/cve/CVE-2026-64343.html * https://www.suse.com/security/cve/CVE-2026-64344.html * https://www.suse.com/security/cve/CVE-2026-64346.html * https://www.suse.com/security/cve/CVE-2026-64348.html * https://www.suse.com/security/cve/CVE-2026-64350.html * https://www.suse.com/security/cve/CVE-2026-64351.html * https://www.suse.com/security/cve/CVE-2026-64355.html * https://www.suse.com/security/cve/CVE-2026-64358.html * https://www.suse.com/security/cve/CVE-2026-64362.html * https://www.suse.com/security/cve/CVE-2026-64365.html * https://www.suse.com/security/cve/CVE-2026-64375.html * https://www.suse.com/security/cve/CVE-2026-64376.html * https://www.suse.com/security/cve/CVE-2026-64378.html * https://www.suse.com/security/cve/CVE-2026-64381.html * https://www.suse.com/security/cve/CVE-2026-64382.html * https://www.suse.com/security/cve/CVE-2026-64383.html * https://www.suse.com/security/cve/CVE-2026-64384.html * https://www.suse.com/security/cve/CVE-2026-64385.html * https://www.suse.com/security/cve/CVE-2026-64386.html * https://www.suse.com/security/cve/CVE-2026-64387.html * https://www.suse.com/security/cve/CVE-2026-64388.html * https://www.suse.com/security/cve/CVE-2026-64401.html * https://www.suse.com/security/cve/CVE-2026-64403.html * https://www.suse.com/security/cve/CVE-2026-64406.html * https://www.suse.com/security/cve/CVE-2026-64408.html * https://www.suse.com/security/cve/CVE-2026-64409.html * https://www.suse.com/security/cve/CVE-2026-64411.html * https://www.suse.com/security/cve/CVE-2026-64412.html * https://www.suse.com/security/cve/CVE-2026-64420.html * https://www.suse.com/security/cve/CVE-2026-64421.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64427.html * https://www.suse.com/security/cve/CVE-2026-64429.html * https://www.suse.com/security/cve/CVE-2026-64433.html * https://www.suse.com/security/cve/CVE-2026-64434.html * https://www.suse.com/security/cve/CVE-2026-64436.html * https://www.suse.com/security/cve/CVE-2026-64440.html * https://www.suse.com/security/cve/CVE-2026-64442.html * https://www.suse.com/security/cve/CVE-2026-64443.html * https://www.suse.com/security/cve/CVE-2026-64444.html * https://www.suse.com/security/cve/CVE-2026-64445.html * https://www.suse.com/security/cve/CVE-2026-64448.html * https://www.suse.com/security/cve/CVE-2026-64450.html * https://www.suse.com/security/cve/CVE-2026-64454.html * https://www.suse.com/security/cve/CVE-2026-64455.html * https://www.suse.com/security/cve/CVE-2026-64463.html * https://www.suse.com/security/cve/CVE-2026-64470.html * https://www.suse.com/security/cve/CVE-2026-64471.html * https://www.suse.com/security/cve/CVE-2026-64472.html * https://www.suse.com/security/cve/CVE-2026-64478.html * https://www.suse.com/security/cve/CVE-2026-64479.html * https://www.suse.com/security/cve/CVE-2026-64480.html * https://www.suse.com/security/cve/CVE-2026-64481.html * https://www.suse.com/security/cve/CVE-2026-64482.html * https://www.suse.com/security/cve/CVE-2026-64483.html * https://www.suse.com/security/cve/CVE-2026-64484.html * https://www.suse.com/security/cve/CVE-2026-64486.html * https://www.suse.com/security/cve/CVE-2026-64487.html * https://www.suse.com/security/cve/CVE-2026-64489.html * https://www.suse.com/security/cve/CVE-2026-64494.html * https://www.suse.com/security/cve/CVE-2026-64495.html * https://www.suse.com/security/cve/CVE-2026-64496.html * https://www.suse.com/security/cve/CVE-2026-64497.html * https://www.suse.com/security/cve/CVE-2026-64500.html * https://www.suse.com/security/cve/CVE-2026-64503.html * https://www.suse.com/security/cve/CVE-2026-64504.html * https://www.suse.com/security/cve/CVE-2026-64505.html * https://www.suse.com/security/cve/CVE-2026-64511.html * https://www.suse.com/security/cve/CVE-2026-64512.html * https://www.suse.com/security/cve/CVE-2026-64513.html * https://www.suse.com/security/cve/CVE-2026-64524.html * https://www.suse.com/security/cve/CVE-2026-64527.html * https://www.suse.com/security/cve/CVE-2026-64536.html * https://www.suse.com/security/cve/CVE-2026-64537.html * https://www.suse.com/security/cve/CVE-2026-64538.html * https://www.suse.com/security/cve/CVE-2026-64539.html * https://www.suse.com/security/cve/CVE-2026-64540.html * https://www.suse.com/security/cve/CVE-2026-64541.html * https://www.suse.com/security/cve/CVE-2026-64543.html * https://www.suse.com/security/cve/CVE-2026-64544.html * https://www.suse.com/security/cve/CVE-2026-64545.html * https://www.suse.com/security/cve/CVE-2026-64546.html * https://www.suse.com/security/cve/CVE-2026-64547.html * https://www.suse.com/security/cve/CVE-2026-64548.html * https://www.suse.com/security/cve/CVE-2026-64549.html * https://www.suse.com/security/cve/CVE-2026-64551.html * https://www.suse.com/security/cve/CVE-2026-64552.html * https://www.suse.com/security/cve/CVE-2026-64553.html * https://www.suse.com/security/cve/CVE-2026-64554.html * https://www.suse.com/security/cve/CVE-2026-64562.html * https://www.suse.com/security/cve/CVE-2026-64563.html * https://www.suse.com/security/cve/CVE-2026-64565.html * https://www.suse.com/security/cve/CVE-2026-64567.html * https://www.suse.com/security/cve/CVE-2026-64571.html * https://www.suse.com/security/cve/CVE-2026-64572.html * https://www.suse.com/security/cve/CVE-2026-64573.html * https://www.suse.com/security/cve/CVE-2026-64574.html * https://www.suse.com/security/cve/CVE-2026-64576.html * https://www.suse.com/security/cve/CVE-2026-64577.html * https://www.suse.com/security/cve/CVE-2026-64581.html * https://www.suse.com/security/cve/CVE-2026-64582.html * https://www.suse.com/security/cve/CVE-2026-64583.html * https://www.suse.com/security/cve/CVE-2026-64584.html * https://www.suse.com/security/cve/CVE-2026-64585.html * https://www.suse.com/security/cve/CVE-2026-64593.html * https://www.suse.com/security/cve/CVE-2026-64597.html * https://www.suse.com/security/cve/CVE-2026-64598.html * https://www.suse.com/security/cve/CVE-2026-64599.html * https://www.suse.com/security/cve/CVE-2026-64602.html * https://www.suse.com/security/cve/CVE-2026-64604.html * https://www.suse.com/security/cve/CVE-2026-68081.html * https://www.suse.com/security/cve/CVE-2026-68082.html * https://www.suse.com/security/cve/CVE-2026-68085.html * https://www.suse.com/security/cve/CVE-2026-68086.html * https://www.suse.com/security/cve/CVE-2026-68088.html * https://www.suse.com/security/cve/CVE-2026-68091.html * https://www.suse.com/security/cve/CVE-2026-68093.html * https://www.suse.com/security/cve/CVE-2026-68102.html * https://www.suse.com/security/cve/CVE-2026-68104.html * https://www.suse.com/security/cve/CVE-2026-68106.html * https://www.suse.com/security/cve/CVE-2026-68107.html * https://www.suse.com/security/cve/CVE-2026-68108.html * https://www.suse.com/security/cve/CVE-2026-68110.html * https://www.suse.com/security/cve/CVE-2026-68111.html * https://www.suse.com/security/cve/CVE-2026-68112.html * https://www.suse.com/security/cve/CVE-2026-68115.html * https://www.suse.com/security/cve/CVE-2026-68116.html * https://www.suse.com/security/cve/CVE-2026-68117.html * https://www.suse.com/security/cve/CVE-2026-68121.html * https://www.suse.com/security/cve/CVE-2026-68123.html * https://www.suse.com/security/cve/CVE-2026-68125.html * https://www.suse.com/security/cve/CVE-2026-68126.html * https://www.suse.com/security/cve/CVE-2026-68127.html * https://www.suse.com/security/cve/CVE-2026-68129.html * https://www.suse.com/security/cve/CVE-2026-68132.html * https://www.suse.com/security/cve/CVE-2026-68133.html * https://www.suse.com/security/cve/CVE-2026-68136.html * https://www.suse.com/security/cve/CVE-2026-68137.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://www.suse.com/security/cve/CVE-2026-68139.html * https://www.suse.com/security/cve/CVE-2026-68142.html * https://www.suse.com/security/cve/CVE-2026-68143.html * https://www.suse.com/security/cve/CVE-2026-68145.html * https://www.suse.com/security/cve/CVE-2026-68149.html * https://www.suse.com/security/cve/CVE-2026-68153.html * https://www.suse.com/security/cve/CVE-2026-68154.html * https://www.suse.com/security/cve/CVE-2026-68155.html * https://www.suse.com/security/cve/CVE-2026-68156.html * https://www.suse.com/security/cve/CVE-2026-68157.html * https://www.suse.com/security/cve/CVE-2026-68158.html * https://www.suse.com/security/cve/CVE-2026-68159.html * https://www.suse.com/security/cve/CVE-2026-68160.html * https://www.suse.com/security/cve/CVE-2026-68161.html * https://www.suse.com/security/cve/CVE-2026-68162.html * https://www.suse.com/security/cve/CVE-2026-68166.html * https://www.suse.com/security/cve/CVE-2026-68180.html * https://www.suse.com/security/cve/CVE-2026-68181.html * https://www.suse.com/security/cve/CVE-2026-68182.html * https://www.suse.com/security/cve/CVE-2026-68184.html * https://www.suse.com/security/cve/CVE-2026-68188.html * https://www.suse.com/security/cve/CVE-2026-68189.html * https://www.suse.com/security/cve/CVE-2026-68192.html * https://www.suse.com/security/cve/CVE-2026-68193.html * https://www.suse.com/security/cve/CVE-2026-68194.html * https://www.suse.com/security/cve/CVE-2026-68195.html * https://www.suse.com/security/cve/CVE-2026-68196.html * https://www.suse.com/security/cve/CVE-2026-68197.html * https://www.suse.com/security/cve/CVE-2026-68199.html * https://www.suse.com/security/cve/CVE-2026-68202.html * https://www.suse.com/security/cve/CVE-2026-68204.html * https://www.suse.com/security/cve/CVE-2026-68205.html * https://www.suse.com/security/cve/CVE-2026-68206.html * https://www.suse.com/security/cve/CVE-2026-68207.html * https://www.suse.com/security/cve/CVE-2026-68209.html * https://www.suse.com/security/cve/CVE-2026-68210.html * https://www.suse.com/security/cve/CVE-2026-68212.html * https://www.suse.com/security/cve/CVE-2026-68213.html * https://www.suse.com/security/cve/CVE-2026-68214.html * https://www.suse.com/security/cve/CVE-2026-68215.html * https://www.suse.com/security/cve/CVE-2026-68216.html * https://www.suse.com/security/cve/CVE-2026-68217.html * https://www.suse.com/security/cve/CVE-2026-68218.html * https://www.suse.com/security/cve/CVE-2026-68219.html * https://www.suse.com/security/cve/CVE-2026-68220.html * https://www.suse.com/security/cve/CVE-2026-68222.html * https://www.suse.com/security/cve/CVE-2026-68223.html * https://www.suse.com/security/cve/CVE-2026-68226.html * https://www.suse.com/security/cve/CVE-2026-68227.html * https://www.suse.com/security/cve/CVE-2026-68229.html * https://www.suse.com/security/cve/CVE-2026-68231.html * https://www.suse.com/security/cve/CVE-2026-68234.html * https://www.suse.com/security/cve/CVE-2026-68236.html * https://www.suse.com/security/cve/CVE-2026-68238.html * https://www.suse.com/security/cve/CVE-2026-68243.html * https://www.suse.com/security/cve/CVE-2026-68244.html * https://www.suse.com/security/cve/CVE-2026-68246.html * https://www.suse.com/security/cve/CVE-2026-68247.html * https://www.suse.com/security/cve/CVE-2026-68248.html * https://www.suse.com/security/cve/CVE-2026-68249.html * https://www.suse.com/security/cve/CVE-2026-68250.html * https://www.suse.com/security/cve/CVE-2026-68251.html * https://www.suse.com/security/cve/CVE-2026-68254.html * https://www.suse.com/security/cve/CVE-2026-68255.html * https://www.suse.com/security/cve/CVE-2026-68256.html * https://www.suse.com/security/cve/CVE-2026-68259.html * https://www.suse.com/security/cve/CVE-2026-68269.html * https://www.suse.com/security/cve/CVE-2026-68271.html * https://www.suse.com/security/cve/CVE-2026-68272.html * https://www.suse.com/security/cve/CVE-2026-68277.html * https://www.suse.com/security/cve/CVE-2026-68278.html * https://www.suse.com/security/cve/CVE-2026-68279.html * https://www.suse.com/security/cve/CVE-2026-68280.html * https://www.suse.com/security/cve/CVE-2026-68284.html * https://www.suse.com/security/cve/CVE-2026-68286.html * https://www.suse.com/security/cve/CVE-2026-68288.html * https://www.suse.com/security/cve/CVE-2026-68289.html * https://www.suse.com/security/cve/CVE-2026-68293.html * https://www.suse.com/security/cve/CVE-2026-68297.html * https://www.suse.com/security/cve/CVE-2026-68299.html * https://www.suse.com/security/cve/CVE-2026-68300.html * https://www.suse.com/security/cve/CVE-2026-68303.html * https://www.suse.com/security/cve/CVE-2026-68304.html * https://www.suse.com/security/cve/CVE-2026-68306.html * https://www.suse.com/security/cve/CVE-2026-68308.html * https://www.suse.com/security/cve/CVE-2026-68309.html * https://www.suse.com/security/cve/CVE-2026-68310.html * https://www.suse.com/security/cve/CVE-2026-68312.html * https://www.suse.com/security/cve/CVE-2026-68313.html * https://www.suse.com/security/cve/CVE-2026-68315.html * https://www.suse.com/security/cve/CVE-2026-68320.html * https://www.suse.com/security/cve/CVE-2026-68322.html * https://www.suse.com/security/cve/CVE-2026-68324.html * https://www.suse.com/security/cve/CVE-2026-68325.html * https://www.suse.com/security/cve/CVE-2026-68326.html * https://www.suse.com/security/cve/CVE-2026-68327.html * https://www.suse.com/security/cve/CVE-2026-68328.html * https://www.suse.com/security/cve/CVE-2026-68329.html * https://www.suse.com/security/cve/CVE-2026-68331.html * https://www.suse.com/security/cve/CVE-2026-68333.html * https://www.suse.com/security/cve/CVE-2026-68335.html * https://www.suse.com/security/cve/CVE-2026-68336.html * https://www.suse.com/security/cve/CVE-2026-68339.html * https://www.suse.com/security/cve/CVE-2026-68340.html * https://www.suse.com/security/cve/CVE-2026-68343.html * https://www.suse.com/security/cve/CVE-2026-68346.html * https://www.suse.com/security/cve/CVE-2026-68348.html * https://www.suse.com/security/cve/CVE-2026-68349.html * https://www.suse.com/security/cve/CVE-2026-68350.html * https://www.suse.com/security/cve/CVE-2026-68351.html * https://www.suse.com/security/cve/CVE-2026-68352.html * https://www.suse.com/security/cve/CVE-2026-68353.html * https://www.suse.com/security/cve/CVE-2026-68354.html * https://www.suse.com/security/cve/CVE-2026-68355.html * https://www.suse.com/security/cve/CVE-2026-68357.html * https://www.suse.com/security/cve/CVE-2026-68359.html * https://www.suse.com/security/cve/CVE-2026-68360.html * https://www.suse.com/security/cve/CVE-2026-68361.html * https://www.suse.com/security/cve/CVE-2026-68362.html * https://www.suse.com/security/cve/CVE-2026-68363.html * https://www.suse.com/security/cve/CVE-2026-68365.html * https://www.suse.com/security/cve/CVE-2026-68366.html * https://www.suse.com/security/cve/CVE-2026-68368.html * https://www.suse.com/security/cve/CVE-2026-68369.html * https://www.suse.com/security/cve/CVE-2026-68370.html * https://www.suse.com/security/cve/CVE-2026-68372.html * https://www.suse.com/security/cve/CVE-2026-68373.html * https://www.suse.com/security/cve/CVE-2026-68377.html * https://www.suse.com/security/cve/CVE-2026-68386.html * https://www.suse.com/security/cve/CVE-2026-68391.html * https://www.suse.com/security/cve/CVE-2026-68392.html * https://www.suse.com/security/cve/CVE-2026-68397.html * https://www.suse.com/security/cve/CVE-2026-68398.html * https://www.suse.com/security/cve/CVE-2026-68399.html * https://www.suse.com/security/cve/CVE-2026-68402.html * https://www.suse.com/security/cve/CVE-2026-68403.html * https://www.suse.com/security/cve/CVE-2026-68405.html * https://www.suse.com/security/cve/CVE-2026-68406.html * https://www.suse.com/security/cve/CVE-2026-68407.html * https://www.suse.com/security/cve/CVE-2026-68408.html * https://www.suse.com/security/cve/CVE-2026-68410.html * https://www.suse.com/security/cve/CVE-2026-68413.html * https://www.suse.com/security/cve/CVE-2026-68414.html * https://www.suse.com/security/cve/CVE-2026-68417.html * https://www.suse.com/security/cve/CVE-2026-68418.html * https://www.suse.com/security/cve/CVE-2026-68419.html * https://www.suse.com/security/cve/CVE-2026-68422.html * https://www.suse.com/security/cve/CVE-2026-68425.html * https://www.suse.com/security/cve/CVE-2026-68426.html * https://www.suse.com/security/cve/CVE-2026-68427.html * https://www.suse.com/security/cve/CVE-2026-68428.html * https://www.suse.com/security/cve/CVE-2026-68429.html * https://www.suse.com/security/cve/CVE-2026-68430.html * https://www.suse.com/security/cve/CVE-2026-68432.html * https://www.suse.com/security/cve/CVE-2026-68433.html * https://www.suse.com/security/cve/CVE-2026-68434.html * https://www.suse.com/security/cve/CVE-2026-68444.html * https://www.suse.com/security/cve/CVE-2026-68445.html * https://www.suse.com/security/cve/CVE-2026-68446.html * https://www.suse.com/security/cve/CVE-2026-68450.html * https://www.suse.com/security/cve/CVE-2026-68470.html * https://www.suse.com/security/cve/CVE-2026-68480.html * https://www.suse.com/security/cve/CVE-2026-72020.html * https://www.suse.com/security/cve/CVE-2026-72035.html * https://www.suse.com/security/cve/CVE-2026-72036.html * https://www.suse.com/security/cve/CVE-2026-72069.html * https://www.suse.com/security/cve/CVE-2026-72072.html * https://www.suse.com/security/cve/CVE-2026-72083.html * https://www.suse.com/security/cve/CVE-2026-72084.html * https://www.suse.com/security/cve/CVE-2026-72123.html * https://www.suse.com/security/cve/CVE-2026-72132.html * https://www.suse.com/security/cve/CVE-2026-72221.html * https://www.suse.com/security/cve/CVE-2026-72222.html * https://www.suse.com/security/cve/CVE-2026-72251.html * https://www.suse.com/security/cve/CVE-2026-72254.html * https://www.suse.com/security/cve/CVE-2026-72262.html * https://www.suse.com/security/cve/CVE-2026-72288.html * https://www.suse.com/security/cve/CVE-2026-72289.html * https://www.suse.com/security/cve/CVE-2026-72296.html * https://www.suse.com/security/cve/CVE-2026-72307.html * https://www.suse.com/security/cve/CVE-2026-72308.html * https://www.suse.com/security/cve/CVE-2026-72317.html * https://www.suse.com/security/cve/CVE-2026-72341.html * https://www.suse.com/security/cve/CVE-2026-72342.html * https://www.suse.com/security/cve/CVE-2026-72343.html * https://www.suse.com/security/cve/CVE-2026-72389.html * https://www.suse.com/security/cve/CVE-2026-72463.html * https://www.suse.com/security/cve/CVE-2026-72464.html * https://www.suse.com/security/cve/CVE-2026-72466.html * https://www.suse.com/security/cve/CVE-2026-72467.html * https://www.suse.com/security/cve/CVE-2026-72469.html * https://www.suse.com/security/cve/CVE-2026-72473.html * https://www.suse.com/security/cve/CVE-2026-72494.html * https://www.suse.com/security/cve/CVE-2026-72495.html * https://www.suse.com/security/cve/CVE-2026-72496.html * https://www.suse.com/security/cve/CVE-2026-72499.html * https://www.suse.com/security/cve/CVE-2026-72501.html * https://www.suse.com/security/cve/CVE-2026-72502.html * https://www.suse.com/security/cve/CVE-2026-74269.html * https://www.suse.com/security/cve/CVE-2026-74296.html * https://www.suse.com/security/cve/CVE-2026-74297.html * https://www.suse.com/security/cve/CVE-2026-74318.html * https://www.suse.com/security/cve/CVE-2026-74321.html * https://www.suse.com/security/cve/CVE-2026-74334.html * https://www.suse.com/security/cve/CVE-2026-74345.html * https://www.suse.com/security/cve/CVE-2026-74394.html * https://www.suse.com/security/cve/CVE-2026-74395.html * https://www.suse.com/security/cve/CVE-2026-74454.html * https://www.suse.com/security/cve/CVE-2026-74474.html * https://www.suse.com/security/cve/CVE-2026-74481.html * https://www.suse.com/security/cve/CVE-2026-74482.html * https://www.suse.com/security/cve/CVE-2026-74488.html * https://www.suse.com/security/cve/CVE-2026-74495.html * https://www.suse.com/security/cve/CVE-2026-74496.html * https://www.suse.com/security/cve/CVE-2026-74509.html * https://www.suse.com/security/cve/CVE-2026-74510.html * https://www.suse.com/security/cve/CVE-2026-74512.html * https://www.suse.com/security/cve/CVE-2026-74516.html * https://www.suse.com/security/cve/CVE-2026-74518.html * https://www.suse.com/security/cve/CVE-2026-74527.html * https://www.suse.com/security/cve/CVE-2026-74537.html * https://www.suse.com/security/cve/CVE-2026-74548.html * https://www.suse.com/security/cve/CVE-2026-74550.html * https://www.suse.com/security/cve/CVE-2026-74556.html * https://www.suse.com/security/cve/CVE-2026-74563.html * https://www.suse.com/security/cve/CVE-2026-74566.html * https://www.suse.com/security/cve/CVE-2026-74567.html * https://www.suse.com/security/cve/CVE-2026-74571.html * https://www.suse.com/security/cve/CVE-2026-74581.html * https://www.suse.com/security/cve/CVE-2026-74582.html * https://www.suse.com/security/cve/CVE-2026-74584.html * https://www.suse.com/security/cve/CVE-2026-74610.html * https://www.suse.com/security/cve/CVE-2026-74669.html * https://www.suse.com/security/cve/CVE-2026-74692.html * https://www.suse.com/security/cve/CVE-2026-74694.html * https://www.suse.com/security/cve/CVE-2026-74695.html * https://www.suse.com/security/cve/CVE-2026-74717.html * https://www.suse.com/security/cve/CVE-2026-74722.html * https://www.suse.com/security/cve/CVE-2026-80529.html * https://www.suse.com/security/cve/CVE-2026-80534.html * https://www.suse.com/security/cve/CVE-2026-80590.html * https://www.suse.com/security/cve/CVE-2026-80654.html * https://bugzilla.suse.com/show_bug.cgi?id=1230238 * https://bugzilla.suse.com/show_bug.cgi?id=1235944 * https://bugzilla.suse.com/show_bug.cgi?id=1247455 * https://bugzilla.suse.com/show_bug.cgi?id=1250748 * https://bugzilla.suse.com/show_bug.cgi?id=1251966 * https://bugzilla.suse.com/show_bug.cgi?id=1252682 * https://bugzilla.suse.com/show_bug.cgi?id=1254306 * https://bugzilla.suse.com/show_bug.cgi?id=1255225 * https://bugzilla.suse.com/show_bug.cgi?id=1255250 * https://bugzilla.suse.com/show_bug.cgi?id=1256629 * https://bugzilla.suse.com/show_bug.cgi?id=1256708 * https://bugzilla.suse.com/show_bug.cgi?id=1257154 * https://bugzilla.suse.com/show_bug.cgi?id=1258430 * https://bugzilla.suse.com/show_bug.cgi?id=1258517 * https://bugzilla.suse.com/show_bug.cgi?id=1260522 * https://bugzilla.suse.com/show_bug.cgi?id=1261780 * https://bugzilla.suse.com/show_bug.cgi?id=1261788 * https://bugzilla.suse.com/show_bug.cgi?id=1262073 * https://bugzilla.suse.com/show_bug.cgi?id=1263004 * https://bugzilla.suse.com/show_bug.cgi?id=1263061 * https://bugzilla.suse.com/show_bug.cgi?id=1263133 * https://bugzilla.suse.com/show_bug.cgi?id=1264335 * https://bugzilla.suse.com/show_bug.cgi?id=1264446 * https://bugzilla.suse.com/show_bug.cgi?id=1264541 * https://bugzilla.suse.com/show_bug.cgi?id=1264584 * https://bugzilla.suse.com/show_bug.cgi?id=1264587 * https://bugzilla.suse.com/show_bug.cgi?id=1264619 * https://bugzilla.suse.com/show_bug.cgi?id=1264788 * https://bugzilla.suse.com/show_bug.cgi?id=1265068 * https://bugzilla.suse.com/show_bug.cgi?id=1265121 * https://bugzilla.suse.com/show_bug.cgi?id=1265449 * https://bugzilla.suse.com/show_bug.cgi?id=1265928 * https://bugzilla.suse.com/show_bug.cgi?id=1266402 * https://bugzilla.suse.com/show_bug.cgi?id=1266860 * https://bugzilla.suse.com/show_bug.cgi?id=1266874 * https://bugzilla.suse.com/show_bug.cgi?id=1266897 * https://bugzilla.suse.com/show_bug.cgi?id=1267023 * https://bugzilla.suse.com/show_bug.cgi?id=1267238 * https://bugzilla.suse.com/show_bug.cgi?id=1267501 * https://bugzilla.suse.com/show_bug.cgi?id=1267612 * https://bugzilla.suse.com/show_bug.cgi?id=1268276 * https://bugzilla.suse.com/show_bug.cgi?id=1268972 * https://bugzilla.suse.com/show_bug.cgi?id=1268979 * https://bugzilla.suse.com/show_bug.cgi?id=1268987 * https://bugzilla.suse.com/show_bug.cgi?id=1269004 * https://bugzilla.suse.com/show_bug.cgi?id=1269013 * https://bugzilla.suse.com/show_bug.cgi?id=1269108 * https://bugzilla.suse.com/show_bug.cgi?id=1269113 * https://bugzilla.suse.com/show_bug.cgi?id=1269114 * https://bugzilla.suse.com/show_bug.cgi?id=1269126 * https://bugzilla.suse.com/show_bug.cgi?id=1269167 * https://bugzilla.suse.com/show_bug.cgi?id=1269234 * https://bugzilla.suse.com/show_bug.cgi?id=1269238 * https://bugzilla.suse.com/show_bug.cgi?id=1269242 * https://bugzilla.suse.com/show_bug.cgi?id=1269256 * https://bugzilla.suse.com/show_bug.cgi?id=1269301 * https://bugzilla.suse.com/show_bug.cgi?id=1269306 * https://bugzilla.suse.com/show_bug.cgi?id=1269381 * https://bugzilla.suse.com/show_bug.cgi?id=1269388 * https://bugzilla.suse.com/show_bug.cgi?id=1269412 * https://bugzilla.suse.com/show_bug.cgi?id=1269530 * https://bugzilla.suse.com/show_bug.cgi?id=1269579 * https://bugzilla.suse.com/show_bug.cgi?id=1269590 * https://bugzilla.suse.com/show_bug.cgi?id=1269635 * https://bugzilla.suse.com/show_bug.cgi?id=1269655 * https://bugzilla.suse.com/show_bug.cgi?id=1269665 * https://bugzilla.suse.com/show_bug.cgi?id=1269686 * https://bugzilla.suse.com/show_bug.cgi?id=1269695 * https://bugzilla.suse.com/show_bug.cgi?id=1269713 * https://bugzilla.suse.com/show_bug.cgi?id=1269731 * https://bugzilla.suse.com/show_bug.cgi?id=1269774 * https://bugzilla.suse.com/show_bug.cgi?id=1269783 * https://bugzilla.suse.com/show_bug.cgi?id=1269792 * https://bugzilla.suse.com/show_bug.cgi?id=1269815 * https://bugzilla.suse.com/show_bug.cgi?id=1269965 * https://bugzilla.suse.com/show_bug.cgi?id=1269969 * https://bugzilla.suse.com/show_bug.cgi?id=1269981 * https://bugzilla.suse.com/show_bug.cgi?id=1269985 * https://bugzilla.suse.com/show_bug.cgi?id=1270090 * https://bugzilla.suse.com/show_bug.cgi?id=1270108 * https://bugzilla.suse.com/show_bug.cgi?id=1270111 * https://bugzilla.suse.com/show_bug.cgi?id=1270251 * https://bugzilla.suse.com/show_bug.cgi?id=1271256 * https://bugzilla.suse.com/show_bug.cgi?id=1271365 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 * https://bugzilla.suse.com/show_bug.cgi?id=1271825 * https://bugzilla.suse.com/show_bug.cgi?id=1271830 * https://bugzilla.suse.com/show_bug.cgi?id=1272150 * https://bugzilla.suse.com/show_bug.cgi?id=1272175 * https://bugzilla.suse.com/show_bug.cgi?id=1272179 * https://bugzilla.suse.com/show_bug.cgi?id=1272182 * https://bugzilla.suse.com/show_bug.cgi?id=1272200 * https://bugzilla.suse.com/show_bug.cgi?id=1272210 * https://bugzilla.suse.com/show_bug.cgi?id=1272213 * https://bugzilla.suse.com/show_bug.cgi?id=1272230 * https://bugzilla.suse.com/show_bug.cgi?id=1272260 * https://bugzilla.suse.com/show_bug.cgi?id=1272261 * https://bugzilla.suse.com/show_bug.cgi?id=1272262 * https://bugzilla.suse.com/show_bug.cgi?id=1272297 * https://bugzilla.suse.com/show_bug.cgi?id=1272346 * https://bugzilla.suse.com/show_bug.cgi?id=1272381 * https://bugzilla.suse.com/show_bug.cgi?id=1272385 * https://bugzilla.suse.com/show_bug.cgi?id=1272390 * https://bugzilla.suse.com/show_bug.cgi?id=1272423 * https://bugzilla.suse.com/show_bug.cgi?id=1272429 * https://bugzilla.suse.com/show_bug.cgi?id=1272484 * https://bugzilla.suse.com/show_bug.cgi?id=1272486 * https://bugzilla.suse.com/show_bug.cgi?id=1272497 * https://bugzilla.suse.com/show_bug.cgi?id=1272516 * https://bugzilla.suse.com/show_bug.cgi?id=1272569 * https://bugzilla.suse.com/show_bug.cgi?id=1272571 * https://bugzilla.suse.com/show_bug.cgi?id=1272641 * https://bugzilla.suse.com/show_bug.cgi?id=1272643 * https://bugzilla.suse.com/show_bug.cgi?id=1272662 * https://bugzilla.suse.com/show_bug.cgi?id=1272673 * https://bugzilla.suse.com/show_bug.cgi?id=1272680 * https://bugzilla.suse.com/show_bug.cgi?id=1272682 * https://bugzilla.suse.com/show_bug.cgi?id=1272756 * https://bugzilla.suse.com/show_bug.cgi?id=1272786 * https://bugzilla.suse.com/show_bug.cgi?id=1272788 * https://bugzilla.suse.com/show_bug.cgi?id=1272798 * https://bugzilla.suse.com/show_bug.cgi?id=1272799 * https://bugzilla.suse.com/show_bug.cgi?id=1272868 * https://bugzilla.suse.com/show_bug.cgi?id=1272877 * https://bugzilla.suse.com/show_bug.cgi?id=1272891 * https://bugzilla.suse.com/show_bug.cgi?id=1272963 * https://bugzilla.suse.com/show_bug.cgi?id=1272983 * https://bugzilla.suse.com/show_bug.cgi?id=1273008 * https://bugzilla.suse.com/show_bug.cgi?id=1273019 * https://bugzilla.suse.com/show_bug.cgi?id=1273027 * https://bugzilla.suse.com/show_bug.cgi?id=1273028 * https://bugzilla.suse.com/show_bug.cgi?id=1273030 * https://bugzilla.suse.com/show_bug.cgi?id=1273038 * https://bugzilla.suse.com/show_bug.cgi?id=1273053 * https://bugzilla.suse.com/show_bug.cgi?id=1273054 * https://bugzilla.suse.com/show_bug.cgi?id=1273060 * https://bugzilla.suse.com/show_bug.cgi?id=1273105 * https://bugzilla.suse.com/show_bug.cgi?id=1273249 * https://bugzilla.suse.com/show_bug.cgi?id=1273250 * https://bugzilla.suse.com/show_bug.cgi?id=1273260 * https://bugzilla.suse.com/show_bug.cgi?id=1273273 * https://bugzilla.suse.com/show_bug.cgi?id=1273274 * https://bugzilla.suse.com/show_bug.cgi?id=1273276 * https://bugzilla.suse.com/show_bug.cgi?id=1273281 * https://bugzilla.suse.com/show_bug.cgi?id=1273284 * https://bugzilla.suse.com/show_bug.cgi?id=1273285 * https://bugzilla.suse.com/show_bug.cgi?id=1273289 * https://bugzilla.suse.com/show_bug.cgi?id=1273291 * https://bugzilla.suse.com/show_bug.cgi?id=1273294 * https://bugzilla.suse.com/show_bug.cgi?id=1273302 * https://bugzilla.suse.com/show_bug.cgi?id=1273303 * https://bugzilla.suse.com/show_bug.cgi?id=1273305 * https://bugzilla.suse.com/show_bug.cgi?id=1273310 * https://bugzilla.suse.com/show_bug.cgi?id=1273311 * https://bugzilla.suse.com/show_bug.cgi?id=1273316 * https://bugzilla.suse.com/show_bug.cgi?id=1273318 * https://bugzilla.suse.com/show_bug.cgi?id=1273319 * https://bugzilla.suse.com/show_bug.cgi?id=1273323 * https://bugzilla.suse.com/show_bug.cgi?id=1273325 * https://bugzilla.suse.com/show_bug.cgi?id=1273327 * https://bugzilla.suse.com/show_bug.cgi?id=1273334 * https://bugzilla.suse.com/show_bug.cgi?id=1273335 * https://bugzilla.suse.com/show_bug.cgi?id=1273336 * https://bugzilla.suse.com/show_bug.cgi?id=1273337 * https://bugzilla.suse.com/show_bug.cgi?id=1273338 * https://bugzilla.suse.com/show_bug.cgi?id=1273340 * https://bugzilla.suse.com/show_bug.cgi?id=1273341 * https://bugzilla.suse.com/show_bug.cgi?id=1273346 * https://bugzilla.suse.com/show_bug.cgi?id=1273422 * https://bugzilla.suse.com/show_bug.cgi?id=1273426 * https://bugzilla.suse.com/show_bug.cgi?id=1273443 * https://bugzilla.suse.com/show_bug.cgi?id=1273463 * https://bugzilla.suse.com/show_bug.cgi?id=1273468 * https://bugzilla.suse.com/show_bug.cgi?id=1273469 * https://bugzilla.suse.com/show_bug.cgi?id=1273471 * https://bugzilla.suse.com/show_bug.cgi?id=1273479 * https://bugzilla.suse.com/show_bug.cgi?id=1273480 * https://bugzilla.suse.com/show_bug.cgi?id=1273482 * https://bugzilla.suse.com/show_bug.cgi?id=1273484 * https://bugzilla.suse.com/show_bug.cgi?id=1273488 * https://bugzilla.suse.com/show_bug.cgi?id=1273490 * https://bugzilla.suse.com/show_bug.cgi?id=1273501 * https://bugzilla.suse.com/show_bug.cgi?id=1273503 * https://bugzilla.suse.com/show_bug.cgi?id=1273504 * https://bugzilla.suse.com/show_bug.cgi?id=1273506 * https://bugzilla.suse.com/show_bug.cgi?id=1273523 * https://bugzilla.suse.com/show_bug.cgi?id=1273525 * https://bugzilla.suse.com/show_bug.cgi?id=1273533 * https://bugzilla.suse.com/show_bug.cgi?id=1273536 * https://bugzilla.suse.com/show_bug.cgi?id=1273542 * https://bugzilla.suse.com/show_bug.cgi?id=1273555 * https://bugzilla.suse.com/show_bug.cgi?id=1273578 * https://bugzilla.suse.com/show_bug.cgi?id=1273579 * https://bugzilla.suse.com/show_bug.cgi?id=1273582 * https://bugzilla.suse.com/show_bug.cgi?id=1273596 * https://bugzilla.suse.com/show_bug.cgi?id=1273597 * https://bugzilla.suse.com/show_bug.cgi?id=1273598 * https://bugzilla.suse.com/show_bug.cgi?id=1273600 * https://bugzilla.suse.com/show_bug.cgi?id=1273601 * https://bugzilla.suse.com/show_bug.cgi?id=1273602 * https://bugzilla.suse.com/show_bug.cgi?id=1273603 * https://bugzilla.suse.com/show_bug.cgi?id=1273682 * https://bugzilla.suse.com/show_bug.cgi?id=1273734 * https://bugzilla.suse.com/show_bug.cgi?id=1273738 * https://bugzilla.suse.com/show_bug.cgi?id=1273739 * https://bugzilla.suse.com/show_bug.cgi?id=1273741 * https://bugzilla.suse.com/show_bug.cgi?id=1273742 * https://bugzilla.suse.com/show_bug.cgi?id=1273743 * https://bugzilla.suse.com/show_bug.cgi?id=1273745 * https://bugzilla.suse.com/show_bug.cgi?id=1273748 * https://bugzilla.suse.com/show_bug.cgi?id=1273749 * https://bugzilla.suse.com/show_bug.cgi?id=1273755 * https://bugzilla.suse.com/show_bug.cgi?id=1273762 * https://bugzilla.suse.com/show_bug.cgi?id=1273765 * https://bugzilla.suse.com/show_bug.cgi?id=1273766 * https://bugzilla.suse.com/show_bug.cgi?id=1273769 * https://bugzilla.suse.com/show_bug.cgi?id=1273774 * https://bugzilla.suse.com/show_bug.cgi?id=1273778 * https://bugzilla.suse.com/show_bug.cgi?id=1273780 * https://bugzilla.suse.com/show_bug.cgi?id=1273790 * https://bugzilla.suse.com/show_bug.cgi?id=1273796 * https://bugzilla.suse.com/show_bug.cgi?id=1273804 * https://bugzilla.suse.com/show_bug.cgi?id=1273810 * https://bugzilla.suse.com/show_bug.cgi?id=1273811 * https://bugzilla.suse.com/show_bug.cgi?id=1273813 * https://bugzilla.suse.com/show_bug.cgi?id=1273817 * https://bugzilla.suse.com/show_bug.cgi?id=1273822 * https://bugzilla.suse.com/show_bug.cgi?id=1273824 * https://bugzilla.suse.com/show_bug.cgi?id=1273831 * https://bugzilla.suse.com/show_bug.cgi?id=1273832 * https://bugzilla.suse.com/show_bug.cgi?id=1273834 * https://bugzilla.suse.com/show_bug.cgi?id=1273838 * https://bugzilla.suse.com/show_bug.cgi?id=1273844 * https://bugzilla.suse.com/show_bug.cgi?id=1273849 * https://bugzilla.suse.com/show_bug.cgi?id=1273860 * https://bugzilla.suse.com/show_bug.cgi?id=1273862 * https://bugzilla.suse.com/show_bug.cgi?id=1273867 * https://bugzilla.suse.com/show_bug.cgi?id=1273868 * https://bugzilla.suse.com/show_bug.cgi?id=1273869 * https://bugzilla.suse.com/show_bug.cgi?id=1273872 * https://bugzilla.suse.com/show_bug.cgi?id=1273876 * https://bugzilla.suse.com/show_bug.cgi?id=1273877 * https://bugzilla.suse.com/show_bug.cgi?id=1273880 * https://bugzilla.suse.com/show_bug.cgi?id=1273882 * https://bugzilla.suse.com/show_bug.cgi?id=1273890 * https://bugzilla.suse.com/show_bug.cgi?id=1273891 * https://bugzilla.suse.com/show_bug.cgi?id=1273892 * https://bugzilla.suse.com/show_bug.cgi?id=1273895 * https://bugzilla.suse.com/show_bug.cgi?id=1273896 * https://bugzilla.suse.com/show_bug.cgi?id=1273903 * https://bugzilla.suse.com/show_bug.cgi?id=1273905 * https://bugzilla.suse.com/show_bug.cgi?id=1273930 * https://bugzilla.suse.com/show_bug.cgi?id=1273933 * https://bugzilla.suse.com/show_bug.cgi?id=1273934 * https://bugzilla.suse.com/show_bug.cgi?id=1273935 * https://bugzilla.suse.com/show_bug.cgi?id=1273936 * https://bugzilla.suse.com/show_bug.cgi?id=1273939 * https://bugzilla.suse.com/show_bug.cgi?id=1273940 * https://bugzilla.suse.com/show_bug.cgi?id=1273941 * https://bugzilla.suse.com/show_bug.cgi?id=1273942 * https://bugzilla.suse.com/show_bug.cgi?id=1273944 * https://bugzilla.suse.com/show_bug.cgi?id=1273945 * https://bugzilla.suse.com/show_bug.cgi?id=1273946 * https://bugzilla.suse.com/show_bug.cgi?id=1273956 * https://bugzilla.suse.com/show_bug.cgi?id=1273957 * https://bugzilla.suse.com/show_bug.cgi?id=1273958 * https://bugzilla.suse.com/show_bug.cgi?id=1273966 * https://bugzilla.suse.com/show_bug.cgi?id=1273967 * https://bugzilla.suse.com/show_bug.cgi?id=1273968 * https://bugzilla.suse.com/show_bug.cgi?id=1273972 * https://bugzilla.suse.com/show_bug.cgi?id=1273974 * https://bugzilla.suse.com/show_bug.cgi?id=1273975 * https://bugzilla.suse.com/show_bug.cgi?id=1273977 * https://bugzilla.suse.com/show_bug.cgi?id=1273982 * https://bugzilla.suse.com/show_bug.cgi?id=1273988 * https://bugzilla.suse.com/show_bug.cgi?id=1273990 * https://bugzilla.suse.com/show_bug.cgi?id=1273991 * https://bugzilla.suse.com/show_bug.cgi?id=1273995 * https://bugzilla.suse.com/show_bug.cgi?id=1274001 * https://bugzilla.suse.com/show_bug.cgi?id=1274003 * https://bugzilla.suse.com/show_bug.cgi?id=1274006 * https://bugzilla.suse.com/show_bug.cgi?id=1274011 * https://bugzilla.suse.com/show_bug.cgi?id=1274012 * https://bugzilla.suse.com/show_bug.cgi?id=1274014 * https://bugzilla.suse.com/show_bug.cgi?id=1274017 * https://bugzilla.suse.com/show_bug.cgi?id=1274019 * https://bugzilla.suse.com/show_bug.cgi?id=1274020 * https://bugzilla.suse.com/show_bug.cgi?id=1274026 * https://bugzilla.suse.com/show_bug.cgi?id=1274028 * https://bugzilla.suse.com/show_bug.cgi?id=1274030 * https://bugzilla.suse.com/show_bug.cgi?id=1274031 * https://bugzilla.suse.com/show_bug.cgi?id=1274035 * https://bugzilla.suse.com/show_bug.cgi?id=1274040 * https://bugzilla.suse.com/show_bug.cgi?id=1274041 * https://bugzilla.suse.com/show_bug.cgi?id=1274057 * https://bugzilla.suse.com/show_bug.cgi?id=1274058 * https://bugzilla.suse.com/show_bug.cgi?id=1274061 * https://bugzilla.suse.com/show_bug.cgi?id=1274063 * https://bugzilla.suse.com/show_bug.cgi?id=1274065 * https://bugzilla.suse.com/show_bug.cgi?id=1274067 * https://bugzilla.suse.com/show_bug.cgi?id=1274075 * https://bugzilla.suse.com/show_bug.cgi?id=1274076 * https://bugzilla.suse.com/show_bug.cgi?id=1274077 * https://bugzilla.suse.com/show_bug.cgi?id=1274078 * https://bugzilla.suse.com/show_bug.cgi?id=1274208 * https://bugzilla.suse.com/show_bug.cgi?id=1274226 * https://bugzilla.suse.com/show_bug.cgi?id=1274239 * https://bugzilla.suse.com/show_bug.cgi?id=1274243 * https://bugzilla.suse.com/show_bug.cgi?id=1274258 * https://bugzilla.suse.com/show_bug.cgi?id=1274265 * https://bugzilla.suse.com/show_bug.cgi?id=1274274 * https://bugzilla.suse.com/show_bug.cgi?id=1274277 * https://bugzilla.suse.com/show_bug.cgi?id=1274278 * https://bugzilla.suse.com/show_bug.cgi?id=1274281 * https://bugzilla.suse.com/show_bug.cgi?id=1274283 * https://bugzilla.suse.com/show_bug.cgi?id=1274286 * https://bugzilla.suse.com/show_bug.cgi?id=1274290 * https://bugzilla.suse.com/show_bug.cgi?id=1274294 * https://bugzilla.suse.com/show_bug.cgi?id=1274296 * https://bugzilla.suse.com/show_bug.cgi?id=1274297 * https://bugzilla.suse.com/show_bug.cgi?id=1274298 * https://bugzilla.suse.com/show_bug.cgi?id=1274314 * https://bugzilla.suse.com/show_bug.cgi?id=1274321 * https://bugzilla.suse.com/show_bug.cgi?id=1274491 * https://bugzilla.suse.com/show_bug.cgi?id=1274497 * https://bugzilla.suse.com/show_bug.cgi?id=1274539 * https://bugzilla.suse.com/show_bug.cgi?id=1274541 * https://bugzilla.suse.com/show_bug.cgi?id=1274543 * https://bugzilla.suse.com/show_bug.cgi?id=1274545 * https://bugzilla.suse.com/show_bug.cgi?id=1274547 * https://bugzilla.suse.com/show_bug.cgi?id=1274550 * https://bugzilla.suse.com/show_bug.cgi?id=1274573 * https://bugzilla.suse.com/show_bug.cgi?id=1274578 * https://bugzilla.suse.com/show_bug.cgi?id=1274580 * https://bugzilla.suse.com/show_bug.cgi?id=1274581 * https://bugzilla.suse.com/show_bug.cgi?id=1274620 * https://bugzilla.suse.com/show_bug.cgi?id=1274622 * https://bugzilla.suse.com/show_bug.cgi?id=1274624 * https://bugzilla.suse.com/show_bug.cgi?id=1274629 * https://bugzilla.suse.com/show_bug.cgi?id=1274632 * https://bugzilla.suse.com/show_bug.cgi?id=1274636 * https://bugzilla.suse.com/show_bug.cgi?id=1274639 * https://bugzilla.suse.com/show_bug.cgi?id=1274640 * https://bugzilla.suse.com/show_bug.cgi?id=1274642 * https://bugzilla.suse.com/show_bug.cgi?id=1274644 * https://bugzilla.suse.com/show_bug.cgi?id=1274645 * https://bugzilla.suse.com/show_bug.cgi?id=1274646 * https://bugzilla.suse.com/show_bug.cgi?id=1274649 * https://bugzilla.suse.com/show_bug.cgi?id=1274650 * https://bugzilla.suse.com/show_bug.cgi?id=1274651 * https://bugzilla.suse.com/show_bug.cgi?id=1274656 * https://bugzilla.suse.com/show_bug.cgi?id=1274659 * https://bugzilla.suse.com/show_bug.cgi?id=1274662 * https://bugzilla.suse.com/show_bug.cgi?id=1274663 * https://bugzilla.suse.com/show_bug.cgi?id=1274665 * https://bugzilla.suse.com/show_bug.cgi?id=1274667 * https://bugzilla.suse.com/show_bug.cgi?id=1274670 * https://bugzilla.suse.com/show_bug.cgi?id=1274675 * https://bugzilla.suse.com/show_bug.cgi?id=1274677 * https://bugzilla.suse.com/show_bug.cgi?id=1274678 * https://bugzilla.suse.com/show_bug.cgi?id=1274679 * https://bugzilla.suse.com/show_bug.cgi?id=1274681 * https://bugzilla.suse.com/show_bug.cgi?id=1274682 * https://bugzilla.suse.com/show_bug.cgi?id=1274690 * https://bugzilla.suse.com/show_bug.cgi?id=1274694 * https://bugzilla.suse.com/show_bug.cgi?id=1274696 * https://bugzilla.suse.com/show_bug.cgi?id=1274698 * https://bugzilla.suse.com/show_bug.cgi?id=1274699 * https://bugzilla.suse.com/show_bug.cgi?id=1274700 * https://bugzilla.suse.com/show_bug.cgi?id=1274702 * https://bugzilla.suse.com/show_bug.cgi?id=1274703 * https://bugzilla.suse.com/show_bug.cgi?id=1274705 * https://bugzilla.suse.com/show_bug.cgi?id=1274706 * https://bugzilla.suse.com/show_bug.cgi?id=1274709 * https://bugzilla.suse.com/show_bug.cgi?id=1274710 * https://bugzilla.suse.com/show_bug.cgi?id=1274713 * https://bugzilla.suse.com/show_bug.cgi?id=1274716 * https://bugzilla.suse.com/show_bug.cgi?id=1274721 * https://bugzilla.suse.com/show_bug.cgi?id=1274725 * https://bugzilla.suse.com/show_bug.cgi?id=1274737 * https://bugzilla.suse.com/show_bug.cgi?id=1274738 * https://bugzilla.suse.com/show_bug.cgi?id=1274749 * https://bugzilla.suse.com/show_bug.cgi?id=1274752 * https://bugzilla.suse.com/show_bug.cgi?id=1274753 * https://bugzilla.suse.com/show_bug.cgi?id=1274754 * https://bugzilla.suse.com/show_bug.cgi?id=1274755 * https://bugzilla.suse.com/show_bug.cgi?id=1274756 * https://bugzilla.suse.com/show_bug.cgi?id=1274764 * https://bugzilla.suse.com/show_bug.cgi?id=1274768 * https://bugzilla.suse.com/show_bug.cgi?id=1274770 * https://bugzilla.suse.com/show_bug.cgi?id=1274787 * https://bugzilla.suse.com/show_bug.cgi?id=1274800 * https://bugzilla.suse.com/show_bug.cgi?id=1274801 * https://bugzilla.suse.com/show_bug.cgi?id=1274802 * https://bugzilla.suse.com/show_bug.cgi?id=1274804 * https://bugzilla.suse.com/show_bug.cgi?id=1274805 * https://bugzilla.suse.com/show_bug.cgi?id=1274807 * https://bugzilla.suse.com/show_bug.cgi?id=1274808 * https://bugzilla.suse.com/show_bug.cgi?id=1274811 * https://bugzilla.suse.com/show_bug.cgi?id=1274813 * https://bugzilla.suse.com/show_bug.cgi?id=1274814 * https://bugzilla.suse.com/show_bug.cgi?id=1274831 * https://bugzilla.suse.com/show_bug.cgi?id=1274834 * https://bugzilla.suse.com/show_bug.cgi?id=1274847 * https://bugzilla.suse.com/show_bug.cgi?id=1274853 * https://bugzilla.suse.com/show_bug.cgi?id=1274868 * https://bugzilla.suse.com/show_bug.cgi?id=1274869 * https://bugzilla.suse.com/show_bug.cgi?id=1274872 * https://bugzilla.suse.com/show_bug.cgi?id=1274873 * https://bugzilla.suse.com/show_bug.cgi?id=1274874 * https://bugzilla.suse.com/show_bug.cgi?id=1274876 * https://bugzilla.suse.com/show_bug.cgi?id=1274879 * https://bugzilla.suse.com/show_bug.cgi?id=1274881 * https://bugzilla.suse.com/show_bug.cgi?id=1274883 * https://bugzilla.suse.com/show_bug.cgi?id=1274886 * https://bugzilla.suse.com/show_bug.cgi?id=1274888 * https://bugzilla.suse.com/show_bug.cgi?id=1274891 * https://bugzilla.suse.com/show_bug.cgi?id=1274892 * https://bugzilla.suse.com/show_bug.cgi?id=1274893 * https://bugzilla.suse.com/show_bug.cgi?id=1274894 * https://bugzilla.suse.com/show_bug.cgi?id=1274896 * https://bugzilla.suse.com/show_bug.cgi?id=1274897 * https://bugzilla.suse.com/show_bug.cgi?id=1274898 * https://bugzilla.suse.com/show_bug.cgi?id=1274899 * https://bugzilla.suse.com/show_bug.cgi?id=1274901 * https://bugzilla.suse.com/show_bug.cgi?id=1274902 * https://bugzilla.suse.com/show_bug.cgi?id=1274905 * https://bugzilla.suse.com/show_bug.cgi?id=1274907 * https://bugzilla.suse.com/show_bug.cgi?id=1274908 * https://bugzilla.suse.com/show_bug.cgi?id=1274913 * https://bugzilla.suse.com/show_bug.cgi?id=1274914 * https://bugzilla.suse.com/show_bug.cgi?id=1274920 * https://bugzilla.suse.com/show_bug.cgi?id=1274921 * https://bugzilla.suse.com/show_bug.cgi?id=1274924 * https://bugzilla.suse.com/show_bug.cgi?id=1274925 * https://bugzilla.suse.com/show_bug.cgi?id=1274929 * https://bugzilla.suse.com/show_bug.cgi?id=1274930 * https://bugzilla.suse.com/show_bug.cgi?id=1274933 * https://bugzilla.suse.com/show_bug.cgi?id=1274934 * https://bugzilla.suse.com/show_bug.cgi?id=1274935 * https://bugzilla.suse.com/show_bug.cgi?id=1274941 * https://bugzilla.suse.com/show_bug.cgi?id=1274945 * https://bugzilla.suse.com/show_bug.cgi?id=1274947 * https://bugzilla.suse.com/show_bug.cgi?id=1274951 * https://bugzilla.suse.com/show_bug.cgi?id=1274953 * https://bugzilla.suse.com/show_bug.cgi?id=1274958 * https://bugzilla.suse.com/show_bug.cgi?id=1274968 * https://bugzilla.suse.com/show_bug.cgi?id=1274981 * https://bugzilla.suse.com/show_bug.cgi?id=1275040 * https://bugzilla.suse.com/show_bug.cgi?id=1275069 * https://bugzilla.suse.com/show_bug.cgi?id=1275071 * https://bugzilla.suse.com/show_bug.cgi?id=1275073 * https://bugzilla.suse.com/show_bug.cgi?id=1275076 * https://bugzilla.suse.com/show_bug.cgi?id=1275080 * https://bugzilla.suse.com/show_bug.cgi?id=1275083 * https://bugzilla.suse.com/show_bug.cgi?id=1275088 * https://bugzilla.suse.com/show_bug.cgi?id=1275091 * https://bugzilla.suse.com/show_bug.cgi?id=1275125 * https://bugzilla.suse.com/show_bug.cgi?id=1275126 * https://bugzilla.suse.com/show_bug.cgi?id=1275131 * https://bugzilla.suse.com/show_bug.cgi?id=1275132 * https://bugzilla.suse.com/show_bug.cgi?id=1275150 * https://bugzilla.suse.com/show_bug.cgi?id=1275152 * https://bugzilla.suse.com/show_bug.cgi?id=1275154 * https://bugzilla.suse.com/show_bug.cgi?id=1275155 * https://bugzilla.suse.com/show_bug.cgi?id=1275157 * https://bugzilla.suse.com/show_bug.cgi?id=1275158 * https://bugzilla.suse.com/show_bug.cgi?id=1275161 * https://bugzilla.suse.com/show_bug.cgi?id=1275163 * https://bugzilla.suse.com/show_bug.cgi?id=1275164 * https://bugzilla.suse.com/show_bug.cgi?id=1275169 * https://bugzilla.suse.com/show_bug.cgi?id=1275173 * https://bugzilla.suse.com/show_bug.cgi?id=1275176 * https://bugzilla.suse.com/show_bug.cgi?id=1275185 * https://bugzilla.suse.com/show_bug.cgi?id=1275190 * https://bugzilla.suse.com/show_bug.cgi?id=1275236 * https://bugzilla.suse.com/show_bug.cgi?id=1275237 * https://bugzilla.suse.com/show_bug.cgi?id=1275239 * https://bugzilla.suse.com/show_bug.cgi?id=1275294 * https://bugzilla.suse.com/show_bug.cgi?id=1275301 * https://bugzilla.suse.com/show_bug.cgi?id=1275303 * https://bugzilla.suse.com/show_bug.cgi?id=1275304 * https://bugzilla.suse.com/show_bug.cgi?id=1275305 * https://bugzilla.suse.com/show_bug.cgi?id=1275306 * https://bugzilla.suse.com/show_bug.cgi?id=1275307 * https://bugzilla.suse.com/show_bug.cgi?id=1275470 * https://bugzilla.suse.com/show_bug.cgi?id=1275472 * https://bugzilla.suse.com/show_bug.cgi?id=1275474 * https://bugzilla.suse.com/show_bug.cgi?id=1275479 * https://bugzilla.suse.com/show_bug.cgi?id=1275483 * https://bugzilla.suse.com/show_bug.cgi?id=1275486 * https://bugzilla.suse.com/show_bug.cgi?id=1275487 * https://bugzilla.suse.com/show_bug.cgi?id=1275506 * https://bugzilla.suse.com/show_bug.cgi?id=1275509 * https://bugzilla.suse.com/show_bug.cgi?id=1275511 * https://bugzilla.suse.com/show_bug.cgi?id=1275517 * https://bugzilla.suse.com/show_bug.cgi?id=1275528 * https://bugzilla.suse.com/show_bug.cgi?id=1275535 * https://bugzilla.suse.com/show_bug.cgi?id=1275540 * https://bugzilla.suse.com/show_bug.cgi?id=1275553 * https://bugzilla.suse.com/show_bug.cgi?id=1275555 * https://bugzilla.suse.com/show_bug.cgi?id=1275561 * https://bugzilla.suse.com/show_bug.cgi?id=1275566 * https://bugzilla.suse.com/show_bug.cgi?id=1275569 * https://bugzilla.suse.com/show_bug.cgi?id=1275574 * https://bugzilla.suse.com/show_bug.cgi?id=1275578 * https://bugzilla.suse.com/show_bug.cgi?id=1275582 * https://bugzilla.suse.com/show_bug.cgi?id=1275583 * https://bugzilla.suse.com/show_bug.cgi?id=1275584 * https://bugzilla.suse.com/show_bug.cgi?id=1275591 * https://bugzilla.suse.com/show_bug.cgi?id=1275595 * https://bugzilla.suse.com/show_bug.cgi?id=1275633 * https://bugzilla.suse.com/show_bug.cgi?id=1275636 * https://bugzilla.suse.com/show_bug.cgi?id=1275650 * https://bugzilla.suse.com/show_bug.cgi?id=1275659 * https://bugzilla.suse.com/show_bug.cgi?id=1275665 * https://bugzilla.suse.com/show_bug.cgi?id=1275669 * https://bugzilla.suse.com/show_bug.cgi?id=1275687 * https://bugzilla.suse.com/show_bug.cgi?id=1275688 * https://bugzilla.suse.com/show_bug.cgi?id=1275695 * https://bugzilla.suse.com/show_bug.cgi?id=1275696 * https://bugzilla.suse.com/show_bug.cgi?id=1275704 * https://bugzilla.suse.com/show_bug.cgi?id=1275782 * https://bugzilla.suse.com/show_bug.cgi?id=1275784 * https://bugzilla.suse.com/show_bug.cgi?id=1275787 * https://bugzilla.suse.com/show_bug.cgi?id=1275788 * https://bugzilla.suse.com/show_bug.cgi?id=1275790 * https://bugzilla.suse.com/show_bug.cgi?id=1275797 * https://bugzilla.suse.com/show_bug.cgi?id=1275798 * https://bugzilla.suse.com/show_bug.cgi?id=1275805 * https://bugzilla.suse.com/show_bug.cgi?id=1275817 * https://bugzilla.suse.com/show_bug.cgi?id=1275818 * https://bugzilla.suse.com/show_bug.cgi?id=1275819 * https://bugzilla.suse.com/show_bug.cgi?id=1275820 * https://bugzilla.suse.com/show_bug.cgi?id=1275821 * https://bugzilla.suse.com/show_bug.cgi?id=1275827 * https://bugzilla.suse.com/show_bug.cgi?id=1275864 * https://bugzilla.suse.com/show_bug.cgi?id=1275867 * https://bugzilla.suse.com/show_bug.cgi?id=1275869 * https://bugzilla.suse.com/show_bug.cgi?id=1275870 * https://bugzilla.suse.com/show_bug.cgi?id=1275871 * https://bugzilla.suse.com/show_bug.cgi?id=1275872 * https://bugzilla.suse.com/show_bug.cgi?id=1275886 * https://bugzilla.suse.com/show_bug.cgi?id=1275905 * https://bugzilla.suse.com/show_bug.cgi?id=1275923 * https://bugzilla.suse.com/show_bug.cgi?id=1275925 * https://bugzilla.suse.com/show_bug.cgi?id=1275946 * https://bugzilla.suse.com/show_bug.cgi?id=1275950 * https://bugzilla.suse.com/show_bug.cgi?id=1275954 * https://bugzilla.suse.com/show_bug.cgi?id=1275970 * https://bugzilla.suse.com/show_bug.cgi?id=1275973 * https://bugzilla.suse.com/show_bug.cgi?id=1275975 * https://bugzilla.suse.com/show_bug.cgi?id=1275976 * https://bugzilla.suse.com/show_bug.cgi?id=1276029 * https://bugzilla.suse.com/show_bug.cgi?id=1276257 * https://bugzilla.suse.com/show_bug.cgi?id=1276263 * https://bugzilla.suse.com/show_bug.cgi?id=1276270 * https://bugzilla.suse.com/show_bug.cgi?id=1276273 * https://bugzilla.suse.com/show_bug.cgi?id=1276277 * https://bugzilla.suse.com/show_bug.cgi?id=1276335 * https://bugzilla.suse.com/show_bug.cgi?id=1276346 * https://bugzilla.suse.com/show_bug.cgi?id=1276350 * https://bugzilla.suse.com/show_bug.cgi?id=1276355 * https://bugzilla.suse.com/show_bug.cgi?id=1276446 * https://bugzilla.suse.com/show_bug.cgi?id=1276452 * https://bugzilla.suse.com/show_bug.cgi?id=1276500 * https://bugzilla.suse.com/show_bug.cgi?id=1276507 * https://bugzilla.suse.com/show_bug.cgi?id=1276542 * https://bugzilla.suse.com/show_bug.cgi?id=1276546 * https://bugzilla.suse.com/show_bug.cgi?id=1276551 * https://bugzilla.suse.com/show_bug.cgi?id=1276561 * https://bugzilla.suse.com/show_bug.cgi?id=1276569 * https://bugzilla.suse.com/show_bug.cgi?id=1276665 * https://bugzilla.suse.com/show_bug.cgi?id=1276864 * https://bugzilla.suse.com/show_bug.cgi?id=1276927 * https://bugzilla.suse.com/show_bug.cgi?id=1276931 * https://bugzilla.suse.com/show_bug.cgi?id=1276937 * https://bugzilla.suse.com/show_bug.cgi?id=1276941 * https://bugzilla.suse.com/show_bug.cgi?id=1276943 * https://bugzilla.suse.com/show_bug.cgi?id=1276961 * https://bugzilla.suse.com/show_bug.cgi?id=1277022 * https://bugzilla.suse.com/show_bug.cgi?id=1277034 * https://bugzilla.suse.com/show_bug.cgi?id=1277037 * https://bugzilla.suse.com/show_bug.cgi?id=1277047 * https://bugzilla.suse.com/show_bug.cgi?id=1277054 * https://bugzilla.suse.com/show_bug.cgi?id=1277057 * https://bugzilla.suse.com/show_bug.cgi?id=1277059 * https://bugzilla.suse.com/show_bug.cgi?id=1277064 * https://bugzilla.suse.com/show_bug.cgi?id=1277066 * https://bugzilla.suse.com/show_bug.cgi?id=1277069 * https://bugzilla.suse.com/show_bug.cgi?id=1277073 * https://bugzilla.suse.com/show_bug.cgi?id=1277077 * https://bugzilla.suse.com/show_bug.cgi?id=1277095 * https://bugzilla.suse.com/show_bug.cgi?id=1277155 * https://bugzilla.suse.com/show_bug.cgi?id=1277159 * https://bugzilla.suse.com/show_bug.cgi?id=1277160 * https://bugzilla.suse.com/show_bug.cgi?id=1277202 * https://bugzilla.suse.com/show_bug.cgi?id=1277204 * https://bugzilla.suse.com/show_bug.cgi?id=1277275 * https://bugzilla.suse.com/show_bug.cgi?id=1277285 * https://bugzilla.suse.com/show_bug.cgi?id=1277391 * https://bugzilla.suse.com/show_bug.cgi?id=1277408 * https://bugzilla.suse.com/show_bug.cgi?id=1277516 * https://bugzilla.suse.com/show_bug.cgi?id=1277523 * https://bugzilla.suse.com/show_bug.cgi?id=1277551 * https://bugzilla.suse.com/show_bug.cgi?id=1277625 * https://bugzilla.suse.com/show_bug.cgi?id=1277660 * https://bugzilla.suse.com/show_bug.cgi?id=1277678 * https://bugzilla.suse.com/show_bug.cgi?id=1277688 * https://bugzilla.suse.com/show_bug.cgi?id=1277775 * https://bugzilla.suse.com/show_bug.cgi?id=1277776 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 11 20:31:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 11 Sep 2026 20:31:03 -0000 Subject: SUSE-SU-2026:23543-1: moderate: Security update for opensc Message-ID: <178915866301.7360.16559529628689796016@d0473b53b788> # Security update for opensc Announcement ID: SUSE-SU-2026:23543-1 Release Date: 2026-09-09T14:08:11Z Rating: moderate References: * bsc#1266964 Cross-References: * CVE-2026-40510 CVSS scores: * CVE-2026-40510 ( SUSE ): 4.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-40510 ( SUSE ): 5.7 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-40510 ( NVD ): 1.0 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40510 ( NVD ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-40510 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for opensc fixes the following issue: * CVE-2026-40510: stack buffer overflow in `piv_process_history()` allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device (bsc#1266964). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1648=1 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * opensc-debuginfo-0.26.1-160000.4.1 * opensc-0.26.1-160000.4.1 * opensc-debugsource-0.26.1-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40510.html * https://bugzilla.suse.com/show_bug.cgi?id=1266964 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 08:30:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 08:30:50 -0000 Subject: SUSE-SU-2026:2834-2: important: Security update for clamav Message-ID: <178937465082.11463.2843542208925319331@c8813f945ae1> # Security update for clamav Announcement ID: SUSE-SU-2026:2834-2 Release Date: 2026-09-13T04:03:50Z Rating: important References: * bsc#1270085 * bsc#1270088 * bsc#1270089 * bsc#1270091 * bsc#1270092 * bsc#1270106 * bsc#1270107 * bsc#1270138 Cross-References: * CVE-2026-20213 * CVE-2026-20214 * CVE-2026-20215 * CVE-2026-20216 * CVE-2026-20217 * CVE-2026-20243 * CVE-2026-20244 * CVE-2026-41676 CVSS scores: * CVE-2026-20213 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20213 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20214 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20215 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20216 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20217 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20244 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Micro 5.5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues * CVE-2026-20213: PE file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270107). * CVE-2026-20214: FSG file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270085). * CVE-2026-20215: 7z file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270088). * CVE-2026-20216: InstallShield file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270089). * CVE-2026-20217: PESpin file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270091). * CVE-2026-20243: ALZ file format parser could allow an unauthenticated, remote attacker to cause a denial of service (bsc#1270092). * CVE-2026-20244: DMG file format parser could allow an unauthenticated, remote attacker to cause a denial of service on 32-bit platforms only (bsc#1270106). * CVE-2026-41676: rust-openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270138). Changes for clamav: * Update to 1.5.3: * Hardened clamscan, clamdscan, and clamonacc quarantine actions against time- of-check/time-of-use races that could redirect copied, moved, or removed files under unsafe quarantine directory configurations. * Raised the minimum required CMake version to 3.17 to fix Linux builds with libcurl v8.21.0 when linking static library dependencies. * Metadata preclass scans now run before the final scan verdict. * ClamOnAcc: Fixed errors when recursively excluded paths are children of an included path. * ClamOnAcc: Fixed hash bucket list corruption when two watched paths collide in the same bucket. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-2834=1 ## Package List: * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * clamav-1.5.3-150400.13.8.1 * libclamav12-1.5.3-150400.13.8.1 * libfreshclam4-debuginfo-1.5.3-150400.13.8.1 * clamav-debuginfo-1.5.3-150400.13.8.1 * libclammspack0-debuginfo-1.5.3-150400.13.8.1 * libfreshclam4-1.5.3-150400.13.8.1 * libclamav12-debuginfo-1.5.3-150400.13.8.1 * libclammspack0-1.5.3-150400.13.8.1 * clamav-debugsource-1.5.3-150400.13.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20213.html * https://www.suse.com/security/cve/CVE-2026-20214.html * https://www.suse.com/security/cve/CVE-2026-20215.html * https://www.suse.com/security/cve/CVE-2026-20216.html * https://www.suse.com/security/cve/CVE-2026-20217.html * https://www.suse.com/security/cve/CVE-2026-20243.html * https://www.suse.com/security/cve/CVE-2026-20244.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1270085 * https://bugzilla.suse.com/show_bug.cgi?id=1270088 * https://bugzilla.suse.com/show_bug.cgi?id=1270089 * https://bugzilla.suse.com/show_bug.cgi?id=1270091 * https://bugzilla.suse.com/show_bug.cgi?id=1270092 * https://bugzilla.suse.com/show_bug.cgi?id=1270106 * https://bugzilla.suse.com/show_bug.cgi?id=1270107 * https://bugzilla.suse.com/show_bug.cgi?id=1270138 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 12:30:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 12:30:38 -0000 Subject: SUSE-SU-2026:4154-1: important: Security update for ansible-core Message-ID: <178938903870.17839.6859487543839121901@b9be41dc2e4b> # Security update for ansible-core Announcement ID: SUSE-SU-2026:4154-1 Release Date: 2026-09-14T08:06:52Z Rating: important References: * bsc#1272369 Cross-References: * CVE-2026-11332 * CVE-2026-16493 CVSS scores: * CVE-2026-11332 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11332 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11332 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16493 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16493 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 * Systems Management Module 15-SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for ansible-core fixes the following issues: * CVE-2026-16493: argument injection in ansible-galaxy collection install via git clone (bsc#1272369). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4154 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4154 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4154 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4154 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4154 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4154 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4154 * Systems Management Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Systems-Management-15-SP7-2026-4154 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4154 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * ansible-core-2.18.3-150400.9.17.1 * openSUSE Leap 15.4 (noarch) * ansible-core-2.18.3-150400.9.17.1 * ansible-test-2.18.3-150400.9.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * ansible-core-2.18.3-150400.9.17.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * ansible-core-2.18.3-150400.9.17.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * ansible-core-2.18.3-150400.9.17.1 * SUSE Package Hub 15 15-SP7 (noarch) * ansible-test-2.18.3-150400.9.17.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * ansible-core-2.18.3-150400.9.17.1 * Systems Management Module 15-SP7 (noarch) * ansible-core-2.18.3-150400.9.17.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * ansible-core-2.18.3-150400.9.17.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11332.html * https://www.suse.com/security/cve/CVE-2026-16493.html * https://bugzilla.suse.com/show_bug.cgi?id=1272369 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 12:31:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 12:31:53 -0000 Subject: SUSE-SU-2026:4153-1: important: Security update for java-1_8_0-ibm Message-ID: <178938911373.17839.6264581591216742668@b9be41dc2e4b> # Security update for java-1_8_0-ibm Announcement ID: SUSE-SU-2026:4153-1 Release Date: 2026-09-14T08:05:16Z Rating: important References: * bsc#1274275 * bsc#1274276 * bsc#1275763 * bsc#1275764 * bsc#1275777 * bsc#1275778 * bsc#1275779 * bsc#1277019 * bsc#1277833 Cross-References: * CVE-2026-16243 * CVE-2026-16440 * CVE-2026-60589 * CVE-2026-61308 * CVE-2026-70906 * CVE-2026-70907 * CVE-2026-71054 * CVE-2026-8400 CVSS scores: * CVE-2026-16243 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-16243 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-16243 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-16243 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16440 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-60589 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-60589 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61308 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-61308 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-70906 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-70906 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-70907 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-70907 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-71054 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-71054 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-8400 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-8400 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-8400 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-8400 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Legacy Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves eight vulnerabilities and has one security fix can now be installed. ## Description: This update for java-1_8_0-ibm fixes the following issues: Update to Java 8.0 Service Refresh 8 Fix Pack 71 (bsc#1277833): * CVE-2026-8400: flaw in the ORB component may allow a malicious IIOP server to induce loading and instantation of arbitrary classes (bsc#1274276). * CVE-2026-16243: `arraycmp` SIMD implementation for Z and P does not check if the number of bytes to compare is zero (bsc#1274275). * CVE-2026-16440: a crafted .class file with deeply nested annotations causes a segmentation fault (bsc#1275779). * CVE-2026-60589: OpenJDK: Improve Resource Resolving (bsc#1275777). * CVE-2026-61308: OpenJDK: Enhance HTTP Connections (bsc#1275778). * CVE-2026-70906: OpenJDK: Improve font loading (bsc#1275763). * CVE-2026-70907: OpenJDK: Enhance TLS server (bsc#1275764). * CVE-2026-71054: Vulnerability in Oracle Java SE (component: 2D) (bsc#1277019). * Oracle August 18 2026 CSPU and IBM Security Update August 2026 (bsc#1277833). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4153 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4153 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4153 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4153 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4153 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4153 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-4153 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4153 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4153 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (nosrc ppc64le x86_64) * java-1_8_0-ibm-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.71-150000.3.125.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (nosrc x86_64) * java-1_8_0-ibm-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.71-150000.3.125.1 * java-1_8_0-ibm-devel-1.8.0_sr8.71-150000.3.125.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (nosrc x86_64) * java-1_8_0-ibm-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.71-150000.3.125.1 * java-1_8_0-ibm-devel-1.8.0_sr8.71-150000.3.125.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (nosrc ppc64le x86_64) * java-1_8_0-ibm-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.71-150000.3.125.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (nosrc ppc64le x86_64) * java-1_8_0-ibm-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.71-150000.3.125.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (nosrc ppc64le s390x x86_64) * java-1_8_0-ibm-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.71-150000.3.125.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (ppc64le s390x x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.71-150000.3.125.1 * Legacy Module 15-SP7 (nosrc ppc64le s390x x86_64) * java-1_8_0-ibm-1.8.0_sr8.71-150000.3.125.1 * Legacy Module 15-SP7 (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.71-150000.3.125.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.71-150000.3.125.1 * Legacy Module 15-SP7 (ppc64le s390x x86_64) * java-1_8_0-ibm-src-1.8.0_sr8.71-150000.3.125.1 * java-1_8_0-ibm-devel-1.8.0_sr8.71-150000.3.125.1 * java-1_8_0-ibm-demo-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (nosrc ppc64le s390x x86_64) * java-1_8_0-ibm-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.71-150000.3.125.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (ppc64le s390x x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (nosrc ppc64le s390x x86_64) * java-1_8_0-ibm-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (ppc64le s390x x86_64) * java-1_8_0-ibm-devel-1.8.0_sr8.71-150000.3.125.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * java-1_8_0-ibm-plugin-1.8.0_sr8.71-150000.3.125.1 * java-1_8_0-ibm-alsa-1.8.0_sr8.71-150000.3.125.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16243.html * https://www.suse.com/security/cve/CVE-2026-16440.html * https://www.suse.com/security/cve/CVE-2026-60589.html * https://www.suse.com/security/cve/CVE-2026-61308.html * https://www.suse.com/security/cve/CVE-2026-70906.html * https://www.suse.com/security/cve/CVE-2026-70907.html * https://www.suse.com/security/cve/CVE-2026-71054.html * https://www.suse.com/security/cve/CVE-2026-8400.html * https://bugzilla.suse.com/show_bug.cgi?id=1274275 * https://bugzilla.suse.com/show_bug.cgi?id=1274276 * https://bugzilla.suse.com/show_bug.cgi?id=1275763 * https://bugzilla.suse.com/show_bug.cgi?id=1275764 * https://bugzilla.suse.com/show_bug.cgi?id=1275777 * https://bugzilla.suse.com/show_bug.cgi?id=1275778 * https://bugzilla.suse.com/show_bug.cgi?id=1275779 * https://bugzilla.suse.com/show_bug.cgi?id=1277019 * https://bugzilla.suse.com/show_bug.cgi?id=1277833 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 12:32:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 12:32:43 -0000 Subject: SUSE-SU-2026:4152-1: important: Security update for strongswan Message-ID: <178938916329.17839.7975670741662592615@b9be41dc2e4b> # Security update for strongswan Announcement ID: SUSE-SU-2026:4152-1 Release Date: 2026-09-14T08:03:48Z Rating: important References: * bsc#1276533 * bsc#1276534 * bsc#1276536 * bsc#1276539 * bsc#1276540 * bsc#1276541 * bsc#1276543 * bsc#1276544 * bsc#1276548 Cross-References: * CVE-2026-78123 * CVE-2026-78124 * CVE-2026-78126 * CVE-2026-78127 * CVE-2026-78129 * CVE-2026-78130 * CVE-2026-78131 * CVE-2026-78132 * CVE-2026-78134 CVSS scores: * CVE-2026-78123 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78123 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78123 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78124 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78124 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78124 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-78126 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78126 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78126 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78127 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78127 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78127 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-78129 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78129 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-78129 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78130 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78130 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78130 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78131 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78131 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78131 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-78132 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78132 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78132 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78134 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-78134 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-78134 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves nine vulnerabilities can now be installed. ## Description: This update for strongswan fixes the following issues: * CVE-2026-78123: Undefined Memory Access When Handling PKCS#7 Containers (bsc#1276533). * CVE-2026-78124: Memory Leak When Processing Certificates in PKCS#7 Containers (bsc#1276534). * CVE-2026-78126: NULL-Pointer Dereference When Handling AKA-Synchronization- Failure (bsc#1276536). * CVE-2026-78127: Memory Leak During Message Stringification (bsc#1276539). * CVE-2026-78129: Unbounded Iteration When Decrypting PKCS#7 Containers (bsc#1276540). * CVE-2026-78130: NULL-Pointer Dereference in Attribute Certificate Validation (bsc#1276541). * CVE-2026-78131: Memory Leaks When Parsing Attribute Certificates (bsc#1276543). * CVE-2026-78132: Infinite Loop When Parsing Attribute Certificates (bsc#1276544). * CVE-2026-78134: Missing Inner EAP Method Authentication Details (bsc#1276548). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4152 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4152 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4152 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-4152 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4152 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * strongswan-hmac-5.9.11-150500.5.28.2 * strongswan-libs0-debuginfo-5.9.11-150500.5.28.2 * strongswan-5.9.11-150500.5.28.2 * strongswan-debuginfo-5.9.11-150500.5.28.2 * strongswan-debugsource-5.9.11-150500.5.28.2 * strongswan-ipsec-5.9.11-150500.5.28.2 * strongswan-libs0-5.9.11-150500.5.28.2 * strongswan-ipsec-debuginfo-5.9.11-150500.5.28.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * strongswan-doc-5.9.11-150500.5.28.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * strongswan-hmac-5.9.11-150500.5.28.2 * strongswan-libs0-debuginfo-5.9.11-150500.5.28.2 * strongswan-5.9.11-150500.5.28.2 * strongswan-debuginfo-5.9.11-150500.5.28.2 * strongswan-debugsource-5.9.11-150500.5.28.2 * strongswan-ipsec-5.9.11-150500.5.28.2 * strongswan-libs0-5.9.11-150500.5.28.2 * strongswan-ipsec-debuginfo-5.9.11-150500.5.28.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * strongswan-doc-5.9.11-150500.5.28.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * strongswan-hmac-5.9.11-150500.5.28.2 * strongswan-libs0-debuginfo-5.9.11-150500.5.28.2 * strongswan-5.9.11-150500.5.28.2 * strongswan-debuginfo-5.9.11-150500.5.28.2 * strongswan-debugsource-5.9.11-150500.5.28.2 * strongswan-ipsec-5.9.11-150500.5.28.2 * strongswan-libs0-5.9.11-150500.5.28.2 * strongswan-ipsec-debuginfo-5.9.11-150500.5.28.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * strongswan-doc-5.9.11-150500.5.28.2 * openSUSE Leap 15.5 (aarch64 i586 ppc64le s390x x86_64) * strongswan-nm-5.9.11-150500.5.28.2 * strongswan-hmac-5.9.11-150500.5.28.2 * strongswan-libs0-debuginfo-5.9.11-150500.5.28.2 * strongswan-mysql-debuginfo-5.9.11-150500.5.28.2 * strongswan-5.9.11-150500.5.28.2 * strongswan-debuginfo-5.9.11-150500.5.28.2 * strongswan-nm-debuginfo-5.9.11-150500.5.28.2 * strongswan-debugsource-5.9.11-150500.5.28.2 * strongswan-ipsec-5.9.11-150500.5.28.2 * strongswan-libs0-5.9.11-150500.5.28.2 * strongswan-sqlite-5.9.11-150500.5.28.2 * strongswan-sqlite-debuginfo-5.9.11-150500.5.28.2 * strongswan-mysql-5.9.11-150500.5.28.2 * strongswan-ipsec-debuginfo-5.9.11-150500.5.28.2 * openSUSE Leap 15.5 (noarch) * strongswan-doc-5.9.11-150500.5.28.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * strongswan-hmac-5.9.11-150500.5.28.2 * strongswan-libs0-debuginfo-5.9.11-150500.5.28.2 * strongswan-5.9.11-150500.5.28.2 * strongswan-debuginfo-5.9.11-150500.5.28.2 * strongswan-debugsource-5.9.11-150500.5.28.2 * strongswan-ipsec-5.9.11-150500.5.28.2 * strongswan-libs0-5.9.11-150500.5.28.2 * strongswan-ipsec-debuginfo-5.9.11-150500.5.28.2 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * strongswan-doc-5.9.11-150500.5.28.2 ## References: * https://www.suse.com/security/cve/CVE-2026-78123.html * https://www.suse.com/security/cve/CVE-2026-78124.html * https://www.suse.com/security/cve/CVE-2026-78126.html * https://www.suse.com/security/cve/CVE-2026-78127.html * https://www.suse.com/security/cve/CVE-2026-78129.html * https://www.suse.com/security/cve/CVE-2026-78130.html * https://www.suse.com/security/cve/CVE-2026-78131.html * https://www.suse.com/security/cve/CVE-2026-78132.html * https://www.suse.com/security/cve/CVE-2026-78134.html * https://bugzilla.suse.com/show_bug.cgi?id=1276533 * https://bugzilla.suse.com/show_bug.cgi?id=1276534 * https://bugzilla.suse.com/show_bug.cgi?id=1276536 * https://bugzilla.suse.com/show_bug.cgi?id=1276539 * https://bugzilla.suse.com/show_bug.cgi?id=1276540 * https://bugzilla.suse.com/show_bug.cgi?id=1276541 * https://bugzilla.suse.com/show_bug.cgi?id=1276543 * https://bugzilla.suse.com/show_bug.cgi?id=1276544 * https://bugzilla.suse.com/show_bug.cgi?id=1276548 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 12:33:39 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 12:33:39 -0000 Subject: SUSE-SU-2026:4151-1: moderate: Security update for perl-Mojolicious Message-ID: <178938921925.17839.1412757315454425644@b9be41dc2e4b> # Security update for perl-Mojolicious Announcement ID: SUSE-SU-2026:4151-1 Release Date: 2026-09-14T08:03:13Z Rating: moderate References: * bsc#1271431 Cross-References: * CVE-2026-15747 CVSS scores: * CVE-2026-15747 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-15747 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:H/A:N * CVE-2026-15747 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for perl-Mojolicious fixes the following issue: * CVE-2026-15747: exposing a stable representation of the session CSRF token to a BREACH compression oracle (bsc#1271431). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4151 ## Package List: * SUSE Package Hub 15 15-SP7 (noarch) * perl-Mojolicious-9.370.0-150700.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15747.html * https://bugzilla.suse.com/show_bug.cgi?id=1271431 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 12:34:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 12:34:41 -0000 Subject: SUSE-SU-2026:4150-1: important: Security update for ffmpeg-4 Message-ID: <178938928121.17839.591649018471796712@b9be41dc2e4b> # Security update for ffmpeg-4 Announcement ID: SUSE-SU-2026:4150-1 Release Date: 2026-09-14T08:02:56Z Rating: important References: * bsc#1269550 * bsc#1272755 * bsc#1272757 * bsc#1272759 * bsc#1272760 * bsc#1272761 * bsc#1272762 * bsc#1272763 * bsc#1274268 * bsc#1274270 * bsc#1274282 * bsc#1274287 * bsc#1274289 * bsc#1276408 * bsc#1276409 * bsc#1276410 * bsc#1276412 Cross-References: * CVE-2026-58049 * CVE-2026-64833 * CVE-2026-64834 * CVE-2026-65703 * CVE-2026-65704 * CVE-2026-65705 * CVE-2026-65706 * CVE-2026-66036 * CVE-2026-70628 * CVE-2026-70629 * CVE-2026-70630 * CVE-2026-70631 * CVE-2026-70632 * CVE-2026-75142 * CVE-2026-75143 * CVE-2026-75144 * CVE-2026-75146 CVSS scores: * CVE-2026-58049 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58049 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58049 ( NVD ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58049 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-58049 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-64833 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64833 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-64833 ( NVD ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-64833 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-64834 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64834 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64834 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-64834 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-65703 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-65703 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-65703 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-65703 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-65704 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-65704 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-65704 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-65704 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-65705 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-65705 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-65705 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-65705 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-65706 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-65706 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-65706 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-65706 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66036 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-66036 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-66036 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66036 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66036 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-70628 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70628 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-70628 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70628 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-70629 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-70629 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-70629 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70629 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-70630 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70630 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-70630 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70630 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-70631 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70631 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-70631 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70631 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-70632 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70632 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-70632 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70632 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-75142 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-75142 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-75142 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-75142 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-75143 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-75143 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-75143 ( NVD ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-75143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-75144 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-75144 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-75144 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-75144 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-75146 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-75146 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-75146 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-75146 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 17 vulnerabilities can now be installed. ## Description: This update for ffmpeg-4 fixes the following issues: * CVE-2026-58049: incorrect validation in the RASC video decoder can lead to an out-of-bounds heap write and memory corruption (bsc#1269550). * CVE-2026-64833: Out-of-Bounds Read via S/PDIF Muxer spdifenc.c (bsc#1272755). * CVE-2026-64834: Infinite Loop DoS via RTP/ASF Demuxer (bsc#1272757). * CVE-2026-65703: Out-of-Bounds Write in TDSC Video Decoder (bsc#1272759). * CVE-2026-65704: Out-of-Bounds Write via TY Demuxer and Shorten Decoder (bsc#1272760). * CVE-2026-65705: vf_floodfill Out-of-Bounds Write via filter_frame() (bsc#1272761). * CVE-2026-65706: vf_swaprect Out-of-Bounds Write via NV12 Frame Processing (bsc#1272762). * CVE-2026-66036: Heap Out-of-Bounds Write in vf_hqdn3d Filter (bsc#1272763). * CVE-2026-70628: signed integer underflows during subtitle buffer checks can cause heap buffer overflows (bsc#1274268). * CVE-2026-70629: unvalidated decompressed frame sizes in video decoders can cause uninitialized heap memory reads (bsc#1274270). * CVE-2026-70630: unvalidated decompression sizes in Screenpresso frame decoding can cause uninitialized heap memory reads (bsc#1274282). * CVE-2026-70631: unvalidated decompression sizes in TIFF strip decoding can cause uninitialized heap memory reads (bsc#1274287). * CVE-2026-70632: unenforced frame dimensions in CineForm HD decoding can cause heap-based out-of-bounds writes (bsc#1274289). * CVE-2026-75142: stack buffer overflow in the MPEG-PS muxer (bsc#1276408). * CVE-2026-75143: heap buffer overflow in the RIST protocol reader (bsc#1276409). * CVE-2026-75144: heap buffer overflow in the VC-2/Dirac RTP packetizer (bsc#1276410). * CVE-2026-75146: out-of-bounds read in the DASH demuxer (bsc#1276412). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4150 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4150 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4150 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4150 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4150 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libavformat58_76-debuginfo-4.4.8-150400.3.75.1 * ffmpeg-4-debuginfo-4.4.8-150400.3.75.1 * libavutil56_70-debuginfo-4.4.8-150400.3.75.1 * libavcodec58_134-debuginfo-4.4.8-150400.3.75.1 * libavformat58_76-4.4.8-150400.3.75.1 * ffmpeg-4-debugsource-4.4.8-150400.3.75.1 * libpostproc55_9-4.4.8-150400.3.75.1 * libpostproc55_9-debuginfo-4.4.8-150400.3.75.1 * libavcodec58_134-4.4.8-150400.3.75.1 * libswresample3_9-4.4.8-150400.3.75.1 * libavutil56_70-4.4.8-150400.3.75.1 * libswresample3_9-debuginfo-4.4.8-150400.3.75.1 * libswscale5_9-4.4.8-150400.3.75.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libavformat58_76-debuginfo-4.4.8-150400.3.75.1 * ffmpeg-4-debuginfo-4.4.8-150400.3.75.1 * libavutil56_70-debuginfo-4.4.8-150400.3.75.1 * libavcodec58_134-debuginfo-4.4.8-150400.3.75.1 * libavformat58_76-4.4.8-150400.3.75.1 * ffmpeg-4-debugsource-4.4.8-150400.3.75.1 * libpostproc55_9-4.4.8-150400.3.75.1 * libpostproc55_9-debuginfo-4.4.8-150400.3.75.1 * libavcodec58_134-4.4.8-150400.3.75.1 * libswresample3_9-4.4.8-150400.3.75.1 * libavutil56_70-4.4.8-150400.3.75.1 * libswresample3_9-debuginfo-4.4.8-150400.3.75.1 * libswscale5_9-4.4.8-150400.3.75.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libavformat58_76-debuginfo-4.4.8-150400.3.75.1 * ffmpeg-4-debuginfo-4.4.8-150400.3.75.1 * libavutil56_70-debuginfo-4.4.8-150400.3.75.1 * libavcodec58_134-debuginfo-4.4.8-150400.3.75.1 * libavformat58_76-4.4.8-150400.3.75.1 * ffmpeg-4-debugsource-4.4.8-150400.3.75.1 * libpostproc55_9-4.4.8-150400.3.75.1 * libpostproc55_9-debuginfo-4.4.8-150400.3.75.1 * libavcodec58_134-4.4.8-150400.3.75.1 * libswresample3_9-4.4.8-150400.3.75.1 * libavutil56_70-4.4.8-150400.3.75.1 * libswresample3_9-debuginfo-4.4.8-150400.3.75.1 * libswscale5_9-4.4.8-150400.3.75.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libavdevice58_13-4.4.8-150400.3.75.1 * ffmpeg-4-libavfilter-devel-4.4.8-150400.3.75.1 * libswscale5_9-debuginfo-4.4.8-150400.3.75.1 * libswscale5_9-4.4.8-150400.3.75.1 * ffmpeg-4-4.4.8-150400.3.75.1 * ffmpeg-4-debugsource-4.4.8-150400.3.75.1 * libpostproc55_9-4.4.8-150400.3.75.1 * ffmpeg-4-libavutil-devel-4.4.8-150400.3.75.1 * libavresample4_0-4.4.8-150400.3.75.1 * ffmpeg-4-private-devel-4.4.8-150400.3.75.1 * ffmpeg-4-libavresample-devel-4.4.8-150400.3.75.1 * ffmpeg-4-libavcodec-devel-4.4.8-150400.3.75.1 * libavutil56_70-debuginfo-4.4.8-150400.3.75.1 * ffmpeg-4-libpostproc-devel-4.4.8-150400.3.75.1 * libpostproc55_9-debuginfo-4.4.8-150400.3.75.1 * libavresample4_0-debuginfo-4.4.8-150400.3.75.1 * ffmpeg-4-debuginfo-4.4.8-150400.3.75.1 * ffmpeg-4-libavdevice-devel-4.4.8-150400.3.75.1 * libavformat58_76-4.4.8-150400.3.75.1 * ffmpeg-4-libswresample-devel-4.4.8-150400.3.75.1 * libavdevice58_13-debuginfo-4.4.8-150400.3.75.1 * libswresample3_9-4.4.8-150400.3.75.1 * ffmpeg-4-libavformat-devel-4.4.8-150400.3.75.1 * libavcodec58_134-4.4.8-150400.3.75.1 * libavformat58_76-debuginfo-4.4.8-150400.3.75.1 * ffmpeg-4-libswscale-devel-4.4.8-150400.3.75.1 * libavcodec58_134-debuginfo-4.4.8-150400.3.75.1 * libswresample3_9-debuginfo-4.4.8-150400.3.75.1 * libavutil56_70-4.4.8-150400.3.75.1 * libavfilter7_110-4.4.8-150400.3.75.1 * libavfilter7_110-debuginfo-4.4.8-150400.3.75.1 * openSUSE Leap 15.4 (x86_64) * libavutil56_70-32bit-debuginfo-4.4.8-150400.3.75.1 * libavcodec58_134-32bit-debuginfo-4.4.8-150400.3.75.1 * libavdevice58_13-32bit-4.4.8-150400.3.75.1 * libswscale5_9-32bit-debuginfo-4.4.8-150400.3.75.1 * libavutil56_70-32bit-4.4.8-150400.3.75.1 * libavcodec58_134-32bit-4.4.8-150400.3.75.1 * libpostproc55_9-32bit-debuginfo-4.4.8-150400.3.75.1 * libswresample3_9-32bit-4.4.8-150400.3.75.1 * libswresample3_9-32bit-debuginfo-4.4.8-150400.3.75.1 * libavdevice58_13-32bit-debuginfo-4.4.8-150400.3.75.1 * libavformat58_76-32bit-4.4.8-150400.3.75.1 * libavresample4_0-32bit-debuginfo-4.4.8-150400.3.75.1 * libpostproc55_9-32bit-4.4.8-150400.3.75.1 * libavfilter7_110-32bit-4.4.8-150400.3.75.1 * libavfilter7_110-32bit-debuginfo-4.4.8-150400.3.75.1 * libavresample4_0-32bit-4.4.8-150400.3.75.1 * libswscale5_9-32bit-4.4.8-150400.3.75.1 * libavformat58_76-32bit-debuginfo-4.4.8-150400.3.75.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libavcodec58_134-64bit-debuginfo-4.4.8-150400.3.75.1 * libavutil56_70-64bit-debuginfo-4.4.8-150400.3.75.1 * libpostproc55_9-64bit-4.4.8-150400.3.75.1 * libavformat58_76-64bit-debuginfo-4.4.8-150400.3.75.1 * libswscale5_9-64bit-debuginfo-4.4.8-150400.3.75.1 * libavdevice58_13-64bit-4.4.8-150400.3.75.1 * libavresample4_0-64bit-debuginfo-4.4.8-150400.3.75.1 * libavfilter7_110-64bit-4.4.8-150400.3.75.1 * libavformat58_76-64bit-4.4.8-150400.3.75.1 * libswresample3_9-64bit-debuginfo-4.4.8-150400.3.75.1 * libavcodec58_134-64bit-4.4.8-150400.3.75.1 * libpostproc55_9-64bit-debuginfo-4.4.8-150400.3.75.1 * libavfilter7_110-64bit-debuginfo-4.4.8-150400.3.75.1 * libavutil56_70-64bit-4.4.8-150400.3.75.1 * libswscale5_9-64bit-4.4.8-150400.3.75.1 * libswresample3_9-64bit-4.4.8-150400.3.75.1 * libavdevice58_13-64bit-debuginfo-4.4.8-150400.3.75.1 * libavresample4_0-64bit-4.4.8-150400.3.75.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libavformat58_76-debuginfo-4.4.8-150400.3.75.1 * ffmpeg-4-debuginfo-4.4.8-150400.3.75.1 * libavutil56_70-debuginfo-4.4.8-150400.3.75.1 * libavcodec58_134-debuginfo-4.4.8-150400.3.75.1 * libavformat58_76-4.4.8-150400.3.75.1 * ffmpeg-4-debugsource-4.4.8-150400.3.75.1 * libpostproc55_9-4.4.8-150400.3.75.1 * libpostproc55_9-debuginfo-4.4.8-150400.3.75.1 * libavcodec58_134-4.4.8-150400.3.75.1 * libswresample3_9-4.4.8-150400.3.75.1 * libavutil56_70-4.4.8-150400.3.75.1 * libswresample3_9-debuginfo-4.4.8-150400.3.75.1 * libswscale5_9-4.4.8-150400.3.75.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58049.html * https://www.suse.com/security/cve/CVE-2026-64833.html * https://www.suse.com/security/cve/CVE-2026-64834.html * https://www.suse.com/security/cve/CVE-2026-65703.html * https://www.suse.com/security/cve/CVE-2026-65704.html * https://www.suse.com/security/cve/CVE-2026-65705.html * https://www.suse.com/security/cve/CVE-2026-65706.html * https://www.suse.com/security/cve/CVE-2026-66036.html * https://www.suse.com/security/cve/CVE-2026-70628.html * https://www.suse.com/security/cve/CVE-2026-70629.html * https://www.suse.com/security/cve/CVE-2026-70630.html * https://www.suse.com/security/cve/CVE-2026-70631.html * https://www.suse.com/security/cve/CVE-2026-70632.html * https://www.suse.com/security/cve/CVE-2026-75142.html * https://www.suse.com/security/cve/CVE-2026-75143.html * https://www.suse.com/security/cve/CVE-2026-75144.html * https://www.suse.com/security/cve/CVE-2026-75146.html * https://bugzilla.suse.com/show_bug.cgi?id=1269550 * https://bugzilla.suse.com/show_bug.cgi?id=1272755 * https://bugzilla.suse.com/show_bug.cgi?id=1272757 * https://bugzilla.suse.com/show_bug.cgi?id=1272759 * https://bugzilla.suse.com/show_bug.cgi?id=1272760 * https://bugzilla.suse.com/show_bug.cgi?id=1272761 * https://bugzilla.suse.com/show_bug.cgi?id=1272762 * https://bugzilla.suse.com/show_bug.cgi?id=1272763 * https://bugzilla.suse.com/show_bug.cgi?id=1274268 * https://bugzilla.suse.com/show_bug.cgi?id=1274270 * https://bugzilla.suse.com/show_bug.cgi?id=1274282 * https://bugzilla.suse.com/show_bug.cgi?id=1274287 * https://bugzilla.suse.com/show_bug.cgi?id=1274289 * https://bugzilla.suse.com/show_bug.cgi?id=1276408 * https://bugzilla.suse.com/show_bug.cgi?id=1276409 * https://bugzilla.suse.com/show_bug.cgi?id=1276410 * https://bugzilla.suse.com/show_bug.cgi?id=1276412 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 12:36:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 12:36:00 -0000 Subject: SUSE-SU-2026:4149-1: important: Security update for ffmpeg-4 Message-ID: <178938936026.17839.8173464525680682459@b9be41dc2e4b> # Security update for ffmpeg-4 Announcement ID: SUSE-SU-2026:4149-1 Release Date: 2026-09-14T08:02:23Z Rating: important References: * bsc#1269550 * bsc#1272755 * bsc#1272757 * bsc#1272759 * bsc#1272760 * bsc#1272761 * bsc#1272762 * bsc#1272763 * bsc#1274268 * bsc#1274270 * bsc#1274282 * bsc#1274287 * bsc#1274289 * bsc#1276408 * bsc#1276409 * bsc#1276410 * bsc#1276412 Cross-References: * CVE-2026-58049 * CVE-2026-64833 * CVE-2026-64834 * CVE-2026-65703 * CVE-2026-65704 * CVE-2026-65705 * CVE-2026-65706 * CVE-2026-66036 * CVE-2026-70628 * CVE-2026-70629 * CVE-2026-70630 * CVE-2026-70631 * CVE-2026-70632 * CVE-2026-75142 * CVE-2026-75143 * CVE-2026-75144 * CVE-2026-75146 CVSS scores: * CVE-2026-58049 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-58049 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-58049 ( NVD ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-58049 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-58049 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-64833 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64833 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-64833 ( NVD ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-64833 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-64834 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64834 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64834 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-64834 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-65703 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-65703 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-65703 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-65703 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-65704 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-65704 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-65704 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-65704 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-65705 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-65705 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-65705 ( NVD ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-65705 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-65706 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-65706 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-65706 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-65706 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66036 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-66036 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-66036 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66036 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-66036 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-70628 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70628 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-70628 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70628 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-70629 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-70629 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-70629 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70629 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-70630 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70630 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-70630 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70630 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-70631 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70631 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-70631 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70631 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-70632 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70632 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-70632 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-70632 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-75142 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-75142 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-75142 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-75142 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-75143 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-75143 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-75143 ( NVD ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-75143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-75144 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-75144 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-75144 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-75144 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-75146 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-75146 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-75146 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-75146 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 17 vulnerabilities can now be installed. ## Description: This update for ffmpeg-4 fixes the following issues: * CVE-2026-58049: incorrect validation in the RASC video decoder can lead to an out-of-bounds heap write and memory corruption (bsc#1269550). * CVE-2026-64833: Out-of-Bounds Read via S/PDIF Muxer spdifenc.c (bsc#1272755). * CVE-2026-64834: Infinite Loop DoS via RTP/ASF Demuxer (bsc#1272757). * CVE-2026-65703: Out-of-Bounds Write in TDSC Video Decoder (bsc#1272759). * CVE-2026-65704: Out-of-Bounds Write via TY Demuxer and Shorten Decoder (bsc#1272760). * CVE-2026-65705: vf_floodfill Out-of-Bounds Write via filter_frame() (bsc#1272761). * CVE-2026-65706: vf_swaprect Out-of-Bounds Write via NV12 Frame Processing (bsc#1272762). * CVE-2026-66036: Heap Out-of-Bounds Write in vf_hqdn3d Filter (bsc#1272763). * CVE-2026-70628: signed integer underflows during subtitle buffer checks can cause heap buffer overflows (bsc#1274268). * CVE-2026-70629: unvalidated decompressed frame sizes in video decoders can cause uninitialized heap memory reads (bsc#1274270). * CVE-2026-70630: unvalidated decompression sizes in Screenpresso frame decoding can cause uninitialized heap memory reads (bsc#1274282). * CVE-2026-70631: unvalidated decompression sizes in TIFF strip decoding can cause uninitialized heap memory reads (bsc#1274287). * CVE-2026-70632: unenforced frame dimensions in CineForm HD decoding can cause heap-based out-of-bounds writes (bsc#1274289). * CVE-2026-75142: stack buffer overflow in the MPEG-PS muxer (bsc#1276408). * CVE-2026-75143: heap buffer overflow in the RIST protocol reader (bsc#1276409). * CVE-2026-75144: heap buffer overflow in the VC-2/Dirac RTP packetizer (bsc#1276410). * CVE-2026-75146: out-of-bounds read in the DASH demuxer (bsc#1276412). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4149 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-4149 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4149 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libavcodec58_134-4.4.8-150600.13.55.1 * libswscale5_9-4.4.8-150600.13.55.1 * ffmpeg-4-libavcodec-devel-4.4.8-150600.13.55.1 * ffmpeg-4-libswresample-devel-4.4.8-150600.13.55.1 * libavfilter7_110-4.4.8-150600.13.55.1 * ffmpeg-4-libswscale-devel-4.4.8-150600.13.55.1 * libavformat58_76-debuginfo-4.4.8-150600.13.55.1 * libpostproc55_9-debuginfo-4.4.8-150600.13.55.1 * libavformat58_76-4.4.8-150600.13.55.1 * ffmpeg-4-debugsource-4.4.8-150600.13.55.1 * libavdevice58_13-debuginfo-4.4.8-150600.13.55.1 * ffmpeg-4-private-devel-4.4.8-150600.13.55.1 * ffmpeg-4-debuginfo-4.4.8-150600.13.55.1 * ffmpeg-4-4.4.8-150600.13.55.1 * libavutil56_70-debuginfo-4.4.8-150600.13.55.1 * libavutil56_70-4.4.8-150600.13.55.1 * ffmpeg-4-libavutil-devel-4.4.8-150600.13.55.1 * libavdevice58_13-4.4.8-150600.13.55.1 * libavresample4_0-debuginfo-4.4.8-150600.13.55.1 * ffmpeg-4-libavfilter-devel-4.4.8-150600.13.55.1 * libswresample3_9-debuginfo-4.4.8-150600.13.55.1 * ffmpeg-4-libavformat-devel-4.4.8-150600.13.55.1 * libavfilter7_110-debuginfo-4.4.8-150600.13.55.1 * libswscale5_9-debuginfo-4.4.8-150600.13.55.1 * ffmpeg-4-libavdevice-devel-4.4.8-150600.13.55.1 * ffmpeg-4-libavresample-devel-4.4.8-150600.13.55.1 * ffmpeg-4-libpostproc-devel-4.4.8-150600.13.55.1 * libavresample4_0-4.4.8-150600.13.55.1 * libswresample3_9-4.4.8-150600.13.55.1 * libavcodec58_134-debuginfo-4.4.8-150600.13.55.1 * libpostproc55_9-4.4.8-150600.13.55.1 * openSUSE Leap 15.6 (x86_64) * libavdevice58_13-32bit-debuginfo-4.4.8-150600.13.55.1 * libavfilter7_110-32bit-4.4.8-150600.13.55.1 * libavformat58_76-32bit-4.4.8-150600.13.55.1 * libavcodec58_134-32bit-debuginfo-4.4.8-150600.13.55.1 * libavdevice58_13-32bit-4.4.8-150600.13.55.1 * libavutil56_70-32bit-4.4.8-150600.13.55.1 * libavutil56_70-32bit-debuginfo-4.4.8-150600.13.55.1 * libswresample3_9-32bit-4.4.8-150600.13.55.1 * libswresample3_9-32bit-debuginfo-4.4.8-150600.13.55.1 * libswscale5_9-32bit-debuginfo-4.4.8-150600.13.55.1 * libavcodec58_134-32bit-4.4.8-150600.13.55.1 * libswscale5_9-32bit-4.4.8-150600.13.55.1 * libavresample4_0-32bit-4.4.8-150600.13.55.1 * libavresample4_0-32bit-debuginfo-4.4.8-150600.13.55.1 * libpostproc55_9-32bit-4.4.8-150600.13.55.1 * libavformat58_76-32bit-debuginfo-4.4.8-150600.13.55.1 * libpostproc55_9-32bit-debuginfo-4.4.8-150600.13.55.1 * libavfilter7_110-32bit-debuginfo-4.4.8-150600.13.55.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libswscale5_9-64bit-debuginfo-4.4.8-150600.13.55.1 * libavfilter7_110-64bit-4.4.8-150600.13.55.1 * libavutil56_70-64bit-debuginfo-4.4.8-150600.13.55.1 * libswscale5_9-64bit-4.4.8-150600.13.55.1 * libavdevice58_13-64bit-debuginfo-4.4.8-150600.13.55.1 * libavfilter7_110-64bit-debuginfo-4.4.8-150600.13.55.1 * libavcodec58_134-64bit-4.4.8-150600.13.55.1 * libpostproc55_9-64bit-debuginfo-4.4.8-150600.13.55.1 * libswresample3_9-64bit-debuginfo-4.4.8-150600.13.55.1 * libavresample4_0-64bit-debuginfo-4.4.8-150600.13.55.1 * libswresample3_9-64bit-4.4.8-150600.13.55.1 * libavformat58_76-64bit-debuginfo-4.4.8-150600.13.55.1 * libavutil56_70-64bit-4.4.8-150600.13.55.1 * libavformat58_76-64bit-4.4.8-150600.13.55.1 * libavcodec58_134-64bit-debuginfo-4.4.8-150600.13.55.1 * libpostproc55_9-64bit-4.4.8-150600.13.55.1 * libavdevice58_13-64bit-4.4.8-150600.13.55.1 * libavresample4_0-64bit-4.4.8-150600.13.55.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * libavcodec58_134-debuginfo-4.4.8-150600.13.55.1 * libavutil56_70-4.4.8-150600.13.55.1 * libavcodec58_134-4.4.8-150600.13.55.1 * libavformat58_76-4.4.8-150600.13.55.1 * ffmpeg-4-debugsource-4.4.8-150600.13.55.1 * libswscale5_9-4.4.8-150600.13.55.1 * libswresample3_9-4.4.8-150600.13.55.1 * ffmpeg-4-debuginfo-4.4.8-150600.13.55.1 * libswresample3_9-debuginfo-4.4.8-150600.13.55.1 * libavutil56_70-debuginfo-4.4.8-150600.13.55.1 * libavformat58_76-debuginfo-4.4.8-150600.13.55.1 * libswscale5_9-debuginfo-4.4.8-150600.13.55.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * libavcodec58_134-4.4.8-150600.13.55.1 * libswscale5_9-4.4.8-150600.13.55.1 * ffmpeg-4-libavcodec-devel-4.4.8-150600.13.55.1 * ffmpeg-4-libswresample-devel-4.4.8-150600.13.55.1 * libavfilter7_110-4.4.8-150600.13.55.1 * ffmpeg-4-libswscale-devel-4.4.8-150600.13.55.1 * libavformat58_76-debuginfo-4.4.8-150600.13.55.1 * libpostproc55_9-debuginfo-4.4.8-150600.13.55.1 * libavformat58_76-4.4.8-150600.13.55.1 * ffmpeg-4-debugsource-4.4.8-150600.13.55.1 * libavdevice58_13-debuginfo-4.4.8-150600.13.55.1 * ffmpeg-4-private-devel-4.4.8-150600.13.55.1 * ffmpeg-4-debuginfo-4.4.8-150600.13.55.1 * ffmpeg-4-4.4.8-150600.13.55.1 * libavutil56_70-debuginfo-4.4.8-150600.13.55.1 * libavutil56_70-4.4.8-150600.13.55.1 * ffmpeg-4-libavutil-devel-4.4.8-150600.13.55.1 * libavdevice58_13-4.4.8-150600.13.55.1 * libavresample4_0-debuginfo-4.4.8-150600.13.55.1 * ffmpeg-4-libavfilter-devel-4.4.8-150600.13.55.1 * libswresample3_9-debuginfo-4.4.8-150600.13.55.1 * ffmpeg-4-libavformat-devel-4.4.8-150600.13.55.1 * libavfilter7_110-debuginfo-4.4.8-150600.13.55.1 * libswscale5_9-debuginfo-4.4.8-150600.13.55.1 * ffmpeg-4-libavdevice-devel-4.4.8-150600.13.55.1 * ffmpeg-4-libavresample-devel-4.4.8-150600.13.55.1 * ffmpeg-4-libpostproc-devel-4.4.8-150600.13.55.1 * libavresample4_0-4.4.8-150600.13.55.1 * libswresample3_9-4.4.8-150600.13.55.1 * libavcodec58_134-debuginfo-4.4.8-150600.13.55.1 * libpostproc55_9-4.4.8-150600.13.55.1 ## References: * https://www.suse.com/security/cve/CVE-2026-58049.html * https://www.suse.com/security/cve/CVE-2026-64833.html * https://www.suse.com/security/cve/CVE-2026-64834.html * https://www.suse.com/security/cve/CVE-2026-65703.html * https://www.suse.com/security/cve/CVE-2026-65704.html * https://www.suse.com/security/cve/CVE-2026-65705.html * https://www.suse.com/security/cve/CVE-2026-65706.html * https://www.suse.com/security/cve/CVE-2026-66036.html * https://www.suse.com/security/cve/CVE-2026-70628.html * https://www.suse.com/security/cve/CVE-2026-70629.html * https://www.suse.com/security/cve/CVE-2026-70630.html * https://www.suse.com/security/cve/CVE-2026-70631.html * https://www.suse.com/security/cve/CVE-2026-70632.html * https://www.suse.com/security/cve/CVE-2026-75142.html * https://www.suse.com/security/cve/CVE-2026-75143.html * https://www.suse.com/security/cve/CVE-2026-75144.html * https://www.suse.com/security/cve/CVE-2026-75146.html * https://bugzilla.suse.com/show_bug.cgi?id=1269550 * https://bugzilla.suse.com/show_bug.cgi?id=1272755 * https://bugzilla.suse.com/show_bug.cgi?id=1272757 * https://bugzilla.suse.com/show_bug.cgi?id=1272759 * https://bugzilla.suse.com/show_bug.cgi?id=1272760 * https://bugzilla.suse.com/show_bug.cgi?id=1272761 * https://bugzilla.suse.com/show_bug.cgi?id=1272762 * https://bugzilla.suse.com/show_bug.cgi?id=1272763 * https://bugzilla.suse.com/show_bug.cgi?id=1274268 * https://bugzilla.suse.com/show_bug.cgi?id=1274270 * https://bugzilla.suse.com/show_bug.cgi?id=1274282 * https://bugzilla.suse.com/show_bug.cgi?id=1274287 * https://bugzilla.suse.com/show_bug.cgi?id=1274289 * https://bugzilla.suse.com/show_bug.cgi?id=1276408 * https://bugzilla.suse.com/show_bug.cgi?id=1276409 * https://bugzilla.suse.com/show_bug.cgi?id=1276410 * https://bugzilla.suse.com/show_bug.cgi?id=1276412 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 12:36:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 12:36:57 -0000 Subject: SUSE-SU-2026:4148-1: important: Security update for NetworkManager Message-ID: <178938941769.17839.12747680131350197656@b9be41dc2e4b> # Security update for NetworkManager Announcement ID: SUSE-SU-2026:4148-1 Release Date: 2026-09-14T08:02:02Z Rating: important References: * bsc#1267696 * bsc#1276764 Cross-References: * CVE-2026-10805 * CVE-2026-19685 CVSS scores: * CVE-2026-10805 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-10805 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19685 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-19685 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-19685 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19685 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for NetworkManager fixes the following issues: * CVE-2026-10805: Local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). * CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4148 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4148 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4148 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4148 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-4148 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4148 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libnm0-1.44.2-150600.3.10.1 * NetworkManager-1.44.2-150600.3.10.1 * NetworkManager-debugsource-1.44.2-150600.3.10.1 * libnm0-debuginfo-1.44.2-150600.3.10.1 * typelib-1_0-NM-1_0-1.44.2-150600.3.10.1 * NetworkManager-wwan-1.44.2-150600.3.10.1 * NetworkManager-debuginfo-1.44.2-150600.3.10.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * NetworkManager-cloud-setup-1.44.2-150600.3.10.1 * NetworkManager-1.44.2-150600.3.10.1 * NetworkManager-devel-1.44.2-150600.3.10.1 * NetworkManager-wwan-1.44.2-150600.3.10.1 * NetworkManager-debugsource-1.44.2-150600.3.10.1 * NetworkManager-cloud-setup-debuginfo-1.44.2-150600.3.10.1 * libnm0-debuginfo-1.44.2-150600.3.10.1 * typelib-1_0-NM-1_0-1.44.2-150600.3.10.1 * NetworkManager-tui-debuginfo-1.44.2-150600.3.10.1 * NetworkManager-tui-1.44.2-150600.3.10.1 * NetworkManager-pppoe-debuginfo-1.44.2-150600.3.10.1 * NetworkManager-bluetooth-debuginfo-1.44.2-150600.3.10.1 * NetworkManager-ovs-debuginfo-1.44.2-150600.3.10.1 * NetworkManager-wwan-debuginfo-1.44.2-150600.3.10.1 * libnm0-1.44.2-150600.3.10.1 * NetworkManager-pppoe-1.44.2-150600.3.10.1 * NetworkManager-bluetooth-1.44.2-150600.3.10.1 * NetworkManager-debuginfo-1.44.2-150600.3.10.1 * NetworkManager-ovs-1.44.2-150600.3.10.1 * openSUSE Leap 15.6 (x86_64) * NetworkManager-devel-32bit-1.44.2-150600.3.10.1 * libnm0-32bit-debuginfo-1.44.2-150600.3.10.1 * libnm0-32bit-1.44.2-150600.3.10.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libnm0-64bit-1.44.2-150600.3.10.1 * NetworkManager-devel-64bit-1.44.2-150600.3.10.1 * libnm0-64bit-debuginfo-1.44.2-150600.3.10.1 * openSUSE Leap 15.6 (noarch) * NetworkManager-lang-1.44.2-150600.3.10.1 * NetworkManager-branding-upstream-1.44.2-150600.3.10.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libnm0-1.44.2-150600.3.10.1 * NetworkManager-debugsource-1.44.2-150600.3.10.1 * libnm0-debuginfo-1.44.2-150600.3.10.1 * typelib-1_0-NM-1_0-1.44.2-150600.3.10.1 * NetworkManager-debuginfo-1.44.2-150600.3.10.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * NetworkManager-debuginfo-1.44.2-150600.3.10.1 * NetworkManager-wwan-1.44.2-150600.3.10.1 * NetworkManager-1.44.2-150600.3.10.1 * NetworkManager-debugsource-1.44.2-150600.3.10.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * NetworkManager-cloud-setup-1.44.2-150600.3.10.1 * NetworkManager-tui-debuginfo-1.44.2-150600.3.10.1 * NetworkManager-tui-1.44.2-150600.3.10.1 * NetworkManager-wwan-debuginfo-1.44.2-150600.3.10.1 * NetworkManager-debugsource-1.44.2-150600.3.10.1 * NetworkManager-cloud-setup-debuginfo-1.44.2-150600.3.10.1 * NetworkManager-devel-1.44.2-150600.3.10.1 * NetworkManager-debuginfo-1.44.2-150600.3.10.1 * NetworkManager-pppoe-1.44.2-150600.3.10.1 * NetworkManager-wwan-1.44.2-150600.3.10.1 * NetworkManager-pppoe-debuginfo-1.44.2-150600.3.10.1 * NetworkManager-bluetooth-1.44.2-150600.3.10.1 * NetworkManager-bluetooth-debuginfo-1.44.2-150600.3.10.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (noarch) * NetworkManager-lang-1.44.2-150600.3.10.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libnm0-1.44.2-150600.3.10.1 * NetworkManager-1.44.2-150600.3.10.1 * NetworkManager-debugsource-1.44.2-150600.3.10.1 * libnm0-debuginfo-1.44.2-150600.3.10.1 * typelib-1_0-NM-1_0-1.44.2-150600.3.10.1 * NetworkManager-wwan-1.44.2-150600.3.10.1 * NetworkManager-debuginfo-1.44.2-150600.3.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10805.html * https://www.suse.com/security/cve/CVE-2026-19685.html * https://bugzilla.suse.com/show_bug.cgi?id=1267696 * https://bugzilla.suse.com/show_bug.cgi?id=1276764 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 12:38:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 12:38:01 -0000 Subject: SUSE-SU-2026:4147-1: important: Security update for strongswan Message-ID: <178938948145.17839.1838998488599126016@b9be41dc2e4b> # Security update for strongswan Announcement ID: SUSE-SU-2026:4147-1 Release Date: 2026-09-14T08:01:21Z Rating: important References: * bsc#1276533 * bsc#1276534 * bsc#1276536 * bsc#1276539 * bsc#1276540 * bsc#1276541 * bsc#1276543 Cross-References: * CVE-2026-78123 * CVE-2026-78124 * CVE-2026-78126 * CVE-2026-78127 * CVE-2026-78129 * CVE-2026-78130 * CVE-2026-78131 CVSS scores: * CVE-2026-78123 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78123 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78123 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78124 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78124 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78124 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-78126 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78126 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78126 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78127 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78127 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78127 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-78129 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78129 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-78129 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78130 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78130 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78130 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78131 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78131 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78131 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for strongswan fixes the following issues: * CVE-2026-78123: Undefined Memory Access When Handling PKCS#7 Containers (bsc#1276533). * CVE-2026-78124: Memory Leak When Processing Certificates in PKCS#7 Containers (bsc#1276534). * CVE-2026-78126: NULL-Pointer Dereference When Handling AKA-Synchronization- Failure (bsc#1276536). * CVE-2026-78127: Memory Leak During Message Stringification (bsc#1276539). * CVE-2026-78129: Unbounded Iteration When Decrypting PKCS#7 Containers (bsc#1276540). * CVE-2026-78130: NULL-Pointer Dereference in Attribute Certificate Validation (bsc#1276541). * CVE-2026-78131: Memory Leaks When Parsing Attribute Certificates (bsc#1276543). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4147 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4147 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * strongswan-debugsource-5.1.3-26.43.2 * strongswan-ipsec-debuginfo-5.1.3-26.43.2 * strongswan-ipsec-5.1.3-26.43.2 * strongswan-5.1.3-26.43.2 * strongswan-libs0-debuginfo-5.1.3-26.43.2 * strongswan-hmac-5.1.3-26.43.2 * strongswan-libs0-5.1.3-26.43.2 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * strongswan-doc-5.1.3-26.43.2 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * strongswan-debugsource-5.1.3-26.43.2 * strongswan-ipsec-debuginfo-5.1.3-26.43.2 * strongswan-ipsec-5.1.3-26.43.2 * strongswan-5.1.3-26.43.2 * strongswan-libs0-debuginfo-5.1.3-26.43.2 * strongswan-hmac-5.1.3-26.43.2 * strongswan-libs0-5.1.3-26.43.2 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * strongswan-doc-5.1.3-26.43.2 ## References: * https://www.suse.com/security/cve/CVE-2026-78123.html * https://www.suse.com/security/cve/CVE-2026-78124.html * https://www.suse.com/security/cve/CVE-2026-78126.html * https://www.suse.com/security/cve/CVE-2026-78127.html * https://www.suse.com/security/cve/CVE-2026-78129.html * https://www.suse.com/security/cve/CVE-2026-78130.html * https://www.suse.com/security/cve/CVE-2026-78131.html * https://bugzilla.suse.com/show_bug.cgi?id=1276533 * https://bugzilla.suse.com/show_bug.cgi?id=1276534 * https://bugzilla.suse.com/show_bug.cgi?id=1276536 * https://bugzilla.suse.com/show_bug.cgi?id=1276539 * https://bugzilla.suse.com/show_bug.cgi?id=1276540 * https://bugzilla.suse.com/show_bug.cgi?id=1276541 * https://bugzilla.suse.com/show_bug.cgi?id=1276543 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 12:38:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 12:38:52 -0000 Subject: SUSE-SU-2026:4146-1: important: Security update for strongswan Message-ID: <178938953291.17839.1449726401171983989@b9be41dc2e4b> # Security update for strongswan Announcement ID: SUSE-SU-2026:4146-1 Release Date: 2026-09-14T08:00:59Z Rating: important References: * bsc#1276533 * bsc#1276534 * bsc#1276536 * bsc#1276539 * bsc#1276540 * bsc#1276541 * bsc#1276543 * bsc#1276544 * bsc#1276548 * bsc#1276549 Cross-References: * CVE-2026-78123 * CVE-2026-78124 * CVE-2026-78126 * CVE-2026-78127 * CVE-2026-78129 * CVE-2026-78130 * CVE-2026-78131 * CVE-2026-78132 * CVE-2026-78134 * CVE-2026-78135 CVSS scores: * CVE-2026-78123 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78123 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78123 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78124 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78124 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78124 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-78126 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78126 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78126 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78127 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78127 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78127 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-78129 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78129 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-78129 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78130 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78130 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78130 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78131 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78131 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78131 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-78132 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78132 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78132 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78134 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-78134 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-78134 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-78135 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-78135 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-78135 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for strongswan fixes the following issues: * CVE-2026-78123: Undefined Memory Access When Handling PKCS#7 Containers (bsc#1276533). * CVE-2026-78124: Memory Leak When Processing Certificates in PKCS#7 Containers (bsc#1276534). * CVE-2026-78126: NULL-Pointer Dereference When Handling AKA-Synchronization- Failure (bsc#1276536). * CVE-2026-78127: Memory Leak During Message Stringification (bsc#1276539). * CVE-2026-78129: Unbounded Iteration When Decrypting PKCS#7 Containers (bsc#1276540). * CVE-2026-78130: NULL-Pointer Dereference in Attribute Certificate Validation (bsc#1276541). * CVE-2026-78131: Memory Leaks When Parsing Attribute Certificates (bsc#1276543). * CVE-2026-78132: Infinite Loop When Parsing Attribute Certificates (bsc#1276544). * CVE-2026-78134: Missing Inner EAP Method Authentication Details (bsc#1276548). * CVE-2026-78135: Creation of a Child SA Pre-Authentication (bsc#1276549). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4146 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4146 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4146 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4146 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4146 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * strongswan-ipsec-debuginfo-5.9.11-150400.19.40.2 * strongswan-libs0-debuginfo-5.9.11-150400.19.40.2 * strongswan-debuginfo-5.9.11-150400.19.40.2 * strongswan-5.9.11-150400.19.40.2 * strongswan-ipsec-5.9.11-150400.19.40.2 * strongswan-hmac-5.9.11-150400.19.40.2 * strongswan-libs0-5.9.11-150400.19.40.2 * strongswan-debugsource-5.9.11-150400.19.40.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * strongswan-doc-5.9.11-150400.19.40.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * strongswan-ipsec-debuginfo-5.9.11-150400.19.40.2 * strongswan-libs0-debuginfo-5.9.11-150400.19.40.2 * strongswan-debuginfo-5.9.11-150400.19.40.2 * strongswan-5.9.11-150400.19.40.2 * strongswan-ipsec-5.9.11-150400.19.40.2 * strongswan-hmac-5.9.11-150400.19.40.2 * strongswan-libs0-5.9.11-150400.19.40.2 * strongswan-debugsource-5.9.11-150400.19.40.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * strongswan-doc-5.9.11-150400.19.40.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * strongswan-ipsec-debuginfo-5.9.11-150400.19.40.2 * strongswan-libs0-debuginfo-5.9.11-150400.19.40.2 * strongswan-debuginfo-5.9.11-150400.19.40.2 * strongswan-5.9.11-150400.19.40.2 * strongswan-ipsec-5.9.11-150400.19.40.2 * strongswan-hmac-5.9.11-150400.19.40.2 * strongswan-libs0-5.9.11-150400.19.40.2 * strongswan-debugsource-5.9.11-150400.19.40.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * strongswan-doc-5.9.11-150400.19.40.2 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * strongswan-ipsec-debuginfo-5.9.11-150400.19.40.2 * strongswan-libs0-debuginfo-5.9.11-150400.19.40.2 * strongswan-mysql-debuginfo-5.9.11-150400.19.40.2 * strongswan-debuginfo-5.9.11-150400.19.40.2 * strongswan-sqlite-5.9.11-150400.19.40.2 * strongswan-5.9.11-150400.19.40.2 * strongswan-ipsec-5.9.11-150400.19.40.2 * strongswan-nm-5.9.11-150400.19.40.2 * strongswan-sqlite-debuginfo-5.9.11-150400.19.40.2 * strongswan-hmac-5.9.11-150400.19.40.2 * strongswan-nm-debuginfo-5.9.11-150400.19.40.2 * strongswan-libs0-5.9.11-150400.19.40.2 * strongswan-mysql-5.9.11-150400.19.40.2 * strongswan-debugsource-5.9.11-150400.19.40.2 * openSUSE Leap 15.4 (noarch) * strongswan-doc-5.9.11-150400.19.40.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * strongswan-ipsec-debuginfo-5.9.11-150400.19.40.2 * strongswan-libs0-debuginfo-5.9.11-150400.19.40.2 * strongswan-debuginfo-5.9.11-150400.19.40.2 * strongswan-5.9.11-150400.19.40.2 * strongswan-ipsec-5.9.11-150400.19.40.2 * strongswan-hmac-5.9.11-150400.19.40.2 * strongswan-libs0-5.9.11-150400.19.40.2 * strongswan-debugsource-5.9.11-150400.19.40.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * strongswan-doc-5.9.11-150400.19.40.2 ## References: * https://www.suse.com/security/cve/CVE-2026-78123.html * https://www.suse.com/security/cve/CVE-2026-78124.html * https://www.suse.com/security/cve/CVE-2026-78126.html * https://www.suse.com/security/cve/CVE-2026-78127.html * https://www.suse.com/security/cve/CVE-2026-78129.html * https://www.suse.com/security/cve/CVE-2026-78130.html * https://www.suse.com/security/cve/CVE-2026-78131.html * https://www.suse.com/security/cve/CVE-2026-78132.html * https://www.suse.com/security/cve/CVE-2026-78134.html * https://www.suse.com/security/cve/CVE-2026-78135.html * https://bugzilla.suse.com/show_bug.cgi?id=1276533 * https://bugzilla.suse.com/show_bug.cgi?id=1276534 * https://bugzilla.suse.com/show_bug.cgi?id=1276536 * https://bugzilla.suse.com/show_bug.cgi?id=1276539 * https://bugzilla.suse.com/show_bug.cgi?id=1276540 * https://bugzilla.suse.com/show_bug.cgi?id=1276541 * https://bugzilla.suse.com/show_bug.cgi?id=1276543 * https://bugzilla.suse.com/show_bug.cgi?id=1276544 * https://bugzilla.suse.com/show_bug.cgi?id=1276548 * https://bugzilla.suse.com/show_bug.cgi?id=1276549 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 12:39:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 12:39:49 -0000 Subject: SUSE-SU-2026:4145-1: moderate: Security update for python-sqlparse Message-ID: <178938958914.17839.4608109862439360843@b9be41dc2e4b> # Security update for python-sqlparse Announcement ID: SUSE-SU-2026:4145-1 Release Date: 2026-09-14T08:00:23Z Rating: moderate References: * bsc#1278097 Cross-References: * CVE-2026-84305 CVSS scores: * CVE-2026-84305 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84305 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-84305 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.6 * Public Cloud Module 15-SP6 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for python-sqlparse fixes the following issue: * CVE-2026-84305: Reindentation of tuple lists causes near-cap quadratic CPU consumption (bsc#1278097). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-4145 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4145 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-4145 ## Package List: * Public Cloud Module 15-SP6 (noarch) * python311-sqlparse-0.4.4-150600.3.12.1 * openSUSE Leap 15.6 (noarch) * python311-sqlparse-0.4.4-150600.3.12.1 * Python 3 Module 15-SP7 (noarch) * python311-sqlparse-0.4.4-150600.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-84305.html * https://bugzilla.suse.com/show_bug.cgi?id=1278097 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 12:40:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 12:40:47 -0000 Subject: SUSE-SU-2026:4144-1: important: Security update for NetworkManager Message-ID: <178938964706.17839.10300965775722718655@b9be41dc2e4b> # Security update for NetworkManager Announcement ID: SUSE-SU-2026:4144-1 Release Date: 2026-09-14T08:00:00Z Rating: important References: * bsc#1267696 * bsc#1276764 Cross-References: * CVE-2026-10805 * CVE-2026-19685 CVSS scores: * CVE-2026-10805 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-10805 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19685 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-19685 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-19685 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19685 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves two vulnerabilities can now be installed. ## Description: This update for NetworkManager fixes the following issues: * CVE-2026-10805: Local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). * CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4144 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4144 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4144 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4144 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4144 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * NetworkManager-debugsource-1.32.12-150400.3.6.1 * NetworkManager-1.32.12-150400.3.6.1 * typelib-1_0-NM-1_0-1.32.12-150400.3.6.1 * libnm0-1.32.12-150400.3.6.1 * NetworkManager-debuginfo-1.32.12-150400.3.6.1 * libnm0-debuginfo-1.32.12-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * NetworkManager-debugsource-1.32.12-150400.3.6.1 * NetworkManager-1.32.12-150400.3.6.1 * typelib-1_0-NM-1_0-1.32.12-150400.3.6.1 * libnm0-1.32.12-150400.3.6.1 * NetworkManager-debuginfo-1.32.12-150400.3.6.1 * libnm0-debuginfo-1.32.12-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * NetworkManager-debugsource-1.32.12-150400.3.6.1 * NetworkManager-1.32.12-150400.3.6.1 * typelib-1_0-NM-1_0-1.32.12-150400.3.6.1 * libnm0-1.32.12-150400.3.6.1 * NetworkManager-debuginfo-1.32.12-150400.3.6.1 * libnm0-debuginfo-1.32.12-150400.3.6.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * NetworkManager-debugsource-1.32.12-150400.3.6.1 * NetworkManager-1.32.12-150400.3.6.1 * typelib-1_0-NM-1_0-1.32.12-150400.3.6.1 * libnm0-1.32.12-150400.3.6.1 * NetworkManager-debuginfo-1.32.12-150400.3.6.1 * libnm0-debuginfo-1.32.12-150400.3.6.1 * NetworkManager-devel-1.32.12-150400.3.6.1 * openSUSE Leap 15.4 (x86_64) * libnm0-32bit-debuginfo-1.32.12-150400.3.6.1 * NetworkManager-devel-32bit-1.32.12-150400.3.6.1 * libnm0-32bit-1.32.12-150400.3.6.1 * openSUSE Leap 15.4 (aarch64_ilp32) * NetworkManager-devel-64bit-1.32.12-150400.3.6.1 * libnm0-64bit-debuginfo-1.32.12-150400.3.6.1 * libnm0-64bit-1.32.12-150400.3.6.1 * openSUSE Leap 15.4 (noarch) * NetworkManager-lang-1.32.12-150400.3.6.1 * NetworkManager-branding-upstream-1.32.12-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * NetworkManager-debugsource-1.32.12-150400.3.6.1 * NetworkManager-1.32.12-150400.3.6.1 * typelib-1_0-NM-1_0-1.32.12-150400.3.6.1 * libnm0-1.32.12-150400.3.6.1 * NetworkManager-debuginfo-1.32.12-150400.3.6.1 * libnm0-debuginfo-1.32.12-150400.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10805.html * https://www.suse.com/security/cve/CVE-2026-19685.html * https://bugzilla.suse.com/show_bug.cgi?id=1267696 * https://bugzilla.suse.com/show_bug.cgi?id=1276764 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 12:41:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 12:41:53 -0000 Subject: SUSE-SU-2026:4143-1: important: Security update for strongswan Message-ID: <178938971381.17839.1361690254930522297@b9be41dc2e4b> # Security update for strongswan Announcement ID: SUSE-SU-2026:4143-1 Release Date: 2026-09-14T07:59:34Z Rating: important References: * bsc#1276533 * bsc#1276534 * bsc#1276536 * bsc#1276539 * bsc#1276540 * bsc#1276541 * bsc#1276543 * bsc#1276544 * bsc#1276548 Cross-References: * CVE-2026-78123 * CVE-2026-78124 * CVE-2026-78126 * CVE-2026-78127 * CVE-2026-78129 * CVE-2026-78130 * CVE-2026-78131 * CVE-2026-78132 * CVE-2026-78134 CVSS scores: * CVE-2026-78123 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78123 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78123 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78124 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78124 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78124 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-78126 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78126 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78126 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78127 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78127 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78127 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-78129 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78129 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-78129 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78130 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78130 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78130 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78131 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78131 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78131 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-78132 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78132 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78132 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78134 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-78134 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-78134 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves nine vulnerabilities can now be installed. ## Description: This update for strongswan fixes the following issues: * CVE-2026-78123: Undefined Memory Access When Handling PKCS#7 Containers (bsc#1276533). * CVE-2026-78124: Memory Leak When Processing Certificates in PKCS#7 Containers (bsc#1276534). * CVE-2026-78126: NULL-Pointer Dereference When Handling AKA-Synchronization- Failure (bsc#1276536). * CVE-2026-78127: Memory Leak During Message Stringification (bsc#1276539). * CVE-2026-78129: Unbounded Iteration When Decrypting PKCS#7 Containers (bsc#1276540). * CVE-2026-78130: NULL-Pointer Dereference in Attribute Certificate Validation (bsc#1276541). * CVE-2026-78131: Memory Leaks When Parsing Attribute Certificates (bsc#1276543). * CVE-2026-78132: Infinite Loop When Parsing Attribute Certificates (bsc#1276544). * CVE-2026-78134: Missing Inner EAP Method Authentication Details (bsc#1276548). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4143 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4143 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4143 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * strongswan-hmac-5.9.12-150600.3.23.2 * strongswan-ipsec-5.9.12-150600.3.23.2 * strongswan-libs0-debuginfo-5.9.12-150600.3.23.2 * strongswan-debugsource-5.9.12-150600.3.23.2 * strongswan-ipsec-debuginfo-5.9.12-150600.3.23.2 * strongswan-debuginfo-5.9.12-150600.3.23.2 * strongswan-libs0-5.9.12-150600.3.23.2 * strongswan-5.9.12-150600.3.23.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * strongswan-doc-5.9.12-150600.3.23.2 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * strongswan-hmac-5.9.12-150600.3.23.2 * strongswan-mysql-debuginfo-5.9.12-150600.3.23.2 * strongswan-mysql-5.9.12-150600.3.23.2 * strongswan-ipsec-5.9.12-150600.3.23.2 * strongswan-libs0-debuginfo-5.9.12-150600.3.23.2 * strongswan-debugsource-5.9.12-150600.3.23.2 * strongswan-ipsec-debuginfo-5.9.12-150600.3.23.2 * strongswan-debuginfo-5.9.12-150600.3.23.2 * strongswan-libs0-5.9.12-150600.3.23.2 * strongswan-sqlite-5.9.12-150600.3.23.2 * strongswan-nm-debuginfo-5.9.12-150600.3.23.2 * strongswan-5.9.12-150600.3.23.2 * strongswan-sqlite-debuginfo-5.9.12-150600.3.23.2 * strongswan-nm-5.9.12-150600.3.23.2 * openSUSE Leap 15.6 (noarch) * strongswan-doc-5.9.12-150600.3.23.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * strongswan-hmac-5.9.12-150600.3.23.2 * strongswan-ipsec-5.9.12-150600.3.23.2 * strongswan-libs0-debuginfo-5.9.12-150600.3.23.2 * strongswan-debugsource-5.9.12-150600.3.23.2 * strongswan-ipsec-debuginfo-5.9.12-150600.3.23.2 * strongswan-debuginfo-5.9.12-150600.3.23.2 * strongswan-libs0-5.9.12-150600.3.23.2 * strongswan-5.9.12-150600.3.23.2 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * strongswan-doc-5.9.12-150600.3.23.2 ## References: * https://www.suse.com/security/cve/CVE-2026-78123.html * https://www.suse.com/security/cve/CVE-2026-78124.html * https://www.suse.com/security/cve/CVE-2026-78126.html * https://www.suse.com/security/cve/CVE-2026-78127.html * https://www.suse.com/security/cve/CVE-2026-78129.html * https://www.suse.com/security/cve/CVE-2026-78130.html * https://www.suse.com/security/cve/CVE-2026-78131.html * https://www.suse.com/security/cve/CVE-2026-78132.html * https://www.suse.com/security/cve/CVE-2026-78134.html * https://bugzilla.suse.com/show_bug.cgi?id=1276533 * https://bugzilla.suse.com/show_bug.cgi?id=1276534 * https://bugzilla.suse.com/show_bug.cgi?id=1276536 * https://bugzilla.suse.com/show_bug.cgi?id=1276539 * https://bugzilla.suse.com/show_bug.cgi?id=1276540 * https://bugzilla.suse.com/show_bug.cgi?id=1276541 * https://bugzilla.suse.com/show_bug.cgi?id=1276543 * https://bugzilla.suse.com/show_bug.cgi?id=1276544 * https://bugzilla.suse.com/show_bug.cgi?id=1276548 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 12:43:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 12:43:27 -0000 Subject: SUSE-SU-2026:4141-1: important: Security update for libvirt Message-ID: <178938980705.17839.10603268285543889592@b9be41dc2e4b> # Security update for libvirt Announcement ID: SUSE-SU-2026:4141-1 Release Date: 2026-09-14T07:59:03Z Rating: important References: * bsc#1274576 * bsc#1274946 * bsc#1275264 * bsc#1275265 * bsc#1275863 Cross-References: * CVE-2026-18917 * CVE-2026-61477 * CVE-2026-63622 * CVE-2026-63623 * CVE-2026-77159 CVSS scores: * CVE-2026-18917 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-18917 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-61477 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-61477 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61477 ( NVD ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-63622 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63622 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63622 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63623 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-63623 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-63623 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-77159 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-77159 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-77159 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves five vulnerabilities can now be installed. ## Description: This update for libvirt fixes the following issues: * CVE-2026-18917: Integer overflow in NodeGetFreePages RPC handler leading to heap buffer overflow (bsc#1275863). * CVE-2026-61477: newline injection in network XML DNS TXT/SRV fields allows dnsmasq config directive injection (bsc#1274576). * CVE-2026-63622: `swtpm` privilege escalation via symlink following (bsc#1275264). * CVE-2026-63623: information disclosure via world-readable storage volume images during clone/convert (bsc#1275265). * CVE-2026-77159: root `chown()` on `swtpm` logfile follows symlinks (bsc#1274946). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4141 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4141 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libvirt-daemon-driver-network-5.1.0-13.48.1 * libvirt-daemon-driver-storage-logical-5.1.0-13.48.1 * libvirt-daemon-qemu-5.1.0-13.48.1 * libvirt-daemon-driver-storage-mpath-5.1.0-13.48.1 * libvirt-daemon-driver-nwfilter-5.1.0-13.48.1 * libvirt-5.1.0-13.48.1 * libvirt-daemon-driver-storage-scsi-5.1.0-13.48.1 * libvirt-daemon-driver-storage-5.1.0-13.48.1 * libvirt-daemon-lxc-5.1.0-13.48.1 * libvirt-nss-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-lxc-5.1.0-13.48.1 * libvirt-client-debuginfo-5.1.0-13.48.1 * libvirt-admin-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-nodedev-5.1.0-13.48.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-5.1.0-13.48.1 * libvirt-daemon-config-network-5.1.0-13.48.1 * libvirt-libs-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-storage-disk-5.1.0-13.48.1 * libvirt-daemon-driver-storage-disk-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-secret-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-storage-core-5.1.0-13.48.1 * libvirt-daemon-config-nwfilter-5.1.0-13.48.1 * libvirt-daemon-driver-storage-scsi-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-secret-5.1.0-13.48.1 * libvirt-doc-5.1.0-13.48.1 * libvirt-daemon-driver-lxc-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-storage-iscsi-5.1.0-13.48.1 * libvirt-daemon-driver-storage-logical-debuginfo-5.1.0-13.48.1 * libvirt-client-5.1.0-13.48.1 * libvirt-daemon-debuginfo-5.1.0-13.48.1 * libvirt-lock-sanlock-debuginfo-5.1.0-13.48.1 * libvirt-nss-5.1.0-13.48.1 * libvirt-daemon-driver-interface-5.1.0-13.48.1 * libvirt-admin-5.1.0-13.48.1 * libvirt-daemon-5.1.0-13.48.1 * libvirt-debugsource-5.1.0-13.48.1 * libvirt-libs-5.1.0-13.48.1 * libvirt-lock-sanlock-5.1.0-13.48.1 * libvirt-daemon-hooks-5.1.0-13.48.1 * libvirt-daemon-driver-storage-mpath-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-nwfilter-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-nodedev-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-storage-core-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-interface-debuginfo-5.1.0-13.48.1 * libvirt-devel-5.1.0-13.48.1 * libvirt-daemon-driver-network-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-qemu-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-qemu-5.1.0-13.48.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (x86_64) * libvirt-daemon-xen-5.1.0-13.48.1 * libvirt-daemon-driver-libxl-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-libxl-5.1.0-13.48.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 x86_64) * libvirt-daemon-driver-storage-rbd-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-storage-rbd-5.1.0-13.48.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libvirt-daemon-driver-network-5.1.0-13.48.1 * libvirt-daemon-driver-storage-logical-5.1.0-13.48.1 * libvirt-daemon-qemu-5.1.0-13.48.1 * libvirt-daemon-driver-storage-mpath-5.1.0-13.48.1 * libvirt-daemon-driver-nwfilter-5.1.0-13.48.1 * libvirt-5.1.0-13.48.1 * libvirt-daemon-driver-storage-scsi-5.1.0-13.48.1 * libvirt-daemon-driver-storage-rbd-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-storage-5.1.0-13.48.1 * libvirt-daemon-lxc-5.1.0-13.48.1 * libvirt-nss-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-lxc-5.1.0-13.48.1 * libvirt-client-debuginfo-5.1.0-13.48.1 * libvirt-admin-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-nodedev-5.1.0-13.48.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-libxl-debuginfo-5.1.0-13.48.1 * libvirt-daemon-config-network-5.1.0-13.48.1 * libvirt-libs-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-storage-disk-5.1.0-13.48.1 * libvirt-daemon-driver-storage-disk-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-secret-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-storage-core-5.1.0-13.48.1 * libvirt-daemon-config-nwfilter-5.1.0-13.48.1 * libvirt-daemon-driver-storage-scsi-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-secret-5.1.0-13.48.1 * libvirt-doc-5.1.0-13.48.1 * libvirt-daemon-driver-lxc-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-storage-iscsi-5.1.0-13.48.1 * libvirt-daemon-driver-storage-logical-debuginfo-5.1.0-13.48.1 * libvirt-client-5.1.0-13.48.1 * libvirt-daemon-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-storage-rbd-5.1.0-13.48.1 * libvirt-lock-sanlock-debuginfo-5.1.0-13.48.1 * libvirt-nss-5.1.0-13.48.1 * libvirt-daemon-driver-interface-5.1.0-13.48.1 * libvirt-admin-5.1.0-13.48.1 * libvirt-daemon-5.1.0-13.48.1 * libvirt-debugsource-5.1.0-13.48.1 * libvirt-libs-5.1.0-13.48.1 * libvirt-lock-sanlock-5.1.0-13.48.1 * libvirt-daemon-hooks-5.1.0-13.48.1 * libvirt-daemon-driver-storage-mpath-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-libxl-5.1.0-13.48.1 * libvirt-daemon-driver-nwfilter-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-nodedev-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-storage-core-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-interface-debuginfo-5.1.0-13.48.1 * libvirt-devel-5.1.0-13.48.1 * libvirt-daemon-driver-network-debuginfo-5.1.0-13.48.1 * libvirt-daemon-driver-qemu-debuginfo-5.1.0-13.48.1 * libvirt-daemon-xen-5.1.0-13.48.1 * libvirt-daemon-driver-qemu-5.1.0-13.48.1 ## References: * https://www.suse.com/security/cve/CVE-2026-18917.html * https://www.suse.com/security/cve/CVE-2026-61477.html * https://www.suse.com/security/cve/CVE-2026-63622.html * https://www.suse.com/security/cve/CVE-2026-63623.html * https://www.suse.com/security/cve/CVE-2026-77159.html * https://bugzilla.suse.com/show_bug.cgi?id=1274576 * https://bugzilla.suse.com/show_bug.cgi?id=1274946 * https://bugzilla.suse.com/show_bug.cgi?id=1275264 * https://bugzilla.suse.com/show_bug.cgi?id=1275265 * https://bugzilla.suse.com/show_bug.cgi?id=1275863 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 12:44:20 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 12:44:20 -0000 Subject: SUSE-SU-2026:4140-1: important: Security update for MozillaFirefox, mozilla-nspr, mozilla-nss, rust-cbindgen Message-ID: <178938986062.17839.13535695823060601094@b9be41dc2e4b> # Security update for MozillaFirefox, mozilla-nspr, mozilla-nss, rust-cbindgen Announcement ID: SUSE-SU-2026:4140-1 Release Date: 2026-09-14T07:42:51Z Rating: important References: * bsc#1262698 * bsc#1262701 * bsc#1266262 * bsc#1266263 * bsc#1271649 * bsc#1272772 * bsc#1272773 * bsc#1272774 * bsc#1274867 * bsc#1278001 * bsc#1279863 Cross-References: * CVE-2026-16349 * CVE-2026-16350 * CVE-2026-16351 * CVE-2026-16352 * CVE-2026-16353 * CVE-2026-16354 * CVE-2026-16355 * CVE-2026-16356 * CVE-2026-16357 * CVE-2026-16358 * CVE-2026-16359 * CVE-2026-16360 * CVE-2026-16362 * CVE-2026-16363 * CVE-2026-16364 * CVE-2026-16365 * CVE-2026-16366 * CVE-2026-16367 * CVE-2026-16368 * CVE-2026-16369 * CVE-2026-16370 * CVE-2026-16371 * CVE-2026-16372 * CVE-2026-16373 * CVE-2026-16374 * CVE-2026-16375 * CVE-2026-16376 * CVE-2026-16377 * CVE-2026-16378 * CVE-2026-16379 * CVE-2026-16380 * CVE-2026-16381 * CVE-2026-16382 * CVE-2026-16383 * CVE-2026-16384 * CVE-2026-16385 * CVE-2026-16386 * CVE-2026-16387 * CVE-2026-16388 * CVE-2026-16389 * CVE-2026-16390 * CVE-2026-16391 * CVE-2026-16392 * CVE-2026-16393 * CVE-2026-16394 * CVE-2026-16395 * CVE-2026-16396 * CVE-2026-16397 * CVE-2026-16398 * CVE-2026-16399 * CVE-2026-16400 * CVE-2026-16401 * CVE-2026-16402 * CVE-2026-16403 * CVE-2026-16404 * CVE-2026-16405 * CVE-2026-16406 * CVE-2026-16407 * CVE-2026-16408 * CVE-2026-16409 * CVE-2026-16410 * CVE-2026-16411 * CVE-2026-16412 * CVE-2026-74934 * CVE-2026-74935 * CVE-2026-74936 * CVE-2026-74937 * CVE-2026-74938 * CVE-2026-74939 * CVE-2026-74940 * CVE-2026-74941 * CVE-2026-74942 * CVE-2026-74943 * CVE-2026-74944 * CVE-2026-74945 * CVE-2026-74946 * CVE-2026-74947 * CVE-2026-74948 * CVE-2026-74949 * CVE-2026-74950 * CVE-2026-74952 * CVE-2026-74953 * CVE-2026-74954 * CVE-2026-74955 * CVE-2026-74956 * CVE-2026-74957 * CVE-2026-74958 * CVE-2026-74959 * CVE-2026-74960 * CVE-2026-74961 * CVE-2026-74962 * CVE-2026-74963 * CVE-2026-74964 * CVE-2026-74965 * CVE-2026-74966 * CVE-2026-74967 * CVE-2026-74968 * CVE-2026-74969 * CVE-2026-74970 * CVE-2026-74971 * CVE-2026-74972 * CVE-2026-74973 * CVE-2026-74974 * CVE-2026-74976 * CVE-2026-74977 * CVE-2026-74978 * CVE-2026-74979 * CVE-2026-74981 * CVE-2026-74982 * CVE-2026-74983 * CVE-2026-74984 * CVE-2026-74985 * CVE-2026-74986 * CVE-2026-74987 * CVE-2026-74988 * CVE-2026-74990 * CVE-2026-75874 * CVE-2026-84118 * CVE-2026-84119 * CVE-2026-84120 * CVE-2026-84121 * CVE-2026-84122 * CVE-2026-84123 * CVE-2026-84124 * CVE-2026-84125 * CVE-2026-84129 * CVE-2026-84130 * CVE-2026-84131 * CVE-2026-84132 * CVE-2026-84133 * CVE-2026-84134 * CVE-2026-84136 * CVE-2026-84137 * CVE-2026-84139 * CVE-2026-84140 * CVE-2026-84141 * CVE-2026-84143 * CVE-2026-84144 * CVE-2026-84145 CVSS scores: * CVE-2026-16349 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-16349 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16350 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16350 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16351 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-16351 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16352 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16352 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16353 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16353 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16354 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16356 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16357 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16358 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16359 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16360 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16362 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16363 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16364 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16365 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16366 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16367 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-16368 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16369 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16370 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16371 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16372 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16374 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16375 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16376 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16377 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16378 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16379 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16380 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16381 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16382 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16384 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16385 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16386 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16387 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16388 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16389 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16390 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16391 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16392 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-16393 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-16394 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16395 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16396 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16397 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-16398 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16399 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16400 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16401 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16403 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-16404 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N * CVE-2026-16405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16406 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16407 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16408 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16409 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16410 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16411 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16412 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74934 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74934 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74935 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74935 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74936 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74936 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74936 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74937 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74938 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74938 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74939 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74940 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74940 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74941 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74942 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74943 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74943 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74944 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74944 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74945 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-74946 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74947 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74948 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-74949 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74950 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74952 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74953 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-74955 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74956 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74957 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74958 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-74959 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74960 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74961 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74962 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74963 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-74963 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74964 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74965 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74966 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-74967 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74968 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74969 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74970 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74971 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-74972 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-74973 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74974 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74976 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-74977 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74978 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74979 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74981 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74982 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74983 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74984 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74985 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74986 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74987 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74988 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74990 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74990 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-75874 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-84118 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84118 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84119 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-84119 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-84120 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84120 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84121 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-84121 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-84122 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84122 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84123 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84123 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84124 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84124 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84125 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84125 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84129 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84130 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84131 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84131 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84132 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84133 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84134 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-84136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84137 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-84137 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84139 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-84139 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84140 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84140 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84141 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84141 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84144 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84145 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84145 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 139 vulnerabilities can now be installed. ## Description: This update for MozillaFirefox, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: This update ships Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867) * CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935 Privilege escalation in the DOM: Networking component * CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937 Use-after-free in the JavaScript: GC component * CVE-2026-74938 Mitigation bypass in the JavaScript: GC component * CVE-2026-74939 Privilege escalation in the DOM: Navigation component * CVE-2026-74940 Use-after-free in the Graphics: Text component * CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942 Privilege escalation in the Remote Settings Client component * CVE-2026-74943 Use-after-free in the Graphics: ImageLib component * CVE-2026-74944 Use-after- free in the DOM: Core & HTML component * CVE-2026-74945 Information disclosure in the Graphics: Text component * CVE-2026-74946 Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947 Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948 Information disclosure in the Graphics component * CVE-2026-74949 Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950 Privilege escalation in the Downloads API component * CVE-2026-74953 Privilege escalation in the Networking: Cookies component * CVE-2026-74954 Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955 Privilege escalation in the Request Handling component * CVE-2026-74956 Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957 Mitigation bypass in the Safe Browsing component * CVE-2026-74958 Information disclosure in the WebRTC component * CVE-2026-74959 Mitigation bypass in the Storage: Cache API component * CVE-2026-74960 Site isolation issue in the WebExtensions component * CVE-2026-74961 Side-channel in the Web Audio component * CVE-2026-74962 Site isolation issue in the Networking: Cookies component * CVE-2026-74963 Same- origin policy bypass in the Networking: Cookies component * CVE-2026-74964 Integer overflow in the Graphics component * CVE-2026-74965 Privilege escalation in the Shell Integration component * CVE-2026-74966 Information disclosure in the Form Autofill component * CVE-2026-74967 Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968 Site isolation issue in the Graphics: WebRender component * CVE-2026-74969 Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970 Site isolation issue in the Graphics component * CVE-2026-74971 Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972 Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973 Race condition, use-after-free in the Graphics component * CVE-2026-74974 Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977 Integer overflow in the Graphics component * CVE-2026-74978 Clickjacking issue in the Widget component * CVE-2026-74979 Mitigation bypass in the Add-ons Manager component * CVE-2026-74981 Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982 Denial-of-service in the Widget component * CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984 Race condition in the JavaScript Engine component * CVE-2026-74985 Privilege escalation in the Enterprise Policies component * CVE-2026-74986 Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987 Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988 Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990 Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 \- Firefox Extended Support Release 153.0esr ESR * New: ## General \- Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. \- Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. \- The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. \- Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. \- Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs \- Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. \- Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. \- Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. \- Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. \- A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy \- Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. \- Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. \- Firefox now uses Safe Browsing V5 for phishing and malware protection. \- Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. \- Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations \- Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. \- A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility \- Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows \- Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. \- Firefox web apps are also available for Microsoft Store installations. \- Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS \- Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. \- WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux \- Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. \- Firefox no longer requires a restart after package manager updates and uses less memory on Linux. \- Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. \- WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. \- Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. \- Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. \- Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649) * CVE-2026-16349 Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350 Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362 Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351 Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352 Sandbox escape due to use-after- free in the Disability Access APIs component * CVE-2026-16363 JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364 Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365 Privilege escalation in the DOM: Workers component * CVE-2026-16366 Privilege escalation in the DOM: Navigation component * CVE-2026-16353 Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354 Information disclosure in the Graphics: ImageLib component * CVE-2026-16367 Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368 Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369 Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356 Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357 Incorrect boundary conditions in the Graphics component * CVE-2026-16370 Mitigation bypass in the DOM: Networking component * CVE-2026-16371 Privilege escalation in the DOM: Navigation component * CVE-2026-16372 Privilege escalation in the DOM: Content Processes component * CVE-2026-16373 Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374 Information disclosure in the Framework component in DevTools * CVE-2026-16375 Site isolation issue in the Networking: HTTP component * CVE-2026-16376 Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377 Mitigation bypass in the PDF Viewer component * CVE-2026-16378 Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379 Privilege escalation in the DOM: Content Processes component * CVE-2026-16358 Site isolation issue in the Graphics: WebRender component * CVE-2026-16380 Mitigation bypass in the Networking component * CVE-2026-16381 Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382 Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383 Mitigation bypass in the DOM: Networking component * CVE-2026-16384 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387 Site isolation issue in the Networking component * CVE-2026-16388 Sandbox escape in the DOM: Networking component * CVE-2026-16389 Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390 Mitigation bypass in the Enterprise Policies component * CVE-2026-16391 Information disclosure in the Storage: IndexedDB component * CVE-2026-16392 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393 Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359 Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394 Mitigation bypass in the DOM: Security component * CVE-2026-16395 Integer overflow in the Audio/Video component * CVE-2026-16396 Privilege escalation in WebExtensions * CVE-2026-16397 Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398 Site isolation issue in the Graphics component * CVE-2026-16399 Site isolation issue in the DOM: Navigation component * CVE-2026-16400 Information disclosure in the DOM: Security component * CVE-2026-16401 Privilege escalation in the Data Loss Prevention component * CVE-2026-16402 Integer overflow in the Graphics: ImageLib component * CVE-2026-16403 Spoofing issue in the Address Bar component * CVE-2026-16404 Spoofing issue in Firefox for Android * CVE-2026-16405 Information disclosure in the Networking: WebSockets component * CVE-2026-16406 Mitigation bypass in the Networking component * CVE-2026-16407 Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408 Integer overflow in the Audio/Video: Playback component * CVE-2026-16409 Invalid pointer in the Security: PSM component * CVE-2026-16410 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411 Memory safety bugs fixed in Firefox 153 * CVE-2026-16412 Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360 Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867) * CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935 Privilege escalation in the DOM: Networking component * CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939 Privilege escalation in the DOM: Navigation component * CVE-2026-74940 Use-after-free in the Graphics: Text component * CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942 Privilege escalation in the Remote Settings Client component * CVE-2026-74943 Use-after-free in the Graphics: ImageLib component * CVE-2026-74944 Use-after-free in the DOM: Core & HTML component * CVE-2026-74945 Information disclosure in the Graphics: Text component * CVE-2026-74946 Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948 Information disclosure in the Graphics component * CVE-2026-74949 Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953 Privilege escalation in the Networking: Cookies component * CVE-2026-74957 Mitigation bypass in the Safe Browsing component * CVE-2026-74959 Mitigation bypass in the Storage: Cache API component * CVE-2026-74960 Site isolation issue in the WebExtensions component * CVE-2026-74962 Site isolation issue in the Networking: Cookies component * CVE-2026-74963 Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964 Integer overflow in the Graphics component * CVE-2026-74965 Privilege escalation in the Shell Integration component * CVE-2026-74967 Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969 Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971 Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972 Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973 Race condition, use-after-free in the Graphics component * CVE-2026-74974 Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987 Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990 Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: * Update to version v0.29.4+git0: * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields * Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove "display" feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with "void" default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: Update to NSPR 4.39: * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig Update to version 4.38.2: * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 Update to version 4.38.1: * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. Update to version 4.38: * Removed support for HPUX and _PR_POLL_WITH_SELECT (bmo#1965666, bmo#1965916) * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char (bmo#375149) Update to version 4.37: * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support "%e" format specifier Changes in mozilla-nss: * Fix potential crash in nss-fips-approved-crypto-non-ec.patch (boo#1279863) * Fix upper bound to allow FIPS approval for P-521. * Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). * Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. * Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). * Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). * Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). * Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). * Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). * Add zeroization for ML-KEM, ported from upstream (bsc#1272774). * Add zeroization for ML-DSA (bsc#1272774). * Add ML-DSA robustness and test fixes. * Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). * Apply jitter entropy patch unconditionally (bsc#1262701). Update to NSS 3.125: * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren?t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ?Community ? Network Security Services (NSS)?. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. * update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix "testing if key corruption is detected in attribute" failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl * update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o * update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. * update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. * update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). * update to NSS 3.120.1 * no upstream releasenotes * update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. * Revert back to original naming scheme of tarballs * update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs * update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. * Adjusted for changed naming scheme of tarballs for this release by upstream * update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* * update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch * update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don?t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function * update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions * update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. * update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions * update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool * rebase FIPS patches to adjust for upstream FIPS work * update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4140 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4140 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libsoftokn3-3.125-58.147.1 * MozillaFirefox-debuginfo-153.2.0-118.5.4 * mozilla-nss-3.125-58.147.1 * MozillaFirefox-translations-common-153.2.0-118.5.4 * mozilla-nss-sysinit-debuginfo-3.125-58.147.1 * mozilla-nss-sysinit-3.125-58.147.1 * mozilla-nss-debuginfo-3.125-58.147.1 * MozillaFirefox-branding-SLE-153-41.3.8 * mozilla-nss-tools-debuginfo-3.125-58.147.1 * libfreebl3-3.125-58.147.1 * libsoftokn3-debuginfo-3.125-58.147.1 * mozilla-nss-certs-3.125-58.147.1 * libfreebl3-debuginfo-3.125-58.147.1 * mozilla-nss-certs-debuginfo-3.125-58.147.1 * mozilla-nspr-devel-4.39-19.39.1 * mozilla-nss-debugsource-3.125-58.147.1 * mozilla-nss-devel-3.125-58.147.1 * MozillaFirefox-debugsource-153.2.0-118.5.4 * MozillaFirefox-153.2.0-118.5.4 * mozilla-nspr-debuginfo-4.39-19.39.1 * mozilla-nss-tools-3.125-58.147.1 * mozilla-nspr-4.39-19.39.1 * mozilla-nspr-debugsource-4.39-19.39.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libfreebl3-32bit-3.125-58.147.1 * libfreebl3-debuginfo-32bit-3.125-58.147.1 * mozilla-nspr-debuginfo-32bit-4.39-19.39.1 * mozilla-nss-sysinit-debuginfo-32bit-3.125-58.147.1 * mozilla-nss-32bit-3.125-58.147.1 * libsoftokn3-debuginfo-32bit-3.125-58.147.1 * mozilla-nss-certs-debuginfo-32bit-3.125-58.147.1 * mozilla-nss-certs-32bit-3.125-58.147.1 * libsoftokn3-32bit-3.125-58.147.1 * mozilla-nss-debuginfo-32bit-3.125-58.147.1 * mozilla-nss-sysinit-32bit-3.125-58.147.1 * mozilla-nspr-32bit-4.39-19.39.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * MozillaFirefox-devel-153.2.0-118.5.4 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * mozilla-nspr-debuginfo-32bit-4.39-19.39.1 * libsoftokn3-3.125-58.147.1 * MozillaFirefox-debuginfo-153.2.0-118.5.4 * mozilla-nss-3.125-58.147.1 * MozillaFirefox-translations-common-153.2.0-118.5.4 * mozilla-nss-sysinit-debuginfo-3.125-58.147.1 * libfreebl3-32bit-3.125-58.147.1 * mozilla-nss-sysinit-3.125-58.147.1 * libsoftokn3-debuginfo-32bit-3.125-58.147.1 * mozilla-nss-certs-32bit-3.125-58.147.1 * libsoftokn3-32bit-3.125-58.147.1 * mozilla-nss-debuginfo-32bit-3.125-58.147.1 * mozilla-nss-debuginfo-3.125-58.147.1 * MozillaFirefox-branding-SLE-153-41.3.8 * mozilla-nss-sysinit-32bit-3.125-58.147.1 * mozilla-nss-tools-debuginfo-3.125-58.147.1 * libfreebl3-3.125-58.147.1 * libsoftokn3-debuginfo-3.125-58.147.1 * libfreebl3-debuginfo-32bit-3.125-58.147.1 * mozilla-nss-certs-3.125-58.147.1 * libfreebl3-debuginfo-3.125-58.147.1 * mozilla-nss-certs-debuginfo-3.125-58.147.1 * mozilla-nss-32bit-3.125-58.147.1 * mozilla-nspr-devel-4.39-19.39.1 * mozilla-nspr-32bit-4.39-19.39.1 * MozillaFirefox-debugsource-153.2.0-118.5.4 * MozillaFirefox-153.2.0-118.5.4 * mozilla-nss-debugsource-3.125-58.147.1 * mozilla-nss-devel-3.125-58.147.1 * mozilla-nspr-debuginfo-4.39-19.39.1 * mozilla-nss-sysinit-debuginfo-32bit-3.125-58.147.1 * mozilla-nss-tools-3.125-58.147.1 * mozilla-nspr-4.39-19.39.1 * mozilla-nss-certs-debuginfo-32bit-3.125-58.147.1 * mozilla-nspr-debugsource-4.39-19.39.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * MozillaFirefox-devel-153.2.0-118.5.4 ## References: * https://www.suse.com/security/cve/CVE-2026-16349.html * https://www.suse.com/security/cve/CVE-2026-16350.html * https://www.suse.com/security/cve/CVE-2026-16351.html * https://www.suse.com/security/cve/CVE-2026-16352.html * https://www.suse.com/security/cve/CVE-2026-16353.html * https://www.suse.com/security/cve/CVE-2026-16354.html * https://www.suse.com/security/cve/CVE-2026-16355.html * https://www.suse.com/security/cve/CVE-2026-16356.html * https://www.suse.com/security/cve/CVE-2026-16357.html * https://www.suse.com/security/cve/CVE-2026-16358.html * https://www.suse.com/security/cve/CVE-2026-16359.html * https://www.suse.com/security/cve/CVE-2026-16360.html * https://www.suse.com/security/cve/CVE-2026-16362.html * https://www.suse.com/security/cve/CVE-2026-16363.html * https://www.suse.com/security/cve/CVE-2026-16364.html * https://www.suse.com/security/cve/CVE-2026-16365.html * https://www.suse.com/security/cve/CVE-2026-16366.html * https://www.suse.com/security/cve/CVE-2026-16367.html * https://www.suse.com/security/cve/CVE-2026-16368.html * https://www.suse.com/security/cve/CVE-2026-16369.html * https://www.suse.com/security/cve/CVE-2026-16370.html * https://www.suse.com/security/cve/CVE-2026-16371.html * https://www.suse.com/security/cve/CVE-2026-16372.html * https://www.suse.com/security/cve/CVE-2026-16373.html * https://www.suse.com/security/cve/CVE-2026-16374.html * https://www.suse.com/security/cve/CVE-2026-16375.html * https://www.suse.com/security/cve/CVE-2026-16376.html * https://www.suse.com/security/cve/CVE-2026-16377.html * https://www.suse.com/security/cve/CVE-2026-16378.html * https://www.suse.com/security/cve/CVE-2026-16379.html * https://www.suse.com/security/cve/CVE-2026-16380.html * https://www.suse.com/security/cve/CVE-2026-16381.html * https://www.suse.com/security/cve/CVE-2026-16382.html * https://www.suse.com/security/cve/CVE-2026-16383.html * https://www.suse.com/security/cve/CVE-2026-16384.html * https://www.suse.com/security/cve/CVE-2026-16385.html * https://www.suse.com/security/cve/CVE-2026-16386.html * https://www.suse.com/security/cve/CVE-2026-16387.html * https://www.suse.com/security/cve/CVE-2026-16388.html * https://www.suse.com/security/cve/CVE-2026-16389.html * https://www.suse.com/security/cve/CVE-2026-16390.html * https://www.suse.com/security/cve/CVE-2026-16391.html * https://www.suse.com/security/cve/CVE-2026-16392.html * https://www.suse.com/security/cve/CVE-2026-16393.html * https://www.suse.com/security/cve/CVE-2026-16394.html * https://www.suse.com/security/cve/CVE-2026-16395.html * https://www.suse.com/security/cve/CVE-2026-16396.html * https://www.suse.com/security/cve/CVE-2026-16397.html * https://www.suse.com/security/cve/CVE-2026-16398.html * https://www.suse.com/security/cve/CVE-2026-16399.html * https://www.suse.com/security/cve/CVE-2026-16400.html * https://www.suse.com/security/cve/CVE-2026-16401.html * https://www.suse.com/security/cve/CVE-2026-16402.html * https://www.suse.com/security/cve/CVE-2026-16403.html * https://www.suse.com/security/cve/CVE-2026-16404.html * https://www.suse.com/security/cve/CVE-2026-16405.html * https://www.suse.com/security/cve/CVE-2026-16406.html * https://www.suse.com/security/cve/CVE-2026-16407.html * https://www.suse.com/security/cve/CVE-2026-16408.html * https://www.suse.com/security/cve/CVE-2026-16409.html * https://www.suse.com/security/cve/CVE-2026-16410.html * https://www.suse.com/security/cve/CVE-2026-16411.html * https://www.suse.com/security/cve/CVE-2026-16412.html * https://www.suse.com/security/cve/CVE-2026-74934.html * https://www.suse.com/security/cve/CVE-2026-74935.html * https://www.suse.com/security/cve/CVE-2026-74936.html * https://www.suse.com/security/cve/CVE-2026-74937.html * https://www.suse.com/security/cve/CVE-2026-74938.html * https://www.suse.com/security/cve/CVE-2026-74939.html * https://www.suse.com/security/cve/CVE-2026-74940.html * https://www.suse.com/security/cve/CVE-2026-74941.html * https://www.suse.com/security/cve/CVE-2026-74942.html * https://www.suse.com/security/cve/CVE-2026-74943.html * https://www.suse.com/security/cve/CVE-2026-74944.html * https://www.suse.com/security/cve/CVE-2026-74945.html * https://www.suse.com/security/cve/CVE-2026-74946.html * https://www.suse.com/security/cve/CVE-2026-74947.html * https://www.suse.com/security/cve/CVE-2026-74948.html * https://www.suse.com/security/cve/CVE-2026-74949.html * https://www.suse.com/security/cve/CVE-2026-74950.html * https://www.suse.com/security/cve/CVE-2026-74952.html * https://www.suse.com/security/cve/CVE-2026-74953.html * https://www.suse.com/security/cve/CVE-2026-74954.html * https://www.suse.com/security/cve/CVE-2026-74955.html * https://www.suse.com/security/cve/CVE-2026-74956.html * https://www.suse.com/security/cve/CVE-2026-74957.html * https://www.suse.com/security/cve/CVE-2026-74958.html * https://www.suse.com/security/cve/CVE-2026-74959.html * https://www.suse.com/security/cve/CVE-2026-74960.html * https://www.suse.com/security/cve/CVE-2026-74961.html * https://www.suse.com/security/cve/CVE-2026-74962.html * https://www.suse.com/security/cve/CVE-2026-74963.html * https://www.suse.com/security/cve/CVE-2026-74964.html * https://www.suse.com/security/cve/CVE-2026-74965.html * https://www.suse.com/security/cve/CVE-2026-74966.html * https://www.suse.com/security/cve/CVE-2026-74967.html * https://www.suse.com/security/cve/CVE-2026-74968.html * https://www.suse.com/security/cve/CVE-2026-74969.html * https://www.suse.com/security/cve/CVE-2026-74970.html * https://www.suse.com/security/cve/CVE-2026-74971.html * https://www.suse.com/security/cve/CVE-2026-74972.html * https://www.suse.com/security/cve/CVE-2026-74973.html * https://www.suse.com/security/cve/CVE-2026-74974.html * https://www.suse.com/security/cve/CVE-2026-74976.html * https://www.suse.com/security/cve/CVE-2026-74977.html * https://www.suse.com/security/cve/CVE-2026-74978.html * https://www.suse.com/security/cve/CVE-2026-74979.html * https://www.suse.com/security/cve/CVE-2026-74981.html * https://www.suse.com/security/cve/CVE-2026-74982.html * https://www.suse.com/security/cve/CVE-2026-74983.html * https://www.suse.com/security/cve/CVE-2026-74984.html * https://www.suse.com/security/cve/CVE-2026-74985.html * https://www.suse.com/security/cve/CVE-2026-74986.html * https://www.suse.com/security/cve/CVE-2026-74987.html * https://www.suse.com/security/cve/CVE-2026-74988.html * https://www.suse.com/security/cve/CVE-2026-74990.html * https://www.suse.com/security/cve/CVE-2026-75874.html * https://www.suse.com/security/cve/CVE-2026-84118.html * https://www.suse.com/security/cve/CVE-2026-84119.html * https://www.suse.com/security/cve/CVE-2026-84120.html * https://www.suse.com/security/cve/CVE-2026-84121.html * https://www.suse.com/security/cve/CVE-2026-84122.html * https://www.suse.com/security/cve/CVE-2026-84123.html * https://www.suse.com/security/cve/CVE-2026-84124.html * https://www.suse.com/security/cve/CVE-2026-84125.html * https://www.suse.com/security/cve/CVE-2026-84129.html * https://www.suse.com/security/cve/CVE-2026-84130.html * https://www.suse.com/security/cve/CVE-2026-84131.html * https://www.suse.com/security/cve/CVE-2026-84132.html * https://www.suse.com/security/cve/CVE-2026-84133.html * https://www.suse.com/security/cve/CVE-2026-84134.html * https://www.suse.com/security/cve/CVE-2026-84136.html * https://www.suse.com/security/cve/CVE-2026-84137.html * https://www.suse.com/security/cve/CVE-2026-84139.html * https://www.suse.com/security/cve/CVE-2026-84140.html * https://www.suse.com/security/cve/CVE-2026-84141.html * https://www.suse.com/security/cve/CVE-2026-84143.html * https://www.suse.com/security/cve/CVE-2026-84144.html * https://www.suse.com/security/cve/CVE-2026-84145.html * https://bugzilla.suse.com/show_bug.cgi?id=1262698 * https://bugzilla.suse.com/show_bug.cgi?id=1262701 * https://bugzilla.suse.com/show_bug.cgi?id=1266262 * https://bugzilla.suse.com/show_bug.cgi?id=1266263 * https://bugzilla.suse.com/show_bug.cgi?id=1271649 * https://bugzilla.suse.com/show_bug.cgi?id=1272772 * https://bugzilla.suse.com/show_bug.cgi?id=1272773 * https://bugzilla.suse.com/show_bug.cgi?id=1272774 * https://bugzilla.suse.com/show_bug.cgi?id=1274867 * https://bugzilla.suse.com/show_bug.cgi?id=1278001 * https://bugzilla.suse.com/show_bug.cgi?id=1279863 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 12:45:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 12:45:42 -0000 Subject: SUSE-SU-2026:4139-1: critical: Security update for dovecot23 Message-ID: <178938994296.17839.9066013753455602063@b9be41dc2e4b> # Security update for dovecot23 Announcement ID: SUSE-SU-2026:4139-1 Release Date: 2026-09-14T07:22:34Z Rating: critical References: * bsc#1229183 * bsc#1229184 * bsc#1260894 * bsc#1260895 * bsc#1260897 * bsc#1260898 * bsc#1260899 * bsc#1260900 * bsc#1260901 * bsc#1260902 * bsc#1265147 * bsc#1265148 * bsc#1265149 * bsc#1265150 * bsc#1276794 * bsc#1276795 * bsc#1276799 * bsc#1276800 * bsc#1276802 * bsc#1276804 * bsc#1276809 * bsc#1276811 * bsc#1276812 * bsc#1276815 * bsc#1276817 * bsc#1276820 * bsc#1276824 * bsc#1276826 * bsc#1276827 * bsc#1276828 * bsc#1276830 * bsc#1276833 * bsc#1276835 * bsc#1276837 Cross-References: * CVE-2024-23184 * CVE-2024-23185 * CVE-2025-59028 * CVE-2025-59031 * CVE-2025-59032 * CVE-2026-27852 * CVE-2026-27855 * CVE-2026-27856 * CVE-2026-27857 * CVE-2026-27858 * CVE-2026-27859 * CVE-2026-33263 * CVE-2026-33603 * CVE-2026-33604 * CVE-2026-33605 * CVE-2026-33606 * CVE-2026-33607 * CVE-2026-40014 * CVE-2026-40015 * CVE-2026-40016 * CVE-2026-40019 * CVE-2026-40020 * CVE-2026-40203 * CVE-2026-40205 * CVE-2026-42006 * CVE-2026-42007 * CVE-2026-42008 * CVE-2026-42391 * CVE-2026-42393 * CVE-2026-42395 * CVE-2026-52681 * CVE-2026-52687 * CVE-2026-73208 * CVE-2026-73209 CVSS scores: * CVE-2024-23184 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:L * CVE-2024-23184 ( SUSE ): 5.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L * CVE-2024-23184 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N * CVE-2024-23185 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2024-23185 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2024-23185 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59028 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-59028 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59028 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-59031 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-59031 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2025-59031 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2025-59032 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-59032 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59032 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59032 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27852 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27852 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27855 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-27855 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-27855 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-27855 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-27856 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-27856 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-27856 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-27856 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-27856 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-27857 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27857 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-27857 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-27857 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27857 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27858 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27858 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27858 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27858 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27859 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-27859 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-27859 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33263 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-33263 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33263 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33603 ( SUSE ): 7.6 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33603 ( SUSE ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33603 ( NVD ): 6.8 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33603 ( NVD ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-33604 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33604 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-33604 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-33605 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33605 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33605 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33606 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33606 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N * CVE-2026-33606 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N * CVE-2026-33607 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-33607 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33607 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40014 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40014 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-40014 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-40015 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-40015 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40015 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40016 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40016 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40016 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40016 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40019 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40019 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40019 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40020 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-40020 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40020 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40020 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40203 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-40203 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-40203 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-40205 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-40205 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-40205 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-42006 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42006 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42006 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42006 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42007 ( SUSE ): 8.5 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-42007 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-42007 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-42008 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42008 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-42008 ( NVD ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-42391 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42391 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42391 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42393 ( SUSE ): 2.3 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-42393 ( SUSE ): 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42393 ( NVD ): 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42395 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42395 ( NVD ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52681 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52681 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52681 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52687 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52687 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52687 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73208 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-73208 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-73208 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-73209 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:L/SI:N/SA:N * CVE-2026-73209 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73209 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * Server Applications Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 34 vulnerabilities can now be installed. ## Description: This update for dovecot23 fixes the following issues: * CVE-2024-23184: parsing of messages containing many address headers (From, To, Cc, Bcc, etc.) could be excessively CPU intensive (bsc#1229184). * CVE-2024-23185: large headers can cause resource exhaustion when parsing message (bsc#1229183). * CVE-2025-59028: Invalid base64 authentication can cause DoS for other logins (bsc#1260894). * CVE-2025-59031: decode2text.sh OOXML extraction may follow symlinks and read unintended files during indexing (bsc#1260895). * CVE-2025-59032: pigeonhole: ManageSieve panic occurs with sieve-connect as a client (bsc#1260902). * CVE-2026-27852: DoS by sending mail with bad header (bsc#1276799). * CVE-2026-27855: OTP driver vulnerable to replay attack (bsc#1260900). * CVE-2026-27856: Doveadm credentials were not checked using timing-safe checking function (bsc#1260899). * CVE-2026-27857: sending excessive parenthesis causes imap-login to use excessive memory (bsc#1260898). * CVE-2026-27858: pigeonhole: managesieve-login can allocate large amount of memory during authentication (bsc#1260901). * CVE-2026-27859: excessive RFC 2231 MIME parameters in email would can excessive CPU usage (bsc#1260897). * CVE-2026-33263: submission-login: Panic when mail_max_userip_connections is reached (bsc#1276794). * CVE-2026-33603: login: base64 input can contain tabs that bypass IPC protection (bsc#1265147). * CVE-2026-33604: SMTP Smuggling via Missing Dot-Stuffing (bsc#1276802). * CVE-2026-33605: managesieve-login: Pre-auth crash (bsc#1276809). * CVE-2026-33606: dsync: Mail content can cause dsync protocol injection (bsc#1276800). * CVE-2026-33607: IMAP LIST match_sub() Exponential Backtracking -- CPU Denial of Service (bsc#1276795). * CVE-2026-40014: CPU DoS via Crafted References Header (bsc#1276804). * CVE-2026-40015: imap-hibernate can be crashed (bsc#1276812). * CVE-2026-40016: Sieve :contains/:matches O(NxM) substring match bypasses sieve_max_cpu_time limit (bsc#1265148). * CVE-2026-40019: managesieve-login pre-auth infinite loop (bsc#1276811). * CVE-2026-40020: IMAP folders can be shared-spammed to everyone (bsc#1265149). * CVE-2026-40203: IMAP Compression Can Reveal Whether a Small Synced Email Body Matches Sender-Chosen Text (bsc#1276815). * CVE-2026-40205: OAuth2 passdb scope enforcement bypass via OR semantics in remote validation path (bsc#1276820). * CVE-2026-42006: imap-login: uncontrolled memory usage with excessive bracing over IMAP (bsc#1265150). * CVE-2026-42007: editheader RCE (bsc#1276817). * CVE-2026-42008: XCLIENT FORWARD= bare token not namespaced (bsc#1276824). * CVE-2026-42391: imap: Pre-login memory/CPU growth with ID command (bsc#1276835). * CVE-2026-42393: doveadm_password or api key length can still be leaked with timing comparisons (bsc#1276827). * CVE-2026-42395: Single NUL-Byte XCLIENT FORWARD Payload Crashes (bsc#1276826). * CVE-2026-52681: Sieve resource usage tracking lost when active script changes (bsc#1276828). * CVE-2026-52687: IMAP: COMPRESS ZSTD can cause excessive memory usage (bsc#1276837). * CVE-2026-73208: auth: db-oauth2: aud claim used as fallback for missing scope claim (bsc#1276830). * CVE-2026-73209: imap-login crash: Self-recursion on zero-output decompress chunks (bsc#1276833). Changes for dovecot23: * Update to version 2.3.21.1. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4139 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4139 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4139 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4139 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4139 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4139 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4139 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4139 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-4139 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4139 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4139 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * dovecot23-fts-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-2.3.21.1-150200.76.1 * dovecot23-fts-solr-debuginfo-2.3.21.1-150200.76.1 * dovecot23-debugsource-2.3.21.1-150200.76.1 * dovecot23-fts-squat-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-2.3.21.1-150200.76.1 * dovecot23-debuginfo-2.3.21.1-150200.76.1 * dovecot23-devel-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-solr-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-squat-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-2.3.21.1-150200.76.1 * dovecot23-fts-debuginfo-2.3.21.1-150200.76.1 * dovecot23-2.3.21.1-150200.76.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * dovecot23-fts-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-2.3.21.1-150200.76.1 * dovecot23-fts-solr-debuginfo-2.3.21.1-150200.76.1 * dovecot23-debugsource-2.3.21.1-150200.76.1 * dovecot23-fts-squat-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-2.3.21.1-150200.76.1 * dovecot23-debuginfo-2.3.21.1-150200.76.1 * dovecot23-devel-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-solr-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-squat-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-2.3.21.1-150200.76.1 * dovecot23-fts-debuginfo-2.3.21.1-150200.76.1 * dovecot23-2.3.21.1-150200.76.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * dovecot23-fts-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-2.3.21.1-150200.76.1 * dovecot23-fts-solr-debuginfo-2.3.21.1-150200.76.1 * dovecot23-debugsource-2.3.21.1-150200.76.1 * dovecot23-fts-squat-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-2.3.21.1-150200.76.1 * dovecot23-debuginfo-2.3.21.1-150200.76.1 * dovecot23-devel-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-solr-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-squat-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-2.3.21.1-150200.76.1 * dovecot23-fts-debuginfo-2.3.21.1-150200.76.1 * dovecot23-2.3.21.1-150200.76.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * dovecot23-fts-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-2.3.21.1-150200.76.1 * dovecot23-fts-solr-debuginfo-2.3.21.1-150200.76.1 * dovecot23-debugsource-2.3.21.1-150200.76.1 * dovecot23-fts-squat-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-2.3.21.1-150200.76.1 * dovecot23-debuginfo-2.3.21.1-150200.76.1 * dovecot23-devel-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-solr-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-squat-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-2.3.21.1-150200.76.1 * dovecot23-fts-debuginfo-2.3.21.1-150200.76.1 * dovecot23-2.3.21.1-150200.76.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * dovecot23-fts-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-2.3.21.1-150200.76.1 * dovecot23-fts-solr-debuginfo-2.3.21.1-150200.76.1 * dovecot23-debugsource-2.3.21.1-150200.76.1 * dovecot23-fts-squat-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-2.3.21.1-150200.76.1 * dovecot23-debuginfo-2.3.21.1-150200.76.1 * dovecot23-devel-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-solr-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-squat-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-2.3.21.1-150200.76.1 * dovecot23-fts-debuginfo-2.3.21.1-150200.76.1 * dovecot23-2.3.21.1-150200.76.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * dovecot23-fts-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-2.3.21.1-150200.76.1 * dovecot23-fts-solr-debuginfo-2.3.21.1-150200.76.1 * dovecot23-debugsource-2.3.21.1-150200.76.1 * dovecot23-fts-squat-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-2.3.21.1-150200.76.1 * dovecot23-debuginfo-2.3.21.1-150200.76.1 * dovecot23-devel-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-solr-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-squat-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-2.3.21.1-150200.76.1 * dovecot23-fts-debuginfo-2.3.21.1-150200.76.1 * dovecot23-2.3.21.1-150200.76.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * dovecot23-fts-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-2.3.21.1-150200.76.1 * dovecot23-fts-solr-debuginfo-2.3.21.1-150200.76.1 * dovecot23-debugsource-2.3.21.1-150200.76.1 * dovecot23-fts-squat-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-2.3.21.1-150200.76.1 * dovecot23-debuginfo-2.3.21.1-150200.76.1 * dovecot23-devel-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-solr-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-squat-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-2.3.21.1-150200.76.1 * dovecot23-fts-debuginfo-2.3.21.1-150200.76.1 * dovecot23-2.3.21.1-150200.76.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * dovecot23-fts-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-2.3.21.1-150200.76.1 * dovecot23-fts-solr-debuginfo-2.3.21.1-150200.76.1 * dovecot23-debugsource-2.3.21.1-150200.76.1 * dovecot23-fts-squat-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-2.3.21.1-150200.76.1 * dovecot23-debuginfo-2.3.21.1-150200.76.1 * dovecot23-devel-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-solr-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-squat-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-2.3.21.1-150200.76.1 * dovecot23-fts-debuginfo-2.3.21.1-150200.76.1 * dovecot23-2.3.21.1-150200.76.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * dovecot23-fts-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-2.3.21.1-150200.76.1 * dovecot23-fts-solr-debuginfo-2.3.21.1-150200.76.1 * dovecot23-debugsource-2.3.21.1-150200.76.1 * dovecot23-fts-squat-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-2.3.21.1-150200.76.1 * dovecot23-debuginfo-2.3.21.1-150200.76.1 * dovecot23-devel-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-solr-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-squat-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-2.3.21.1-150200.76.1 * dovecot23-fts-debuginfo-2.3.21.1-150200.76.1 * dovecot23-2.3.21.1-150200.76.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * dovecot23-fts-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-2.3.21.1-150200.76.1 * dovecot23-fts-solr-debuginfo-2.3.21.1-150200.76.1 * dovecot23-debugsource-2.3.21.1-150200.76.1 * dovecot23-fts-squat-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-2.3.21.1-150200.76.1 * dovecot23-debuginfo-2.3.21.1-150200.76.1 * dovecot23-devel-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-solr-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-squat-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-2.3.21.1-150200.76.1 * dovecot23-fts-debuginfo-2.3.21.1-150200.76.1 * dovecot23-2.3.21.1-150200.76.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * dovecot23-fts-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-2.3.21.1-150200.76.1 * dovecot23-fts-solr-debuginfo-2.3.21.1-150200.76.1 * dovecot23-debugsource-2.3.21.1-150200.76.1 * dovecot23-fts-squat-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-2.3.21.1-150200.76.1 * dovecot23-debuginfo-2.3.21.1-150200.76.1 * dovecot23-devel-2.3.21.1-150200.76.1 * dovecot23-fts-lucene-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-solr-2.3.21.1-150200.76.1 * dovecot23-backend-sqlite-debuginfo-2.3.21.1-150200.76.1 * dovecot23-fts-squat-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-pgsql-debuginfo-2.3.21.1-150200.76.1 * dovecot23-backend-mysql-2.3.21.1-150200.76.1 * dovecot23-fts-debuginfo-2.3.21.1-150200.76.1 * dovecot23-2.3.21.1-150200.76.1 ## References: * https://www.suse.com/security/cve/CVE-2024-23184.html * https://www.suse.com/security/cve/CVE-2024-23185.html * https://www.suse.com/security/cve/CVE-2025-59028.html * https://www.suse.com/security/cve/CVE-2025-59031.html * https://www.suse.com/security/cve/CVE-2025-59032.html * https://www.suse.com/security/cve/CVE-2026-27852.html * https://www.suse.com/security/cve/CVE-2026-27855.html * https://www.suse.com/security/cve/CVE-2026-27856.html * https://www.suse.com/security/cve/CVE-2026-27857.html * https://www.suse.com/security/cve/CVE-2026-27858.html * https://www.suse.com/security/cve/CVE-2026-27859.html * https://www.suse.com/security/cve/CVE-2026-33263.html * https://www.suse.com/security/cve/CVE-2026-33603.html * https://www.suse.com/security/cve/CVE-2026-33604.html * https://www.suse.com/security/cve/CVE-2026-33605.html * https://www.suse.com/security/cve/CVE-2026-33606.html * https://www.suse.com/security/cve/CVE-2026-33607.html * https://www.suse.com/security/cve/CVE-2026-40014.html * https://www.suse.com/security/cve/CVE-2026-40015.html * https://www.suse.com/security/cve/CVE-2026-40016.html * https://www.suse.com/security/cve/CVE-2026-40019.html * https://www.suse.com/security/cve/CVE-2026-40020.html * https://www.suse.com/security/cve/CVE-2026-40203.html * https://www.suse.com/security/cve/CVE-2026-40205.html * https://www.suse.com/security/cve/CVE-2026-42006.html * https://www.suse.com/security/cve/CVE-2026-42007.html * https://www.suse.com/security/cve/CVE-2026-42008.html * https://www.suse.com/security/cve/CVE-2026-42391.html * https://www.suse.com/security/cve/CVE-2026-42393.html * https://www.suse.com/security/cve/CVE-2026-42395.html * https://www.suse.com/security/cve/CVE-2026-52681.html * https://www.suse.com/security/cve/CVE-2026-52687.html * https://www.suse.com/security/cve/CVE-2026-73208.html * https://www.suse.com/security/cve/CVE-2026-73209.html * https://bugzilla.suse.com/show_bug.cgi?id=1229183 * https://bugzilla.suse.com/show_bug.cgi?id=1229184 * https://bugzilla.suse.com/show_bug.cgi?id=1260894 * https://bugzilla.suse.com/show_bug.cgi?id=1260895 * https://bugzilla.suse.com/show_bug.cgi?id=1260897 * https://bugzilla.suse.com/show_bug.cgi?id=1260898 * https://bugzilla.suse.com/show_bug.cgi?id=1260899 * https://bugzilla.suse.com/show_bug.cgi?id=1260900 * https://bugzilla.suse.com/show_bug.cgi?id=1260901 * https://bugzilla.suse.com/show_bug.cgi?id=1260902 * https://bugzilla.suse.com/show_bug.cgi?id=1265147 * https://bugzilla.suse.com/show_bug.cgi?id=1265148 * https://bugzilla.suse.com/show_bug.cgi?id=1265149 * https://bugzilla.suse.com/show_bug.cgi?id=1265150 * https://bugzilla.suse.com/show_bug.cgi?id=1276794 * https://bugzilla.suse.com/show_bug.cgi?id=1276795 * https://bugzilla.suse.com/show_bug.cgi?id=1276799 * https://bugzilla.suse.com/show_bug.cgi?id=1276800 * https://bugzilla.suse.com/show_bug.cgi?id=1276802 * https://bugzilla.suse.com/show_bug.cgi?id=1276804 * https://bugzilla.suse.com/show_bug.cgi?id=1276809 * https://bugzilla.suse.com/show_bug.cgi?id=1276811 * https://bugzilla.suse.com/show_bug.cgi?id=1276812 * https://bugzilla.suse.com/show_bug.cgi?id=1276815 * https://bugzilla.suse.com/show_bug.cgi?id=1276817 * https://bugzilla.suse.com/show_bug.cgi?id=1276820 * https://bugzilla.suse.com/show_bug.cgi?id=1276824 * https://bugzilla.suse.com/show_bug.cgi?id=1276826 * https://bugzilla.suse.com/show_bug.cgi?id=1276827 * https://bugzilla.suse.com/show_bug.cgi?id=1276828 * https://bugzilla.suse.com/show_bug.cgi?id=1276830 * https://bugzilla.suse.com/show_bug.cgi?id=1276833 * https://bugzilla.suse.com/show_bug.cgi?id=1276835 * https://bugzilla.suse.com/show_bug.cgi?id=1276837 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:32:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:32:43 -0000 Subject: SUSE-SU-2026:23662-1: moderate: Security update for multipath-tools Message-ID: <178940356352.576.13398280995879748596@5ac198222802> # Security update for multipath-tools Announcement ID: SUSE-SU-2026:23662-1 Release Date: 2026-09-07T15:03:57Z Rating: moderate References: * bsc#1277199 * bsc#1277203 * bsc#1277205 * bsc#1277208 * bsc#1277209 * bsc#1277210 * bsc#1277212 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has seven fixes can now be installed. ## Description: This update for multipath-tools fixes the following issues: * Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205). * Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210). * SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212). * Local Denial of Service via Blocking IPC Send Operations (bsc#1277199). * Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209). * DoS on multipathd socket by exhausting connections (bsc#1277203). * Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208). Changes for multipath-tools: * Update to version 0.12.4+278+suse.9cf9c5c. * Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1633 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1633 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * multipath-tools-debuginfo-0.12.4+278+suse.9cf9c5c-160000.1.1 * libdmmp-devel-0.12.4+278+suse.9cf9c5c-160000.1.1 * libmpath0-0.12.4+278+suse.9cf9c5c-160000.1.1 * kpartx-0.12.4+278+suse.9cf9c5c-160000.1.1 * kpartx-debuginfo-0.12.4+278+suse.9cf9c5c-160000.1.1 * multipath-tools-0.12.4+278+suse.9cf9c5c-160000.1.1 * multipath-tools-devel-0.12.4+278+suse.9cf9c5c-160000.1.1 * libdmmp0_2_0-0.12.4+278+suse.9cf9c5c-160000.1.1 * libmpath0-debuginfo-0.12.4+278+suse.9cf9c5c-160000.1.1 * multipath-tools-debugsource-0.12.4+278+suse.9cf9c5c-160000.1.1 * libdmmp0_2_0-debuginfo-0.12.4+278+suse.9cf9c5c-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * multipath-tools-debuginfo-0.12.4+278+suse.9cf9c5c-160000.1.1 * libdmmp-devel-0.12.4+278+suse.9cf9c5c-160000.1.1 * libmpath0-0.12.4+278+suse.9cf9c5c-160000.1.1 * kpartx-0.12.4+278+suse.9cf9c5c-160000.1.1 * kpartx-debuginfo-0.12.4+278+suse.9cf9c5c-160000.1.1 * multipath-tools-0.12.4+278+suse.9cf9c5c-160000.1.1 * multipath-tools-devel-0.12.4+278+suse.9cf9c5c-160000.1.1 * libdmmp0_2_0-0.12.4+278+suse.9cf9c5c-160000.1.1 * libmpath0-debuginfo-0.12.4+278+suse.9cf9c5c-160000.1.1 * multipath-tools-debugsource-0.12.4+278+suse.9cf9c5c-160000.1.1 * libdmmp0_2_0-debuginfo-0.12.4+278+suse.9cf9c5c-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1277199 * https://bugzilla.suse.com/show_bug.cgi?id=1277203 * https://bugzilla.suse.com/show_bug.cgi?id=1277205 * https://bugzilla.suse.com/show_bug.cgi?id=1277208 * https://bugzilla.suse.com/show_bug.cgi?id=1277209 * https://bugzilla.suse.com/show_bug.cgi?id=1277210 * https://bugzilla.suse.com/show_bug.cgi?id=1277212 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:33:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:33:46 -0000 Subject: SUSE-SU-2026:23660-1: moderate: Security update for libusb-1_0 Message-ID: <178940362608.576.8393216214917242084@5ac198222802> # Security update for libusb-1_0 Announcement ID: SUSE-SU-2026:23660-1 Release Date: 2026-09-07T10:17:39Z Rating: moderate References: * bsc#1266664 * bsc#1266667 Cross-References: * CVE-2026-23679 * CVE-2026-47104 CVSS scores: * CVE-2026-23679 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23679 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23679 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23679 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23679 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-47104 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47104 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47104 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47104 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for libusb-1_0 fixes the following issues: * CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). * CVE-2026-47104: one-byte out-of-bounds read in `parse_iad_array()` allows attackers to trigger a denial of service via a malformed USB descriptor (bsc#1266667). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1631 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1631 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libusb-1_0-0-1.0.28-160000.3.1 * libusb-1_0-debugsource-1.0.28-160000.3.1 * libusb-1_0-devel-1.0.28-160000.3.1 * libusb-1_0-0-debuginfo-1.0.28-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libusb-1_0-0-1.0.28-160000.3.1 * libusb-1_0-debugsource-1.0.28-160000.3.1 * libusb-1_0-devel-1.0.28-160000.3.1 * libusb-1_0-0-debuginfo-1.0.28-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23679.html * https://www.suse.com/security/cve/CVE-2026-47104.html * https://bugzilla.suse.com/show_bug.cgi?id=1266664 * https://bugzilla.suse.com/show_bug.cgi?id=1266667 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:34:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:34:28 -0000 Subject: SUSE-SU-2026:23659-1: important: Security update for aws-nitro-enclaves-cli Message-ID: <178940366878.576.5520818119263401404@5ac198222802> # Security update for aws-nitro-enclaves-cli Announcement ID: SUSE-SU-2026:23659-1 Release Date: 2026-09-07T10:17:39Z Rating: important References: * bsc#1257933 * bsc#1270202 * bsc#1274300 Cross-References: * CVE-2026-25541 * CVE-2026-25727 * CVE-2026-41676 CVSS scores: * CVE-2026-25541 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25541 ( NVD ): 5.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( NVD ): 6.8 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for aws-nitro-enclaves-cli fixes the following issues: * CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to undefined behavior and crashes (bsc#1274300). * CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257933). * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270202). Changes for aws-nitro-enclaves-cli: * Update to version 1.5.0 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1630 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1630 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * aws-nitro-enclaves-binaryblobs-upstream-1.5.0~git0.2950b36-160000.1.1 * aws-nitro-enclaves-cli-debugsource-1.5.0~git0.2950b36-160000.1.1 * aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.5.0~git0.2950b36-160000.1.1 * system-group-ne-1.5.0~git0.2950b36-160000.1.1 * aws-nitro-enclaves-cli-1.5.0~git0.2950b36-160000.1.1 * aws-nitro-enclaves-cli-debuginfo-1.5.0~git0.2950b36-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * aws-nitro-enclaves-binaryblobs-upstream-1.5.0~git0.2950b36-160000.1.1 * aws-nitro-enclaves-cli-debugsource-1.5.0~git0.2950b36-160000.1.1 * aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.5.0~git0.2950b36-160000.1.1 * system-group-ne-1.5.0~git0.2950b36-160000.1.1 * aws-nitro-enclaves-cli-1.5.0~git0.2950b36-160000.1.1 * aws-nitro-enclaves-cli-debuginfo-1.5.0~git0.2950b36-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25541.html * https://www.suse.com/security/cve/CVE-2026-25727.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1257933 * https://bugzilla.suse.com/show_bug.cgi?id=1270202 * https://bugzilla.suse.com/show_bug.cgi?id=1274300 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:35:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:35:55 -0000 Subject: SUSE-SU-2026:23656-1: important: Security update for NetworkManager Message-ID: <178940375573.576.11444108405662112063@5ac198222802> # Security update for NetworkManager Announcement ID: SUSE-SU-2026:23656-1 Release Date: 2026-09-06T17:07:25Z Rating: important References: * bsc#1267696 * bsc#1276764 Cross-References: * CVE-2026-10805 * CVE-2026-19685 CVSS scores: * CVE-2026-10805 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-10805 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19685 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-19685 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-19685 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19685 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for NetworkManager fixes the following issues: * CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). * CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1624 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1624 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * NetworkManager-devel-1.52.0-160000.5.1 * NetworkManager-1.52.0-160000.5.1 * libnm0-1.52.0-160000.5.1 * typelib-1_0-NM-1_0-1.52.0-160000.5.1 * NetworkManager-cloud-setup-debuginfo-1.52.0-160000.5.1 * NetworkManager-cloud-setup-1.52.0-160000.5.1 * NetworkManager-wwan-1.52.0-160000.5.1 * libnm0-debuginfo-1.52.0-160000.5.1 * NetworkManager-pppoe-debuginfo-1.52.0-160000.5.1 * NetworkManager-pppoe-1.52.0-160000.5.1 * NetworkManager-tui-debuginfo-1.52.0-160000.5.1 * NetworkManager-debuginfo-1.52.0-160000.5.1 * NetworkManager-wwan-debuginfo-1.52.0-160000.5.1 * NetworkManager-tui-1.52.0-160000.5.1 * NetworkManager-debugsource-1.52.0-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * NetworkManager-lang-1.52.0-160000.5.1 * NetworkManager-config-server-1.52.0-160000.5.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * NetworkManager-devel-1.52.0-160000.5.1 * NetworkManager-1.52.0-160000.5.1 * libnm0-1.52.0-160000.5.1 * typelib-1_0-NM-1_0-1.52.0-160000.5.1 * NetworkManager-cloud-setup-debuginfo-1.52.0-160000.5.1 * NetworkManager-cloud-setup-1.52.0-160000.5.1 * NetworkManager-wwan-1.52.0-160000.5.1 * libnm0-debuginfo-1.52.0-160000.5.1 * NetworkManager-pppoe-debuginfo-1.52.0-160000.5.1 * NetworkManager-pppoe-1.52.0-160000.5.1 * NetworkManager-tui-debuginfo-1.52.0-160000.5.1 * NetworkManager-debuginfo-1.52.0-160000.5.1 * NetworkManager-wwan-debuginfo-1.52.0-160000.5.1 * NetworkManager-tui-1.52.0-160000.5.1 * NetworkManager-debugsource-1.52.0-160000.5.1 * SUSE Linux Enterprise Server 16.0 (noarch) * NetworkManager-lang-1.52.0-160000.5.1 * NetworkManager-config-server-1.52.0-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10805.html * https://www.suse.com/security/cve/CVE-2026-19685.html * https://bugzilla.suse.com/show_bug.cgi?id=1267696 * https://bugzilla.suse.com/show_bug.cgi?id=1276764 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:40:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:40:12 -0000 Subject: SUSE-SU-2026:23646-1: moderate: Security update for multipath-tools Message-ID: <178940401217.576.14342544866912824869@5ac198222802> # Security update for multipath-tools Announcement ID: SUSE-SU-2026:23646-1 Release Date: 2026-09-07T15:33:05Z Rating: moderate References: * bsc#1277199 * bsc#1277203 * bsc#1277205 * bsc#1277208 * bsc#1277209 * bsc#1277210 * bsc#1277212 Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has seven fixes can now be installed. ## Description: This update for multipath-tools fixes the following issues: * Heap Out-of-Bounds Read in Custom Format String Parser via Trailing `%` (bsc#1277205). * Path traversal in device-mapper-multipath failed_wwids management (bsc#1277210). * SCSI PRIN READ FULL STATUS responses can cause heap buffer overflows (bsc#1277212). * Local Denial of Service via Blocking IPC Send Operations (bsc#1277199). * Heap Out-of-Bounds Read in GPT Header Validation (bsc#1277209). * DoS on multipathd socket by exhausting connections (bsc#1277203). * Heap out-of-bounds read in device-mapper-multipath ALUA RTPG parsing (bsc#1277208). Changes for multipath-tools: * Update to version 0.12.4+278+suse.9cf9c5c. * Add missing NULL check in DM parser (gh#opensvc/multipath-tools#155). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1633 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * multipath-tools-debuginfo-0.12.4+278+suse.9cf9c5c-160000.1.1 * libdmmp-devel-0.12.4+278+suse.9cf9c5c-160000.1.1 * libmpath0-0.12.4+278+suse.9cf9c5c-160000.1.1 * kpartx-0.12.4+278+suse.9cf9c5c-160000.1.1 * kpartx-debuginfo-0.12.4+278+suse.9cf9c5c-160000.1.1 * multipath-tools-0.12.4+278+suse.9cf9c5c-160000.1.1 * multipath-tools-devel-0.12.4+278+suse.9cf9c5c-160000.1.1 * libdmmp0_2_0-0.12.4+278+suse.9cf9c5c-160000.1.1 * libmpath0-debuginfo-0.12.4+278+suse.9cf9c5c-160000.1.1 * multipath-tools-debugsource-0.12.4+278+suse.9cf9c5c-160000.1.1 * libdmmp0_2_0-debuginfo-0.12.4+278+suse.9cf9c5c-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1277199 * https://bugzilla.suse.com/show_bug.cgi?id=1277203 * https://bugzilla.suse.com/show_bug.cgi?id=1277205 * https://bugzilla.suse.com/show_bug.cgi?id=1277208 * https://bugzilla.suse.com/show_bug.cgi?id=1277209 * https://bugzilla.suse.com/show_bug.cgi?id=1277210 * https://bugzilla.suse.com/show_bug.cgi?id=1277212 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:41:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:41:13 -0000 Subject: SUSE-SU-2026:23644-1: moderate: Security update for libusb-1_0 Message-ID: <178940407349.576.6671393301021334618@5ac198222802> # Security update for libusb-1_0 Announcement ID: SUSE-SU-2026:23644-1 Release Date: 2026-09-07T10:34:06Z Rating: moderate References: * bsc#1266664 * bsc#1266667 Cross-References: * CVE-2026-23679 * CVE-2026-47104 CVSS scores: * CVE-2026-23679 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23679 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23679 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-23679 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23679 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-47104 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47104 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47104 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47104 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-47104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for libusb-1_0 fixes the following issues: * CVE-2026-23679: NULL pointer dereference in `parse_interface()` allows attackers to crash applications by supplying a malformed USB configuration descriptor (bsc#1266664). * CVE-2026-47104: one-byte out-of-bounds read in `parse_iad_array()` allows attackers to trigger a denial of service via a malformed USB descriptor (bsc#1266667). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1631 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libusb-1_0-0-1.0.28-160000.3.1 * libusb-1_0-debugsource-1.0.28-160000.3.1 * libusb-1_0-devel-1.0.28-160000.3.1 * libusb-1_0-0-debuginfo-1.0.28-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-23679.html * https://www.suse.com/security/cve/CVE-2026-47104.html * https://bugzilla.suse.com/show_bug.cgi?id=1266664 * https://bugzilla.suse.com/show_bug.cgi?id=1266667 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:41:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:41:54 -0000 Subject: SUSE-SU-2026:23643-1: important: Security update for aws-nitro-enclaves-cli Message-ID: <178940411492.576.8790477496796752734@5ac198222802> # Security update for aws-nitro-enclaves-cli Announcement ID: SUSE-SU-2026:23643-1 Release Date: 2026-09-07T10:34:06Z Rating: important References: * bsc#1257933 * bsc#1270202 * bsc#1274300 Cross-References: * CVE-2026-25541 * CVE-2026-25727 * CVE-2026-41676 CVSS scores: * CVE-2026-25541 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25541 ( NVD ): 5.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( NVD ): 6.8 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-41676 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-41676 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-41676 ( NVD ): 7.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41676 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for aws-nitro-enclaves-cli fixes the following issues: * CVE-2026-25541: bytes: integer overflow in 'BytesMut:reserve' can lead to undefined behavior and crashes (bsc#1274300). * CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257933). * CVE-2026-41676: openssl: `Deriver:derive` and `PkeyCtxRef:derive` can overflow short buffers on OpenSSL 1.1.1 (bsc#1270202). Changes for aws-nitro-enclaves-cli: * Update to version 1.5.0 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1630 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * aws-nitro-enclaves-binaryblobs-upstream-1.5.0~git0.2950b36-160000.1.1 * aws-nitro-enclaves-cli-debugsource-1.5.0~git0.2950b36-160000.1.1 * aws-nitro-enclaves-binaryblobs-upstream-debuginfo-1.5.0~git0.2950b36-160000.1.1 * system-group-ne-1.5.0~git0.2950b36-160000.1.1 * aws-nitro-enclaves-cli-1.5.0~git0.2950b36-160000.1.1 * aws-nitro-enclaves-cli-debuginfo-1.5.0~git0.2950b36-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-25541.html * https://www.suse.com/security/cve/CVE-2026-25727.html * https://www.suse.com/security/cve/CVE-2026-41676.html * https://bugzilla.suse.com/show_bug.cgi?id=1257933 * https://bugzilla.suse.com/show_bug.cgi?id=1270202 * https://bugzilla.suse.com/show_bug.cgi?id=1274300 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:43:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:43:46 -0000 Subject: SUSE-SU-2026:23639-1: important: Security update for NetworkManager Message-ID: <178940422639.576.16528435541804372456@5ac198222802> # Security update for NetworkManager Announcement ID: SUSE-SU-2026:23639-1 Release Date: 2026-09-06T17:00:57Z Rating: important References: * bsc#1267696 * bsc#1276764 Cross-References: * CVE-2026-10805 * CVE-2026-19685 CVSS scores: * CVE-2026-10805 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-10805 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19685 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-19685 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-19685 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19685 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for NetworkManager fixes the following issues: * CVE-2026-10805: local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). * CVE-2026-19685: missing user ownership checks for 802.1X directory properties can allow WPA-Enterprise server certificate validation bypass (bsc#1276764). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1624 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * NetworkManager-devel-1.52.0-160000.5.1 * NetworkManager-1.52.0-160000.5.1 * libnm0-1.52.0-160000.5.1 * typelib-1_0-NM-1_0-1.52.0-160000.5.1 * NetworkManager-cloud-setup-debuginfo-1.52.0-160000.5.1 * NetworkManager-cloud-setup-1.52.0-160000.5.1 * NetworkManager-wwan-1.52.0-160000.5.1 * libnm0-debuginfo-1.52.0-160000.5.1 * NetworkManager-pppoe-debuginfo-1.52.0-160000.5.1 * NetworkManager-pppoe-1.52.0-160000.5.1 * NetworkManager-tui-debuginfo-1.52.0-160000.5.1 * NetworkManager-debuginfo-1.52.0-160000.5.1 * NetworkManager-wwan-debuginfo-1.52.0-160000.5.1 * NetworkManager-tui-1.52.0-160000.5.1 * NetworkManager-debugsource-1.52.0-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * NetworkManager-lang-1.52.0-160000.5.1 * NetworkManager-config-server-1.52.0-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10805.html * https://www.suse.com/security/cve/CVE-2026-19685.html * https://bugzilla.suse.com/show_bug.cgi?id=1267696 * https://bugzilla.suse.com/show_bug.cgi?id=1276764 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:44:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:44:31 -0000 Subject: SUSE-SU-2026:23638-1: moderate: Security update for curl Message-ID: <178940427156.576.15561345493801504811@5ac198222802> # Security update for curl Announcement ID: SUSE-SU-2026:23638-1 Release Date: 2026-09-06T16:54:54Z Rating: moderate References: * bsc#1262633 * bsc#1263440 * bsc#1268412 * bsc#1277476 * bsc#1277479 * bsc#1277480 Cross-References: * CVE-2026-13608 * CVE-2026-5773 * CVE-2026-7168 * CVE-2026-80229 * CVE-2026-80230 * CVE-2026-8926 CVSS scores: * CVE-2026-13608 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-13608 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-13608 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-5773 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-5773 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-5773 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-5773 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-7168 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-7168 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-7168 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-7168 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-80229 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-80229 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-80229 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80230 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-80230 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-80230 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-8926 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8926 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-8926 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for curl fixes the following issues: * CVE-2026-5773: wrong reuse of SMB connection (bsc#1262633). * CVE-2026-7168: cross-proxy Digest auth state leak (bsc#1263440). * CVE-2026-8926: password leak with netrc and user in URL (bsc#1268412). * CVE-2026-13608: OpenLDAP SASL authentication bypass (bsc#1277476). * CVE-2026-80229: OpenSSL provider use-after-free (bsc#1277479). * CVE-2026-80230: OpenSSL pinning bypass (bsc#1277480). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1622 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1622 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libcurl-mini4-8.14.1-160000.9.1 * libcurl-mini4-debuginfo-8.14.1-160000.9.1 * libcurl4-8.14.1-160000.9.1 * libcurl-devel-8.14.1-160000.9.1 * curl-mini-debugsource-8.14.1-160000.9.1 * libcurl4-debuginfo-8.14.1-160000.9.1 * curl-8.14.1-160000.9.1 * curl-debugsource-8.14.1-160000.9.1 * curl-debuginfo-8.14.1-160000.9.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * libcurl-devel-doc-8.14.1-160000.9.1 * curl-zsh-completion-8.14.1-160000.9.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libcurl-mini4-8.14.1-160000.9.1 * libcurl-mini4-debuginfo-8.14.1-160000.9.1 * libcurl4-8.14.1-160000.9.1 * libcurl-devel-8.14.1-160000.9.1 * curl-mini-debugsource-8.14.1-160000.9.1 * libcurl4-debuginfo-8.14.1-160000.9.1 * curl-8.14.1-160000.9.1 * curl-debugsource-8.14.1-160000.9.1 * curl-debuginfo-8.14.1-160000.9.1 * SUSE Linux Enterprise Server 16.0 (noarch) * libcurl-devel-doc-8.14.1-160000.9.1 * curl-zsh-completion-8.14.1-160000.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13608.html * https://www.suse.com/security/cve/CVE-2026-5773.html * https://www.suse.com/security/cve/CVE-2026-7168.html * https://www.suse.com/security/cve/CVE-2026-80229.html * https://www.suse.com/security/cve/CVE-2026-80230.html * https://www.suse.com/security/cve/CVE-2026-8926.html * https://bugzilla.suse.com/show_bug.cgi?id=1262633 * https://bugzilla.suse.com/show_bug.cgi?id=1263440 * https://bugzilla.suse.com/show_bug.cgi?id=1268412 * https://bugzilla.suse.com/show_bug.cgi?id=1277476 * https://bugzilla.suse.com/show_bug.cgi?id=1277479 * https://bugzilla.suse.com/show_bug.cgi?id=1277480 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:45:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:45:33 -0000 Subject: SUSE-SU-2026:23636-1: moderate: Security update for mcphost Message-ID: <178940433397.576.9497818588249441174@5ac198222802> # Security update for mcphost Announcement ID: SUSE-SU-2026:23636-1 Release Date: 2026-09-06T16:47:56Z Rating: moderate References: * bsc#1276612 * bsc#1278013 Cross-References: * CVE-2026-41178 * CVE-2026-81092 CVSS scores: * CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-81092 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-81092 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-81092 ( NVD ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-81092 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for mcphost fixes the following issues: * CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276612). * CVE-2026-81092: github.com/mark3labs/mcp-go/server: requests accepted in HTTP transports without Host header checks can lead to tool usage and resource exposure in target server (bsc#1278013). Changes for mcphost: * Update github.com/mark3labs/mcp-go/server to v0.56.0. * Update go.opentelemetry.io/otel to 1.44.0. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1619 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1619 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * mcphost-0.34.0-160000.4.1 * mcphost-debuginfo-0.34.0-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * mcphost-0.34.0-160000.4.1 * mcphost-debuginfo-0.34.0-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41178.html * https://www.suse.com/security/cve/CVE-2026-81092.html * https://bugzilla.suse.com/show_bug.cgi?id=1276612 * https://bugzilla.suse.com/show_bug.cgi?id=1278013 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:46:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:46:13 -0000 Subject: SUSE-SU-2026:23635-1: important: Security update for php-composer2 Message-ID: <178940437310.576.13789501438318600903@5ac198222802> # Security update for php-composer2 Announcement ID: SUSE-SU-2026:23635-1 Release Date: 2026-09-06T16:46:15Z Rating: important References: * bsc#1278257 Cross-References: * CVE-2026-84361 CVSS scores: * CVE-2026-84361 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84361 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for php-composer2 fixes the following issue: * CVE-2026-84361: Arbitrary code execution via malicious Perforce source URL (bsc#1278257). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1626 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1626 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * php-composer2-2.8.9-160000.5.1 * SUSE Linux Enterprise Server 16.0 (noarch) * php-composer2-2.8.9-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-84361.html * https://bugzilla.suse.com/show_bug.cgi?id=1278257 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:46:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:46:53 -0000 Subject: SUSE-SU-2026:23634-1: moderate: Security update for python-sqlparse Message-ID: <178940441309.576.133470126331453019@5ac198222802> # Security update for python-sqlparse Announcement ID: SUSE-SU-2026:23634-1 Release Date: 2026-09-06T16:46:15Z Rating: moderate References: * bsc#1278097 Cross-References: * CVE-2026-84305 CVSS scores: * CVE-2026-84305 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84305 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-84305 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-sqlparse fixes the following issue: * CVE-2026-84305: Reindentation of tuple lists causes near-cap quadratic CPU consumption (bsc#1278097). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1625 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1625 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-sqlparse-0.5.3-160000.5.1 * SUSE Linux Enterprise Server 16.0 (noarch) * python313-sqlparse-0.5.3-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-84305.html * https://bugzilla.suse.com/show_bug.cgi?id=1278097 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:47:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:47:32 -0000 Subject: SUSE-SU-2026:23633-1: moderate: Security update for perl-URI Message-ID: <178940445247.576.18439816873561689925@5ac198222802> # Security update for perl-URI Announcement ID: SUSE-SU-2026:23633-1 Release Date: 2026-09-06T16:46:15Z Rating: moderate References: * bsc#1277886 Cross-References: * CVE-2026-19953 CVSS scores: * CVE-2026-19953 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:L/SI:L/SA:L * CVE-2026-19953 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-19953 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for perl-URI fixes the following issue: * CVE-2026-19953: non-NFC host names encoded to non-standard punycode labels due to missing normalization in `nameprep` (bsc#1277886). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1621 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1621 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * perl-URI-5.310.0-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * perl-URI-5.310.0-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-19953.html * https://bugzilla.suse.com/show_bug.cgi?id=1277886 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:48:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:48:54 -0000 Subject: SUSE-SU-2026:23630-1: moderate: Security update for msgpack-c Message-ID: <178940453432.576.17907198547212429910@5ac198222802> # Security update for msgpack-c Announcement ID: SUSE-SU-2026:23630-1 Release Date: 2026-09-06T16:46:15Z Rating: moderate References: * bsc#1275911 Cross-References: * CVE-2026-72854 CVSS scores: * CVE-2026-72854 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L * CVE-2026-72854 ( NVD ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-72854 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for msgpack-c fixes the following issue: Update to release 7.0.2: * CVE-2026-72854: Integer Overflow in msgpack_unpacker_expand_buffer Causes a False-Success Undersized Reservation (bsc#1275911). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1616 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1616 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libmsgpack-c2-7.0.2-160000.1.1 * libmsgpack-c2-debuginfo-7.0.2-160000.1.1 * msgpack-c-debugsource-7.0.2-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libmsgpack-c2-7.0.2-160000.1.1 * libmsgpack-c2-debuginfo-7.0.2-160000.1.1 * msgpack-c-debugsource-7.0.2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-72854.html * https://bugzilla.suse.com/show_bug.cgi?id=1275911 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:49:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:49:53 -0000 Subject: SUSE-SU-2026:23628-1: moderate: Security update for rpcbind Message-ID: <178940459385.576.13835797117718545705@5ac198222802> # Security update for rpcbind Announcement ID: SUSE-SU-2026:23628-1 Release Date: 2026-09-06T16:46:15Z Rating: moderate References: * bsc#1272340 Cross-References: * CVE-2026-16461 CVSS scores: * CVE-2026-16461 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-16461 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for rpcbind fixes the following issue: * CVE-2026-16461: stack buffer overflow in rpcinfo rpcbdump() short-mode version-list formatting (bsc#1272340). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1613 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1613 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * rpcbind-debuginfo-1.2.9-160000.2.1 * rpcbind-1.2.9-160000.2.1 * rpcbind-debugsource-1.2.9-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * rpcbind-debuginfo-1.2.9-160000.2.1 * rpcbind-1.2.9-160000.2.1 * rpcbind-debugsource-1.2.9-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16461.html * https://bugzilla.suse.com/show_bug.cgi?id=1272340 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:50:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:50:32 -0000 Subject: SUSE-SU-2026:23627-1: low: Security update for bzip2 Message-ID: <178940463263.576.9314334211509391682@5ac198222802> # Security update for bzip2 Announcement ID: SUSE-SU-2026:23627-1 Release Date: 2026-09-04T13:53:27Z Rating: low References: * bsc#1266786 Cross-References: * CVE-2026-42250 CVSS scores: * CVE-2026-42250 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-42250 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-42250 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for bzip2 fixes the following issue: * CVE-2026-42250: off-by-one error in the `bzip2recover` utility when processing a specially crafted file can lead to a crash (bsc#1266786). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1610 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1610 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * bzip2-debuginfo-1.0.8-160000.3.1 * libbz2-1-1.0.8-160000.3.1 * bzip2-1.0.8-160000.3.1 * libbz2-1-debuginfo-1.0.8-160000.3.1 * libbz2-devel-1.0.8-160000.3.1 * bzip2-debugsource-1.0.8-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * bzip2-doc-1.0.8-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * libbz2-1-x86-64-v3-1.0.8-160000.3.1 * libbz2-1-x86-64-v3-debuginfo-1.0.8-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * bzip2-debuginfo-1.0.8-160000.3.1 * libbz2-1-1.0.8-160000.3.1 * bzip2-1.0.8-160000.3.1 * libbz2-1-debuginfo-1.0.8-160000.3.1 * libbz2-devel-1.0.8-160000.3.1 * bzip2-debugsource-1.0.8-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * bzip2-doc-1.0.8-160000.3.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * libbz2-1-x86-64-v3-1.0.8-160000.3.1 * libbz2-1-x86-64-v3-debuginfo-1.0.8-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-42250.html * https://bugzilla.suse.com/show_bug.cgi?id=1266786 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:51:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:51:35 -0000 Subject: SUSE-SU-2026:23625-1: moderate: Security update for govulncheck-vulndb Message-ID: <178940469552.576.7317727214138222310@5ac198222802> # Security update for govulncheck-vulndb Announcement ID: SUSE-SU-2026:23625-1 Release Date: 2026-09-04T12:30:23Z Rating: moderate References: * jsc#PED-11136 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that contains one feature can now be installed. ## Description: This update for govulncheck-vulndb fixes the following issues: * Update to version 0.0.20260827T195228 2026-08-27T19:52:28Z (jsc#PED-11136). Go CVE Numbering Authority IDs added or updated with aliases: * GO-2026-5026 CVE-2026-39821 * GO-2026-6225 * GO-2026-6250 CVE-2026-63328 GHSA-8rc5-4fr6-64pw * GO-2026-6253 CVE-2026-17106 GHSA-hfg8-hc9c-6c3h * GO-2026-6254 CVE-2026-53941 GHSA-vjhx-2cqw-3q6q * GO-2026-6255 CVE-2026-61711 GHSA-7236-3392-c5c6 * GO-2026-6256 CVE-2026-61712 GHSA-72x6-4j93-7w86 * GO-2026-6258 CVE-2026-45404 GHSA-42cj-99w8-cp2p * GO-2026-6259 CVE-2026-32637 GHSA-j2g6-362q-6qc6 * GO-2026-6260 CVE-2026-55149 GHSA-qqff-5854-px68 * GO-2026-6261 CVE-2026-54061 GHSA-rrwh-6jrq-wp5v * GO-2026-6262 GHSA-22w5-2fxg-vrwx * GO-2026-6263 CVE-2026-54168 GHSA-6f2p-296r-cc28 * GO-2026-6264 CVE-2026-54245 GHSA-7q96-f8xw-jv5j * GO-2026-6265 GHSA-8fxq-53rx-ph5f * GO-2026-6266 CVE-2026-54167 GHSA-f5f4-3hh4-f54m * GO-2026-6267 GHSA-h58c-xccx-75m3 * GO-2026-6268 GHSA-q9c5-pp7m-fm2g * GO-2026-6269 GHSA-rxhg-vcww-2mpw * GO-2026-6270 CVE-2026-54162 GHSA-x3g7-qrwc-f6c5 * GO-2026-6271 CVE-2026-67448 GHSA-8r62-w5wh-fc5m * GO-2026-6272 CVE-2026-67447 GHSA-r553-m4fv-5v97 * GO-2026-6273 CVE-2026-64679 GHSA-26w5-6g95-gj28 * GO-2026-6274 CVE-2026-76905 GHSA-mmfr-pmjx-hw9w * GO-2026-6275 CVE-2026-77354 GHSA-xhj3-7xw9-vr34 * GO-2026-6277 GHSA-4ph6-mjv7-3fq6 * GO-2026-6278 GHSA-w67g-5rqw-f597 * GO-2026-6279 CVE-2026-6046 GHSA-3vmp-whvv-5v9v * GO-2026-6280 CVE-2026-7387 GHSA-6hxm-w4hv-vgvw * GO-2026-6281 CVE-2026-6961 GHSA-8qq9-cqj8-82w4 * GO-2026-6282 CVE-2026-7184 GHSA-9p44-r552-4wp9 * GO-2026-6283 CVE-2026-6689 GHSA-c28q-m4gf-vg4q * GO-2026-6284 CVE-2026-55477 GHSA-jm48-m3rr-9hgg * GO-2026-6285 CVE-2026-6739 GHSA-m2w9-h2mm-79qr * GO-2026-6286 CVE-2026-3433 GHSA-rp4v-qc77-phm4 * GO-2026-6287 GHSA-vx2m-jpxr-xv7w * GO-2026-6288 CVE-2026-11624 GHSA-76g7-m3xw-x9gr * GO-2026-6289 GHSA-w8j7-39hp-8x59 * GO-2026-6290 CVE-2026-55581 GHSA-3x77-wg38-92r3 * GO-2026-6291 CVE-2026-55582 GHSA-74hp-mggr-hv58 * GO-2026-6292 CVE-2026-55580 GHSA-f5pj-2738-996m * GO-2026-6293 CVE-2026-55677 GHSA-vfp3-v2gw-7wfq * GO-2026-6294 CVE-2026-55092 GHSA-mcj4-mphf-j9ff * GO-2026-6295 CVE-2026-55637 GHSA-cmwv-wf9p-p8wx * GO-2026-6296 CVE-2026-54523 GHSA-79gf-7frw-68m9 * GO-2026-6297 CVE-2026-50879 GHSA-g743-m6x3-v6wm * GO-2026-6298 CVE-2026-54563 GHSA-w5fv-7x5q-g8qp * GO-2026-6299 CVE-2026-50884 GHSA-5442-mh7f-72px * GO-2026-6300 CVE-2026-50891 GHSA-rcqf-cpv9-g5jf * GO-2026-6301 CVE-2026-42350 GHSA-g7gw-m874-7rmf * Update to version 0.0.20260819T170606 2026-08-19T17:06:06Z. Go CVE Numbering Authority IDs added or updated with aliases: * GO-2026-4720 GHSA-v3mg-9v85-fcm7 * GO-2026-4942 CVE-2026-35172 GHSA-f2g3-hh2r-cwgc * GO-2026-4950 * GO-2026-6093 GHSA-464c-974j-9xm6 * GO-2026-6094 GHSA-gcjh-h69q-9w9g * GO-2026-6095 GHSA-r277-6w6q-xmqw * GO-2026-6097 CVE-2026-55495 GHSA-49h3-cwhj-4737 * GO-2026-6098 CVE-2026-55496 GHSA-8r7f-r8hj-r3rv * GO-2026-6099 CVE-2026-57497 GHSA-g35j-m5xg-vh3q * GO-2026-6100 CVE-2026-55497 GHSA-g9j2-8w95-3vwv * GO-2026-6101 CVE-2026-55502 GHSA-hq88-5x99-x3gf * GO-2026-6102 CVE-2026-55499 GHSA-w8x7-h2px-xmq8 * GO-2026-6103 CVE-2026-73564 GHSA-26gq-p25f-99cp * GO-2026-6104 CVE-2026-62323 GHSA-c3jm-gv5r-9wcp * GO-2026-6105 GHSA-c534-2w9c-x7fm * GO-2026-6106 GHSA-v6w6-358x-2433 * GO-2026-6107 CVE-2026-73500 GHSA-6vch-q96h-7gc3 * GO-2026-6108 CVE-2026-73505 GHSA-6xj8-qv9j-xcjq * GO-2026-6109 GHSA-86cx-wwf4-phq4 * GO-2026-6110 CVE-2026-73509 GHSA-95cv-r8x4-vh75 * GO-2026-6111 CVE-2026-73506 GHSA-fwjx-9p69-h25h * GO-2026-6112 CVE-2026-73502 GHSA-jpcw-4wr7-c3vq * GO-2026-6113 GHSA-p6ph-3jx2-3337 * GO-2026-6114 CVE-2026-73499 GHSA-xg4h-6gfc-h4m8 * GO-2026-6115 CVE-2026-56867 * GO-2026-6117 GHSA-hp74-gm6m-2qm5 * GO-2026-6118 CVE-2026-47427 GHSA-w4q6-qw23-4rg7 * GO-2026-6119 CVE-2026-43983 GHSA-w6p7-2fxx-4f44 * GO-2026-6120 CVE-2026-54593 GHSA-8r6w-3qq5-4p4r * GO-2026-6121 CVE-2026-54345 GHSA-6r28-9ppf-4hj5 * GO-2026-6122 CVE-2026-54332 GHSA-g6v3-7xmc-w563 * GO-2026-6123 CVE-2026-49446 GHSA-2rx5-2g7j-2659 * GO-2026-6124 CVE-2026-49447 GHSA-5fqm-cc34-fcf5 * GO-2026-6125 CVE-2026-11479 GHSA-6h35-9p2w-3j3r * GO-2026-6126 CVE-2026-11465 GHSA-7v3v-cp44-vc8m * GO-2026-6127 CVE-2026-50567 GHSA-q6vm-xqc9-v3ff * GO-2026-6128 CVE-2026-11481 GHSA-q76h-p6jh-9rw3 * GO-2026-6129 CVE-2026-50570 GHSA-qf5v-m7p4-95rp * GO-2026-6130 CVE-2026-50568 GHSA-r5jh-q2mw-gcx4 * GO-2026-6131 CVE-2026-50569 GHSA-vchh-r53j-8mpw * GO-2026-6132 CVE-2026-62325 GHSA-rjrw-mjq6-hpmm * GO-2026-6133 CVE-2026-54719 GHSA-rmxw-pq4x-3fvh * GO-2026-6134 CVE-2026-66064 GHSA-964w-f6gj-5236 * GO-2026-6135 CVE-2026-54650 GHSA-fh2f-xfxc-q9cc * GO-2026-6136 CVE-2026-64863 GHSA-hq33-8jgp-8qq3 * GO-2026-6137 CVE-2026-66063 GHSA-wg2q-39h6-66x9 * GO-2026-6138 CVE-2026-54638 GHSA-whmm-qj9r-wvr2 * GO-2026-6139 CVE-2026-54735 GHSA-4p3g-4hcj-wpvx * GO-2026-6140 CVE-2026-11500 GHSA-jqpm-wf57-qx5c * GO-2026-6141 CVE-2026-54693 GHSA-jq8w-8q2f-ffm9 * GO-2026-6142 CVE-2026-54680 GHSA-mjqf-28ph-426h * GO-2026-6143 GHSA-xvg2-cgv6-6h7v * GO-2026-6144 CVE-2026-67439 GHSA-jm28-2wcr-qf3h * GO-2026-6145 CVE-2026-67438 GHSA-xc5w-4v5w-7x65 * GO-2026-6146 CVE-2026-67437 GHSA-xpxj-f2fm-rqch * GO-2026-6147 CVE-2026-25688 GHSA-hmr2-99jm-8x45 * GO-2026-6148 CVE-2026-25699 GHSA-w754-5646-xq9j * GO-2026-6151 CVE-2026-34033 GHSA-6qwm-5fm9-cvjx * GO-2026-6152 CVE-2026-34905 GHSA-85r2-pvg8-89r9 * GO-2026-6153 CVE-2026-33582 GHSA-v553-g2w6-295p * GO-2026-6154 CVE-2026-34031 GHSA-x4f6-mqg6-28xx * GO-2026-6155 CVE-2026-65834 GHSA-68cj-mvg9-rgm2 * GO-2026-6156 CVE-2026-52856 GHSA-ghrq-5wpp-hxx5 * GO-2026-6157 CVE-2026-65835 GHSA-jr6p-8pjj-mfx6 * GO-2026-6158 CVE-2026-52855 GHSA-pfvc-3p5h-x7h6 * GO-2026-6159 CVE-2026-52857 GHSA-q6hh-gp44-4hcm * GO-2026-6160 CVE-2026-54725 GHSA-r2v3-8gwf-7ghm * GO-2026-6161 CVE-2026-53551 GHSA-qj55-47fp-p62j * GO-2026-6162 CVE-2026-54787 GHSA-wqqc-jjcq-vfxm * GO-2026-6163 CVE-2026-54909 GHSA-34rh-wp3j-6cxc * GO-2026-6164 CVE-2026-54910 GHSA-vvp7-h4fj-m28w * GO-2026-6165 CVE-2026-54908 GHSA-wg4g-wm44-ch5j * GO-2026-6166 CVE-2026-56868 * GO-2026-6168 CVE-2026-56869 * GO-2026-6169 CVE-2026-56870 * GO-2026-6170 CVE-2026-56871 * GO-2026-6171 CVE-2026-56872 * GO-2026-6172 CVE-2026-56873 * GO-2026-6173 CVE-2026-56874 * GO-2026-6181 GHSA-gwfq-86j8-7qhv * GO-2026-6182 CVE-2026-71312 GHSA-2m8m-jhrm-w6j2 * GO-2026-6183 GHSA-3x6r-wxxg-53vv * GO-2026-6184 CVE-2026-71309 GHSA-45pq-889g-fcgh * GO-2026-6185 CVE-2026-59732 GHSA-4vr5-p2gc-h23p * GO-2026-6186 CVE-2026-71313 GHSA-7p4m-qxvv-g567 * GO-2026-6187 CVE-2026-71311 GHSA-8c48-q9wj-3w37 * GO-2026-6188 GHSA-8mxv-9xhp-86h4 * GO-2026-6189 GHSA-8v25-v8p6-qf7v * GO-2026-6190 GHSA-945v-v9p3-v5xw * GO-2026-6191 CVE-2026-54572 GHSA-cf44-9pgv-m4xc * GO-2026-6192 CVE-2026-65602 GHSA-42cj-m3vj-89wv * GO-2026-6195 CVE-2026-59733 GHSA-fqj9-69pf-6pjg * GO-2026-6196 GHSA-gx4c-2hqx-cw2r * GO-2026-6197 GHSA-h4mf-4v27-hggj * GO-2026-6198 CVE-2026-65601 GHSA-qq9q-x9w4-chhj * GO-2026-6199 CVE-2026-71310 GHSA-xhf4-832v-7xcr * GO-2026-6201 CVE-2026-71324 GHSA-3ccp-42pg-hgv6 * GO-2026-6202 CVE-2026-54764 GHSA-3q9r-p662-5j8m * GO-2026-6203 CVE-2026-71325 GHSA-62fc-8686-hfmq * GO-2026-6204 CVE-2026-71326 GHSA-6765-c87h-8mrf * GO-2026-6205 CVE-2026-54765 GHSA-6p8f-p8j2-rqmv * GO-2026-6207 CVE-2026-67309 GHSA-8rxv-jg7p-wvg3 * GO-2026-6208 CVE-2026-65600 GHSA-cxjq-mrr5-89rv * GO-2026-6209 CVE-2026-71327 GHSA-fgjj-px3w-67xx * GO-2026-6211 CVE-2026-54763 GHSA-x677-9fxg-v5c5 * GO-2026-6212 CVE-2026-39904 GHSA-42jc-v69j-g38f * GO-2026-6213 CVE-2026-71556 GHSA-hc8v-wwc9-vgxm * GO-2026-6214 CVE-2026-71557 GHSA-qgq7-7hm3-q39j * GO-2026-6216 * GO-2026-6219 CVE-2026-73080 GHSA-87fv-vqqr-m4jr * GO-2026-6220 CVE-2026-48786 GHSA-88p2-jj8w-j8qg * GO-2026-6221 CVE-2026-54917 GHSA-w62w-66v9-vvgv * GO-2026-6223 CVE-2026-54526 GHSA-48p8-g2fx-3wwm * GO-2026-6224 CVE-2026-53469 GHSA-6xvf-9742-48w2 * GO-2026-6227 CVE-2026-35511 GHSA-29rf-f4vv-pvq6 * GO-2026-6228 CVE-2026-53471 GHSA-2fqw-7c6r-2cq6 * GO-2026-6229 CVE-2026-53470 GHSA-v5m8-5455-qw2x * GO-2026-6230 CVE-2026-53657 GHSA-2j9v-p4xj-cjw2 * GO-2026-6231 CVE-2026-53476 GHSA-7j4w-x8x8-5mvg * GO-2026-6232 CVE-2026-53475 GHSA-8g5p-jxp9-457c * GO-2026-6233 CVE-2026-53474 GHSA-vf2h-7x3w-97fr * GO-2026-6234 CVE-2026-53658 GHSA-xghw-p77p-3r7x * GO-2026-6237 * GO-2026-6238 CVE-2026-10722 GHSA-xhgw-qwwf-pg32 * GO-2026-6240 CVE-2026-64859 GHSA-6x2c-phff-wx57 * GO-2026-6241 CVE-2026-45099 GHSA-8394-6f8r-whxg * GO-2026-6242 CVE-2026-71479 GHSA-8r8v-xf7q-rcpr * GO-2026-6243 CVE-2026-64865 GHSA-j6gc-4893-qwmp * GO-2026-6244 CVE-2026-64866 GHSA-p845-629j-rcj6 * GO-2026-6245 CVE-2026-64868 GHSA-v828-m3pf-vq9q * GO-2026-6246 GHSA-fhgh-wq4q-r37x * GO-2026-6247 CVE-2026-55062 GHSA-m6jg-wr9m-cg2f * GO-2026-6248 CVE-2026-55061 GHSA-qmcq-xw74-w667 * GO-2026-6249 CVE-2026-25700 GHSA-4gw2-vg4x-7p29 * Update to version 0.0.20260814T162254 2026-08-14T16:22:54Z. Go CVE Numbering Authority IDs added or updated with aliases: * GO-2026-5021 CVE-2026-42508 GHSA-5cgq-3rg8-m6cv * GO-2026-5942 CVE-2026-46600 * GO-2026-5972 CVE-2026-33818 * GO-2026-6088 CVE-2026-56859 * GO-2026-6089 CVE-2026-56853 * GO-2026-6090 CVE-2026-56862 * GO-2026-6091 CVE-2026-56858 * GO-2026-6179 CVE-2026-56865 * GO-2026-6180 CVE-2026-56864 * GO-2026-6218 CVE-2026-56860 * GO-2026-6222 CVE-2026-46603 * Update to version 0.0.20260811T232133 2026-08-11T23:21:33Z. Go CVE Numbering Authority IDs added or updated with aliases: * GO-2026-5005 CVE-2026-39833 GHSA-jppx-rxg9-jmrx * GO-2026-5006 CVE-2026-39832 GHSA-f5wc-c3c7-36mc * GO-2026-5075 CVE-2026-57210 GHSA-38x9-25wx-7fg2 * GO-2026-5119 CVE-2026-48119 GHSA-4g6j-g789-rghm * GO-2026-5152 CVE-2026-48491 GHSA-5r4w-85f3-pw66 * GO-2026-5274 CVE-2026-40173 GHSA-95mq-xwj4-r47p * GO-2026-5287 CVE-2026-53622 GHSA-9cr8-q42q-g8m7 * GO-2026-5306 CVE-2026-34179 GHSA-c3h3-89qf-jqm5 * GO-2026-5368 CVE-2026-34177 GHSA-fm2x-c5qw-4h6f * GO-2026-5466 CVE-2026-41179 GHSA-jfwf-28xr-xw6q * GO-2026-5516 CVE-2026-41327 GHSA-mrxx-39g5-ph77 * GO-2026-5529 CVE-2026-34976 GHSA-p5rh-vmhp-gvcw * GO-2026-5532 CVE-2026-41181 GHSA-p6hg-qh38-555r * GO-2026-5576 CVE-2026-34178 GHSA-q96j-3fmm-7fv4 * GO-2026-5596 CVE-2026-49980 GHSA-qw24-gh76-8rvv * GO-2026-5668 CVE-2026-41568 GHSA-vp62-88p7-qqf5 * GO-2026-5970 CVE-2026-56852 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1609 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1609 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * govulncheck-vulndb-0.0.20260827T195228-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * govulncheck-vulndb-0.0.20260827T195228-160000.1.1 ## References: * https://jira.suse.com/browse/PED-11136 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:52:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:52:19 -0000 Subject: SUSE-SU-2026:23624-1: moderate: Security update for java-21-openjdk Message-ID: <178940473978.576.9797908551164065197@5ac198222802> # Security update for java-21-openjdk Announcement ID: SUSE-SU-2026:23624-1 Release Date: 2026-09-04T09:13:52Z Rating: moderate References: * bsc#1221224 * bsc#1275035 * bsc#1275764 * bsc#1275777 * bsc#1275778 Cross-References: * CVE-2026-60589 * CVE-2026-61308 * CVE-2026-70907 CVSS scores: * CVE-2026-60589 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-60589 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61308 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-61308 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-70907 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-70907 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities and has two fixes can now be installed. ## Description: This update for java-21-openjdk fixes the following issues: Security issues fixed: * CVE-2026-60589: OpenJDK: Improve Resource Resolving (bsc#1275777). * CVE-2026-61308: OpenJDK: Enhance HTTP Connections (bsc#1275778). * CVE-2026-70907: OpenJDK: Enhance TLS server (bsc#1275764). Non security issue fixed: * java-21-openjdk classlist depends on the CPU count of the build machine (bsc#1221224). Changes for java-21-openjdk: * Update to jdk-21.0.12.1+1 (August 2026 CSPU) * backport upcoming upgrade of timezone data (bsc#1275035) * Explicitly use G1 if the JVM supports it. GC ergonomics pick SerialGC on single-CPU machines. SerialGC does not support dumping of the shared heap, thus the classlist is different on a single-CPU builder. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1607 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1607 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * java-21-openjdk-demo-21.0.12.1-160000.1.1 * java-21-openjdk-21.0.12.1-160000.1.1 * java-21-openjdk-devel-debuginfo-21.0.12.1-160000.1.1 * java-21-openjdk-devel-21.0.12.1-160000.1.1 * java-21-openjdk-jmods-21.0.12.1-160000.1.1 * java-21-openjdk-headless-21.0.12.1-160000.1.1 * java-21-openjdk-src-21.0.12.1-160000.1.1 * java-21-openjdk-headless-debuginfo-21.0.12.1-160000.1.1 * java-21-openjdk-debuginfo-21.0.12.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * java-21-openjdk-javadoc-21.0.12.1-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * java-21-openjdk-demo-21.0.12.1-160000.1.1 * java-21-openjdk-21.0.12.1-160000.1.1 * java-21-openjdk-devel-debuginfo-21.0.12.1-160000.1.1 * java-21-openjdk-devel-21.0.12.1-160000.1.1 * java-21-openjdk-jmods-21.0.12.1-160000.1.1 * java-21-openjdk-headless-21.0.12.1-160000.1.1 * java-21-openjdk-src-21.0.12.1-160000.1.1 * java-21-openjdk-headless-debuginfo-21.0.12.1-160000.1.1 * java-21-openjdk-debuginfo-21.0.12.1-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * java-21-openjdk-javadoc-21.0.12.1-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-60589.html * https://www.suse.com/security/cve/CVE-2026-61308.html * https://www.suse.com/security/cve/CVE-2026-70907.html * https://bugzilla.suse.com/show_bug.cgi?id=1221224 * https://bugzilla.suse.com/show_bug.cgi?id=1275035 * https://bugzilla.suse.com/show_bug.cgi?id=1275764 * https://bugzilla.suse.com/show_bug.cgi?id=1275777 * https://bugzilla.suse.com/show_bug.cgi?id=1275778 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:53:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:53:41 -0000 Subject: SUSE-SU-2026:23621-1: moderate: Security update for libidn Message-ID: <178940482192.576.4739748379037592020@5ac198222802> # Security update for libidn Announcement ID: SUSE-SU-2026:23621-1 Release Date: 2026-09-04T07:30:15Z Rating: moderate References: * bsc#1268965 Cross-References: * CVE-2026-57053 CVSS scores: * CVE-2026-57053 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-57053 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-57053 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-57053 ( NVD ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for libidn fixes the following issue: * CVE-2026-57053: out-of-bounds read in `ToUnicode` APIs (bsc#1268965). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1606 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1606 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libidn-tools-1.43-160000.3.1 * libidn12-1.43-160000.3.1 * libidn-tools-debuginfo-1.43-160000.3.1 * libidn12-debuginfo-1.43-160000.3.1 * libidn-devel-1.43-160000.3.1 * libidn-debugsource-1.43-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libidn-tools-1.43-160000.3.1 * libidn12-1.43-160000.3.1 * libidn-tools-debuginfo-1.43-160000.3.1 * libidn12-debuginfo-1.43-160000.3.1 * libidn-devel-1.43-160000.3.1 * libidn-debugsource-1.43-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-57053.html * https://bugzilla.suse.com/show_bug.cgi?id=1268965 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:54:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:54:28 -0000 Subject: SUSE-SU-2026:23620-1: moderate: Security update for systemd Message-ID: <178940486818.576.593339247712801743@5ac198222802> # Security update for systemd Announcement ID: SUSE-SU-2026:23620-1 Release Date: 2026-09-03T20:25:16Z Rating: moderate References: * bsc#1237515 * bsc#1254924 * bsc#1259418 * bsc#1259650 * bsc#1261400 * bsc#1271444 Cross-References: * CVE-2026-16742 * CVE-2026-29111 * CVE-2026-40226 * CVE-2026-4105 CVSS scores: * CVE-2026-16742 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16742 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-29111 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-29111 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-29111 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40226 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-40226 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-40226 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4105 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-4105 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-4105 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities and has two fixes can now be installed. ## Description: This update for systemd fixes the following issue: Security issue fixed: * CVE-2026-16742: `systemd-homed`: local privilege escalation due to missing home record signature verification on the authentication path (bsc#1271444). Non security issue fixed: * `systemd-resolved` fails to start due to write access to `tmpfs` denied (bsc#1237515). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1602 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1602 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * systemd-container-debuginfo-257.13-160000.4.1 * systemd-resolved-257.13-160000.4.1 * libsystemd0-257.13-160000.4.1 * systemd-resolved-debuginfo-257.13-160000.4.1 * systemd-devel-257.13-160000.4.1 * udev-257.13-160000.4.1 * systemd-debugsource-257.13-160000.4.1 * libsystemd0-debuginfo-257.13-160000.4.1 * systemd-debuginfo-257.13-160000.4.1 * libudev1-257.13-160000.4.1 * libudev1-debuginfo-257.13-160000.4.1 * systemd-experimental-debuginfo-257.13-160000.4.1 * systemd-journal-remote-257.13-160000.4.1 * systemd-portable-257.13-160000.4.1 * systemd-experimental-257.13-160000.4.1 * systemd-257.13-160000.4.1 * systemd-container-257.13-160000.4.1 * systemd-homed-257.13-160000.4.1 * systemd-homed-debuginfo-257.13-160000.4.1 * udev-debuginfo-257.13-160000.4.1 * systemd-journal-remote-debuginfo-257.13-160000.4.1 * systemd-portable-debuginfo-257.13-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * systemd-lang-257.13-160000.4.1 * systemd-doc-257.13-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * systemd-container-debuginfo-257.13-160000.4.1 * systemd-resolved-257.13-160000.4.1 * libsystemd0-257.13-160000.4.1 * systemd-resolved-debuginfo-257.13-160000.4.1 * systemd-devel-257.13-160000.4.1 * udev-257.13-160000.4.1 * systemd-debugsource-257.13-160000.4.1 * libsystemd0-debuginfo-257.13-160000.4.1 * systemd-debuginfo-257.13-160000.4.1 * libudev1-257.13-160000.4.1 * libudev1-debuginfo-257.13-160000.4.1 * systemd-experimental-debuginfo-257.13-160000.4.1 * systemd-journal-remote-257.13-160000.4.1 * systemd-portable-257.13-160000.4.1 * systemd-experimental-257.13-160000.4.1 * systemd-257.13-160000.4.1 * systemd-container-257.13-160000.4.1 * systemd-homed-257.13-160000.4.1 * systemd-homed-debuginfo-257.13-160000.4.1 * udev-debuginfo-257.13-160000.4.1 * systemd-journal-remote-debuginfo-257.13-160000.4.1 * systemd-portable-debuginfo-257.13-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * systemd-lang-257.13-160000.4.1 * systemd-doc-257.13-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16742.html * https://www.suse.com/security/cve/CVE-2026-29111.html * https://www.suse.com/security/cve/CVE-2026-40226.html * https://www.suse.com/security/cve/CVE-2026-4105.html * https://bugzilla.suse.com/show_bug.cgi?id=1237515 * https://bugzilla.suse.com/show_bug.cgi?id=1254924 * https://bugzilla.suse.com/show_bug.cgi?id=1259418 * https://bugzilla.suse.com/show_bug.cgi?id=1259650 * https://bugzilla.suse.com/show_bug.cgi?id=1261400 * https://bugzilla.suse.com/show_bug.cgi?id=1271444 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:55:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:55:07 -0000 Subject: SUSE-SU-2026:23619-1: moderate: Security update for google-cloud-sap-agent Message-ID: <178940490722.576.5140083677096894049@5ac198222802> # Security update for google-cloud-sap-agent Announcement ID: SUSE-SU-2026:23619-1 Release Date: 2026-09-03T20:17:00Z Rating: moderate References: * bsc#1276667 Cross-References: * CVE-2026-41178 CVSS scores: * CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for google-cloud-sap-agent fixes the following issue: * CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276667). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1603 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1603 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * google-cloud-sap-agent-debuginfo-3.15-160000.3.1 * google-cloud-sap-agent-3.15-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * google-cloud-sap-agent-debuginfo-3.15-160000.3.1 * google-cloud-sap-agent-3.15-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41178.html * https://bugzilla.suse.com/show_bug.cgi?id=1276667 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:55:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:55:46 -0000 Subject: SUSE-SU-2026:23618-1: moderate: Security update for fuse-overlayfs Message-ID: <178940494608.576.15468561402654425363@5ac198222802> # Security update for fuse-overlayfs Announcement ID: SUSE-SU-2026:23618-1 Release Date: 2026-09-03T20:11:38Z Rating: moderate References: * bsc#1273100 Cross-References: * CVE-2026-52791 CVSS scores: * CVE-2026-52791 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-52791 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-52791 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for fuse-overlayfs fixes the following issue: * CVE-2026-52791: privilege escalation due to SUID/SGID bit preservation after truncate operation (bsc#1273100). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1601 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1601 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * fuse-overlayfs-debugsource-1.15-160000.3.1 * fuse-overlayfs-1.15-160000.3.1 * fuse-overlayfs-debuginfo-1.15-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * fuse-overlayfs-debugsource-1.15-160000.3.1 * fuse-overlayfs-1.15-160000.3.1 * fuse-overlayfs-debuginfo-1.15-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-52791.html * https://bugzilla.suse.com/show_bug.cgi?id=1273100 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:57:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:57:34 -0000 Subject: SUSE-SU-2026:23614-1: important: Security update for dracut Message-ID: <178940505499.576.2740614454854336335@5ac198222802> # Security update for dracut Announcement ID: SUSE-SU-2026:23614-1 Release Date: 2026-09-03T16:43:28Z Rating: important References: * bsc#1268322 * bsc#1273580 Cross-References: * CVE-2026-16445 * CVE-2026-6893 CVSS scores: * CVE-2026-16445 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16445 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-6893 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6893 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for dracut fixes the following issues: Update to version 059+suse.730.g73d3411aa. * CVE-2026-6893: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` (bsc#1268322). * CVE-2026-16445: improper handling and escaping of DHCP options can lead to command injection and root code execution within the `initramfs` during system boot (bsc#1273580). Changes for dracut: * Update to version 059+suse.730.g73d3411aa: * fix(network-legacy): sanitize values written to /tmp/net.${netif}.override * fix(network-legacy): sanitize values written to /tmp/net.${netif}.gw * fix(network-legacy): sanitize values written to /tmp/net.${netif}.hostname * fix(network-legacy): strip DHCP-supplied domain to a safe charset ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1597 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1597 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dracut-ima-059+suse.730.g73d3411aa-160000.1.1 * dracut-fips-059+suse.730.g73d3411aa-160000.1.1 * dracut-debugsource-059+suse.730.g73d3411aa-160000.1.1 * dracut-059+suse.730.g73d3411aa-160000.1.1 * dracut-debuginfo-059+suse.730.g73d3411aa-160000.1.1 * dracut-tools-059+suse.730.g73d3411aa-160000.1.1 * dracut-extra-059+suse.730.g73d3411aa-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * dracut-ima-059+suse.730.g73d3411aa-160000.1.1 * dracut-fips-059+suse.730.g73d3411aa-160000.1.1 * dracut-debugsource-059+suse.730.g73d3411aa-160000.1.1 * dracut-059+suse.730.g73d3411aa-160000.1.1 * dracut-debuginfo-059+suse.730.g73d3411aa-160000.1.1 * dracut-tools-059+suse.730.g73d3411aa-160000.1.1 * dracut-extra-059+suse.730.g73d3411aa-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16445.html * https://www.suse.com/security/cve/CVE-2026-6893.html * https://bugzilla.suse.com/show_bug.cgi?id=1268322 * https://bugzilla.suse.com/show_bug.cgi?id=1273580 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:58:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:58:18 -0000 Subject: SUSE-SU-2026:23613-1: moderate: Security update for sssd Message-ID: <178940509877.576.10872549041927166187@5ac198222802> # Security update for sssd Announcement ID: SUSE-SU-2026:23613-1 Release Date: 2026-09-03T16:43:28Z Rating: moderate References: * bsc#1273009 * bsc#1273922 * bsc#1273924 * bsc#1273925 * bsc#1274748 Cross-References: * CVE-2026-68742 * CVE-2026-68743 * CVE-2026-68744 CVSS scores: * CVE-2026-68742 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68742 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68742 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68743 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68743 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68743 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68743 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68744 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68744 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-68744 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities and has two fixes can now be installed. ## Description: This update for sssd fixes the following issues: Security issues fixed: * CVE-2026-68742: insufficient validation in the NSS responder can lead to an out-of-bounds read and a process crash when a crafted GETHOSTBYADDR request is sent to the NSS responder socket (bsc#1273922). * CVE-2026-68743: insufficient validation in the PAM responder can lead to an out-of-bounds read and a process crash when a crafted protocol v1 request is processed (bsc#1273925). * CVE-2026-68744: improper memory management in the NSS responder can lead to uninitialized heap memory disclosure from the `sssd_nss` process (bsc#1273924). Other updates and bugfixes: * Add `systemd-tmpfiles` configuration file to populate `/var/lib/sss` with the correct permissions on transactional servers (bsc#1274748). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1596 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1596 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libipa_hbac-devel-2.10.2-160000.5.1 * sssd-tools-debuginfo-2.10.2-160000.5.1 * sssd-krb5-common-2.10.2-160000.5.1 * libsss_certmap0-debuginfo-2.10.2-160000.5.1 * sssd-kcm-2.10.2-160000.5.1 * sssd-dbus-2.10.2-160000.5.1 * sssd-ldap-2.10.2-160000.5.1 * python3-sss_nss_idmap-2.10.2-160000.5.1 * sssd-debuginfo-2.10.2-160000.5.1 * python3-sss_nss_idmap-debuginfo-2.10.2-160000.5.1 * sssd-2.10.2-160000.5.1 * sssd-krb5-2.10.2-160000.5.1 * sssd-proxy-2.10.2-160000.5.1 * libipa_hbac0-2.10.2-160000.5.1 * sssd-ipa-2.10.2-160000.5.1 * python3-ipa_hbac-debuginfo-2.10.2-160000.5.1 * libnfsidmap-sss-debuginfo-2.10.2-160000.5.1 * sssd-proxy-debuginfo-2.10.2-160000.5.1 * libsss_idmap-devel-2.10.2-160000.5.1 * python3-sssd-config-2.10.2-160000.5.1 * sssd-ipa-debuginfo-2.10.2-160000.5.1 * libsss_idmap0-2.10.2-160000.5.1 * sssd-krb5-common-debuginfo-2.10.2-160000.5.1 * libipa_hbac0-debuginfo-2.10.2-160000.5.1 * sssd-winbind-idmap-2.10.2-160000.5.1 * sssd-tools-2.10.2-160000.5.1 * sssd-winbind-idmap-debuginfo-2.10.2-160000.5.1 * libsss_nss_idmap0-2.10.2-160000.5.1 * sssd-debugsource-2.10.2-160000.5.1 * libnfsidmap-sss-2.10.2-160000.5.1 * libsss_certmap-devel-2.10.2-160000.5.1 * python3-ipa_hbac-2.10.2-160000.5.1 * sssd-dbus-debuginfo-2.10.2-160000.5.1 * sssd-ad-debuginfo-2.10.2-160000.5.1 * libsss_certmap0-2.10.2-160000.5.1 * libsss_idmap0-debuginfo-2.10.2-160000.5.1 * python3-sss-murmur-2.10.2-160000.5.1 * sssd-ldap-debuginfo-2.10.2-160000.5.1 * sssd-kcm-debuginfo-2.10.2-160000.5.1 * python3-sssd-config-debuginfo-2.10.2-160000.5.1 * libsss_nss_idmap0-debuginfo-2.10.2-160000.5.1 * sssd-ad-2.10.2-160000.5.1 * python3-sss-murmur-debuginfo-2.10.2-160000.5.1 * libsss_nss_idmap-devel-2.10.2-160000.5.1 * sssd-krb5-debuginfo-2.10.2-160000.5.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libipa_hbac-devel-2.10.2-160000.5.1 * sssd-tools-debuginfo-2.10.2-160000.5.1 * sssd-krb5-common-2.10.2-160000.5.1 * libsss_certmap0-debuginfo-2.10.2-160000.5.1 * sssd-kcm-2.10.2-160000.5.1 * sssd-dbus-2.10.2-160000.5.1 * sssd-ldap-2.10.2-160000.5.1 * python3-sss_nss_idmap-2.10.2-160000.5.1 * sssd-debuginfo-2.10.2-160000.5.1 * python3-sss_nss_idmap-debuginfo-2.10.2-160000.5.1 * sssd-2.10.2-160000.5.1 * sssd-krb5-2.10.2-160000.5.1 * sssd-proxy-2.10.2-160000.5.1 * libipa_hbac0-2.10.2-160000.5.1 * sssd-ipa-2.10.2-160000.5.1 * python3-ipa_hbac-debuginfo-2.10.2-160000.5.1 * libnfsidmap-sss-debuginfo-2.10.2-160000.5.1 * sssd-proxy-debuginfo-2.10.2-160000.5.1 * libsss_idmap-devel-2.10.2-160000.5.1 * python3-sssd-config-2.10.2-160000.5.1 * sssd-ipa-debuginfo-2.10.2-160000.5.1 * libsss_idmap0-2.10.2-160000.5.1 * sssd-krb5-common-debuginfo-2.10.2-160000.5.1 * libipa_hbac0-debuginfo-2.10.2-160000.5.1 * sssd-winbind-idmap-2.10.2-160000.5.1 * sssd-tools-2.10.2-160000.5.1 * sssd-winbind-idmap-debuginfo-2.10.2-160000.5.1 * libsss_nss_idmap0-2.10.2-160000.5.1 * sssd-debugsource-2.10.2-160000.5.1 * libnfsidmap-sss-2.10.2-160000.5.1 * libsss_certmap-devel-2.10.2-160000.5.1 * python3-ipa_hbac-2.10.2-160000.5.1 * sssd-dbus-debuginfo-2.10.2-160000.5.1 * sssd-ad-debuginfo-2.10.2-160000.5.1 * libsss_certmap0-2.10.2-160000.5.1 * libsss_idmap0-debuginfo-2.10.2-160000.5.1 * python3-sss-murmur-2.10.2-160000.5.1 * sssd-ldap-debuginfo-2.10.2-160000.5.1 * sssd-kcm-debuginfo-2.10.2-160000.5.1 * python3-sssd-config-debuginfo-2.10.2-160000.5.1 * libsss_nss_idmap0-debuginfo-2.10.2-160000.5.1 * sssd-ad-2.10.2-160000.5.1 * python3-sss-murmur-debuginfo-2.10.2-160000.5.1 * libsss_nss_idmap-devel-2.10.2-160000.5.1 * sssd-krb5-debuginfo-2.10.2-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-68742.html * https://www.suse.com/security/cve/CVE-2026-68743.html * https://www.suse.com/security/cve/CVE-2026-68744.html * https://bugzilla.suse.com/show_bug.cgi?id=1273009 * https://bugzilla.suse.com/show_bug.cgi?id=1273922 * https://bugzilla.suse.com/show_bug.cgi?id=1273924 * https://bugzilla.suse.com/show_bug.cgi?id=1273925 * https://bugzilla.suse.com/show_bug.cgi?id=1274748 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 16:59:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 16:59:00 -0000 Subject: SUSE-SU-2026:23612-1: moderate: Security update for cpio Message-ID: <178940514017.576.3021036422592942434@5ac198222802> # Security update for cpio Announcement ID: SUSE-SU-2026:23612-1 Release Date: 2026-09-03T14:47:37Z Rating: moderate References: * bsc#1274856 * bsc#1274857 * bsc#1274858 Cross-References: * CVE-2026-66484 * CVE-2026-66485 * CVE-2026-66486 CVSS scores: * CVE-2026-66484 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-66484 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66485 ( SUSE ): 5.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H * CVE-2026-66485 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-66486 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-66486 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for cpio fixes the following issues: * CVE-2026-66484: improper sanitization in the tar archive extraction functionality allows for the creation of hard links outside intended directory via malicious tar archives (bsc#1274856). * CVE-2026-66485: improper memory management in the `make_path` function when allocating memory allows for denial of service via crafted archives (bsc#1274857). * CVE-2026-66486: improper encoding or escaping of output in the archive member listing functionality allows for terminal control sequence injection via crafted archive member names (bsc#1274858). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1595 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1595 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * cpio-2.15-160000.3.1 * cpio-mt-debuginfo-2.15-160000.3.1 * cpio-debuginfo-2.15-160000.3.1 * cpio-mt-2.15-160000.3.1 * cpio-debugsource-2.15-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * cpio-lang-2.15-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * cpio-2.15-160000.3.1 * cpio-mt-debuginfo-2.15-160000.3.1 * cpio-debuginfo-2.15-160000.3.1 * cpio-mt-2.15-160000.3.1 * cpio-debugsource-2.15-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * cpio-lang-2.15-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-66484.html * https://www.suse.com/security/cve/CVE-2026-66485.html * https://www.suse.com/security/cve/CVE-2026-66486.html * https://bugzilla.suse.com/show_bug.cgi?id=1274856 * https://bugzilla.suse.com/show_bug.cgi?id=1274857 * https://bugzilla.suse.com/show_bug.cgi?id=1274858 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:00:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:00:04 -0000 Subject: SUSE-SU-2026:23610-1: moderate: Security update for java-17-openjdk Message-ID: <178940520484.576.12541237673139981271@5ac198222802> # Security update for java-17-openjdk Announcement ID: SUSE-SU-2026:23610-1 Release Date: 2026-09-03T12:49:19Z Rating: moderate References: * bsc#1275035 * bsc#1275764 * bsc#1275777 * bsc#1275778 Cross-References: * CVE-2026-60589 * CVE-2026-61308 * CVE-2026-70907 CVSS scores: * CVE-2026-60589 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-60589 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61308 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-61308 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-70907 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-70907 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities and has one fix can now be installed. ## Description: This update for java-17-openjdk fixes the following issues: Upgrade to upstream tag jdk-17.0.20.1+1 (August 2026 CSPU). * CVE-2026-60589: unauthenticated attacker with network access via multiple protocols can gain unauthorized read access to a subset of accessible data (bsc#1275777). * CVE-2026-61308: unauthenticated attacker with network access via HTTP can gain unauthorized access to critical data (bsc#1275778). * CVE-2026-70907: unauthenticated attacker with network access via TLS can cause a partial denial of service (bsc#1275764). Changes for java-17-openjdk: * Upgrade to upstream tag jdk-17.0.20.1+1 (August 2026 CSPU): * JDK-8389947: [17u] Remove designator `DEFAULT_PROMOTED_VERSION_PRE=ea` for release 17.0.20.1. * JDK-8333743: Change `.jcheck/conf` branches property to match valid branches * JDK-8388790: Bump update version for OpenJDK: jdk-17.0.20.1 * Backport upcoming upgrade of timezone data (bsc#1275035) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1593 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1593 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * java-17-openjdk-headless-17.0.20.1-160000.1.1 * java-17-openjdk-17.0.20.1-160000.1.1 * java-17-openjdk-demo-17.0.20.1-160000.1.1 * java-17-openjdk-jmods-17.0.20.1-160000.1.1 * java-17-openjdk-devel-17.0.20.1-160000.1.1 * java-17-openjdk-debuginfo-17.0.20.1-160000.1.1 * java-17-openjdk-devel-debuginfo-17.0.20.1-160000.1.1 * java-17-openjdk-src-17.0.20.1-160000.1.1 * java-17-openjdk-headless-debuginfo-17.0.20.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * java-17-openjdk-javadoc-17.0.20.1-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * java-17-openjdk-headless-17.0.20.1-160000.1.1 * java-17-openjdk-17.0.20.1-160000.1.1 * java-17-openjdk-demo-17.0.20.1-160000.1.1 * java-17-openjdk-jmods-17.0.20.1-160000.1.1 * java-17-openjdk-devel-17.0.20.1-160000.1.1 * java-17-openjdk-debuginfo-17.0.20.1-160000.1.1 * java-17-openjdk-devel-debuginfo-17.0.20.1-160000.1.1 * java-17-openjdk-src-17.0.20.1-160000.1.1 * java-17-openjdk-headless-debuginfo-17.0.20.1-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * java-17-openjdk-javadoc-17.0.20.1-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-60589.html * https://www.suse.com/security/cve/CVE-2026-61308.html * https://www.suse.com/security/cve/CVE-2026-70907.html * https://bugzilla.suse.com/show_bug.cgi?id=1275035 * https://bugzilla.suse.com/show_bug.cgi?id=1275764 * https://bugzilla.suse.com/show_bug.cgi?id=1275777 * https://bugzilla.suse.com/show_bug.cgi?id=1275778 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:00:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:00:59 -0000 Subject: SUSE-SU-2026:23609-1: important: Security update for openssl-3 Message-ID: <178940525972.576.17117193095144664414@5ac198222802> # Security update for openssl-3 Announcement ID: SUSE-SU-2026:23609-1 Release Date: 2026-09-02T16:08:23Z Rating: important References: * bsc#1266343 * bsc#1274774 * bsc#1274777 * bsc#1274788 * bsc#1274790 * bsc#1274791 * bsc#1274792 * bsc#1274795 * bsc#1274796 * bsc#1274797 * bsc#1274798 * bsc#1275837 Cross-References: * CVE-2026-14456 * CVE-2026-14457 * CVE-2026-18798 * CVE-2026-34181 * CVE-2026-54874 * CVE-2026-63072 * CVE-2026-63073 * CVE-2026-63074 * CVE-2026-63075 * CVE-2026-63076 * CVE-2026-75803 CVSS scores: * CVE-2026-14456 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-14456 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-14457 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-14457 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-18798 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-18798 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34181 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-34181 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-34181 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54874 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-54874 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63073 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-63073 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63074 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63074 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63075 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63075 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-75803 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-75803 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 11 vulnerabilities and has one fix can now be installed. ## Description: This update for openssl-3 fixes the following issues: August 2026 release. * CVE-2026-14456: unbounded memory growth in QUIC server incoming channel queue (bsc#1274791). * CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1274792). * CVE-2026-18798: QUIC server may trigger double free when processing INITIAL packet (bsc#1274777). * CVE-2026-34181: PKCS#12 files with PBMAC1 are accepted with short HMAC keys (bsc#1266343). * CVE-2026-54874: excessive memory use buffering DTLS records for a future epoch (bsc#1274795). * CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1274788). * CVE-2026-63073: untrusted sender DN used as format string in CMP response validation (bsc#1274796). * CVE-2026-63074: CMP indefinite cache growth of `ExtraCerts` (bsc#1274797). * CVE-2026-63075: QUIC ACK-only packet retention can cause memory exhaustion (bsc#1274798). * CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1274790). * CVE-2026-75803: AEAD forgeries with empty ciphertext when using `EVP_Cipher()` (bsc#1275837). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1592 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1592 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * openssl-3-debugsource-3.5.0-160000.10.1 * openssl-3-debuginfo-3.5.0-160000.10.1 * libopenssl3-debuginfo-3.5.0-160000.10.1 * libopenssl-3-fips-provider-3.5.0-160000.10.1 * libopenssl-3-devel-3.5.0-160000.10.1 * openssl-3-3.5.0-160000.10.1 * libopenssl-3-fips-provider-debuginfo-3.5.0-160000.10.1 * libopenssl3-3.5.0-160000.10.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * libopenssl-3-fips-provider-x86-64-v3-3.5.0-160000.10.1 * libopenssl3-x86-64-v3-3.5.0-160000.10.1 * libopenssl3-x86-64-v3-debuginfo-3.5.0-160000.10.1 * libopenssl-3-fips-provider-x86-64-v3-debuginfo-3.5.0-160000.10.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * openssl-3-doc-3.5.0-160000.10.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * openssl-3-debugsource-3.5.0-160000.10.1 * openssl-3-debuginfo-3.5.0-160000.10.1 * libopenssl3-debuginfo-3.5.0-160000.10.1 * libopenssl-3-fips-provider-3.5.0-160000.10.1 * libopenssl-3-devel-3.5.0-160000.10.1 * openssl-3-3.5.0-160000.10.1 * libopenssl-3-fips-provider-debuginfo-3.5.0-160000.10.1 * libopenssl3-3.5.0-160000.10.1 * SUSE Linux Enterprise Server 16.0 (noarch) * openssl-3-doc-3.5.0-160000.10.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * libopenssl-3-fips-provider-x86-64-v3-3.5.0-160000.10.1 * libopenssl3-x86-64-v3-3.5.0-160000.10.1 * libopenssl3-x86-64-v3-debuginfo-3.5.0-160000.10.1 * libopenssl-3-fips-provider-x86-64-v3-debuginfo-3.5.0-160000.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14456.html * https://www.suse.com/security/cve/CVE-2026-14457.html * https://www.suse.com/security/cve/CVE-2026-18798.html * https://www.suse.com/security/cve/CVE-2026-34181.html * https://www.suse.com/security/cve/CVE-2026-54874.html * https://www.suse.com/security/cve/CVE-2026-63072.html * https://www.suse.com/security/cve/CVE-2026-63073.html * https://www.suse.com/security/cve/CVE-2026-63074.html * https://www.suse.com/security/cve/CVE-2026-63075.html * https://www.suse.com/security/cve/CVE-2026-63076.html * https://www.suse.com/security/cve/CVE-2026-75803.html * https://bugzilla.suse.com/show_bug.cgi?id=1266343 * https://bugzilla.suse.com/show_bug.cgi?id=1274774 * https://bugzilla.suse.com/show_bug.cgi?id=1274777 * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1274790 * https://bugzilla.suse.com/show_bug.cgi?id=1274791 * https://bugzilla.suse.com/show_bug.cgi?id=1274792 * https://bugzilla.suse.com/show_bug.cgi?id=1274795 * https://bugzilla.suse.com/show_bug.cgi?id=1274796 * https://bugzilla.suse.com/show_bug.cgi?id=1274797 * https://bugzilla.suse.com/show_bug.cgi?id=1274798 * https://bugzilla.suse.com/show_bug.cgi?id=1275837 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:01:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:01:59 -0000 Subject: SUSE-SU-2026:23607-1: low: Security update for python-ruff Message-ID: <178940531923.576.12087283690869962601@5ac198222802> # Security update for python-ruff Announcement ID: SUSE-SU-2026:23607-1 Release Date: 2026-09-02T14:10:13Z Rating: low References: * bsc#1249011 Cross-References: * CVE-2025-58160 CVSS scores: * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-ruff fixes the following issue: * CVE-2025-58160: tracing-subscriber: untrusted user input containing ANSI escape sequences can be injected into terminal output after being logged (bsc#1249011). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1589 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1589 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python313-ruff-0.11.13-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python313-ruff-0.11.13-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-58160.html * https://bugzilla.suse.com/show_bug.cgi?id=1249011 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:02:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:02:36 -0000 Subject: SUSE-SU-2026:23606-1: moderate: Security update for lkl Message-ID: <178940535648.576.16937857647604783167@5ac198222802> # Security update for lkl Announcement ID: SUSE-SU-2026:23606-1 Release Date: 2026-09-02T14:08:25Z Rating: moderate References: Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that can now be installed. ## Description: This update for lkl fixes the following issues: Changes in lkl: * Updated to match current kernel. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1590 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1590 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * lkl-debugsource-0.6.4+git.4863.9c68545add5d-160000.1.1 * lkl-debuginfo-0.6.4+git.4863.9c68545add5d-160000.1.1 * lklfuse-0.6.4+git.4863.9c68545add5d-160000.1.1 * lklfuse-debuginfo-0.6.4+git.4863.9c68545add5d-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64) * lkl-debugsource-0.6.4+git.4863.9c68545add5d-160000.1.1 * lkl-debuginfo-0.6.4+git.4863.9c68545add5d-160000.1.1 * lklfuse-0.6.4+git.4863.9c68545add5d-160000.1.1 * lklfuse-debuginfo-0.6.4+git.4863.9c68545add5d-160000.1.1 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:03:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:03:50 -0000 Subject: SUSE-SU-2026:23604-1: important: Security update for openexr Message-ID: <178940543005.576.18058753023257610447@5ac198222802> # Security update for openexr Announcement ID: SUSE-SU-2026:23604-1 Release Date: 2026-09-02T09:44:40Z Rating: important References: * bsc#1276428 * bsc#1276848 * bsc#1276849 * bsc#1276850 * bsc#1276853 * bsc#1276855 * bsc#1276856 * bsc#1276857 * bsc#1276858 * bsc#1276859 * bsc#1276862 Cross-References: * CVE-2026-59183 * CVE-2026-59184 * CVE-2026-59186 * CVE-2026-59189 * CVE-2026-59981 * CVE-2026-59982 * CVE-2026-59983 * CVE-2026-59984 * CVE-2026-59985 * CVE-2026-61555 * CVE-2026-68515 CVSS scores: * CVE-2026-59183 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59183 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59184 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-59184 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-59186 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-59186 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H * CVE-2026-59189 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-59189 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-59981 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-59981 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-59982 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-59982 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-59983 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59983 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59984 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59984 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59985 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59985 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-61555 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-61555 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-68515 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-68515 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for openexr fixes the following issues: * CVE-2026-59183: unmapped memory access leading to crash due to `int32_t` multiplication overflow in `unpack_sample_table()` when decoding a crafted deep tiled EXR file (bsc#1276428). * CVE-2026-59184: out-of-bounds or use-after-free writes when processing a crafted EXR with a nonzero `dataWindow.min` (bsc#1276849). * CVE-2026-59186: heap out-of-bounds write on 32-bit/ILP32 builds when a crafted tiled EXR is read through the public `TiledRgbaInputFile` RGBA API (bsc#1276850). * CVE-2026-59189: heap out-of-bounds read when processing a deep image that has a non-zero `dataWindow` origin (bsc#1276855). * CVE-2026-59981: heap out-of-bounds read when procesing a deep image that has a non-zero `dataWindow` origin (bsc#1276862). * CVE-2026-59982: out-of-bounds pointer access when processing a crafted deep EXR that has a non-zero `dataWindow` origin (bsc#1276853). * CVE-2026-59983: out-of-bounds read in ILP32 builds when processing a crafted uncompressed deep-tile EXR (bsc#1276856). * CVE-2026-59984: out-of-bounds write in ILP32 builds when processing a crafted B44-compressed scanline EXR (bsc#1276857). * CVE-2026-59985: out-of-bounds read in ILP32 builds when processing a crafted RLE-compressed EXR (bsc#1276858). * CVE-2026-61555: undefined behavior when processing a crafted EXR with an empty `multiView` header attribute (bsc#1276859). * CVE-2026-68515: heap out-of-bounds write in `exrmultiview` when combining two specially crafted, individually valid scanline EXR files whose union `dataWindow` is not aligned to one view's channel subsampling (bsc#1276848). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1585 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1585 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libIex-3_2-31-3.2.2-160000.10.1 * libOpenEXRUtil-3_2-31-3.2.2-160000.10.1 * libOpenEXRUtil-3_2-31-debuginfo-3.2.2-160000.10.1 * openexr-debugsource-3.2.2-160000.10.1 * libIlmThread-3_2-31-debuginfo-3.2.2-160000.10.1 * libOpenEXR-3_2-31-debuginfo-3.2.2-160000.10.1 * openexr-3.2.2-160000.10.1 * openexr-debuginfo-3.2.2-160000.10.1 * libIex-3_2-31-debuginfo-3.2.2-160000.10.1 * libOpenEXRCore-3_2-31-debuginfo-3.2.2-160000.10.1 * libOpenEXRCore-3_2-31-3.2.2-160000.10.1 * libIlmThread-3_2-31-3.2.2-160000.10.1 * libOpenEXR-3_2-31-3.2.2-160000.10.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * libOpenEXR-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.10.1 * libIex-3_2-31-x86-64-v3-3.2.2-160000.10.1 * libIex-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.10.1 * libIlmThread-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.10.1 * libOpenEXRUtil-3_2-31-x86-64-v3-3.2.2-160000.10.1 * libOpenEXRUtil-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.10.1 * libOpenEXR-3_2-31-x86-64-v3-3.2.2-160000.10.1 * libOpenEXRCore-3_2-31-x86-64-v3-3.2.2-160000.10.1 * libOpenEXRCore-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.10.1 * libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.10.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * openexr-doc-3.2.2-160000.10.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libIex-3_2-31-3.2.2-160000.10.1 * libOpenEXRUtil-3_2-31-3.2.2-160000.10.1 * libOpenEXRUtil-3_2-31-debuginfo-3.2.2-160000.10.1 * openexr-debugsource-3.2.2-160000.10.1 * libIlmThread-3_2-31-debuginfo-3.2.2-160000.10.1 * libOpenEXR-3_2-31-debuginfo-3.2.2-160000.10.1 * openexr-3.2.2-160000.10.1 * openexr-debuginfo-3.2.2-160000.10.1 * libIex-3_2-31-debuginfo-3.2.2-160000.10.1 * libOpenEXRCore-3_2-31-debuginfo-3.2.2-160000.10.1 * libOpenEXRCore-3_2-31-3.2.2-160000.10.1 * libIlmThread-3_2-31-3.2.2-160000.10.1 * libOpenEXR-3_2-31-3.2.2-160000.10.1 * SUSE Linux Enterprise Server 16.0 (noarch) * openexr-doc-3.2.2-160000.10.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * libOpenEXR-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.10.1 * libIex-3_2-31-x86-64-v3-3.2.2-160000.10.1 * libIex-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.10.1 * libIlmThread-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.10.1 * libOpenEXRUtil-3_2-31-x86-64-v3-3.2.2-160000.10.1 * libOpenEXRUtil-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.10.1 * libOpenEXR-3_2-31-x86-64-v3-3.2.2-160000.10.1 * libOpenEXRCore-3_2-31-x86-64-v3-3.2.2-160000.10.1 * libOpenEXRCore-3_2-31-x86-64-v3-debuginfo-3.2.2-160000.10.1 * libIlmThread-3_2-31-x86-64-v3-3.2.2-160000.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59183.html * https://www.suse.com/security/cve/CVE-2026-59184.html * https://www.suse.com/security/cve/CVE-2026-59186.html * https://www.suse.com/security/cve/CVE-2026-59189.html * https://www.suse.com/security/cve/CVE-2026-59981.html * https://www.suse.com/security/cve/CVE-2026-59982.html * https://www.suse.com/security/cve/CVE-2026-59983.html * https://www.suse.com/security/cve/CVE-2026-59984.html * https://www.suse.com/security/cve/CVE-2026-59985.html * https://www.suse.com/security/cve/CVE-2026-61555.html * https://www.suse.com/security/cve/CVE-2026-68515.html * https://bugzilla.suse.com/show_bug.cgi?id=1276428 * https://bugzilla.suse.com/show_bug.cgi?id=1276848 * https://bugzilla.suse.com/show_bug.cgi?id=1276849 * https://bugzilla.suse.com/show_bug.cgi?id=1276850 * https://bugzilla.suse.com/show_bug.cgi?id=1276853 * https://bugzilla.suse.com/show_bug.cgi?id=1276855 * https://bugzilla.suse.com/show_bug.cgi?id=1276856 * https://bugzilla.suse.com/show_bug.cgi?id=1276857 * https://bugzilla.suse.com/show_bug.cgi?id=1276858 * https://bugzilla.suse.com/show_bug.cgi?id=1276859 * https://bugzilla.suse.com/show_bug.cgi?id=1276862 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:04:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:04:34 -0000 Subject: SUSE-SU-2026:23603-1: important: Security update for libvirt Message-ID: <178940547446.576.5579616760179572332@5ac198222802> # Security update for libvirt Announcement ID: SUSE-SU-2026:23603-1 Release Date: 2026-09-02T09:44:39Z Rating: important References: * bsc#1274576 * bsc#1274946 * bsc#1275264 * bsc#1275265 * bsc#1275863 Cross-References: * CVE-2026-18917 * CVE-2026-61477 * CVE-2026-63622 * CVE-2026-63623 * CVE-2026-77159 CVSS scores: * CVE-2026-18917 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-18917 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-61477 ( SUSE ): 5.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-61477 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-61477 ( NVD ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-63622 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63622 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63622 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63623 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-63623 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-63623 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-77159 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-77159 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-77159 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for libvirt fixes the following issues: * CVE-2026-18917: integer overflow in `NodeGetFreePages` RPC handler leads to heap buffer overflow and allows for possible local privilege escalation (bsc#1275863). * CVE-2026-61477: newline injection in network XML DNS TXT/SRV fields allows for `dnsmasq` configuration directive injection and can lead to arbitrary code execution as root (bsc#1274576). * CVE-2026-63622: symlink-following in `virFileChownFiles()` allows `swtpm` user to trick the root-level `libvirt` daemon into changing the ownership of an arbitrary file and can lead to privilege escalation (bsc#1275264). * CVE-2026-63623: newly created volume images are temporarily world-readable during clone/convert operations, which can lead to sensitive information disclosure (bsc#1275265). * CVE-2026-77159: root `chown()` on `swtpm` logfile follows symlinks and allows for root-owned file ownership changes, which can lead to privilege escalation (bsc#1274946). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1586 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1586 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libvirt-daemon-driver-storage-core-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-mpath-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-nodedev-11.4.0-160000.5.1 * libvirt-daemon-driver-qemu-11.4.0-160000.5.1 * libvirt-daemon-common-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-11.4.0-160000.5.1 * libvirt-devel-11.4.0-160000.5.1 * libvirt-daemon-log-11.4.0-160000.5.1 * libvirt-nss-11.4.0-160000.5.1 * libvirt-daemon-debuginfo-11.4.0-160000.5.1 * libvirt-client-qemu-11.4.0-160000.5.1 * libvirt-daemon-lock-11.4.0-160000.5.1 * libvirt-daemon-driver-nwfilter-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-iscsi-direct-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-scsi-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-logical-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-secret-11.4.0-160000.5.1 * libvirt-nss-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-config-network-11.4.0-160000.5.1 * libvirt-daemon-driver-secret-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-iscsi-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-mpath-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-scsi-11.4.0-160000.5.1 * libvirt-daemon-plugin-lockd-debuginfo-11.4.0-160000.5.1 * libvirt-client-11.4.0-160000.5.1 * libvirt-client-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-proxy-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-disk-11.4.0-160000.5.1 * libvirt-daemon-hooks-11.4.0-160000.5.1 * libvirt-debugsource-11.4.0-160000.5.1 * libvirt-daemon-driver-nodedev-debuginfo-11.4.0-160000.5.1 * libvirt-libs-debuginfo-11.4.0-160000.5.1 * libvirt-ssh-proxy-11.4.0-160000.5.1 * libvirt-daemon-config-nwfilter-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-common-11.4.0-160000.5.1 * libvirt-daemon-qemu-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-logical-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-core-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-network-11.4.0-160000.5.1 * libvirt-daemon-proxy-11.4.0-160000.5.1 * libvirt-daemon-log-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-nwfilter-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-disk-debuginfo-11.4.0-160000.5.1 * libvirt-libs-11.4.0-160000.5.1 * libvirt-daemon-lock-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-network-debuginfo-11.4.0-160000.5.1 * libvirt-ssh-proxy-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-qemu-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-11.4.0-160000.5.1 * libvirt-daemon-plugin-lockd-11.4.0-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * libvirt-doc-11.4.0-160000.5.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libvirt-daemon-driver-storage-core-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-mpath-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-nodedev-11.4.0-160000.5.1 * libvirt-daemon-driver-qemu-11.4.0-160000.5.1 * libvirt-daemon-common-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-11.4.0-160000.5.1 * libvirt-devel-11.4.0-160000.5.1 * libvirt-daemon-log-11.4.0-160000.5.1 * libvirt-nss-11.4.0-160000.5.1 * libvirt-daemon-debuginfo-11.4.0-160000.5.1 * libvirt-client-qemu-11.4.0-160000.5.1 * libvirt-daemon-lock-11.4.0-160000.5.1 * libvirt-daemon-driver-nwfilter-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-iscsi-direct-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-scsi-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-logical-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-secret-11.4.0-160000.5.1 * libvirt-nss-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-config-network-11.4.0-160000.5.1 * libvirt-daemon-driver-secret-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-iscsi-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-iscsi-direct-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-mpath-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-scsi-11.4.0-160000.5.1 * libvirt-daemon-plugin-lockd-debuginfo-11.4.0-160000.5.1 * libvirt-client-11.4.0-160000.5.1 * libvirt-client-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-proxy-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-disk-11.4.0-160000.5.1 * libvirt-daemon-hooks-11.4.0-160000.5.1 * libvirt-debugsource-11.4.0-160000.5.1 * libvirt-daemon-driver-nodedev-debuginfo-11.4.0-160000.5.1 * libvirt-libs-debuginfo-11.4.0-160000.5.1 * libvirt-ssh-proxy-11.4.0-160000.5.1 * libvirt-daemon-config-nwfilter-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-iscsi-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-common-11.4.0-160000.5.1 * libvirt-daemon-qemu-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-logical-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-core-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-network-11.4.0-160000.5.1 * libvirt-daemon-proxy-11.4.0-160000.5.1 * libvirt-daemon-log-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-nwfilter-11.4.0-160000.5.1 * libvirt-daemon-driver-storage-disk-debuginfo-11.4.0-160000.5.1 * libvirt-libs-11.4.0-160000.5.1 * libvirt-daemon-lock-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-network-debuginfo-11.4.0-160000.5.1 * libvirt-ssh-proxy-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-driver-qemu-debuginfo-11.4.0-160000.5.1 * libvirt-daemon-11.4.0-160000.5.1 * libvirt-daemon-plugin-lockd-11.4.0-160000.5.1 * SUSE Linux Enterprise Server 16.0 (noarch) * libvirt-doc-11.4.0-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-18917.html * https://www.suse.com/security/cve/CVE-2026-61477.html * https://www.suse.com/security/cve/CVE-2026-63622.html * https://www.suse.com/security/cve/CVE-2026-63623.html * https://www.suse.com/security/cve/CVE-2026-77159.html * https://bugzilla.suse.com/show_bug.cgi?id=1274576 * https://bugzilla.suse.com/show_bug.cgi?id=1274946 * https://bugzilla.suse.com/show_bug.cgi?id=1275264 * https://bugzilla.suse.com/show_bug.cgi?id=1275265 * https://bugzilla.suse.com/show_bug.cgi?id=1275863 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:05:08 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:05:08 -0000 Subject: SUSE-SU-2026:23602-1: important: Security update for ucode-intel Message-ID: <178940550859.576.16644860592703370080@5ac198222802> # Security update for ucode-intel Announcement ID: SUSE-SU-2026:23602-1 Release Date: 2026-09-02T09:34:17Z Rating: important References: * bsc#1265189 * bsc#1274785 Cross-References: * CVE-2025-31936 * CVE-2025-31938 * CVE-2025-35973 * CVE-2025-35979 * CVE-2026-20707 * CVE-2026-20713 * CVE-2026-20716 * CVE-2026-20760 * CVE-2026-20901 * CVE-2026-20917 CVSS scores: * CVE-2025-31936 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31936 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:N * CVE-2025-31936 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31938 ( SUSE ): 4.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-31938 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2025-31938 ( NVD ): 4.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35973 ( SUSE ): 4.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35973 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N * CVE-2025-35973 ( NVD ): 4.5 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35979 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-35979 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-35979 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20707 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20707 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-20707 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20713 ( SUSE ): 4.5 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20713 ( SUSE ): 7.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N * CVE-2026-20713 ( NVD ): 4.5 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( SUSE ): 7.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-20716 ( NVD ): 7.2 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20716 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-20760 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20760 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20760 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20901 ( NVD ): 4.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20901 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N * CVE-2026-20917 ( SUSE ): 4.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-20917 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N * CVE-2026-20917 ( NVD ): 4.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 10 vulnerabilities can now be installed. ## Description: This update for ucode-intel fixes the following issues: * Intel CPU Microcode was updated to the 20260812 release (bsc#1274785) * Removed MTL/06-aa-04/c0 due to functional issues observed when loading the MCU in some platforms. * Intel CPU Microcode was updated to the 20260811 release (bsc#1274785) * Security updates for INTEL-SA-01379 / CVE-2025-31936 * Security updates for INTEL-SA-01404 / CVE-2025-31938 * Security updates for INTEL-SA-01423 / CVE-2026-20917 * Security updates for INTEL-SA-01428 / CVE-2025-35973 * Security updates for INTEL-SA-01435 / CVE-2026-20716 * Security updates for INTEL-SA-01441 / CVE-2026-20760 * Security updates for INTEL-SA-01442 / CVE-2026-20713 / CVE-2026-20901 * Security updates for INTEL-SA-01443 / CVE-2026-20707 * Update for functional issues. * Intel CPU Microcode was updated to the 20260512 release (bsc#1265189) * CVE-2025-35979: Security updates for INTEL-SA-01420 * https://www.intel.com/content/www/us/en/security-center/advisory/intel- sa-01420.html * Update for various functional issues. ##### New Platforms Processor Stepping F-M-S/PI Old Ver New Ver Products PTL 404 A1 06-cc-03/90 0000011b Intel Core Ultra Processor (Series 3) PTL-H 484/12Xe A0/B0 06-cc-02/90 0000011b Intel Core Ultra Processor (Series 3) ##### Updated Platforms Processor Stepping F-M-S/PI Old Ver New Ver Products :--------------- :--------- :------------ :--------- :--------- :--------- ARL-H A1 06-c5-02/82 0000011b 00000121 Core Ultra Processor (Series 2) ARL-S/HX (8P) B0 06-c6-02/82 0000011b 00000121 Core Ultra Processor (Series 2) EMR-SP A1 06-cf-02/87 210002d3 210002e0 Xeon Scalable Gen5 GNR-AP/SP Bx/Hx/Lx 06-ad-01/95 01000405 01000423 Xeon 6900/6700/6500 Series Processors with P-Cores GNR-D B0/B1 06-ae-01/97 01000303 01000307 Xeon 6700P-B/6500P-B Series SoC with P-Cores GNR-SP R1S Bx/Hx/Lx 06-ad-01/20 0a000133 0a000142 Xeon 6700/6500-Series Processors with P-Cores LNL B0 06-bd-01/80 00000125 00000126 Core Ultra 200 V Series Processor SPR-SP E4/S2 06-8f-07/87 2b000661 2b000670 Xeon Scalable Gen4 SPR-SP E5/S3 06-8f-08/87 2b000661 2b000670 Xeon Scalable Gen4 SRF-AP/SP C0 06-af-03/01 03000382 030003a3 Xeon 6900/6700-Series Processors with E-Cores * Update to microcode-20260227: * Update for functional issues. Refer to Intel? Xeon? 6700P-B/6500P-B-Series SoC with P-Cores for details. ##### Updated Platforms Processor Stepping F-M-S/PI Old Ver New Ver Products GNR-D B0/B1 06-ae-01/97 010002f3 01000303 Xeon 6700P-B/6500P-B Series SoC with P-Cores ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1584 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1584 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * ucode-intel-20260812-160000.1.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * ucode-intel-20260812-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-31936.html * https://www.suse.com/security/cve/CVE-2025-31938.html * https://www.suse.com/security/cve/CVE-2025-35973.html * https://www.suse.com/security/cve/CVE-2025-35979.html * https://www.suse.com/security/cve/CVE-2026-20707.html * https://www.suse.com/security/cve/CVE-2026-20713.html * https://www.suse.com/security/cve/CVE-2026-20716.html * https://www.suse.com/security/cve/CVE-2026-20760.html * https://www.suse.com/security/cve/CVE-2026-20901.html * https://www.suse.com/security/cve/CVE-2026-20917.html * https://bugzilla.suse.com/show_bug.cgi?id=1265189 * https://bugzilla.suse.com/show_bug.cgi?id=1274785 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:05:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:05:44 -0000 Subject: SUSE-SU-2026:23601-1: important: Security update for LibVNCServer Message-ID: <178940554427.576.10141383631944021737@5ac198222802> # Security update for LibVNCServer Announcement ID: SUSE-SU-2026:23601-1 Release Date: 2026-09-02T09:34:17Z Rating: important References: * bsc#1276218 Cross-References: * CVE-2026-50538 CVSS scores: * CVE-2026-50538 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-50538 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for LibVNCServer fixes the following issue: * CVE-2026-50538: malicious or MiTM VNC servers can force a connecting `libvncclient` to write attacker-controlled data past the end of a framebuffer, which can lead to a crash or arbitrary code execution (bsc#1276218). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1583 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1583 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libvncclient1-debuginfo-0.9.14-160000.6.1 * libvncserver1-debuginfo-0.9.14-160000.6.1 * libvncclient1-0.9.14-160000.6.1 * libvncserver1-0.9.14-160000.6.1 * LibVNCServer-debugsource-0.9.14-160000.6.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libvncclient1-debuginfo-0.9.14-160000.6.1 * libvncserver1-debuginfo-0.9.14-160000.6.1 * libvncclient1-0.9.14-160000.6.1 * libvncserver1-0.9.14-160000.6.1 * LibVNCServer-debugsource-0.9.14-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50538.html * https://bugzilla.suse.com/show_bug.cgi?id=1276218 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:07:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:07:37 -0000 Subject: SUSE-SU-2026:23597-1: important: Security update for c-ares Message-ID: <178940565731.576.17328580408376748300@5ac198222802> # Security update for c-ares Announcement ID: SUSE-SU-2026:23597-1 Release Date: 2026-09-01T15:51:21Z Rating: important References: * bsc#1270416 * bsc#1276290 * bsc#1276291 Cross-References: * CVE-2026-33630 * CVE-2026-69184 * CVE-2026-69186 CVSS scores: * CVE-2026-33630 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33630 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33630 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-69184 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-69186 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for c-ares fixes the following issues: Updat to c-ares 1.36.8. * CVE-2026-33630: remotely triggerable use-after-free/double-free in query- completion handling via `ares_getaddrinfo()` over TCP (bsc#1270416). * CVE-2026-69184: CPU exhaustion denial of service via unbounded DNS name compression pointer chains (bsc#1276290). * CVE-2026-69186: memory amplification denial of service via unvalidated DNS header record counts (bsc#1276291). Changes for c-ares: * For details, see https://c-ares.org/changelog.html. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1579 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1579 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * c-ares-utils-1.34.8-160000.1.1 * libcares2-debuginfo-1.34.8-160000.1.1 * libcares2-1.34.8-160000.1.1 * c-ares-utils-debuginfo-1.34.8-160000.1.1 * c-ares-debugsource-1.34.8-160000.1.1 * c-ares-devel-1.34.8-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * c-ares-utils-1.34.8-160000.1.1 * libcares2-debuginfo-1.34.8-160000.1.1 * libcares2-1.34.8-160000.1.1 * c-ares-utils-debuginfo-1.34.8-160000.1.1 * c-ares-debugsource-1.34.8-160000.1.1 * c-ares-devel-1.34.8-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33630.html * https://www.suse.com/security/cve/CVE-2026-69184.html * https://www.suse.com/security/cve/CVE-2026-69186.html * https://bugzilla.suse.com/show_bug.cgi?id=1270416 * https://bugzilla.suse.com/show_bug.cgi?id=1276290 * https://bugzilla.suse.com/show_bug.cgi?id=1276291 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:09:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:09:07 -0000 Subject: SUSE-SU-2026:23595-1: critical: Security update for dovecot24 Message-ID: <178940574773.576.11934608923667844939@5ac198222802> # Security update for dovecot24 Announcement ID: SUSE-SU-2026:23595-1 Release Date: 2026-09-01T14:11:32Z Rating: critical References: * bsc#1276794 * bsc#1276795 * bsc#1276799 * bsc#1276800 * bsc#1276802 * bsc#1276804 * bsc#1276807 * bsc#1276809 * bsc#1276810 * bsc#1276812 * bsc#1276813 * bsc#1276815 * bsc#1276817 * bsc#1276819 * bsc#1276820 * bsc#1276824 * bsc#1276826 * bsc#1276827 * bsc#1276828 * bsc#1276829 * bsc#1276830 * bsc#1276833 * bsc#1276835 * bsc#1276837 Cross-References: * CVE-2026-27852 * CVE-2026-33263 * CVE-2026-33604 * CVE-2026-33605 * CVE-2026-33606 * CVE-2026-33607 * CVE-2026-40013 * CVE-2026-40014 * CVE-2026-40015 * CVE-2026-40017 * CVE-2026-40018 * CVE-2026-40203 * CVE-2026-40204 * CVE-2026-40205 * CVE-2026-42007 * CVE-2026-42008 * CVE-2026-42391 * CVE-2026-42392 * CVE-2026-42393 * CVE-2026-42395 * CVE-2026-52681 * CVE-2026-52687 * CVE-2026-73208 * CVE-2026-73209 CVSS scores: * CVE-2026-27852 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27852 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33263 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-33263 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33263 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33604 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33604 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-33604 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-33605 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-33605 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33605 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33606 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33606 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N * CVE-2026-33606 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N * CVE-2026-33607 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-33607 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-33607 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40013 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-40013 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40013 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40014 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40014 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-40014 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-40015 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-40015 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40015 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-40017 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40017 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-40017 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-40018 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-40018 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-40018 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-40203 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-40203 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-40203 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-40204 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-40204 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-40204 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-40205 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-40205 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-40205 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-42007 ( SUSE ): 8.5 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-42007 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-42007 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-42008 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-42008 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-42008 ( NVD ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-42391 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-42391 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42391 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-42392 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-42392 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42392 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42393 ( SUSE ): 2.3 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-42393 ( SUSE ): 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42393 ( NVD ): 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-42395 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42395 ( NVD ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52681 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-52681 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52681 ( NVD ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-52687 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52687 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52687 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73208 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-73208 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-73208 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-73209 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:L/SI:N/SA:N * CVE-2026-73209 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73209 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for dovecot24 fixes the following issues: Update to 2.4.5. * CVE-2026-33263: `submission-login`: panic when `mail_max_userip_connections` is reached (bsc#1276794). * CVE-2026-27852: DoS by sending mail with bad header (bsc#1276799). * CVE-2026-33604: SMTP smuggling via missing dot-stuffing after bare carriage return (bsc#1276802). * CVE-2026-33605: `managesieve-login`: pre-auth crash (bsc#1276809). * CVE-2026-33606: `dsync`: mail content can cause `dsync` protocol injection (bsc#1276800). * CVE-2026-33607: IMAP `LIST` `match_sub()` exponential backtracking leading to CPU denial of service (bsc#1276795). * CVE-2026-40013: stack buffer underflow in `pigeonhole` `ManageSieve` `CHECKSCRIPT/PUTSCRIPT` (bsc#1276807). * CVE-2026-40014: CPU DoS via crafted references header (bsc#1276804). * CVE-2026-40015: `imap-hibernate` can be crashed (bsc#1276812). * CVE-2026-40017: CPU DoS via CRC32 hash collision in `strmap` (bsc#1276813). * CVE-2026-40018: MySQL multi-byte escaping performed incorrectly (bsc#1276810). * CVE-2026-40203: IMAP compression can reveal whether a small synced email body matches sender-chosen text (bsc#1276815). * CVE-2026-40204: `lda_mailbox_autocreate` can bypass ACL restrictions (bsc#1276819). * CVE-2026-40205: OAuth2 `passdb` scope enforcement bypass via OR semantics in remote validation path (bsc#1276820). * CVE-2026-42007: `sieve` `editheader` RCE (bsc#1276817). * CVE-2026-42008: `XCLIENT FORWARD= bare` token not namespaced (bsc#1276824). * CVE-2026-42391: `imap`: pre-login memory/CPU growth with `ID` command (bsc#1276835). * CVE-2026-42392: `imap-urlauth` leaks memory into user-visible error messages (bsc#1276829). * CVE-2026-42393: `doveadm_password` or api key length can be leaked with timing comparisons (bsc#1276827). * CVE-2026-52687: `imap`: `COMPRESS ZSTD` can cause excessive memory usage (bsc#1276837). * CVE-2026-42395: single NUL-byte `XCLIENT FORWARD` payload crashes (bsc#1276826). * CVE-2026-52681: `sieve` resource usage tracking lost when active script changes (bsc#1276828). * CVE-2026-73208: `auth`: `db-oauth2`: `aud` claim used as fallback for missing scope claim (bsc#1276830). * CVE-2026-73209: `imap-login` crash due to self-recursion on zero-output decompress chunks (bsc#1276833). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1578 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1578 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dovecot24-fts-solr-debuginfo-2.4.4-160000.2.1 * dovecot24-backend-mysql-debuginfo-2.4.4-160000.2.1 * dovecot24-backend-sqlite-2.4.4-160000.2.1 * dovecot24-backend-mysql-2.4.4-160000.2.1 * dovecot24-backend-pgsql-2.4.4-160000.2.1 * dovecot24-fts-2.4.4-160000.2.1 * dovecot24-fts-solr-2.4.4-160000.2.1 * dovecot24-backend-pgsql-debuginfo-2.4.4-160000.2.1 * dovecot24-backend-sqlite-debuginfo-2.4.4-160000.2.1 * dovecot24-fts-debuginfo-2.4.4-160000.2.1 * dovecot24-debugsource-2.4.4-160000.2.1 * dovecot24-2.4.4-160000.2.1 * dovecot24-debuginfo-2.4.4-160000.2.1 * dovecot24-devel-2.4.4-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * dovecot24-fts-solr-debuginfo-2.4.4-160000.2.1 * dovecot24-backend-mysql-debuginfo-2.4.4-160000.2.1 * dovecot24-backend-sqlite-2.4.4-160000.2.1 * dovecot24-backend-mysql-2.4.4-160000.2.1 * dovecot24-backend-pgsql-2.4.4-160000.2.1 * dovecot24-fts-2.4.4-160000.2.1 * dovecot24-fts-solr-2.4.4-160000.2.1 * dovecot24-backend-pgsql-debuginfo-2.4.4-160000.2.1 * dovecot24-backend-sqlite-debuginfo-2.4.4-160000.2.1 * dovecot24-fts-debuginfo-2.4.4-160000.2.1 * dovecot24-debugsource-2.4.4-160000.2.1 * dovecot24-2.4.4-160000.2.1 * dovecot24-debuginfo-2.4.4-160000.2.1 * dovecot24-devel-2.4.4-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-27852.html * https://www.suse.com/security/cve/CVE-2026-33263.html * https://www.suse.com/security/cve/CVE-2026-33604.html * https://www.suse.com/security/cve/CVE-2026-33605.html * https://www.suse.com/security/cve/CVE-2026-33606.html * https://www.suse.com/security/cve/CVE-2026-33607.html * https://www.suse.com/security/cve/CVE-2026-40013.html * https://www.suse.com/security/cve/CVE-2026-40014.html * https://www.suse.com/security/cve/CVE-2026-40015.html * https://www.suse.com/security/cve/CVE-2026-40017.html * https://www.suse.com/security/cve/CVE-2026-40018.html * https://www.suse.com/security/cve/CVE-2026-40203.html * https://www.suse.com/security/cve/CVE-2026-40204.html * https://www.suse.com/security/cve/CVE-2026-40205.html * https://www.suse.com/security/cve/CVE-2026-42007.html * https://www.suse.com/security/cve/CVE-2026-42008.html * https://www.suse.com/security/cve/CVE-2026-42391.html * https://www.suse.com/security/cve/CVE-2026-42392.html * https://www.suse.com/security/cve/CVE-2026-42393.html * https://www.suse.com/security/cve/CVE-2026-42395.html * https://www.suse.com/security/cve/CVE-2026-52681.html * https://www.suse.com/security/cve/CVE-2026-52687.html * https://www.suse.com/security/cve/CVE-2026-73208.html * https://www.suse.com/security/cve/CVE-2026-73209.html * https://bugzilla.suse.com/show_bug.cgi?id=1276794 * https://bugzilla.suse.com/show_bug.cgi?id=1276795 * https://bugzilla.suse.com/show_bug.cgi?id=1276799 * https://bugzilla.suse.com/show_bug.cgi?id=1276800 * https://bugzilla.suse.com/show_bug.cgi?id=1276802 * https://bugzilla.suse.com/show_bug.cgi?id=1276804 * https://bugzilla.suse.com/show_bug.cgi?id=1276807 * https://bugzilla.suse.com/show_bug.cgi?id=1276809 * https://bugzilla.suse.com/show_bug.cgi?id=1276810 * https://bugzilla.suse.com/show_bug.cgi?id=1276812 * https://bugzilla.suse.com/show_bug.cgi?id=1276813 * https://bugzilla.suse.com/show_bug.cgi?id=1276815 * https://bugzilla.suse.com/show_bug.cgi?id=1276817 * https://bugzilla.suse.com/show_bug.cgi?id=1276819 * https://bugzilla.suse.com/show_bug.cgi?id=1276820 * https://bugzilla.suse.com/show_bug.cgi?id=1276824 * https://bugzilla.suse.com/show_bug.cgi?id=1276826 * https://bugzilla.suse.com/show_bug.cgi?id=1276827 * https://bugzilla.suse.com/show_bug.cgi?id=1276828 * https://bugzilla.suse.com/show_bug.cgi?id=1276829 * https://bugzilla.suse.com/show_bug.cgi?id=1276830 * https://bugzilla.suse.com/show_bug.cgi?id=1276833 * https://bugzilla.suse.com/show_bug.cgi?id=1276835 * https://bugzilla.suse.com/show_bug.cgi?id=1276837 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:10:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:10:07 -0000 Subject: SUSE-SU-2026:23593-1: important: Security update for apache2-mod_auth_openidc Message-ID: <178940580747.576.13956964658057304977@5ac198222802> # Security update for apache2-mod_auth_openidc Announcement ID: SUSE-SU-2026:23593-1 Release Date: 2026-09-01T10:25:03Z Rating: important References: * bsc#1276217 Cross-References: * CVE-2026-54789 CVSS scores: * CVE-2026-54789 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54789 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for apache2-mod_auth_openidc fixes the following issue: * CVE-2026-54789: out-of-bounds read and one-byte out-of-bounds write in the state-cookie parser of `mod_auth_openidc` (bsc#1276217). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1575 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1575 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * apache2-mod_auth_openidc-2.4.17.1-160000.2.1 * apache2-mod_auth_openidc-debuginfo-2.4.17.1-160000.2.1 * apache2-mod_auth_openidc-debugsource-2.4.17.1-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * apache2-mod_auth_openidc-2.4.17.1-160000.2.1 * apache2-mod_auth_openidc-debuginfo-2.4.17.1-160000.2.1 * apache2-mod_auth_openidc-debugsource-2.4.17.1-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54789.html * https://bugzilla.suse.com/show_bug.cgi?id=1276217 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:10:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:10:46 -0000 Subject: SUSE-SU-2026:23592-1: moderate: Security update for wicked2nm Message-ID: <178940584643.576.1890000287427913076@5ac198222802> # Security update for wicked2nm Announcement ID: SUSE-SU-2026:23592-1 Release Date: 2026-09-01T05:39:34Z Rating: moderate References: * bsc#1271848 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for wicked2nm fixes the following issue: Update to v1.5.2. Security issues fixed: * `serde_with`: `KeyValueMap` serialization panics on empty sequence or map entries (bsc#1271848). Other updates and bugfixes: * Build(deps): bump `serde_with` from 3.18.0 to 3.21.0. * Fix flaky tests. * Fix `team_lacp_ethtool` test by setting `lacp active` explicitly. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1574 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1574 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * wicked2nm-1.5.2-160000.1.1 * wicked2nm-debuginfo-1.5.2-160000.1.1 * wicked2nm-debugsource-1.5.2-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * wicked2nm-1.5.2-160000.1.1 * wicked2nm-debuginfo-1.5.2-160000.1.1 * wicked2nm-debugsource-1.5.2-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1271848 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:11:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:11:29 -0000 Subject: SUSE-SU-2026:23591-1: important: Security update for java-25-openjdk Message-ID: <178940588994.576.5699397776539774693@5ac198222802> # Security update for java-25-openjdk Announcement ID: SUSE-SU-2026:23591-1 Release Date: 2026-08-31T16:20:07Z Rating: important References: * bsc#1275035 * bsc#1275763 * bsc#1275764 * bsc#1275777 * bsc#1275778 Cross-References: * CVE-2026-60589 * CVE-2026-61308 * CVE-2026-70906 * CVE-2026-70907 CVSS scores: * CVE-2026-60589 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-60589 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61308 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-61308 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-70906 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-70906 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-70907 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-70907 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities and has one fix can now be installed. ## Description: This update for java-25-openjdk fixes the following issues: * CVE-2026-60589: OpenJDK: Improve Resource Resolving (bsc#1275777). * CVE-2026-61308: OpenJDK: Enhance HTTP Connections (bsc#1275778). * CVE-2026-70906: OpenJDK: Improve font loading (bsc#1275763). * CVE-2026-70907: OpenJDK: Enhance TLS server (bsc#1275764). Changes for java-25-openjdk: * Update to jdk-25.0.4.1+1 (August 2026 CSPU) * backport upcoming upgrade of timezone data (bsc#1275035) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1572 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1572 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * java-25-openjdk-devel-25.0.4.1-160000.1.1 * java-25-openjdk-devel-debuginfo-25.0.4.1-160000.1.1 * java-25-openjdk-demo-25.0.4.1-160000.1.1 * java-25-openjdk-headless-25.0.4.1-160000.1.1 * java-25-openjdk-headless-debuginfo-25.0.4.1-160000.1.1 * java-25-openjdk-25.0.4.1-160000.1.1 * java-25-openjdk-src-25.0.4.1-160000.1.1 * java-25-openjdk-debuginfo-25.0.4.1-160000.1.1 * java-25-openjdk-jmods-25.0.4.1-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * java-25-openjdk-javadoc-25.0.4.1-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * java-25-openjdk-devel-25.0.4.1-160000.1.1 * java-25-openjdk-devel-debuginfo-25.0.4.1-160000.1.1 * java-25-openjdk-demo-25.0.4.1-160000.1.1 * java-25-openjdk-headless-25.0.4.1-160000.1.1 * java-25-openjdk-headless-debuginfo-25.0.4.1-160000.1.1 * java-25-openjdk-25.0.4.1-160000.1.1 * java-25-openjdk-src-25.0.4.1-160000.1.1 * java-25-openjdk-debuginfo-25.0.4.1-160000.1.1 * java-25-openjdk-jmods-25.0.4.1-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * java-25-openjdk-javadoc-25.0.4.1-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-60589.html * https://www.suse.com/security/cve/CVE-2026-61308.html * https://www.suse.com/security/cve/CVE-2026-70906.html * https://www.suse.com/security/cve/CVE-2026-70907.html * https://bugzilla.suse.com/show_bug.cgi?id=1275035 * https://bugzilla.suse.com/show_bug.cgi?id=1275763 * https://bugzilla.suse.com/show_bug.cgi?id=1275764 * https://bugzilla.suse.com/show_bug.cgi?id=1275777 * https://bugzilla.suse.com/show_bug.cgi?id=1275778 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:12:20 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:12:20 -0000 Subject: SUSE-SU-2026:23590-1: critical: Security update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen Message-ID: <178940594081.576.15350263475424465434@5ac198222802> # Security update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen Announcement ID: SUSE-SU-2026:23590-1 Release Date: 2026-08-31T15:29:17Z Rating: critical References: * bsc#1262698 * bsc#1262701 * bsc#1266262 * bsc#1266263 * bsc#1271649 * bsc#1272772 * bsc#1272773 * bsc#1272774 * bsc#1274867 Cross-References: * CVE-2026-16349 * CVE-2026-16350 * CVE-2026-16351 * CVE-2026-16352 * CVE-2026-16353 * CVE-2026-16354 * CVE-2026-16355 * CVE-2026-16356 * CVE-2026-16357 * CVE-2026-16358 * CVE-2026-16359 * CVE-2026-16360 * CVE-2026-16362 * CVE-2026-16363 * CVE-2026-16364 * CVE-2026-16365 * CVE-2026-16366 * CVE-2026-16367 * CVE-2026-16368 * CVE-2026-16369 * CVE-2026-16370 * CVE-2026-16371 * CVE-2026-16372 * CVE-2026-16373 * CVE-2026-16374 * CVE-2026-16375 * CVE-2026-16376 * CVE-2026-16377 * CVE-2026-16378 * CVE-2026-16379 * CVE-2026-16380 * CVE-2026-16381 * CVE-2026-16382 * CVE-2026-16383 * CVE-2026-16384 * CVE-2026-16385 * CVE-2026-16386 * CVE-2026-16387 * CVE-2026-16388 * CVE-2026-16389 * CVE-2026-16390 * CVE-2026-16391 * CVE-2026-16392 * CVE-2026-16393 * CVE-2026-16394 * CVE-2026-16395 * CVE-2026-16396 * CVE-2026-16397 * CVE-2026-16398 * CVE-2026-16399 * CVE-2026-16400 * CVE-2026-16401 * CVE-2026-16402 * CVE-2026-16403 * CVE-2026-16404 * CVE-2026-16405 * CVE-2026-16406 * CVE-2026-16407 * CVE-2026-16408 * CVE-2026-16409 * CVE-2026-16410 * CVE-2026-16411 * CVE-2026-16412 * CVE-2026-74934 * CVE-2026-74935 * CVE-2026-74936 * CVE-2026-74937 * CVE-2026-74938 * CVE-2026-74939 * CVE-2026-74940 * CVE-2026-74941 * CVE-2026-74942 * CVE-2026-74943 * CVE-2026-74944 * CVE-2026-74945 * CVE-2026-74946 * CVE-2026-74947 * CVE-2026-74948 * CVE-2026-74949 * CVE-2026-74950 * CVE-2026-74953 * CVE-2026-74954 * CVE-2026-74955 * CVE-2026-74956 * CVE-2026-74957 * CVE-2026-74958 * CVE-2026-74959 * CVE-2026-74960 * CVE-2026-74961 * CVE-2026-74962 * CVE-2026-74963 * CVE-2026-74964 * CVE-2026-74965 * CVE-2026-74966 * CVE-2026-74967 * CVE-2026-74968 * CVE-2026-74969 * CVE-2026-74970 * CVE-2026-74971 * CVE-2026-74972 * CVE-2026-74973 * CVE-2026-74974 * CVE-2026-74976 * CVE-2026-74977 * CVE-2026-74978 * CVE-2026-74979 * CVE-2026-74981 * CVE-2026-74982 * CVE-2026-74983 * CVE-2026-74984 * CVE-2026-74985 * CVE-2026-74986 * CVE-2026-74987 * CVE-2026-74988 * CVE-2026-74990 CVSS scores: * CVE-2026-16349 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-16349 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16350 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16350 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16351 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-16351 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16352 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16352 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16353 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16353 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16354 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16356 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16357 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16358 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16359 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16360 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16362 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16363 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16364 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16365 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16366 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16367 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-16368 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16369 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16370 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16371 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16372 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16374 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16375 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16376 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16377 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16378 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16379 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16380 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16381 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16382 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16384 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16385 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16386 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16387 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16388 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16389 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16390 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16391 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16392 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-16393 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-16394 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16395 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16396 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16397 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-16398 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16399 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16400 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16401 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16403 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-16404 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N * CVE-2026-16405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16406 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16407 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16408 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16409 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16410 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16411 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16412 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74934 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74934 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74935 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74935 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74936 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74936 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74936 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74937 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74938 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74938 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74939 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74940 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74940 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74941 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74942 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74943 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74943 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74944 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74944 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74945 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-74946 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74947 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74948 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-74949 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74950 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74953 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-74955 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74956 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74957 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74958 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-74959 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74960 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74961 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74962 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74963 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-74963 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74964 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74965 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74966 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-74967 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74968 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74969 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74970 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74971 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-74972 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-74973 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74974 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74976 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-74977 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74978 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74979 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74981 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74982 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74983 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74984 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74985 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74986 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74987 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74988 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74990 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74990 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 115 vulnerabilities can now be installed. ## Description: This update for MozillaFirefox, mozilla-nss, mozilla-nspr, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.1.0 ESR. * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935 Privilege escalation in the DOM: Networking component * CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937 Use-after-free in the JavaScript: GC component * CVE-2026-74938 Mitigation bypass in the JavaScript: GC component * CVE-2026-74939 Privilege escalation in the DOM: Navigation component * CVE-2026-74940 Use-after-free in the Graphics: Text component * CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942 Privilege escalation in the Remote Settings Client component * CVE-2026-74943 Use-after-free in the Graphics: ImageLib component * CVE-2026-74944 Use-after-free in the DOM: Core & HTML component * CVE-2026-74945 Information disclosure in the Graphics: Text component * CVE-2026-74946 Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947 Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948 Information disclosure in the Graphics component * CVE-2026-74949 Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950 Privilege escalation in the Downloads API component * CVE-2026-74953 Privilege escalation in the Networking: Cookies component * CVE-2026-74954 Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955 Privilege escalation in the Request Handling component * CVE-2026-74956 Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957 Mitigation bypass in the Safe Browsing component * CVE-2026-74958 Information disclosure in the WebRTC component * CVE-2026-74959 Mitigation bypass in the Storage: Cache API component * CVE-2026-74960 Site isolation issue in the WebExtensions component * CVE-2026-74961 Side-channel in the Web Audio component * CVE-2026-74962 Site isolation issue in the Networking: Cookies component * CVE-2026-74963 Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964 Integer overflow in the Graphics component * CVE-2026-74965 Privilege escalation in the Shell Integration component * CVE-2026-74966 Information disclosure in the Form Autofill component * CVE-2026-74967 Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968 Site isolation issue in the Graphics: WebRender component * CVE-2026-74969 Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970 Site isolation issue in the Graphics component * CVE-2026-74971 Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972 Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973 Race condition, use-after-free in the Graphics component * CVE-2026-74974 Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977 Integer overflow in the Graphics component * CVE-2026-74978 Clickjacking issue in the Widget component * CVE-2026-74979 Mitigation bypass in the Add-ons Manager component * CVE-2026-74981 Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982 Denial-of-service in the Widget component * CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984 Race condition in the JavaScript Engine component * CVE-2026-74985 Privilege escalation in the Enterprise Policies component * CVE-2026-74986 Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987 Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988 Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990 Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Firefox Extended Support Release 153.0esr ESR * New: ## General * Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. * Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. * The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. * Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. * Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on-device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs * Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. * Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. * Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. * Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. * A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy * Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. * Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. * Firefox now uses Safe Browsing V5 for phishing and malware protection. * Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. * Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations * Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. * A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility * Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Linux * Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. * Firefox no longer requires a restart after package manager updates and uses less memory on Linux. * Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. * WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. * Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. * Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. * Enterprise policy documentation has moved to https://firefox-admin- docs.mozilla.org/. * Fixed: Various security fixes. * MFSA 2026-68 (bsc#1271649): * CVE-2026-16349 Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350 Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362 Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351 Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352 Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363 JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364 Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365 Privilege escalation in the DOM: Workers component * CVE-2026-16366 Privilege escalation in the DOM: Navigation component * CVE-2026-16353 Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354 Information disclosure in the Graphics: ImageLib component * CVE-2026-16367 Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368 Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369 Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356 Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357 Incorrect boundary conditions in the Graphics component * CVE-2026-16370 Mitigation bypass in the DOM: Networking component * CVE-2026-16371 Privilege escalation in the DOM: Navigation component * CVE-2026-16372 Privilege escalation in the DOM: Content Processes component * CVE-2026-16373 Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374 Information disclosure in the Framework component in DevTools * CVE-2026-16375 Site isolation issue in the Networking: HTTP component * CVE-2026-16376 Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377 Mitigation bypass in the PDF Viewer component * CVE-2026-16378 Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379 Privilege escalation in the DOM: Content Processes component * CVE-2026-16358 Site isolation issue in the Graphics: WebRender component * CVE-2026-16380 Mitigation bypass in the Networking component * CVE-2026-16381 Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382 Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383 Mitigation bypass in the DOM: Networking component * CVE-2026-16384 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387 Site isolation issue in the Networking component * CVE-2026-16388 Sandbox escape in the DOM: Networking component * CVE-2026-16389 Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390 Mitigation bypass in the Enterprise Policies component * CVE-2026-16391 Information disclosure in the Storage: IndexedDB component * CVE-2026-16392 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393 Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359 Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394 Mitigation bypass in the DOM: Security component * CVE-2026-16395 Integer overflow in the Audio/Video component * CVE-2026-16396 Privilege escalation in WebExtensions * CVE-2026-16397 Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398 Site isolation issue in the Graphics component * CVE-2026-16399 Site isolation issue in the DOM: Navigation component * CVE-2026-16400 Information disclosure in the DOM: Security component * CVE-2026-16401 Privilege escalation in the Data Loss Prevention component * CVE-2026-16402 Integer overflow in the Graphics: ImageLib component * CVE-2026-16403 Spoofing issue in the Address Bar component * CVE-2026-16404 Spoofing issue in Firefox for Android * CVE-2026-16405 Information disclosure in the Networking: WebSockets component * CVE-2026-16406 Mitigation bypass in the Networking component * CVE-2026-16407 Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408 Integer overflow in the Audio/Video: Playback component * CVE-2026-16409 Invalid pointer in the Security: PSM component * CVE-2026-16410 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411 Memory safety bugs fixed in Firefox 153 * CVE-2026-16412 Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360 Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 Changes in mozilla-nss: * Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). * Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). * Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). * Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). * Add zeroization for ML-KEM, ported from upstream (bsc#1272774). * Add zeroization for ML-DSA (bsc#1272774). * Add ML-DSA robustness and test fixes. * Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Update fuzz/config/tstclnt_arguments.py. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren?t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ?Community ? Network Security Services (NSS)?. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. * update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix "testing if key corruption is detected in attribute" failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl * update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o * update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. * update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. * update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). * update to NSS 3.120.1 * no upstream releasenotes * update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. * update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs * update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. * Adjusted for changed naming scheme of tarballs for this release by upstream * update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* * update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch * update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don?t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function * update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions * update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. * update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions * update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool * update to NSS 3.113 * Fix alias for mac workers on try. * Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. Changes in mozilla-nspr: * update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig * update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 * update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. * update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char * update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support "%e" format specifier Changes in rust-cbindgen: * Update to version v0.29.4+git0: * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields * Update to version 0.29.2+git0: * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * Explicitly request serde's std features to avoid issues with newer toml versions. * enum: Track dependencies properly in enumerations. * Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove "display" feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with "void" default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * tests: Fix symbol file and tests. * tests: Run rustfmt. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1570 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1570 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * mozilla-nss-tools-3.125-160000.1.1 * rust-cbindgen-debugsource-0.29.4+git0-160000.1.1 * mozilla-nss-tools-debuginfo-3.125-160000.1.1 * libsoftokn3-debuginfo-3.125-160000.1.1 * mozilla-nss-devel-3.125-160000.1.1 * rust-cbindgen-debuginfo-0.29.4+git0-160000.1.1 * mozilla-nss-certs-debuginfo-3.125-160000.1.1 * mozilla-nspr-devel-4.39-160000.1.1 * rust-cbindgen-0.29.4+git0-160000.1.1 * MozillaFirefox-translations-common-153.1.0-160000.1.1 * libfreebl3-debuginfo-3.125-160000.1.1 * mozilla-nss-sysinit-3.125-160000.1.1 * MozillaFirefox-branding-SLE-153-160000.1.1 * libfreebl3-3.125-160000.1.1 * MozillaFirefox-debuginfo-153.1.0-160000.1.1 * libsoftokn3-3.125-160000.1.1 * MozillaFirefox-153.1.0-160000.1.1 * MozillaFirefox-translations-other-153.1.0-160000.1.1 * MozillaFirefox-debugsource-153.1.0-160000.1.1 * mozilla-nss-debugsource-3.125-160000.1.1 * mozilla-nspr-debugsource-4.39-160000.1.1 * mozilla-nspr-debuginfo-4.39-160000.1.1 * mozilla-nspr-4.39-160000.1.1 * mozilla-nss-sysinit-debuginfo-3.125-160000.1.1 * mozilla-nss-debuginfo-3.125-160000.1.1 * mozilla-nss-certs-3.125-160000.1.1 * mozilla-nss-3.125-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * MozillaFirefox-devel-153.1.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * mozilla-nss-tools-3.125-160000.1.1 * rust-cbindgen-debugsource-0.29.4+git0-160000.1.1 * mozilla-nss-tools-debuginfo-3.125-160000.1.1 * libsoftokn3-debuginfo-3.125-160000.1.1 * mozilla-nss-devel-3.125-160000.1.1 * rust-cbindgen-debuginfo-0.29.4+git0-160000.1.1 * mozilla-nss-certs-debuginfo-3.125-160000.1.1 * mozilla-nspr-devel-4.39-160000.1.1 * rust-cbindgen-0.29.4+git0-160000.1.1 * libfreebl3-debuginfo-3.125-160000.1.1 * mozilla-nss-sysinit-3.125-160000.1.1 * MozillaFirefox-branding-SLE-153-160000.1.1 * libfreebl3-3.125-160000.1.1 * libsoftokn3-3.125-160000.1.1 * mozilla-nss-debugsource-3.125-160000.1.1 * mozilla-nspr-debugsource-4.39-160000.1.1 * mozilla-nspr-debuginfo-4.39-160000.1.1 * mozilla-nspr-4.39-160000.1.1 * mozilla-nss-sysinit-debuginfo-3.125-160000.1.1 * mozilla-nss-debuginfo-3.125-160000.1.1 * mozilla-nss-certs-3.125-160000.1.1 * mozilla-nss-3.125-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64) * MozillaFirefox-debuginfo-153.1.0-160000.1.1 * MozillaFirefox-translations-other-153.1.0-160000.1.1 * MozillaFirefox-153.1.0-160000.1.1 * MozillaFirefox-debugsource-153.1.0-160000.1.1 * MozillaFirefox-translations-common-153.1.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * MozillaFirefox-devel-153.1.0-160000.1.1 * MozillaFirefox-devel-153.1.0-160000.1.2 * SUSE Linux Enterprise Server 16.0 (s390x) * MozillaFirefox-translations-other-153.1.0-160000.1.2 * MozillaFirefox-translations-common-153.1.0-160000.1.2 * MozillaFirefox-debuginfo-153.1.0-160000.1.2 * MozillaFirefox-153.1.0-160000.1.2 * MozillaFirefox-debugsource-153.1.0-160000.1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-16349.html * https://www.suse.com/security/cve/CVE-2026-16350.html * https://www.suse.com/security/cve/CVE-2026-16351.html * https://www.suse.com/security/cve/CVE-2026-16352.html * https://www.suse.com/security/cve/CVE-2026-16353.html * https://www.suse.com/security/cve/CVE-2026-16354.html * https://www.suse.com/security/cve/CVE-2026-16355.html * https://www.suse.com/security/cve/CVE-2026-16356.html * https://www.suse.com/security/cve/CVE-2026-16357.html * https://www.suse.com/security/cve/CVE-2026-16358.html * https://www.suse.com/security/cve/CVE-2026-16359.html * https://www.suse.com/security/cve/CVE-2026-16360.html * https://www.suse.com/security/cve/CVE-2026-16362.html * https://www.suse.com/security/cve/CVE-2026-16363.html * https://www.suse.com/security/cve/CVE-2026-16364.html * https://www.suse.com/security/cve/CVE-2026-16365.html * https://www.suse.com/security/cve/CVE-2026-16366.html * https://www.suse.com/security/cve/CVE-2026-16367.html * https://www.suse.com/security/cve/CVE-2026-16368.html * https://www.suse.com/security/cve/CVE-2026-16369.html * https://www.suse.com/security/cve/CVE-2026-16370.html * https://www.suse.com/security/cve/CVE-2026-16371.html * https://www.suse.com/security/cve/CVE-2026-16372.html * https://www.suse.com/security/cve/CVE-2026-16373.html * https://www.suse.com/security/cve/CVE-2026-16374.html * https://www.suse.com/security/cve/CVE-2026-16375.html * https://www.suse.com/security/cve/CVE-2026-16376.html * https://www.suse.com/security/cve/CVE-2026-16377.html * https://www.suse.com/security/cve/CVE-2026-16378.html * https://www.suse.com/security/cve/CVE-2026-16379.html * https://www.suse.com/security/cve/CVE-2026-16380.html * https://www.suse.com/security/cve/CVE-2026-16381.html * https://www.suse.com/security/cve/CVE-2026-16382.html * https://www.suse.com/security/cve/CVE-2026-16383.html * https://www.suse.com/security/cve/CVE-2026-16384.html * https://www.suse.com/security/cve/CVE-2026-16385.html * https://www.suse.com/security/cve/CVE-2026-16386.html * https://www.suse.com/security/cve/CVE-2026-16387.html * https://www.suse.com/security/cve/CVE-2026-16388.html * https://www.suse.com/security/cve/CVE-2026-16389.html * https://www.suse.com/security/cve/CVE-2026-16390.html * https://www.suse.com/security/cve/CVE-2026-16391.html * https://www.suse.com/security/cve/CVE-2026-16392.html * https://www.suse.com/security/cve/CVE-2026-16393.html * https://www.suse.com/security/cve/CVE-2026-16394.html * https://www.suse.com/security/cve/CVE-2026-16395.html * https://www.suse.com/security/cve/CVE-2026-16396.html * https://www.suse.com/security/cve/CVE-2026-16397.html * https://www.suse.com/security/cve/CVE-2026-16398.html * https://www.suse.com/security/cve/CVE-2026-16399.html * https://www.suse.com/security/cve/CVE-2026-16400.html * https://www.suse.com/security/cve/CVE-2026-16401.html * https://www.suse.com/security/cve/CVE-2026-16402.html * https://www.suse.com/security/cve/CVE-2026-16403.html * https://www.suse.com/security/cve/CVE-2026-16404.html * https://www.suse.com/security/cve/CVE-2026-16405.html * https://www.suse.com/security/cve/CVE-2026-16406.html * https://www.suse.com/security/cve/CVE-2026-16407.html * https://www.suse.com/security/cve/CVE-2026-16408.html * https://www.suse.com/security/cve/CVE-2026-16409.html * https://www.suse.com/security/cve/CVE-2026-16410.html * https://www.suse.com/security/cve/CVE-2026-16411.html * https://www.suse.com/security/cve/CVE-2026-16412.html * https://www.suse.com/security/cve/CVE-2026-74934.html * https://www.suse.com/security/cve/CVE-2026-74935.html * https://www.suse.com/security/cve/CVE-2026-74936.html * https://www.suse.com/security/cve/CVE-2026-74937.html * https://www.suse.com/security/cve/CVE-2026-74938.html * https://www.suse.com/security/cve/CVE-2026-74939.html * https://www.suse.com/security/cve/CVE-2026-74940.html * https://www.suse.com/security/cve/CVE-2026-74941.html * https://www.suse.com/security/cve/CVE-2026-74942.html * https://www.suse.com/security/cve/CVE-2026-74943.html * https://www.suse.com/security/cve/CVE-2026-74944.html * https://www.suse.com/security/cve/CVE-2026-74945.html * https://www.suse.com/security/cve/CVE-2026-74946.html * https://www.suse.com/security/cve/CVE-2026-74947.html * https://www.suse.com/security/cve/CVE-2026-74948.html * https://www.suse.com/security/cve/CVE-2026-74949.html * https://www.suse.com/security/cve/CVE-2026-74950.html * https://www.suse.com/security/cve/CVE-2026-74953.html * https://www.suse.com/security/cve/CVE-2026-74954.html * https://www.suse.com/security/cve/CVE-2026-74955.html * https://www.suse.com/security/cve/CVE-2026-74956.html * https://www.suse.com/security/cve/CVE-2026-74957.html * https://www.suse.com/security/cve/CVE-2026-74958.html * https://www.suse.com/security/cve/CVE-2026-74959.html * https://www.suse.com/security/cve/CVE-2026-74960.html * https://www.suse.com/security/cve/CVE-2026-74961.html * https://www.suse.com/security/cve/CVE-2026-74962.html * https://www.suse.com/security/cve/CVE-2026-74963.html * https://www.suse.com/security/cve/CVE-2026-74964.html * https://www.suse.com/security/cve/CVE-2026-74965.html * https://www.suse.com/security/cve/CVE-2026-74966.html * https://www.suse.com/security/cve/CVE-2026-74967.html * https://www.suse.com/security/cve/CVE-2026-74968.html * https://www.suse.com/security/cve/CVE-2026-74969.html * https://www.suse.com/security/cve/CVE-2026-74970.html * https://www.suse.com/security/cve/CVE-2026-74971.html * https://www.suse.com/security/cve/CVE-2026-74972.html * https://www.suse.com/security/cve/CVE-2026-74973.html * https://www.suse.com/security/cve/CVE-2026-74974.html * https://www.suse.com/security/cve/CVE-2026-74976.html * https://www.suse.com/security/cve/CVE-2026-74977.html * https://www.suse.com/security/cve/CVE-2026-74978.html * https://www.suse.com/security/cve/CVE-2026-74979.html * https://www.suse.com/security/cve/CVE-2026-74981.html * https://www.suse.com/security/cve/CVE-2026-74982.html * https://www.suse.com/security/cve/CVE-2026-74983.html * https://www.suse.com/security/cve/CVE-2026-74984.html * https://www.suse.com/security/cve/CVE-2026-74985.html * https://www.suse.com/security/cve/CVE-2026-74986.html * https://www.suse.com/security/cve/CVE-2026-74987.html * https://www.suse.com/security/cve/CVE-2026-74988.html * https://www.suse.com/security/cve/CVE-2026-74990.html * https://bugzilla.suse.com/show_bug.cgi?id=1262698 * https://bugzilla.suse.com/show_bug.cgi?id=1262701 * https://bugzilla.suse.com/show_bug.cgi?id=1266262 * https://bugzilla.suse.com/show_bug.cgi?id=1266263 * https://bugzilla.suse.com/show_bug.cgi?id=1271649 * https://bugzilla.suse.com/show_bug.cgi?id=1272772 * https://bugzilla.suse.com/show_bug.cgi?id=1272773 * https://bugzilla.suse.com/show_bug.cgi?id=1272774 * https://bugzilla.suse.com/show_bug.cgi?id=1274867 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:13:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:13:03 -0000 Subject: SUSE-SU-2026:23589-1: important: Security update for emacs Message-ID: <178940598347.576.9762043562866041872@5ac198222802> # Security update for emacs Announcement ID: SUSE-SU-2026:23589-1 Release Date: 2026-08-31T11:52:13Z Rating: important References: * bsc#1271643 * bsc#1275927 * bsc#1275941 * bsc#1276264 Cross-References: * CVE-2026-77219 * CVE-2026-79992 CVSS scores: * CVE-2026-77219 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-77219 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-77219 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-79992 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-79992 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities and has two fixes can now be installed. ## Description: This update for emacs fixes the following issues: Security issues fixed: * Arbitrary code execution when opening a specially crafted file (bsc#1275941). * CVE-2026-77219: integer overflow in the PBM/PPM/PGM image loader leads to heap memory content leaks when a crafted image with large dimensions and an elevated max color index is processed (bsc#1276264). * CVE-2026-79992: improper argument sanitization in TRAMP leads to arbitrary code execution via crafted filenames (bsc#1275927). Other updates and bugfixes: * Fix memory leak in wayland port (bsc#1271643). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1568 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1568 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * emacs-nox-debuginfo-30.2-160000.3.1 * etags-30.2-160000.3.1 * emacs-x11-debuginfo-30.2-160000.3.1 * etags-debuginfo-30.2-160000.3.1 * emacs-30.2-160000.3.1 * emacs-nox-30.2-160000.3.1 * emacs-x11-30.2-160000.3.1 * emacs-eln-30.2-160000.3.1 * emacs-debuginfo-30.2-160000.3.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * emacs-el-30.2-160000.3.1 * emacs-info-30.2-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * emacs-nox-debuginfo-30.2-160000.3.1 * etags-30.2-160000.3.1 * emacs-x11-debuginfo-30.2-160000.3.1 * etags-debuginfo-30.2-160000.3.1 * emacs-30.2-160000.3.1 * emacs-nox-30.2-160000.3.1 * emacs-x11-30.2-160000.3.1 * emacs-eln-30.2-160000.3.1 * emacs-debuginfo-30.2-160000.3.1 * SUSE Linux Enterprise Server 16.0 (noarch) * emacs-el-30.2-160000.3.1 * emacs-info-30.2-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-77219.html * https://www.suse.com/security/cve/CVE-2026-79992.html * https://bugzilla.suse.com/show_bug.cgi?id=1271643 * https://bugzilla.suse.com/show_bug.cgi?id=1275927 * https://bugzilla.suse.com/show_bug.cgi?id=1275941 * https://bugzilla.suse.com/show_bug.cgi?id=1276264 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:16:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:16:58 -0000 Subject: SUSE-SU-2026:23583-1: moderate: Security update for libgpg-error Message-ID: <178940621880.576.13332453039269045418@5ac198222802> # Security update for libgpg-error Announcement ID: SUSE-SU-2026:23583-1 Release Date: 2026-08-31T05:56:31Z Rating: moderate References: * bsc#1263078 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has one fix can now be installed. ## Description: This update for libgpg-error fixes the following issue: * Out-of-bounds read in `_gpgrt_vfnameconcat` of `stringutils.c` when the `GPGRT_FCONCAT_SYSCONF` flag is used (bsc#1263078). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1562 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1562 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libgpg-error-debugsource-1.58-160000.2.1 * libgpg-error-devel-debuginfo-1.58-160000.2.1 * libgpg-error0-1.58-160000.2.1 * libgpg-error-devel-1.58-160000.2.1 * libgpg-error0-debuginfo-1.58-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libgpg-error-debugsource-1.58-160000.2.1 * libgpg-error-devel-debuginfo-1.58-160000.2.1 * libgpg-error0-1.58-160000.2.1 * libgpg-error-devel-1.58-160000.2.1 * libgpg-error0-debuginfo-1.58-160000.2.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1263078 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:18:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:18:07 -0000 Subject: SUSE-SU-2026:23582-1: important: Security update for postgresql17 Message-ID: <178940628787.576.3021033248940202073@5ac198222802> # Security update for postgresql17 Announcement ID: SUSE-SU-2026:23582-1 Release Date: 2026-08-30T15:35:36Z Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275053 * bsc#1275054 * bsc#1275055 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275062 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14672 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-14681 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14662 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14664 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14666 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14668 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14669 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14672 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14672 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14678 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14679 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14680 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14681 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14681 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-15741 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15741 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15742 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16241 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18024 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18408 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19385 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6464 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6469 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6470 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6471 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for postgresql17 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). * CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). * CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). * CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql17: * Let `llvmjit-devel` require the `llc` and `clang` binaries to fix build of extensions on SLE-16 and newer. * Use LLVM 15 on SLE-15 up to SP5 and LLVM 17 on SP6 and SP7. * Update to version 17.11: * https://www.postgresql.org/docs/17/release-17-11.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1558 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1558 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * postgresql17-debugsource-17.11-160000.1.1 * postgresql17-debuginfo-17.11-160000.1.1 * postgresql17-devel-debuginfo-17.11-160000.1.1 * postgresql17-plpython-debuginfo-17.11-160000.1.1 * postgresql17-contrib-17.11-160000.1.1 * postgresql17-17.11-160000.1.1 * postgresql17-devel-17.11-160000.1.1 * postgresql17-plperl-debuginfo-17.11-160000.1.1 * postgresql17-pltcl-debuginfo-17.11-160000.1.1 * postgresql17-server-17.11-160000.1.1 * postgresql17-server-debuginfo-17.11-160000.1.1 * postgresql17-server-devel-17.11-160000.1.1 * postgresql17-contrib-debuginfo-17.11-160000.1.1 * postgresql17-pltcl-17.11-160000.1.1 * postgresql17-plperl-17.11-160000.1.1 * postgresql17-server-devel-debuginfo-17.11-160000.1.1 * postgresql17-plpython-17.11-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * postgresql17-docs-17.11-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * postgresql17-debugsource-17.11-160000.1.1 * postgresql17-debuginfo-17.11-160000.1.1 * postgresql17-devel-debuginfo-17.11-160000.1.1 * postgresql17-plpython-debuginfo-17.11-160000.1.1 * postgresql17-contrib-17.11-160000.1.1 * postgresql17-17.11-160000.1.1 * postgresql17-devel-17.11-160000.1.1 * postgresql17-plperl-debuginfo-17.11-160000.1.1 * postgresql17-pltcl-debuginfo-17.11-160000.1.1 * postgresql17-server-17.11-160000.1.1 * postgresql17-server-debuginfo-17.11-160000.1.1 * postgresql17-server-devel-17.11-160000.1.1 * postgresql17-contrib-debuginfo-17.11-160000.1.1 * postgresql17-pltcl-17.11-160000.1.1 * postgresql17-plperl-17.11-160000.1.1 * postgresql17-server-devel-debuginfo-17.11-160000.1.1 * postgresql17-plpython-17.11-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * postgresql17-docs-17.11-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14672.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-14681.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html * https://bugzilla.suse.com/show_bug.cgi?id=1275001 * https://bugzilla.suse.com/show_bug.cgi?id=1275002 * https://bugzilla.suse.com/show_bug.cgi?id=1275042 * https://bugzilla.suse.com/show_bug.cgi?id=1275043 * https://bugzilla.suse.com/show_bug.cgi?id=1275044 * https://bugzilla.suse.com/show_bug.cgi?id=1275046 * https://bugzilla.suse.com/show_bug.cgi?id=1275047 * https://bugzilla.suse.com/show_bug.cgi?id=1275048 * https://bugzilla.suse.com/show_bug.cgi?id=1275049 * https://bugzilla.suse.com/show_bug.cgi?id=1275050 * https://bugzilla.suse.com/show_bug.cgi?id=1275051 * https://bugzilla.suse.com/show_bug.cgi?id=1275053 * https://bugzilla.suse.com/show_bug.cgi?id=1275054 * https://bugzilla.suse.com/show_bug.cgi?id=1275055 * https://bugzilla.suse.com/show_bug.cgi?id=1275056 * https://bugzilla.suse.com/show_bug.cgi?id=1275057 * https://bugzilla.suse.com/show_bug.cgi?id=1275058 * https://bugzilla.suse.com/show_bug.cgi?id=1275059 * https://bugzilla.suse.com/show_bug.cgi?id=1275062 * https://bugzilla.suse.com/show_bug.cgi?id=1275063 * https://bugzilla.suse.com/show_bug.cgi?id=1275064 * https://bugzilla.suse.com/show_bug.cgi?id=1275065 * https://bugzilla.suse.com/show_bug.cgi?id=1275066 * https://bugzilla.suse.com/show_bug.cgi?id=1275067 * https://bugzilla.suse.com/show_bug.cgi?id=1275068 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:19:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:19:44 -0000 Subject: SUSE-SU-2026:23580-1: important: Security update for postgresql16 Message-ID: <178940638412.576.11675244885488953066@5ac198222802> # Security update for postgresql16 Announcement ID: SUSE-SU-2026:23580-1 Release Date: 2026-08-30T15:33:59Z Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275053 * bsc#1275054 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275061 * bsc#1275062 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14672 * CVE-2026-14673 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14662 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14664 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14666 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14668 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14669 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14672 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14672 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14673 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14673 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14678 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14679 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14680 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15741 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15741 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15742 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16241 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18024 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18408 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19385 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6464 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6469 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6470 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6471 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 25 vulnerabilities can now be installed. ## Description: This update for postgresql16 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). * CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). * CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). * CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql16: * Let `llvmjit-devel` require the `llc` and `clang` binaries to fix build of extensions on SLE-16 and newer. * Use LLVM 15 on SLE-15 up to SP5 and LLVM 17 on SP6 and SP7. * Update to version 16.15: * https://www.postgresql.org/docs/16/release-16-15.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1557 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1557 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * postgresql16-contrib-16.15-160000.1.1 * postgresql16-devel-16.15-160000.1.1 * postgresql16-devel-debuginfo-16.15-160000.1.1 * postgresql16-plperl-16.15-160000.1.1 * postgresql16-server-16.15-160000.1.1 * postgresql16-plpython-debuginfo-16.15-160000.1.1 * postgresql16-server-debuginfo-16.15-160000.1.1 * postgresql16-16.15-160000.1.1 * postgresql16-pltcl-16.15-160000.1.1 * postgresql16-debugsource-16.15-160000.1.1 * postgresql16-pltcl-debuginfo-16.15-160000.1.1 * postgresql16-plpython-16.15-160000.1.1 * postgresql16-contrib-debuginfo-16.15-160000.1.1 * postgresql16-debuginfo-16.15-160000.1.1 * postgresql16-plperl-debuginfo-16.15-160000.1.1 * postgresql16-server-devel-16.15-160000.1.1 * postgresql16-server-devel-debuginfo-16.15-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * postgresql16-docs-16.15-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * postgresql16-contrib-16.15-160000.1.1 * postgresql16-devel-16.15-160000.1.1 * postgresql16-devel-debuginfo-16.15-160000.1.1 * postgresql16-plperl-16.15-160000.1.1 * postgresql16-server-16.15-160000.1.1 * postgresql16-plpython-debuginfo-16.15-160000.1.1 * postgresql16-server-debuginfo-16.15-160000.1.1 * postgresql16-16.15-160000.1.1 * postgresql16-pltcl-16.15-160000.1.1 * postgresql16-debugsource-16.15-160000.1.1 * postgresql16-pltcl-debuginfo-16.15-160000.1.1 * postgresql16-plpython-16.15-160000.1.1 * postgresql16-contrib-debuginfo-16.15-160000.1.1 * postgresql16-debuginfo-16.15-160000.1.1 * postgresql16-plperl-debuginfo-16.15-160000.1.1 * postgresql16-server-devel-16.15-160000.1.1 * postgresql16-server-devel-debuginfo-16.15-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * postgresql16-docs-16.15-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14672.html * https://www.suse.com/security/cve/CVE-2026-14673.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html * https://bugzilla.suse.com/show_bug.cgi?id=1275001 * https://bugzilla.suse.com/show_bug.cgi?id=1275002 * https://bugzilla.suse.com/show_bug.cgi?id=1275042 * https://bugzilla.suse.com/show_bug.cgi?id=1275043 * https://bugzilla.suse.com/show_bug.cgi?id=1275044 * https://bugzilla.suse.com/show_bug.cgi?id=1275046 * https://bugzilla.suse.com/show_bug.cgi?id=1275047 * https://bugzilla.suse.com/show_bug.cgi?id=1275048 * https://bugzilla.suse.com/show_bug.cgi?id=1275049 * https://bugzilla.suse.com/show_bug.cgi?id=1275050 * https://bugzilla.suse.com/show_bug.cgi?id=1275051 * https://bugzilla.suse.com/show_bug.cgi?id=1275053 * https://bugzilla.suse.com/show_bug.cgi?id=1275054 * https://bugzilla.suse.com/show_bug.cgi?id=1275056 * https://bugzilla.suse.com/show_bug.cgi?id=1275057 * https://bugzilla.suse.com/show_bug.cgi?id=1275058 * https://bugzilla.suse.com/show_bug.cgi?id=1275059 * https://bugzilla.suse.com/show_bug.cgi?id=1275061 * https://bugzilla.suse.com/show_bug.cgi?id=1275062 * https://bugzilla.suse.com/show_bug.cgi?id=1275063 * https://bugzilla.suse.com/show_bug.cgi?id=1275064 * https://bugzilla.suse.com/show_bug.cgi?id=1275065 * https://bugzilla.suse.com/show_bug.cgi?id=1275066 * https://bugzilla.suse.com/show_bug.cgi?id=1275067 * https://bugzilla.suse.com/show_bug.cgi?id=1275068 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:20:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:20:51 -0000 Subject: SUSE-SU-2026:23579-1: important: Security update for postgresql15 Message-ID: <178940645134.576.14655380840856888083@5ac198222802> # Security update for postgresql15 Announcement ID: SUSE-SU-2026:23579-1 Release Date: 2026-08-30T15:33:59Z Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275053 * bsc#1275054 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275061 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14673 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14662 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14664 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14666 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14668 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14669 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14673 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14673 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14678 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14679 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14680 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15741 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15741 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15742 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16241 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18024 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18408 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19385 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6464 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6469 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6470 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6471 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for postgresql15 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). * CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). * CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql15: * Let `llvmjit-devel` require the `llc` and `clang` binaries to fix build of extensions on SLE-16 and newer. * Use LLVM 15 on SLE-15 up to SP5 and LLVM 17 on SP6 and SP7. * Update to version 15.19: * https://www.postgresql.org/docs/15/release-15-19.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1556 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1556 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * postgresql15-server-devel-15.19-160000.1.1 * postgresql15-debuginfo-15.19-160000.1.1 * postgresql15-plperl-debuginfo-15.19-160000.1.1 * postgresql15-contrib-15.19-160000.1.1 * postgresql15-debugsource-15.19-160000.1.1 * postgresql15-15.19-160000.1.1 * postgresql15-server-devel-debuginfo-15.19-160000.1.1 * postgresql15-server-15.19-160000.1.1 * postgresql15-devel-debuginfo-15.19-160000.1.1 * postgresql15-plpython-15.19-160000.1.1 * postgresql15-devel-15.19-160000.1.1 * postgresql15-pltcl-debuginfo-15.19-160000.1.1 * postgresql15-server-debuginfo-15.19-160000.1.1 * postgresql15-plperl-15.19-160000.1.1 * postgresql15-plpython-debuginfo-15.19-160000.1.1 * postgresql15-pltcl-15.19-160000.1.1 * postgresql15-contrib-debuginfo-15.19-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * postgresql15-docs-15.19-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * postgresql15-server-devel-15.19-160000.1.1 * postgresql15-debuginfo-15.19-160000.1.1 * postgresql15-plperl-debuginfo-15.19-160000.1.1 * postgresql15-contrib-15.19-160000.1.1 * postgresql15-debugsource-15.19-160000.1.1 * postgresql15-15.19-160000.1.1 * postgresql15-server-devel-debuginfo-15.19-160000.1.1 * postgresql15-server-15.19-160000.1.1 * postgresql15-devel-debuginfo-15.19-160000.1.1 * postgresql15-plpython-15.19-160000.1.1 * postgresql15-devel-15.19-160000.1.1 * postgresql15-pltcl-debuginfo-15.19-160000.1.1 * postgresql15-server-debuginfo-15.19-160000.1.1 * postgresql15-plperl-15.19-160000.1.1 * postgresql15-plpython-debuginfo-15.19-160000.1.1 * postgresql15-pltcl-15.19-160000.1.1 * postgresql15-contrib-debuginfo-15.19-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * postgresql15-docs-15.19-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14673.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html * https://bugzilla.suse.com/show_bug.cgi?id=1275001 * https://bugzilla.suse.com/show_bug.cgi?id=1275002 * https://bugzilla.suse.com/show_bug.cgi?id=1275042 * https://bugzilla.suse.com/show_bug.cgi?id=1275043 * https://bugzilla.suse.com/show_bug.cgi?id=1275044 * https://bugzilla.suse.com/show_bug.cgi?id=1275046 * https://bugzilla.suse.com/show_bug.cgi?id=1275047 * https://bugzilla.suse.com/show_bug.cgi?id=1275048 * https://bugzilla.suse.com/show_bug.cgi?id=1275049 * https://bugzilla.suse.com/show_bug.cgi?id=1275050 * https://bugzilla.suse.com/show_bug.cgi?id=1275051 * https://bugzilla.suse.com/show_bug.cgi?id=1275053 * https://bugzilla.suse.com/show_bug.cgi?id=1275054 * https://bugzilla.suse.com/show_bug.cgi?id=1275056 * https://bugzilla.suse.com/show_bug.cgi?id=1275057 * https://bugzilla.suse.com/show_bug.cgi?id=1275058 * https://bugzilla.suse.com/show_bug.cgi?id=1275059 * https://bugzilla.suse.com/show_bug.cgi?id=1275061 * https://bugzilla.suse.com/show_bug.cgi?id=1275063 * https://bugzilla.suse.com/show_bug.cgi?id=1275064 * https://bugzilla.suse.com/show_bug.cgi?id=1275065 * https://bugzilla.suse.com/show_bug.cgi?id=1275066 * https://bugzilla.suse.com/show_bug.cgi?id=1275067 * https://bugzilla.suse.com/show_bug.cgi?id=1275068 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:21:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:21:58 -0000 Subject: SUSE-SU-2026:23578-1: important: Security update for postgresql14 Message-ID: <178940651864.576.10154952429145710534@5ac198222802> # Security update for postgresql14 Announcement ID: SUSE-SU-2026:23578-1 Release Date: 2026-08-30T15:33:59Z Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275053 * bsc#1275054 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275061 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14673 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14662 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14664 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14666 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14668 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14669 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14673 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14673 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14678 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14679 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14680 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15741 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15741 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15742 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16241 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18024 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18408 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19385 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6464 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6469 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6470 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6471 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for postgresql14 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). * CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). * CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql14: * Let `llvmjit-devel` require the `llc` and `clang` binaries to fix build of extensions on SLE-16 and newer. * Use LLVM 15 on SLE-15 up to SP5 and LLVM 17 on SP6 and SP7. * Update to version 14.24: * https://www.postgresql.org/docs/14/release-14-24.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1555 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1555 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * postgresql14-pltcl-14.24-160000.1.1 * postgresql14-server-14.24-160000.1.1 * postgresql14-debugsource-14.24-160000.1.1 * postgresql14-contrib-debuginfo-14.24-160000.1.1 * postgresql14-14.24-160000.1.1 * postgresql14-plperl-14.24-160000.1.1 * postgresql14-server-devel-14.24-160000.1.1 * postgresql14-debuginfo-14.24-160000.1.1 * postgresql14-devel-14.24-160000.1.1 * postgresql14-devel-debuginfo-14.24-160000.1.1 * postgresql14-plpython-debuginfo-14.24-160000.1.1 * postgresql14-server-debuginfo-14.24-160000.1.1 * postgresql14-plpython-14.24-160000.1.1 * postgresql14-server-devel-debuginfo-14.24-160000.1.1 * postgresql14-pltcl-debuginfo-14.24-160000.1.1 * postgresql14-plperl-debuginfo-14.24-160000.1.1 * postgresql14-contrib-14.24-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * postgresql14-docs-14.24-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * postgresql14-pltcl-14.24-160000.1.1 * postgresql14-server-14.24-160000.1.1 * postgresql14-debugsource-14.24-160000.1.1 * postgresql14-contrib-debuginfo-14.24-160000.1.1 * postgresql14-14.24-160000.1.1 * postgresql14-plperl-14.24-160000.1.1 * postgresql14-server-devel-14.24-160000.1.1 * postgresql14-debuginfo-14.24-160000.1.1 * postgresql14-devel-14.24-160000.1.1 * postgresql14-devel-debuginfo-14.24-160000.1.1 * postgresql14-plpython-debuginfo-14.24-160000.1.1 * postgresql14-server-debuginfo-14.24-160000.1.1 * postgresql14-plpython-14.24-160000.1.1 * postgresql14-server-devel-debuginfo-14.24-160000.1.1 * postgresql14-pltcl-debuginfo-14.24-160000.1.1 * postgresql14-plperl-debuginfo-14.24-160000.1.1 * postgresql14-contrib-14.24-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * postgresql14-docs-14.24-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14673.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html * https://bugzilla.suse.com/show_bug.cgi?id=1275001 * https://bugzilla.suse.com/show_bug.cgi?id=1275002 * https://bugzilla.suse.com/show_bug.cgi?id=1275042 * https://bugzilla.suse.com/show_bug.cgi?id=1275043 * https://bugzilla.suse.com/show_bug.cgi?id=1275044 * https://bugzilla.suse.com/show_bug.cgi?id=1275046 * https://bugzilla.suse.com/show_bug.cgi?id=1275047 * https://bugzilla.suse.com/show_bug.cgi?id=1275048 * https://bugzilla.suse.com/show_bug.cgi?id=1275049 * https://bugzilla.suse.com/show_bug.cgi?id=1275050 * https://bugzilla.suse.com/show_bug.cgi?id=1275051 * https://bugzilla.suse.com/show_bug.cgi?id=1275053 * https://bugzilla.suse.com/show_bug.cgi?id=1275054 * https://bugzilla.suse.com/show_bug.cgi?id=1275056 * https://bugzilla.suse.com/show_bug.cgi?id=1275057 * https://bugzilla.suse.com/show_bug.cgi?id=1275058 * https://bugzilla.suse.com/show_bug.cgi?id=1275059 * https://bugzilla.suse.com/show_bug.cgi?id=1275061 * https://bugzilla.suse.com/show_bug.cgi?id=1275063 * https://bugzilla.suse.com/show_bug.cgi?id=1275064 * https://bugzilla.suse.com/show_bug.cgi?id=1275065 * https://bugzilla.suse.com/show_bug.cgi?id=1275066 * https://bugzilla.suse.com/show_bug.cgi?id=1275067 * https://bugzilla.suse.com/show_bug.cgi?id=1275068 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:23:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:23:10 -0000 Subject: SUSE-SU-2026:23577-1: important: Security update for postgresql18 Message-ID: <178940659096.576.8211414015676370529@5ac198222802> # Security update for postgresql18 Announcement ID: SUSE-SU-2026:23577-1 Release Date: 2026-08-30T15:26:22Z Rating: important References: * bsc#1275001 * bsc#1275002 * bsc#1275042 * bsc#1275043 * bsc#1275044 * bsc#1275046 * bsc#1275047 * bsc#1275048 * bsc#1275049 * bsc#1275050 * bsc#1275051 * bsc#1275052 * bsc#1275053 * bsc#1275054 * bsc#1275055 * bsc#1275056 * bsc#1275057 * bsc#1275058 * bsc#1275059 * bsc#1275060 * bsc#1275061 * bsc#1275062 * bsc#1275063 * bsc#1275064 * bsc#1275065 * bsc#1275066 * bsc#1275067 * bsc#1275068 Cross-References: * CVE-2026-14662 * CVE-2026-14663 * CVE-2026-14664 * CVE-2026-14666 * CVE-2026-14668 * CVE-2026-14669 * CVE-2026-14670 * CVE-2026-14671 * CVE-2026-14672 * CVE-2026-14673 * CVE-2026-14676 * CVE-2026-14677 * CVE-2026-14678 * CVE-2026-14679 * CVE-2026-14680 * CVE-2026-14681 * CVE-2026-15741 * CVE-2026-15742 * CVE-2026-16238 * CVE-2026-16239 * CVE-2026-16241 * CVE-2026-18024 * CVE-2026-18408 * CVE-2026-19385 * CVE-2026-6464 * CVE-2026-6469 * CVE-2026-6470 * CVE-2026-6471 CVSS scores: * CVE-2026-14662 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14662 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14663 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14663 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14664 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14664 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14666 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14666 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14668 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14668 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-14669 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14669 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14670 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14671 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14672 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14672 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14673 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14673 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14676 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14676 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14677 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14678 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14678 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-14679 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14679 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-14680 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14680 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-14681 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-14681 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-15741 ( SUSE ): 8.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15741 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-15742 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-15742 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16238 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16238 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16239 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16241 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16241 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-18024 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18024 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-18408 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H * CVE-2026-18408 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-19385 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-19385 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6464 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-6464 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6469 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6469 ( NVD ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-6470 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6470 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6471 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6471 ( NVD ): 7.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 28 vulnerabilities can now be installed. ## Description: This update for postgresql18 fixes the following issues: * CVE-2026-6464: `psql` `COPY FROM STDIN` early failure processes data lines as `psql` commands (bsc#1275046). * CVE-2026-6469: `ALTER TABLE ALTER TYPE` resets extended statistics ownership (bsc#1275044). * CVE-2026-6470: failure to check type `USAGE` privilege (bsc#1275043). * CVE-2026-6471: logical decoding can `dlopen` arbitrary file (bsc#1275042). * CVE-2026-14662: `tsvector` and `tsquery` undersize allocations, via integer wraparound (bsc#1275001). * CVE-2026-14663: `pgcrypto`, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (bsc#1275002). * CVE-2026-14664: `regexp` heap buffer overflow executes arbitrary code (bsc#1275068). * CVE-2026-14666: row security caching disregards role modifications (bsc#1275067). * CVE-2026-14668: `ctid` type confusion in selectivity estimator discloses derivative of arbitrary read (bsc#1275066). * CVE-2026-14669: `to_char` heap buffer overflow executes arbitrary code (bsc#1275065). * CVE-2026-14670: `plperl` tied object heap buffer overflow executes arbitrary code (bsc#1275064). * CVE-2026-14671: `refint` plan cache type confusion executes arbitrary code (bsc#1275063). * CVE-2026-14672: observable response discrepancy with non-default `scram_iterations` provides user existence oracle (bsc#1275062). * CVE-2026-14673: `amcheck` does not clear untrusted search path (bsc#1275061). * CVE-2026-14676: `pg_stat_statements` heap buffer overflow executes arbitrary code (bsc#1275060). * CVE-2026-14677: 32-bit `pltcl` and `plperl` undersize allocations, via integer wraparound (bsc#1275059). * CVE-2026-14678: `pg_trgm` `picksplit` reads past end of buffer (bsc#1275058). * CVE-2026-14679: stack buffer overflow in argument match writes `0x0` and `0x1` to server memory (bsc#1275057). * CVE-2026-14680: type confusion via "internal" arguments (bsc#1275056). * CVE-2026-14681: improper enforcement of GSSAPI encryption when coupled with SSL (bsc#1275055). * CVE-2026-15741: expression deparse allows SQL injection via `EXTRACT` argument (bsc#1275054). * CVE-2026-15742: `fuzzystrmatch` writes effectively-arbitrary addresses, via integer wraparound (bsc#1275053). * CVE-2026-16238: type confusion in `pg_restore_attribute_stats()` executes arbitrary code (bsc#1275052). * CVE-2026-16239: type confusion in cursor `CLOSE + DECLARE` executes arbitrary code (bsc#1275051). * CVE-2026-16241: ECPG integer underflow can crash the client (bsc#1275050). * CVE-2026-18024: `ascii()` function reads past end of buffer (bsc#1275049). * CVE-2026-18408: `psql` `\unrestrict` lets superuser of `pg_dump` origin server execute arbitrary code in `psql` client (bsc#1275048). * CVE-2026-19385: `pg_dump` heap buffer overflow executes arbitrary code (bsc#1275047). Changes for postgresql18: * Let `llvmjit-devel` require the `llc` and `clang` binaries to fix build of extensions on SLE-16 and newer. * Use LLVM 15 on SLE-15 up to SP5 and LLVM 17 on SP6 and SP7. * Update to version 18.6: * https://www.postgresql.org/docs/18/release-18-6.html * https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/ ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1559 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1559 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * postgresql18-devel-18.6-160000.1.1 * libpq5-debuginfo-18.6-160000.1.1 * postgresql18-devel-debuginfo-18.6-160000.1.1 * postgresql18-contrib-18.6-160000.1.1 * postgresql18-18.6-160000.1.1 * postgresql18-plperl-debuginfo-18.6-160000.1.1 * postgresql18-server-18.6-160000.1.1 * postgresql18-plpython-debuginfo-18.6-160000.1.1 * postgresql18-plperl-18.6-160000.1.1 * libecpg6-18.6-160000.1.1 * libecpg6-debuginfo-18.6-160000.1.1 * libpq5-18.6-160000.1.1 * postgresql18-pltcl-18.6-160000.1.1 * postgresql18-server-devel-18.6-160000.1.1 * postgresql18-debugsource-18.6-160000.1.1 * postgresql18-debuginfo-18.6-160000.1.1 * postgresql18-contrib-debuginfo-18.6-160000.1.1 * postgresql18-plpython-18.6-160000.1.1 * postgresql18-server-debuginfo-18.6-160000.1.1 * postgresql18-server-devel-debuginfo-18.6-160000.1.1 * postgresql18-pltcl-debuginfo-18.6-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * postgresql18-docs-18.6-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * postgresql18-devel-18.6-160000.1.1 * libpq5-debuginfo-18.6-160000.1.1 * postgresql18-devel-debuginfo-18.6-160000.1.1 * postgresql18-contrib-18.6-160000.1.1 * postgresql18-18.6-160000.1.1 * postgresql18-plperl-debuginfo-18.6-160000.1.1 * postgresql18-server-18.6-160000.1.1 * postgresql18-plpython-debuginfo-18.6-160000.1.1 * postgresql18-plperl-18.6-160000.1.1 * libecpg6-18.6-160000.1.1 * libecpg6-debuginfo-18.6-160000.1.1 * libpq5-18.6-160000.1.1 * postgresql18-pltcl-18.6-160000.1.1 * postgresql18-server-devel-18.6-160000.1.1 * postgresql18-debugsource-18.6-160000.1.1 * postgresql18-debuginfo-18.6-160000.1.1 * postgresql18-contrib-debuginfo-18.6-160000.1.1 * postgresql18-plpython-18.6-160000.1.1 * postgresql18-server-debuginfo-18.6-160000.1.1 * postgresql18-server-devel-debuginfo-18.6-160000.1.1 * postgresql18-pltcl-debuginfo-18.6-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * postgresql18-docs-18.6-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14662.html * https://www.suse.com/security/cve/CVE-2026-14663.html * https://www.suse.com/security/cve/CVE-2026-14664.html * https://www.suse.com/security/cve/CVE-2026-14666.html * https://www.suse.com/security/cve/CVE-2026-14668.html * https://www.suse.com/security/cve/CVE-2026-14669.html * https://www.suse.com/security/cve/CVE-2026-14670.html * https://www.suse.com/security/cve/CVE-2026-14671.html * https://www.suse.com/security/cve/CVE-2026-14672.html * https://www.suse.com/security/cve/CVE-2026-14673.html * https://www.suse.com/security/cve/CVE-2026-14676.html * https://www.suse.com/security/cve/CVE-2026-14677.html * https://www.suse.com/security/cve/CVE-2026-14678.html * https://www.suse.com/security/cve/CVE-2026-14679.html * https://www.suse.com/security/cve/CVE-2026-14680.html * https://www.suse.com/security/cve/CVE-2026-14681.html * https://www.suse.com/security/cve/CVE-2026-15741.html * https://www.suse.com/security/cve/CVE-2026-15742.html * https://www.suse.com/security/cve/CVE-2026-16238.html * https://www.suse.com/security/cve/CVE-2026-16239.html * https://www.suse.com/security/cve/CVE-2026-16241.html * https://www.suse.com/security/cve/CVE-2026-18024.html * https://www.suse.com/security/cve/CVE-2026-18408.html * https://www.suse.com/security/cve/CVE-2026-19385.html * https://www.suse.com/security/cve/CVE-2026-6464.html * https://www.suse.com/security/cve/CVE-2026-6469.html * https://www.suse.com/security/cve/CVE-2026-6470.html * https://www.suse.com/security/cve/CVE-2026-6471.html * https://bugzilla.suse.com/show_bug.cgi?id=1275001 * https://bugzilla.suse.com/show_bug.cgi?id=1275002 * https://bugzilla.suse.com/show_bug.cgi?id=1275042 * https://bugzilla.suse.com/show_bug.cgi?id=1275043 * https://bugzilla.suse.com/show_bug.cgi?id=1275044 * https://bugzilla.suse.com/show_bug.cgi?id=1275046 * https://bugzilla.suse.com/show_bug.cgi?id=1275047 * https://bugzilla.suse.com/show_bug.cgi?id=1275048 * https://bugzilla.suse.com/show_bug.cgi?id=1275049 * https://bugzilla.suse.com/show_bug.cgi?id=1275050 * https://bugzilla.suse.com/show_bug.cgi?id=1275051 * https://bugzilla.suse.com/show_bug.cgi?id=1275052 * https://bugzilla.suse.com/show_bug.cgi?id=1275053 * https://bugzilla.suse.com/show_bug.cgi?id=1275054 * https://bugzilla.suse.com/show_bug.cgi?id=1275055 * https://bugzilla.suse.com/show_bug.cgi?id=1275056 * https://bugzilla.suse.com/show_bug.cgi?id=1275057 * https://bugzilla.suse.com/show_bug.cgi?id=1275058 * https://bugzilla.suse.com/show_bug.cgi?id=1275059 * https://bugzilla.suse.com/show_bug.cgi?id=1275060 * https://bugzilla.suse.com/show_bug.cgi?id=1275061 * https://bugzilla.suse.com/show_bug.cgi?id=1275062 * https://bugzilla.suse.com/show_bug.cgi?id=1275063 * https://bugzilla.suse.com/show_bug.cgi?id=1275064 * https://bugzilla.suse.com/show_bug.cgi?id=1275065 * https://bugzilla.suse.com/show_bug.cgi?id=1275066 * https://bugzilla.suse.com/show_bug.cgi?id=1275067 * https://bugzilla.suse.com/show_bug.cgi?id=1275068 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:24:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:24:01 -0000 Subject: SUSE-SU-2026:23576-1: important: Security update for go1.26-openssl Message-ID: <178940664101.576.1493497276079178115@5ac198222802> # Security update for go1.26-openssl Announcement ID: SUSE-SU-2026:23576-1 Release Date: 2026-08-30T15:24:27Z Rating: important References: * bsc#1255111 * bsc#1266609 * bsc#1275024 * bsc#1275025 * bsc#1275026 * bsc#1275028 * bsc#1275029 * bsc#1275032 * bsc#1275033 * bsc#1275034 * jsc#SLE-18320 Cross-References: * CVE-2026-33818 * CVE-2026-39821 * CVE-2026-56853 * CVE-2026-56858 * CVE-2026-56859 * CVE-2026-56860 * CVE-2026-56862 * CVE-2026-56864 * CVE-2026-56865 CVSS scores: * CVE-2026-33818 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33818 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56853 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56853 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56858 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-56858 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-56859 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56859 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56860 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56860 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56862 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56862 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56864 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-56864 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56865 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56865 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves nine vulnerabilities, contains one feature and has one fix can now be installed. ## Description: This update for go1.26-openssl fixes the following issues: Update to version 1.26.7 cut from the go1.25-fips-release branch at the revision tagged go1.26.7-1-openssl-fips. Security issues fixed: * CVE-2026-33818: encoding/asn1: stack exhaustion when parsing deeply-nested, recursive structures can lead to denial of service (bsc#1275034). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266609). * CVE-2026-56853: net/http: first header read timeout not being applied when a server is configured to support unencrypted HTTP/2 allows for denial of service (bsc#1275028). * CVE-2026-56858: html/template: wrong JavaScript regexp context tracking after top-level `{` can lead to XSS (bsc#1275033). * CVE-2026-56859: encoding/xml: stack exhaustion due to recursion depth guard bypass during decoding operations can lead to denial of service (bsc#1275026). * CVE-2026-56860: net/url: quadratic complexity in `resolvePath` when processing backtrack path elements can lead to denial of service (bsc#1275029). * CVE-2026-56862: crypto/tls: handshake messages can bypass non-advancing record limit in TLS 1.3, which can lead to a denial of service (bsc#1275032). * CVE-2026-56864: x/mod/sumdb: a malicious `GOSUMDB` is capable of serving arbitrary module content not contained within the transparency log (bsc#1275025). * CVE-2026-56865: x/mod/sumdb/tlog: a malicious `GOPROXY` is capable of forging sumdb tiles, which allows for bypass of the `GOSUMDB` check and persistence of attacker-controlled module contents to a local Go module cache (bsc#1275024). Other updates and bugfixes: * Update to version 1.26.7 cut from the go1.25-fips-release branch at the revision tagged go1.26.7-1-openssl-fips: (jsc#SLE-18320). * Rebase to 1.26.7 * Support `strictfipsruntime` with `no_openssl` * Fix multiple `no_openssl` build tag issues * go1.26.7 (released 2026-08-19, boo#1255111): * go#80927 net/http: `ReadHeaderTimeout` remains active after unencrypted `HTTP/2` handoff * go1.26.6 (released 2026-08-13): * includes security fixes to the `go` command, and the `crypto/tls`, `encoding/asn1`, `encoding/xml`, `html/template`, `net`, `net/http`, and `net/url` packages, as well as bug fixes to the compiler, the linker, the runtime, and the `crypto/tls` and `os` packages. * go#79876 cmd/compile: `prove` misscompilation in `slicemask` folding leaves garbage in the upper bits * go#80099 cmd/compile: internal compiler error invalid heap allocated var without `Heapaddr` * go#80131 cmd/link: `peCreateExportFile` generates invalid `.def` file when output name has trailing dot (`c-shared` on Windows) * go#80365 os: `Root`'s `MkdirAll` can't create paths ending in forward slashes * go#80367 os: `TestRootMultiReadFile` fails on `netbsd/arm64` after CL 797880 * go#80369 os: `TestRootConsistencyRemoveAll` fails on Plan 9 after CL 797880 * go#80394 runtime: `arm64` found pointer to free object with safe code * go#80441 runtime: uninitialized register due to wrong ABI in `mach_vm_region_trampoline` leads to `libc` following garbage stack data as a pointer * go#80478 cmd/compile: `riscv64` miscompiles struct copy, corrupting a `[]byte` slice field * go#80499 runtime: js/wasm: "found bad pointer in Go heap" \-- link-layout- constant value recorded as a pointer in the write-barrier buffer * go#80579 cmd/compile: `regalloc` uses unreliable type data (like `v.Type.IsSigned()`) to choose the restore of spills * go#80606 crypto/tls: escape hatch for FIPS 140-3 mode Extended Master Secret enforcement * go#80609 net, x/net/dns/dnsmessage: panic when parsing invalid `SVCB` record * go#80615 cmd/compile: `mips64le` misscompile `OffPtr` by a const which doesn't fit 32bits resulting in panic * go#80617 cmd/compile: `mips`/`mips64`, multiply/divide results spilled from `HI`/`LO` corrupted w/ big stack frames * go#80619 cmd/compile: `prove` bug causes invalid indirect call * go#80715 runtime: `fpTracebackPartialExpand` `SIGSEGV` under high panic load * Update to version 1.26.5 cut from the go1.25-fips-release branch at the revision tagged go1.26.5-2-openssl-fips: * Limit `openssl` `RandReader` concurrency ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1561 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1561 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * go1.26-openssl-race-1.26.7-160000.1.1 * go1.26-openssl-doc-1.26.7-160000.1.1 * go1.26-openssl-1.26.7-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.26-openssl-race-1.26.7-160000.1.1 * go1.26-openssl-doc-1.26.7-160000.1.1 * go1.26-openssl-1.26.7-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33818.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56853.html * https://www.suse.com/security/cve/CVE-2026-56858.html * https://www.suse.com/security/cve/CVE-2026-56859.html * https://www.suse.com/security/cve/CVE-2026-56860.html * https://www.suse.com/security/cve/CVE-2026-56862.html * https://www.suse.com/security/cve/CVE-2026-56864.html * https://www.suse.com/security/cve/CVE-2026-56865.html * https://bugzilla.suse.com/show_bug.cgi?id=1255111 * https://bugzilla.suse.com/show_bug.cgi?id=1266609 * https://bugzilla.suse.com/show_bug.cgi?id=1275024 * https://bugzilla.suse.com/show_bug.cgi?id=1275025 * https://bugzilla.suse.com/show_bug.cgi?id=1275026 * https://bugzilla.suse.com/show_bug.cgi?id=1275028 * https://bugzilla.suse.com/show_bug.cgi?id=1275029 * https://bugzilla.suse.com/show_bug.cgi?id=1275032 * https://bugzilla.suse.com/show_bug.cgi?id=1275033 * https://bugzilla.suse.com/show_bug.cgi?id=1275034 * https://jira.suse.com/browse/SLE-18320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:24:39 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:24:39 -0000 Subject: SUSE-SU-2026:23575-1: important: Security update for udisks2 Message-ID: <178940667993.576.8093545773094674079@5ac198222802> # Security update for udisks2 Announcement ID: SUSE-SU-2026:23575-1 Release Date: 2026-08-30T15:19:49Z Rating: important References: * bsc#1274430 Cross-References: * CVE-2026-7867 CVSS scores: * CVE-2026-7867 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-7867 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for udisks2 fixes the following issue: * CVE-2026-7867: insufficient authorization checks on the `as-user` option in the `org.freedesktop.UDisks2.Filesystem.Mount()` D-Bus method can lead to local privilege escalation (bsc#1274430). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1560 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1560 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * typelib-1_0-UDisks-2_0-2.10.1-160000.4.1 * udisks2-2.10.1-160000.4.1 * libudisks2-0-2.10.1-160000.4.1 * libudisks2-0-devel-2.10.1-160000.4.1 * libudisks2-0_btrfs-debuginfo-2.10.1-160000.4.1 * udisks2-debuginfo-2.10.1-160000.4.1 * udisks2-debugsource-2.10.1-160000.4.1 * libudisks2-0-debuginfo-2.10.1-160000.4.1 * libudisks2-0_lsm-2.10.1-160000.4.1 * libudisks2-0_lvm2-2.10.1-160000.4.1 * libudisks2-0_lsm-debuginfo-2.10.1-160000.4.1 * libudisks2-0_btrfs-2.10.1-160000.4.1 * libudisks2-0_lvm2-debuginfo-2.10.1-160000.4.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * udisks2-lang-2.10.1-160000.4.1 * udisks2-zsh-completion-2.10.1-160000.4.1 * udisks2-docs-2.10.1-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * typelib-1_0-UDisks-2_0-2.10.1-160000.4.1 * udisks2-2.10.1-160000.4.1 * libudisks2-0-2.10.1-160000.4.1 * libudisks2-0-devel-2.10.1-160000.4.1 * libudisks2-0_btrfs-debuginfo-2.10.1-160000.4.1 * udisks2-debuginfo-2.10.1-160000.4.1 * udisks2-debugsource-2.10.1-160000.4.1 * libudisks2-0-debuginfo-2.10.1-160000.4.1 * libudisks2-0_lsm-2.10.1-160000.4.1 * libudisks2-0_lvm2-2.10.1-160000.4.1 * libudisks2-0_lsm-debuginfo-2.10.1-160000.4.1 * libudisks2-0_btrfs-2.10.1-160000.4.1 * libudisks2-0_lvm2-debuginfo-2.10.1-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * udisks2-lang-2.10.1-160000.4.1 * udisks2-zsh-completion-2.10.1-160000.4.1 * udisks2-docs-2.10.1-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-7867.html * https://bugzilla.suse.com/show_bug.cgi?id=1274430 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:25:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:25:35 -0000 Subject: SUSE-SU-2026:23574-1: important: Security update for 389-ds Message-ID: <178940673597.576.7424624880257076951@5ac198222802> # Security update for 389-ds Announcement ID: SUSE-SU-2026:23574-1 Release Date: 2026-08-30T14:40:18Z Rating: important References: * bsc#1267975 * bsc#1268041 * bsc#1268046 * bsc#1268047 * bsc#1268057 * bsc#1268058 * bsc#1268060 * bsc#1268062 * bsc#1268064 * bsc#1268065 * bsc#1268115 * bsc#1268298 * bsc#1268491 * bsc#1269120 * bsc#1270695 Cross-References: * CVE-2026-11610 * CVE-2026-11611 * CVE-2026-11774 * CVE-2026-11785 * CVE-2026-11786 * CVE-2026-11787 * CVE-2026-11788 * CVE-2026-11789 * CVE-2026-11790 * CVE-2026-11791 * CVE-2026-11792 * CVE-2026-11793 * CVE-2026-11884 * CVE-2026-12528 CVSS scores: * CVE-2026-11610 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-11610 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-11611 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11611 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11611 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11774 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-11774 ( SUSE ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-11774 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-11774 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-11785 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-11785 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-11785 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-11786 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11786 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-11786 ( NVD ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-11786 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-11787 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-11787 ( SUSE ): 5.0 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-11787 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-11787 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-11788 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11788 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11788 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11788 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11789 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11789 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11789 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11789 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11790 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11790 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11790 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11791 ( SUSE ): 5.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-11791 ( SUSE ): 5.5 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-11791 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-11791 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-11792 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-11792 ( SUSE ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-11792 ( NVD ): 3.3 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-11793 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11793 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11793 ( NVD ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11884 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-11884 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-12528 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-12528 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-12528 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 14 vulnerabilities and has one fix can now be installed. ## Description: This update for 389-ds fixes the following issues: Update to version 3.0.6~git382.7a51ea5f5. Security issues fixed: * CVE-2026-11610: heap buffer overflow in the SASL I/O layer via a crafted oversized LDAP UNBIND packet (bsc#1270695). * CVE-2026-11611: unbounded memory growth allowed by the Content Synchronization persistent search plugin when an authenticated client stops reading sync responses (bsc#1267975). * CVE-2026-11774: integer overflow in the SASL I/O layer leading to heap buffer overflow via crafted SASL packet length prefixes (bsc#1268298). * CVE-2026-11785: type confusion in the SSO token handler can cause partial stack address information disclosure in LDAP responses to authenticated users (bsc#1268065). * CVE-2026-11786: out-of-bounds read in the LDIF parser when processing attribute types with trailing semicolons during database import (bsc#1268064). * CVE-2026-11787: heap buffer overread due to missing checks in string filter parsing (bsc#1268062). * CVE-2026-11788: server crash due to missing allocation failure checks in the dereference control plugin (bsc#1268057). * CVE-2026-11789: integer underflow in the SMD5 password storage plugin leading to a buffer overflow via a crafted password hash (bsc#1268058). * CVE-2026-11790: excessive CPU consumption during authentication due to improper upper bounds enforcement in the PBKDF2-SHA256 password storage plugin (bsc#1268060). * CVE-2026-11791: use-after-free in the schema reload mechanism can be triggered while concurrent LDAP query traffic is active (bsc#1268047). * CVE-2026-11792: heap buffer overflow when audit logging is enabled and short cleartext passwords are logged (bsc#1268046). * CVE-2026-11793: stack buffer overflow leading to crash via crafted credentials with an oversized algorithm ID (bsc#1268041). * CVE-2026-11884: heap buffer overflow leading to crash when serializing objectclass definitions (bsc#1268115). * CVE-2026-12528: heap buffer overflow during ACI parsing via malformed ACI strings (bsc#1268491). Other updates and bugfixes: * Version 3.0.6~git382.7a51ea5f5: * Issue 7711 - Fix typo in accountpolicy --login-history-size help text (#7713) * Issue 7688 - BUG - partial address leak in sso token (#7689) * Issue 7705 - With memberOfEntryScope set, deferred memberOf skips MODIFY operations (#7706) * Issue 7698 - Fix silent entry loss in LMDB bulk import waiter handling (#7699) * Issue 7666 - Replication performance degradation during total init on high- latency storage (#7667) * Issue 7201 - Syscall overhead in LMDB import writer thread (#7204) * Issue 7645 - Add runtime LeakSanitizer leak check (#7646) * Issue 7714 - UI - sass import rules are deprecated * Issue 7658 - Heap Buffer Overflow in sasl_io_recv() via Padded SASL UNBIND * Issue 7710 - MemberOf deferred update - Use condvar instead of sleep loop * Issue 7637 - UI - Using Arrow Keys in New Object Wizard Resulted in DOM Reload * Issue 7578 - schema - attribute refcount is not maintained properly * Issue 7605 - Harden CI test ports against ephemeral allocation (#7692) * Issue 7528 - Retry the CI image pull instead of failing the job (#7691) * Backport Issue 7519 -- ignore obsolete entrydn when entryrdn is in use (#7657) * Issue 7460 - MOD_REPLACE on groups/link attributes modifies overlap targets (#7461) * Issue 7505 - RFE - CLI - add feature to determine which password policy applies to a user * Issue 7670 - BDB range searches intermittently fail with err=1 under write load (#7671) * Issue 7108 - Fix shutdown crash in entry cache destruction (#7163) * Issue 7284 - Creating local password policy succeeds with incorrect passwordInHistory value (#7662) * Issue 7284 - Automated test for creating local password policy with incorrect passwordInHistory value (#7608) * Issue 7200 - repl-agmt create doesn't set some parameters (#7663) * Issue 7573 - Post-import cache autotuning does not recompute entry cache size (#7574) * Version 3.0.6~git359.953dc780a: * Issue 7470 - dsctl localhost tls import-server-key-cert fails with 'expected str, bytes or os.PathLike object, not NoneType' (#7477) * Version 3.0.6~git356.e6c148b60: * Issue 7611 - PBKDF2 password verification should reject invalid iteration count (#7613) * Issue 7558 - Total init sends the suffix entry twice (#7640) * Issue 7635 - Integer Underflow in {SMD5} Password Comparison (#7636) * Issue 7406 - Fix ldap-agent SNMP stats file loading (#7630) * Issue 7621 - Stack Buffer Overflow in Password checkPrefix * Issue 7623 - Heap Buffer Overflow in 389-ds-base Audit Log Password Masking * Issue 7602 - CI - lib389 user compare fails due to parentid mismatch (#7603) * Issue 7537 - CI - Fix replication log monitoring parser/timing failures (#7592) * Issue 7593 - Fix testimony docstring for SASL overflow test (#7606) * Issue 7530 - CI - Stabilize DNA plugin replication tests timing out in CI (#7572) * Issue 7593 - Reject invalid SASL packet length values in sasl_io_start_packet (#7594) * Issue 3555 - UI - Fix audit issue with npm - ws, js-yaml, babel/core (#7599) * Bump fast-uri from 3.1.0 to 3.1.2 in /src/cockpit/389-console (#7487) * Update dependency uuid to v14 [SECURITY] (#7456) * Update cockpit-389-ds-npm (major) (#7448) * Issue 7263 - UI - Use cockpit.file API for temporary file writes (#7590) * Issue 7541 - Add invalid ACL text header regression test (#7591) * Issue 7554 - UI - Revise local password policy layout * Issue 7521 - UI - make changes for cockpit API updates ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1547 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1547 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * 389-ds-snmp-debuginfo-3.0.6~git382.7a51ea5f5-160000.1.1 * 389-ds-debuginfo-3.0.6~git382.7a51ea5f5-160000.1.1 * lib389-3.0.6~git382.7a51ea5f5-160000.1.1 * 389-ds-snmp-3.0.6~git382.7a51ea5f5-160000.1.1 * libsvrcore0-debuginfo-3.0.6~git382.7a51ea5f5-160000.1.1 * 389-ds-3.0.6~git382.7a51ea5f5-160000.1.1 * 389-ds-debugsource-3.0.6~git382.7a51ea5f5-160000.1.1 * 389-ds-devel-3.0.6~git382.7a51ea5f5-160000.1.1 * libsvrcore0-3.0.6~git382.7a51ea5f5-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * 389-ds-snmp-debuginfo-3.0.6~git382.7a51ea5f5-160000.1.1 * 389-ds-debuginfo-3.0.6~git382.7a51ea5f5-160000.1.1 * lib389-3.0.6~git382.7a51ea5f5-160000.1.1 * 389-ds-snmp-3.0.6~git382.7a51ea5f5-160000.1.1 * libsvrcore0-debuginfo-3.0.6~git382.7a51ea5f5-160000.1.1 * 389-ds-3.0.6~git382.7a51ea5f5-160000.1.1 * 389-ds-debugsource-3.0.6~git382.7a51ea5f5-160000.1.1 * 389-ds-devel-3.0.6~git382.7a51ea5f5-160000.1.1 * libsvrcore0-3.0.6~git382.7a51ea5f5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11610.html * https://www.suse.com/security/cve/CVE-2026-11611.html * https://www.suse.com/security/cve/CVE-2026-11774.html * https://www.suse.com/security/cve/CVE-2026-11785.html * https://www.suse.com/security/cve/CVE-2026-11786.html * https://www.suse.com/security/cve/CVE-2026-11787.html * https://www.suse.com/security/cve/CVE-2026-11788.html * https://www.suse.com/security/cve/CVE-2026-11789.html * https://www.suse.com/security/cve/CVE-2026-11790.html * https://www.suse.com/security/cve/CVE-2026-11791.html * https://www.suse.com/security/cve/CVE-2026-11792.html * https://www.suse.com/security/cve/CVE-2026-11793.html * https://www.suse.com/security/cve/CVE-2026-11884.html * https://www.suse.com/security/cve/CVE-2026-12528.html * https://bugzilla.suse.com/show_bug.cgi?id=1267975 * https://bugzilla.suse.com/show_bug.cgi?id=1268041 * https://bugzilla.suse.com/show_bug.cgi?id=1268046 * https://bugzilla.suse.com/show_bug.cgi?id=1268047 * https://bugzilla.suse.com/show_bug.cgi?id=1268057 * https://bugzilla.suse.com/show_bug.cgi?id=1268058 * https://bugzilla.suse.com/show_bug.cgi?id=1268060 * https://bugzilla.suse.com/show_bug.cgi?id=1268062 * https://bugzilla.suse.com/show_bug.cgi?id=1268064 * https://bugzilla.suse.com/show_bug.cgi?id=1268065 * https://bugzilla.suse.com/show_bug.cgi?id=1268115 * https://bugzilla.suse.com/show_bug.cgi?id=1268298 * https://bugzilla.suse.com/show_bug.cgi?id=1268491 * https://bugzilla.suse.com/show_bug.cgi?id=1269120 * https://bugzilla.suse.com/show_bug.cgi?id=1270695 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:26:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:26:25 -0000 Subject: SUSE-SU-2026:23573-1: important: Security update for go1.25-openssl Message-ID: <178940678556.576.5745093877064908201@5ac198222802> # Security update for go1.25-openssl Announcement ID: SUSE-SU-2026:23573-1 Release Date: 2026-08-30T14:38:12Z Rating: important References: * bsc#1244485 * bsc#1266609 * bsc#1275024 * bsc#1275025 * bsc#1275026 * bsc#1275028 * bsc#1275029 * bsc#1275032 * bsc#1275033 * bsc#1275034 * jsc#SLE-18320 Cross-References: * CVE-2026-33818 * CVE-2026-39821 * CVE-2026-56853 * CVE-2026-56858 * CVE-2026-56859 * CVE-2026-56860 * CVE-2026-56862 * CVE-2026-56864 * CVE-2026-56865 CVSS scores: * CVE-2026-33818 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33818 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56853 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56853 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56858 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-56858 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-56859 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56859 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56860 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56860 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56862 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56862 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56864 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-56864 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56865 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-56865 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves nine vulnerabilities, contains one feature and has one fix can now be installed. ## Description: This update for go1.25-openssl fixes the following issues: Update to version 1.25.14 cut from the go1.25-fips-release branch at the revision tagged go1.25.14-1-openssl-fips. Security issues fixed: * CVE-2026-33818: encoding/asn1: stack exhaustion when parsing deeply-nested, recursive structures can lead to denial of service (bsc#1275034). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266609). * CVE-2026-56853: net/http: first header read timeout not being applied when a server is configured to support unencrypted HTTP/2 allows for denial of service (bsc#1275028). * CVE-2026-56858: html/template: wrong JavaScript regexp context tracking after top-level `{` can lead to XSS (bsc#1275033). * CVE-2026-56859: encoding/xml: stack exhaustion due to recursion depth guard bypass during decoding operations can lead to denial of service (bsc#1275026). * CVE-2026-56860: net/url: quadratic complexity in `resolvePath` when processing backtrack path elements can lead to denial of service (bsc#1275029). * CVE-2026-56862: crypto/tls: handshake messages can bypass non-advancing record limit in TLS 1.3, which can lead to a denial of service (bsc#1275032). * CVE-2026-56864: x/mod/sumdb: a malicious `GOSUMDB` is capable of serving arbitrary module content not contained within the transparency log (bsc#1275025). * CVE-2026-56865: x/mod/sumdb/tlog: a malicious `GOPROXY` is capable of forging sumdb tiles, which allows for bypass of the `GOSUMDB` check and persistence of attacker-controlled module contents to a local Go module cache (bsc#1275024). Other updates and bugfixes: * Update to version 1.25.14 cut from the go1.25-fips-release branch at the revision tagged go1.25.14-1-openssl-fips: (jsc#SLE-18320): * Rebase to 1.25.14 * go1.25.14 (released 2026-08-19, boo#1244485): * go#80926 net/http: `ReadHeaderTimeout` remains active after unencrypted HTTP/2 handoff * go1.25.13 (released 2026-08-13): * includes security fixes to the `go` command, and the `crypto/tls`, `encoding/asn1`, `encoding/xml`, `html/template`, `net/http`, and `net/url` packages, as well as bug fixes to the compiler, the runtime, and the `crypto/tls` and `os` packages. * go#79876 cmd/compile: `prove` miscompilation in `slicemask` folding leaves garbage in the upper bits * go#80098 cmd/compile: internal compiler error invalid heap allocated var without `Heapaddr` * go#80364 os: `Root`'s `MkdirAll` can't create paths ending in forward slashes * go#80366 os: `TestRootMultiReadFile` fails on `netbsd/arm64` after CL 797880 * go#80368 os: `TestRootConsistencyRemoveAll` fails on Plan 9 after CL 797880 * go#80393 runtime: `arm64` found pointer to free object with safe code * go#80440 runtime: uninitialized register due to wrong ABI in `mach_vm_region_trampoline` leads to `libc` following garbage stack data as a pointer * go#80477 cmd/compile: `riscv64` miscompiles struct copy, corrupting a `[]byte` slice field * go#80500 runtime: js/wasm: "found bad pointer in Go heap" \-- link-layout- constant value recorded as a pointer in the write-barrier buffer * go#80578 cmd/compile: `regalloc` uses unreliable type data (like `v.Type.IsSigned()`) to choose the restore of spills * go#80605 crypto/tls: escape hatch for FIPS 140-3 mode Extended Master Secret enforcement * go#80614 cmd/compile: `mips64le` miscompiles `OffPtr` by a const which doesn't fit 32bits resulting in panic * go#80616 cmd/compile: `mips`/`mips64`, multiply/divide results spilled from `HI`/`LO` corrupted w/ big stack frames * go#80618 cmd/compile: `prove` bug causes invalid indirect call * go#80737 runtime: `fpTracebackPartialExpand` `SIGSEGV` under high panic load * Update to version 1.25.12 cut from the go1.25-fips-release branch at the revision tagged go1.25.12-2-openssl-fips: * Limit openssl `RandReader` concurrency (#374) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1552 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1552 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * go1.25-openssl-1.25.14-160000.1.1 * go1.25-openssl-race-1.25.14-160000.1.1 * go1.25-openssl-doc-1.25.14-160000.1.1 * go1.25-openssl-debuginfo-1.25.14-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * go1.25-openssl-1.25.14-160000.1.1 * go1.25-openssl-race-1.25.14-160000.1.1 * go1.25-openssl-doc-1.25.14-160000.1.1 * go1.25-openssl-debuginfo-1.25.14-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33818.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56853.html * https://www.suse.com/security/cve/CVE-2026-56858.html * https://www.suse.com/security/cve/CVE-2026-56859.html * https://www.suse.com/security/cve/CVE-2026-56860.html * https://www.suse.com/security/cve/CVE-2026-56862.html * https://www.suse.com/security/cve/CVE-2026-56864.html * https://www.suse.com/security/cve/CVE-2026-56865.html * https://bugzilla.suse.com/show_bug.cgi?id=1244485 * https://bugzilla.suse.com/show_bug.cgi?id=1266609 * https://bugzilla.suse.com/show_bug.cgi?id=1275024 * https://bugzilla.suse.com/show_bug.cgi?id=1275025 * https://bugzilla.suse.com/show_bug.cgi?id=1275026 * https://bugzilla.suse.com/show_bug.cgi?id=1275028 * https://bugzilla.suse.com/show_bug.cgi?id=1275029 * https://bugzilla.suse.com/show_bug.cgi?id=1275032 * https://bugzilla.suse.com/show_bug.cgi?id=1275033 * https://bugzilla.suse.com/show_bug.cgi?id=1275034 * https://jira.suse.com/browse/SLE-18320 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:27:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:27:10 -0000 Subject: SUSE-SU-2026:23572-1: important: Security update for gstreamer-devtools Message-ID: <178940683034.576.8899333011918284075@5ac198222802> # Security update for gstreamer-devtools Announcement ID: SUSE-SU-2026:23572-1 Release Date: 2026-08-30T14:38:11Z Rating: important References: * bsc#1243178 * bsc#1249015 * bsc#1257914 * bsc#1274306 * bsc#1275209 * bsc#1275210 Cross-References: * CVE-2025-4574 * CVE-2025-58160 * CVE-2026-25541 * CVE-2026-25727 * CVE-2026-72813 * CVE-2026-72814 CVSS scores: * CVE-2025-4574 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2025-4574 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2025-4574 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25541 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25541 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25541 ( NVD ): 5.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25541 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25727 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25727 ( NVD ): 6.8 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-25727 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-72813 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72813 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72813 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-72814 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-72814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-72814 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for gstreamer-devtools fixes the following issues: * CVE-2025-4574: crossbeam-channel: internal `Channel` type's `Drop` method has a race condition that can lead to a double-free and memory corruption (bsc#1243178). * CVE-2025-58160: tracing-subscriber: untrusted user input containing ANSI escape sequences can be injected into terminal output when logged and lead to terminal manipulation (bsc#1249015). * CVE-2026-25541: bytes: integer overflow in `BytesMut:reserve` can lead to undefined behavior and crashes (bsc#1274306). * CVE-2026-25727: time: parsing of user-provided input by the RFC 2822 date parser can lead to stack exhaustion (bsc#1257914). * CVE-2026-72813: actix-files: empty `Range` header in GET requests for static files can lead to a process crash (bsc#1275210). * CVE-2026-72814: actix-files: non-existing folders passed as an argument to the `actix_files::Files::new()` method can lead to information disclosure (bsc#1275209). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1545 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1545 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libgstvalidate-1_0-0-debuginfo-1.26.7-160000.2.1 * typelib-1_0-GstValidate-1_0-1.26.7-160000.2.1 * gstreamer-devtools-debuginfo-1.26.7-160000.2.1 * libgstvalidate-1_0-0-1.26.7-160000.2.1 * gstreamer-devtools-debugsource-1.26.7-160000.2.1 * gstreamer-devtools-1.26.7-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libgstvalidate-1_0-0-debuginfo-1.26.7-160000.2.1 * typelib-1_0-GstValidate-1_0-1.26.7-160000.2.1 * gstreamer-devtools-debuginfo-1.26.7-160000.2.1 * libgstvalidate-1_0-0-1.26.7-160000.2.1 * gstreamer-devtools-debugsource-1.26.7-160000.2.1 * gstreamer-devtools-1.26.7-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-4574.html * https://www.suse.com/security/cve/CVE-2025-58160.html * https://www.suse.com/security/cve/CVE-2026-25541.html * https://www.suse.com/security/cve/CVE-2026-25727.html * https://www.suse.com/security/cve/CVE-2026-72813.html * https://www.suse.com/security/cve/CVE-2026-72814.html * https://bugzilla.suse.com/show_bug.cgi?id=1243178 * https://bugzilla.suse.com/show_bug.cgi?id=1249015 * https://bugzilla.suse.com/show_bug.cgi?id=1257914 * https://bugzilla.suse.com/show_bug.cgi?id=1274306 * https://bugzilla.suse.com/show_bug.cgi?id=1275209 * https://bugzilla.suse.com/show_bug.cgi?id=1275210 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:27:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:27:52 -0000 Subject: SUSE-SU-2026:23571-1: moderate: Security update for python-aiohttp Message-ID: <178940687233.576.11556980437661954024@5ac198222802> # Security update for python-aiohttp Announcement ID: SUSE-SU-2026:23571-1 Release Date: 2026-08-30T14:38:11Z Rating: moderate References: * bsc#1273125 * bsc#1273552 * bsc#1273553 Cross-References: * CVE-2026-59881 * CVE-2026-69243 * CVE-2026-69244 CVSS scores: * CVE-2026-59881 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-59881 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-59881 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-69243 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-69243 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-69243 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-69244 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-69244 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-69244 ( NVD ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-aiohttp fixes the following issues: * CVE-2026-59881: excessive resource consumption due to WebSocket client accepting compressed frames without negotiated permessage-deflate (bsc#1273125). * CVE-2026-69243: HTTP request smuggling via the WebSocket upgrade procedure (bsc#1273553). * CVE-2026-69244: out-of-bounds heap read in the C response parser while building an error message for a malformed response (bsc#1273552). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1543 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1543 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python-aiohttp-debugsource-3.11.16-160000.7.1 * python313-aiohttp-debuginfo-3.11.16-160000.7.1 * python313-aiohttp-3.11.16-160000.7.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python-aiohttp-debugsource-3.11.16-160000.7.1 * python313-aiohttp-debuginfo-3.11.16-160000.7.1 * python313-aiohttp-3.11.16-160000.7.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59881.html * https://www.suse.com/security/cve/CVE-2026-69243.html * https://www.suse.com/security/cve/CVE-2026-69244.html * https://bugzilla.suse.com/show_bug.cgi?id=1273125 * https://bugzilla.suse.com/show_bug.cgi?id=1273552 * https://bugzilla.suse.com/show_bug.cgi?id=1273553 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:28:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:28:33 -0000 Subject: SUSE-SU-2026:23570-1: moderate: Security update for python-cryptography Message-ID: <178940691350.576.15943578451438896561@5ac198222802> # Security update for python-cryptography Announcement ID: SUSE-SU-2026:23570-1 Release Date: 2026-08-30T14:36:28Z Rating: moderate References: * bsc#1273516 * bsc#1273549 * bsc#1273551 Cross-References: * CVE-2026-69247 * CVE-2026-69248 * CVE-2026-69249 CVSS scores: * CVE-2026-69247 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-69247 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-69247 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-69248 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-69248 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-69248 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-69249 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-69249 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-69249 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-cryptography fixes the following issues: * CVE-2026-69247: PKCS#7 `EnvelopedData` decryption exposes a Bleichenbacher oracle through distinguishable errors and timing (bsc#1273551). * CVE-2026-69248: verifier accepts wildcard DNS names allowing escape from `permittedSubtrees` (bsc#1273549). * CVE-2026-69249: duplicate self-signed intermediates can cause exponential path-building (bsc#1273516). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1541 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1541 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python313-cryptography-debuginfo-44.0.3-160000.5.1 * python313-cryptography-44.0.3-160000.5.1 * python-cryptography-debugsource-44.0.3-160000.5.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python313-cryptography-debuginfo-44.0.3-160000.5.1 * python313-cryptography-44.0.3-160000.5.1 * python-cryptography-debugsource-44.0.3-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-69247.html * https://www.suse.com/security/cve/CVE-2026-69248.html * https://www.suse.com/security/cve/CVE-2026-69249.html * https://bugzilla.suse.com/show_bug.cgi?id=1273516 * https://bugzilla.suse.com/show_bug.cgi?id=1273549 * https://bugzilla.suse.com/show_bug.cgi?id=1273551 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:29:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:29:58 -0000 Subject: SUSE-SU-2026:23567-1: low: Security update for rav1e Message-ID: <178940699884.576.10051827851043079804@5ac198222802> # Security update for rav1e Announcement ID: SUSE-SU-2026:23567-1 Release Date: 2026-08-30T14:35:10Z Rating: low References: * bsc#1249016 Cross-References: * CVE-2025-58160 CVSS scores: * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for rav1e fixes the following issue: * CVE-2025-58160: tracing-subscriber: untrusted log input can allow ANSI escape sequence injection and terminal manipulation (bsc#1249016). Changes for rav1e: * Update cargo dependencies. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1537 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1537 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * rav1e-debugsource-0.8.1-160000.2.1 * librav1e0_8-0.8.1-160000.2.1 * rav1e-0.8.1-160000.2.1 * rav1e-debuginfo-0.8.1-160000.2.1 * librav1e0_8-debuginfo-0.8.1-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * rav1e-debugsource-0.8.1-160000.2.1 * librav1e0_8-0.8.1-160000.2.1 * rav1e-0.8.1-160000.2.1 * rav1e-debuginfo-0.8.1-160000.2.1 * librav1e0_8-debuginfo-0.8.1-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2025-58160.html * https://bugzilla.suse.com/show_bug.cgi?id=1249016 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:31:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:31:22 -0000 Subject: SUSE-SU-2026:23564-1: moderate: Security update for librest Message-ID: <178940708212.576.14270847414894454353@5ac198222802> # Security update for librest Announcement ID: SUSE-SU-2026:23564-1 Release Date: 2026-08-30T14:33:33Z Rating: moderate References: * bsc#1272399 Cross-References: * CVE-2026-16615 CVSS scores: * CVE-2026-16615 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-16615 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for librest fixes the following issue: * CVE-2026-16615: PKCE implementation for OAuth authorization uses a cryptographically insecure pseudo-random number generator (bsc#1272399). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1550 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1550 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * librest-debugsource-0.9.1-160000.3.1 * typelib-1_0-Rest-1_0-0.9.1-160000.3.1 * librest-1_0-0-debuginfo-0.9.1-160000.3.1 * librest-1_0-0-0.9.1-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * librest-debugsource-0.9.1-160000.3.1 * typelib-1_0-Rest-1_0-0.9.1-160000.3.1 * librest-1_0-0-debuginfo-0.9.1-160000.3.1 * librest-1_0-0-0.9.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16615.html * https://bugzilla.suse.com/show_bug.cgi?id=1272399 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:32:08 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:32:08 -0000 Subject: SUSE-SU-2026:23563-1: moderate: Security update for python-h2 Message-ID: <178940712896.576.1900499510588884168@5ac198222802> # Security update for python-h2 Announcement ID: SUSE-SU-2026:23563-1 Release Date: 2026-08-30T14:33:33Z Rating: moderate References: * bsc#1274386 Cross-References: * CVE-2026-71554 CVSS scores: * CVE-2026-71554 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-71554 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for python-h2 fixes the following issue: * CVE-2026-71554: duplicate `Host` headers are accepted and forwarded to consuming applications, which can lead to request smuggling (bsc#1274386). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1549 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1549 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-h2-4.2.0-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * python313-h2-4.2.0-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-71554.html * https://bugzilla.suse.com/show_bug.cgi?id=1274386 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:32:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:32:50 -0000 Subject: SUSE-SU-2026:23562-1: moderate: Security update for dhcpcd Message-ID: <178940717077.576.14150010335644280372@5ac198222802> # Security update for dhcpcd Announcement ID: SUSE-SU-2026:23562-1 Release Date: 2026-08-30T14:33:33Z Rating: moderate References: * bsc#1268968 * bsc#1268974 * bsc#1268976 * bsc#1268980 Cross-References: * CVE-2026-56113 * CVE-2026-56115 * CVE-2026-56116 * CVE-2026-56117 CVSS scores: * CVE-2026-56113 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56113 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56113 ( NVD ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56113 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56113 ( NVD ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56115 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56115 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56115 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56115 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-56116 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56116 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56116 ( NVD ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56116 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56117 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-56117 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-56117 ( NVD ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-56117 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56117 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for dhcpcd fixes the following issues: Update to 10.5.0. Security issues fixed: * CVE-2026-56113: crafted DHCPv6 RENEW reply can lead to a denial of service (bsc#1268980). * CVE-2026-56115: crafted DHCPv6 ADVERTISE message can cause a one-byte stack out-of-bounds write (bsc#1268976). * CVE-2026-56116: crafted Router Advertisements containing Route Information options with a zero lifetime can lead to a memory leak (bsc#1268974). * CVE-2026-56117: crafted privileged command sent over a writable control socket can lead to a heap use-after-free (bsc#1268968). Changes for dhcpcd: * 10.5.0: * Add missing SPDX-License tags * Format code with clang-format v19 * privsep: Change IPC to use SOCK_STREAM * BPF: Split OS specific code out into own files and add libpcap support * hooks: Escape interface names and use printf * Delete DHCPv6 IA FD from the loop before closing it * eloop: Use kqueue or epoll to wait for a fd to become ready * Darwin: Add initial support for macOS * Import latest pidfile from NetBSD * BPF: Improve headers * compat: Add support for getprogname(3) * route: Rework rt structure so sockaddrs are pointers * dhcp-common: Escape ifname for lease file * privsep: smaller buffer size without INET6 * script: add ifxname as the escaped string * time.h always pulls in struct timespec * route: Use HAVE_RT_MISSFILTER rather than a generic BSD define * privsep: Test defines for all ioctls * if: if_init inits the interface from the kernel * privsep: Add ps_root_gethostname * DHCP: Don't really expire the lease when testing * DHCP: Don't add a trailing : on vendor if no machine arch * privsep: guard setproctitle and only use compat on linux * options: Remove some const to fix compile warnings * privsep: Don't open PF_INET socket for each ioctl * sun: Enable building for privsep * script: Use correct buffer length variable * privsep: Remove PS_BUFLEN * privsep: Simplify readerror * timezone: disallow directory traversal * privsep: ps_root_readfile should return the real file size * linux: Ensure NLA data boundaries are valid * options: Fix userclass boundary * ND6: fix OOB reject mask for an undefined option. * DHCP6: Ensure IA_PD Prefix Lenth is valid * ND: Enforce require and reject policy * ARP: check we have enough to read the frame header * hooks: Quote assignment of compat vars correctly * udev: Ensure we have a subsystem, action and ifname * Fix CI build * DHCP: Santize messages from servers for output * ARP: Iterate over states safely as the cb could remove ours * privsep: Check data is terminated when a string * auth: clear keys with memset_explicit * auth: Ensure remaining dlen matches hash digest length * hooks: don't read past truncated ip6 address starting fe * ipv6: Only regen temp addrs with sufficent pltime * eloop: Improve timespecdiff * eloop: Fix compile warning where UTIME_MAX is a calculation * vsio: Allow zero length options * DHCP6: Fix configuring the suffix to delegated prefixes * IPv6: Fix numerous issues extending temporary address times * capsicum: Avoid some overflow issues in privsep sysctl * script: Fix buffer over and under flows in script_buftoenv * IPv4: uset old_ia when adding an address causes early removal * dhcp: add configurable backoff parameters for DHCPv4 * options: Introdce policy groups * Build all the targets on macos * control: remove unprivileged socket * DHCP: deconfigure even when state is NULL or NONE ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1548 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1548 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * dhcpcd-debuginfo-10.5.0-160000.1.1 * dhcpcd-10.5.0-160000.1.1 * dhcpcd-debugsource-10.5.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * dhcpcd-debuginfo-10.5.0-160000.1.1 * dhcpcd-10.5.0-160000.1.1 * dhcpcd-debugsource-10.5.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56113.html * https://www.suse.com/security/cve/CVE-2026-56115.html * https://www.suse.com/security/cve/CVE-2026-56116.html * https://www.suse.com/security/cve/CVE-2026-56117.html * https://bugzilla.suse.com/show_bug.cgi?id=1268968 * https://bugzilla.suse.com/show_bug.cgi?id=1268974 * https://bugzilla.suse.com/show_bug.cgi?id=1268976 * https://bugzilla.suse.com/show_bug.cgi?id=1268980 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:33:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:33:34 -0000 Subject: SUSE-SU-2026:23561-1: important: Security update for python-sqlparse Message-ID: <178940721420.576.14654492075577343987@5ac198222802> # Security update for python-sqlparse Announcement ID: SUSE-SU-2026:23561-1 Release Date: 2026-08-30T14:33:33Z Rating: important References: * bsc#1268597 * bsc#1275459 * bsc#1275460 * bsc#1275461 * bsc#1275466 Cross-References: * CVE-2026-54284 * CVE-2026-59893 * CVE-2026-59894 * CVE-2026-71491 CVSS scores: * CVE-2026-54284 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54284 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-54284 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59893 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59893 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-59894 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-59894 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59894 ( NVD ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-71491 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-71491 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-71491 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities and has one fix can now be installed. ## Description: This update for python-sqlparse fixes the following issues: * CVE-2026-54284: high algorithm complexity when parsing SQL payloads with hundreds of nesting levels can lead to denial of service via excessive resource consumption (bsc#1275459). * CVE-2026-59893: quadratic complexity when processing unmatched dollar-quoted literal and multiline-comment delimiters can lead to denial of service (bsc#1275461). * CVE-2026-59894: improper backlash escaping allows for injection of Python or PHP code via a crafted SQL input (bsc#1275460). * CVE-2026-71491: quadratic complexity in `group_comments` when processing comment-only statements can lead to denial of services (bsc#1275466). * Incomplete GHSA-27jp-wm6q-gp25 patch (bsc#1268597). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1546 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1546 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-sqlparse-0.5.3-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * python313-sqlparse-0.5.3-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54284.html * https://www.suse.com/security/cve/CVE-2026-59893.html * https://www.suse.com/security/cve/CVE-2026-59894.html * https://www.suse.com/security/cve/CVE-2026-71491.html * https://bugzilla.suse.com/show_bug.cgi?id=1268597 * https://bugzilla.suse.com/show_bug.cgi?id=1275459 * https://bugzilla.suse.com/show_bug.cgi?id=1275460 * https://bugzilla.suse.com/show_bug.cgi?id=1275461 * https://bugzilla.suse.com/show_bug.cgi?id=1275466 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:37:20 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:37:20 -0000 Subject: SUSE-SU-2026:23552-1: important: Security update for vim Message-ID: <178940744066.576.2787172618742472028@5ac198222802> # Security update for vim Announcement ID: SUSE-SU-2026:23552-1 Release Date: 2026-08-28T08:28:19Z Rating: important References: * bsc#1268162 * bsc#1271684 * bsc#1275011 * bsc#1275012 * bsc#1275013 * bsc#1275014 * bsc#1275015 * bsc#1275016 * bsc#1275017 * bsc#1275018 Cross-References: * CVE-2026-73070 * CVE-2026-73071 * CVE-2026-73072 * CVE-2026-73074 * CVE-2026-73075 * CVE-2026-73076 * CVE-2026-73077 * CVE-2026-73078 CVSS scores: * CVE-2026-73070 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-73070 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-73070 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73071 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-73071 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-73071 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-73072 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73072 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-73072 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73074 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73074 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-73074 ( NVD ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73075 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-73075 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-73075 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73076 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73076 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-73076 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73077 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73077 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-73077 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-73078 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-73078 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-73078 ( NVD ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities and has two fixes can now be installed. ## Description: This update for vim fixes the following issues: Updated to version 9.2.0957. Security issues fixed: * CVE-2026-73070: stack buffer overflow in the socket server can lead to denial of service (bsc#1275018). * CVE-2026-73071: use-after-free in JSON decoding can lead to process crash (bsc#1275017). * CVE-2026-73072: heap buffer overflow when loading a spell file can lead to crash or potential code execution (bsc#1275016). * CVE-2026-73074: heap buffer overflow in text property handling can lead to a crash or potential code execution (bsc#1275015). * CVE-2026-73075: out-of-bounds access in popup opacity handling can lead to a conditional memory write (bsc#1275014). * CVE-2026-73076: arbitrary command execution via the vimball record file (bsc#1275013). * CVE-2026-73077: arbitrary code execution due to insecure shell command handling (bsc#1275012). * CVE-2026-73078: arbitrary code execution via crafted netrw menu entries (bsc#1275011). Other updates and bugfixes: * Version 9.2.0957. * tests: Test_fuzzy_completion_bufname_fullpath() creates unnecessary dir (9.2.0781). * tests: missing cleanup in test_mksession.vim (9.2.0782). * tests: personal spell files leak into later tests (9.2.0783). * crash when borrowing statusline highlight in silent Ex mode (9.2.0784). * WinResized not triggered when the whole Vim is resized (9.2.0785). * filetype: containerfile is not recognized (9.2.0786). * regexp: code 0x1ecb duplicated for equivalence class (9.2.0787). * filetype: hip files are not recognized (9.2.0788). * 'statuslineopt' status line too high after a window is minimized (9.2.0789). * 'completeslash' breaks :find completion with 'findfunc' (9.2.0790). * wincol() counts from right side for 'rightleft' (9.2.0791). * runtime(netrw): explore without optional dir broken (9.2.0792). * if session restored a tiny window, restore fails (9.2.0793). * extend() and extendnew() don't handle NULL expr2 properly (9.2.0794). * popup menu shadow is not cleared when the menu shrinks (9.2.0795). * Visual block reselection wrong with 'virtualedit' (9.2.0796). * memory leak in get_qfline_items() on alloc failure (9.2.0797). * memory leak in compile_expr6() on alloc failure (9.2.0798). * memory leak in compile_def_function_body() on alloc failure (9.2.0799). * memory leak in call_func() on alloc failure (9.2.0800). * memory leak in f_getreginfo() on alloc failure (9.2.0801). * memory leak with list_append_dict/dict_add_list on alloc failure (9.2.0802). * memory leak on alloc failure with taglist/gettagstack() (9.2.0803). * wincol() is wrong for a double-wide character with 'rightleft' (9.2.0804). * screenpos() "curscol" is wrong with 'rightleft' (9.2.0805). * 'showcmd' may show internal command keys (9.2.0806). * MS-Windows: ellipsis character is garbled (9.2.0807). * getregionpos: double-free on alloc failure (9.2.0808). * getframelayout() uses wrong function to free lists (9.2.0809). * add_llist_tags() uses wrong function to free dict (9.2.0810). * mksession writes terminal command unquoted (9.2.0811). * :argdelete with pattern leads to wrong argidx() (9.2.0812). * dict_add_func() may corrupt funcref count on failure (9.2.0813). * Vim9: E1041 when reloading an autoload script with exported variables (9.2.0814). * deeply nested regexp patterns may cause stack overflow (9.2.0815). * GTK4: memory leak in gui_gtk_set_dnd_targets() (9.2.0816). * crash when building a stacktrace during an autocommand (9.2.0817). * tests: client-server test fails without X11 server (9.2.0818). * MS-Windows: sixel image shown as raw text in the console (9.2.0819). * GUI: hidden popup image is displayed and not erased (9.2.0820). * filetype: msmtp system-wide rc file not detected (9.2.0821). * GTK4: crash menu id is null in gui_mch_destroy_menu() (9.2.0822). * tests: Test_clientserver_servlist_list may fail (9.2.0823). * Makefile: make tags depends on configure (9.2.0824). * regexp: submatch in a look-behind is empty with the NFA engine (9.2.0825). * highlighting for broken terminals can be improved (9.2.0826). * :startinsert enters Insert mode in a non-modifiable buffer (9.2.0827). * GTK4: hardware rendering can be improved (9.2.0828). * sessions do not preserve script version for expression options (9.2.0829). * the completion menu is not used on terminals without colors (9.2.0830). * diff highlighting hard to read with syntax enabled (9.2.0831). * socketserver: remote commands can be processed in reverse order (9.2.0832). * GTK4: menu mnemonics do not work properly (9.2.0833). * cleared last search pattern is restored from viminfo (9.2.0834). * features in version.c are not sorted (9.2.0835). * filetype: .git-blame-ignore-revs file is not recognized (9.2.0836). * using wrong colors in hl_blend_attr() (9.2.0837). * searchcount() returns wrong cached maxcount (9.2.0838). * [security]: arbitrary code execution via keyword lookup (9.2.0839). * [security]: code injection in netrw via bookmarks (9.2.0840). * [security]: heap overflow when adding > 65535 text properties (9.2.0841). * [security]: stack buffer overflow in socket server (9.2.0842). * [security]: popup: opacity mask indexed out of bounds (9.2.0843). * [security]: use-after-free on json decode error (9.2.0844). * [security]: arbitrary Ex command execution during C omni-completion (9.2.0845). * [security]: heap buffer overflow in set_sofo() (9.2.0846). * [security]: vimball: code execution via .VimballRecord file (9.2.0847). * tagfunc "cmd" with a generic Ex command corrupts the tag entry (9.2.0848). * filetype: osquery config files are not recognized (9.2.0849). * MS-Windows: commands from a client can be lost (9.2.0850). * focus autocommands triggered inconsistently (9.2.0851). * GTK: ligatures not correctly displayed (9.2.0852). * popup: popup images do not support scaling (9.2.0853). * memory leak when reading a spell file with SN_SAL and SN_SOFO (9.2.0854). * 'showcmd' not redrawn with empty mapping triggered on timeout (9.2.0855). * GTK4: undercurl rendering is inefficient (9.2.0856). * popup: opacity popup over a terminal is not cleared when closed (9.2.0857). * MS-Windows GUI: white flash when VimEnter is slow (9.2.0858). * GTK2: link error (9.2.0859). * filetype: xilinx design constraint files are not recognized (9.2.0860). * GTK4: bleed region updates in jumps (9.2.0861). * missing test change from v9.2.0857 (9.2.0862). * MS-Windows GUI: window contents can be missing when VimEnter is slow (9.2.0863). * using some dead code in Wayland feature (9.2.0864). * GTK4: non-hardware accelerated UI is too slow (9.2.0865). * MS-Windows: ":language messages" only works once (9.2.0866). * MS-Windows: messages are not in the display language (9.2.0867). * GTK: window Manager hint prevents giving focus to dialog (9.2.0868). * buf_copy_options() can lose the P_INSECURE flag (9.2.0869). * filetype: marko files are not recognized (9.2.0870). * screen line is lost when splitting a 'winfixheight' window (9.2.0871). * popup with opacity does not use the font of the highlight group (9.2.0872). * :redrawstatus does not update the ruler of the last window (9.2.0873). * fold size is compared against 'foldminlines' of the wrong window (9.2.0874). * GTK4: GUI does not support command-line arguments (9.2.0875). * GTK4: compile error with disabled netbeans feat (9.2.0876). * Vim9: crash when a closure assigns to a variable declared in a loop (9.2.0877). * Vim9: cannot use a script variable of an enclosing block in a lambda (9.2.0878). * popup: "maxwidth" is not respected when 'wrap' is off (9.2.0879). * scroll: window scrolls when using the autocommand window (9.2.0880). * 'smoothscroll' position is lost when the window height changes (9.2.0881). * :bwipe crashes if WinLeave wipes all other buffers (9.2.0882). * scroll: 'smoothscroll' position is lost when using "|" (9.2.0883). * scroll: unreachable 'smoothscroll' code in cursor_correct() (9.2.0884). * scroll: 'smoothscroll' position is lost when the window is squeezed (9.2.0885). * :set completion works for an invalid sub-option name (9.2.0886). * scroll: jump-scrolling when moving the cursor onto a wrapping line (9.2.0887). * mapping: modifier is not recognized after a partial mapping (9.2.0888). * VMS: spurious "INVALID DECC FEATURE VALUE" message at every startup (9.2.0889). * test: test for patch v9.2.0888 can be clarified (9.2.0890). * MS-Windows: filename-modifier ":8:t" causes underflow (9.2.0891). * highlight: wrong column highlighted with 'cursorcolumn' (9.2.0892). * MS-Windows: "*.vim" also matches files with a longer extension (9.2.0893). * filetype: ed script files not recognised (9.2.0894). * test: Test_aucmd_win_scroll_multibyte() is flaky in the GUI (9.2.0895). * scroll: 'smoothscroll' position is lost when splitting a window (9.2.0896). * GTK3 X11 redraws are not coalesced (9.2.0897). * printing support is lacking (9.2.0898). * command output temporary files may collide (9.2.0899). * FocusGained still triggered when closing dialog (9.2.0900). * textprop: wrong cursor line with truncated virtual text (9.2.0901). * Vim9: iterating over a tuple leaks memory (9.2.0902). * Vim9: cannot use an exported function of an autoload import (9.2.0903). * "zb" scrolls incorrectly with cursor just above fold (9.2.0904). * MS-Windows: ghost cursor with ligatures (9.2.0905). * slow transstr() with long strings (9.2.0906). * popup: virtual text is not redrawn when a text property changes (9.2.0907). * cannot use a {} block in a nested :autocmd (9.2.0908). * insert completion is slow to collect many matches (9.2.0909). * runtime(vim): update syntax, contain Ex commands (9.2.0910). * makefiles do not build hardcopy_postscript.c (9.2.0911). * hardcopy: prototypes are hand-written instead of generated (9.2.0912). * statusline: cell below the vertical separator keeps the old highlight (9.2.0913). * diff: undo after :diffget into an empty buffer leaves a line behind (9.2.0914). * tests: two terminal tests in test_popupwin fail on FreeBSD (9.2.0915). * configure: honor `--disable-hardcopy-pango` with GTK UI (9.2.0916). * :quitall not allowed in the command-line window (9.2.0917). * screen: fill char with a zero low byte is stored as a NUL cell (9.2.0918). * screen: the wrong array is copied into ScreenCols on a resize (9.2.0919). * filetype: json-ld files are not recognized (9.2.0920). * test: terminal tests fail on FreeBSD (9.2.0921). * Wayland: modeless selection not redrawn (9.2.0922). * tabpage: closing a tab page loses the alternate tab page (9.2.0923). * tests: Test_termwinscroll() fails on FreeBSD (9.2.0924). * crash when getcompletiontype() gets a NULL string (9.2.0925). * filetype: business Central files are not recognized (9.2.0926). * curswant not set on 8g8 (9.2.0927). * MinGW: tests hang when Vim is built with coverage enabled (9.2.0928). * incorrect completion for 'pumopt' and 'pumborder' (9.2.0929). * floating point exception when displaying pum (9.2.0930). * the GTK4 GUI is still experimental and untested by CI (9.2.0931). * NFA engine fallback can double free the compiled program (9.2.0932). * u_read_undo() leaks the file name when the undo file owner differs (9.2.0933). * filetype: hlsl files are not recognized (9.2.0934). * reading an undo file is slow with many undo headers (9.2.0935). * stringifying a list or dict can free the item being iterated (9.2.0936). * sort() with a numeric option converts each item on every comparison (9.2.0937). * cursorbind: cursor in the other window is not updated after undo (9.2.0938). * mbyte: wrong cell count for an overlong UTF-8 sequence (9.2.0939). * GTK4: columns are lost when a scrollbar appears (9.2.0940). * tests: clipboard tests fail in the GUI when the terminal has no clipboard (9.2.0941). * test: test_mksession_winpos() fails on GTK4 UI (9.2.0942). * test: test_hardcopy fails on GTK4 UI (9.2.0943). * test: tests fail when checking for GTK4 feature (9.2.0944). * sort() with a numeric option can be improved (9.2.0945). * GTK2/3: mouse move starts Visual selection after a dialog (9.2.0946). * GTK4: screen is cleared when moving the mouse after startup (9.2.0947). * GTK4: mouse move starts Visual selection after a dialog (9.2.0948). * GDK_KEY_VoidSymbol might be undefined (9.2.0949). * transstr() can be improved (after 9.2.0906) (9.2.0950). * GTK3: cursor does no longer blink (9.2.0951). * locking a container while stringifying can be improved (9.2.0952). * insert completion code can be improved (9.2.0953). * u_read_undo() can be improved (after 9.2.0935) (9.2.0954). * tests: terminal tests are flaky (9.2.0955). * GTK4: crash when the window is resized while redrawing (9.2.0956). * filetype: ArgoCD config file is not recognized (9.2.0957). * Allow `wrap` and `linebreak` to be set from a modeline (bsc#1268162). * Point `SYS_VIMRC_FILE` at `$VIMRUNTIME/suse.vimrc` rather than `/etc/vimrc`, which we no longer own (bsc#1268162). * Update `suse.vimrc`: source `/etc/vimrc` at the end of the file, so that a local system vimrc still overrides the distribution defaults. * Guard `suse.vimrc` against re-entry to prevent an infinite sourcing loop (bsc#1271684). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1530 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1530 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * vim-9.2.0957-160000.1.1 * gvim-9.2.0957-160000.1.1 * gvim-debuginfo-9.2.0957-160000.1.1 * vim-debuginfo-9.2.0957-160000.1.1 * xxd-debuginfo-9.2.0957-160000.1.1 * vim-small-9.2.0957-160000.1.1 * vim-debugsource-9.2.0957-160000.1.1 * xxd-9.2.0957-160000.1.1 * vim-small-debuginfo-9.2.0957-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * vim-data-9.2.0957-160000.1.1 * vim-data-common-9.2.0957-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * vim-9.2.0957-160000.1.1 * gvim-9.2.0957-160000.1.1 * gvim-debuginfo-9.2.0957-160000.1.1 * vim-debuginfo-9.2.0957-160000.1.1 * xxd-debuginfo-9.2.0957-160000.1.1 * vim-small-9.2.0957-160000.1.1 * vim-debugsource-9.2.0957-160000.1.1 * xxd-9.2.0957-160000.1.1 * vim-small-debuginfo-9.2.0957-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * vim-data-9.2.0957-160000.1.1 * vim-data-common-9.2.0957-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-73070.html * https://www.suse.com/security/cve/CVE-2026-73071.html * https://www.suse.com/security/cve/CVE-2026-73072.html * https://www.suse.com/security/cve/CVE-2026-73074.html * https://www.suse.com/security/cve/CVE-2026-73075.html * https://www.suse.com/security/cve/CVE-2026-73076.html * https://www.suse.com/security/cve/CVE-2026-73077.html * https://www.suse.com/security/cve/CVE-2026-73078.html * https://bugzilla.suse.com/show_bug.cgi?id=1268162 * https://bugzilla.suse.com/show_bug.cgi?id=1271684 * https://bugzilla.suse.com/show_bug.cgi?id=1275011 * https://bugzilla.suse.com/show_bug.cgi?id=1275012 * https://bugzilla.suse.com/show_bug.cgi?id=1275013 * https://bugzilla.suse.com/show_bug.cgi?id=1275014 * https://bugzilla.suse.com/show_bug.cgi?id=1275015 * https://bugzilla.suse.com/show_bug.cgi?id=1275016 * https://bugzilla.suse.com/show_bug.cgi?id=1275017 * https://bugzilla.suse.com/show_bug.cgi?id=1275018 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:38:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:38:04 -0000 Subject: SUSE-SU-2026:23551-1: critical: Security update for apr-util Message-ID: <178940748411.576.7394825400837773166@5ac198222802> # Security update for apr-util Announcement ID: SUSE-SU-2026:23551-1 Release Date: 2026-08-28T08:23:31Z Rating: critical References: * bsc#1274235 * bsc#1274237 * bsc#1274850 * bsc#1274852 * bsc#1274854 Cross-References: * CVE-2025-49506 * CVE-2026-32327 * CVE-2026-34191 * CVE-2026-34501 * CVE-2026-34502 CVSS scores: * CVE-2025-49506 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-49506 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-32327 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-32327 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-34191 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34191 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-34501 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-34501 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34502 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34502 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for apr-util fixes the following issues: * CVE-2025-49506: hash/password content leak via side channel timing attack against `apr_password_validate()` (bsc#1274237). * CVE-2026-32327: XML stack recursion crash (bsc#1274235). * CVE-2026-34191: SQL injection via `apr_dbd_oracle` (bsc#1274850). * CVE-2026-34501: heap buffer overflow in redis client (bsc#1274852). * CVE-2026-34502: heap buffer overflow in APR memcached client (bsc#1274854). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1531 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1531 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * apr-util-debugsource-1.6.3-160000.3.1 * libapr-util1-0-1.6.3-160000.3.1 * libapr-util1-0-dbd-mysql-1.6.3-160000.3.1 * apr-util-devel-1.6.3-160000.3.1 * libapr-util1-0-dbd-pgsql-1.6.3-160000.3.1 * libapr-util1-0-dbd-sqlite3-debuginfo-1.6.3-160000.3.1 * libapr-util1-0-debuginfo-1.6.3-160000.3.1 * libapr-util1-0-dbd-mysql-debuginfo-1.6.3-160000.3.1 * apr-util-debuginfo-1.6.3-160000.3.1 * libapr-util1-0-dbd-sqlite3-1.6.3-160000.3.1 * libapr-util1-0-dbd-pgsql-debuginfo-1.6.3-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * apr-util-debugsource-1.6.3-160000.3.1 * libapr-util1-0-1.6.3-160000.3.1 * libapr-util1-0-dbd-mysql-1.6.3-160000.3.1 * apr-util-devel-1.6.3-160000.3.1 * libapr-util1-0-dbd-pgsql-1.6.3-160000.3.1 * libapr-util1-0-dbd-sqlite3-debuginfo-1.6.3-160000.3.1 * libapr-util1-0-debuginfo-1.6.3-160000.3.1 * libapr-util1-0-dbd-mysql-debuginfo-1.6.3-160000.3.1 * apr-util-debuginfo-1.6.3-160000.3.1 * libapr-util1-0-dbd-sqlite3-1.6.3-160000.3.1 * libapr-util1-0-dbd-pgsql-debuginfo-1.6.3-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49506.html * https://www.suse.com/security/cve/CVE-2026-32327.html * https://www.suse.com/security/cve/CVE-2026-34191.html * https://www.suse.com/security/cve/CVE-2026-34501.html * https://www.suse.com/security/cve/CVE-2026-34502.html * https://bugzilla.suse.com/show_bug.cgi?id=1274235 * https://bugzilla.suse.com/show_bug.cgi?id=1274237 * https://bugzilla.suse.com/show_bug.cgi?id=1274850 * https://bugzilla.suse.com/show_bug.cgi?id=1274852 * https://bugzilla.suse.com/show_bug.cgi?id=1274854 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:38:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:38:43 -0000 Subject: SUSE-SU-2026:23550-1: moderate: Security update for gzip Message-ID: <178940752388.576.17184981962783029236@5ac198222802> # Security update for gzip Announcement ID: SUSE-SU-2026:23550-1 Release Date: 2026-08-27T12:52:38Z Rating: moderate References: * bsc#1269623 * bsc#1272554 Cross-References: * CVE-2026-41992 CVSS scores: * CVE-2026-41992 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-41992 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H * CVE-2026-41992 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41992 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability and has one fix can now be installed. ## Description: This update for gzip fixes the following issues: * CVE-2026-41992: global buffer overflow in the LZH decompression logic due to improper reuse of shared global state between different decompression formats within a single execution (bsc#1269623, bsc#1272554). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1529 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1529 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * gzip-1.13-160000.4.1 * gzip-debuginfo-1.13-160000.4.1 * gzip-debugsource-1.13-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * gzip-1.13-160000.4.1 * gzip-debuginfo-1.13-160000.4.1 * gzip-debugsource-1.13-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41992.html * https://bugzilla.suse.com/show_bug.cgi?id=1269623 * https://bugzilla.suse.com/show_bug.cgi?id=1272554 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:39:48 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:39:48 -0000 Subject: SUSE-SU-2026:23548-1: important: Security update for google-osconfig-agent Message-ID: <178940758808.576.2118478762419580581@5ac198222802> # Security update for google-osconfig-agent Announcement ID: SUSE-SU-2026:23548-1 Release Date: 2026-09-10T08:34:51Z Rating: important References: * bsc#1272118 * bsc#1278967 * bsc#1279297 * bsc#1279414 Cross-References: * CVE-2026-39821 * CVE-2026-56852 * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for google-osconfig-agent fixes the following issues: This update for google-osconfig-agent fixes the following issues: * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272118). * CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279297). * CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279414). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278967). Changes for google-osconfig-agent: * Update to version 20260908.00 * Migrate presubmits from deb11 to deb12 (#1050) * Bump the go_modules group across 1 directory with 3 updates (#1047) * Introduce E2E v2 framework and inventory tests (#1039) * Remove test case for asserting JSON marshal error from task_state.go (#1045) * security: pin GitHub actions to commit SHAs in CodeQL workflow (#1042) * Add Configuration for SCALIBR (#1034) * add CheckState and Cleanup tests (#1008) * Improve unit tests for osinfo/osinfo_linux.go (#1020) * Bump github.com/go-git/go-git/v5 (#1036) * Bump cloud.google.com/go/auth from 0.18.0 to 0.22.0 (#1032) * Bump golang.org/x/crypto from 0.52.0 to 0.54.0 (#1028) * authenticate cloud build to use docker registry (#1030) * Migrate e2e build to internal image (#1024) * Upgrade google.golang.org/grpc to new version. (#1023) * Improve unit tests for ospatch/yum_update.go (#1012) * Improve unit tests for ospatch/updates.go (#1011) * Add unit tests for config/package_resource.go PART 2 (#1005) * Add unit tests for config/package_resource.go PART 1 (#1003) * Add unit tests for policies/local.go (#1015) * Add unit tests for repository_resource.go (#1002) * Add unit tests for installrecipe.go part 2 (#993) * Add unit tests for scalibr.go (#1019) * Add unit tests for installrecipe.go part 1 (#992) * Add test cases for policies/recipes/recipedb.go (#989) * Bump golang.org/x/crypto (#1021) * Add unit tests for policies/recipes/steps.go PART 3 (#976) * Add unit tests for policies/recipes/steps.go PART 2 (#975) * Bump golang.org/x/net (#1017) * upgrade x/net package. (#1018) * Add test cases for config/file_resource.go (#988) * Add unit tests for policies/recipes/artifacts.go (#985) * Add unit tests for policies/recipes/steps.go PART 1 (#974) * Add tests & bugfix for packages/trace.go (#939) * Add unit tests for agentendpoint/agentendpoint_beta.go (#983) * Replace yum install with yum update (#1009) * Bump github.com/containerd/containerd (#1013) * Add unit tests for policies/apt.go PART 2 (#957) * Add test cases for agentendpoint/task_state.go (#984) * Remove deprecated rhel-sap images and add new ones (#1007) * Add test cases for clog/clog.go (#986) * Use explicit upstream GitHub homepage in URL field ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-891 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * google-osconfig-agent-20260908.00-1.1 * google-osconfig-agent-debuginfo-20260908.00-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1272118 * https://bugzilla.suse.com/show_bug.cgi?id=1278967 * https://bugzilla.suse.com/show_bug.cgi?id=1279297 * https://bugzilla.suse.com/show_bug.cgi?id=1279414 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:40:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:40:33 -0000 Subject: SUSE-SU-2026:23547-1: critical: Security update for libzypp, zypper Message-ID: <178940763372.576.14369592516093570048@5ac198222802> # Security update for libzypp, zypper Announcement ID: SUSE-SU-2026:23547-1 Release Date: 2026-09-09T13:02:55Z Rating: critical References: * bsc#1257249 * bsc#1271730 * bsc#1272534 * bsc#1273242 * bsc#1274091 * bsc#1274625 * bsc#1277790 Affected Products: * SUSE Linux Micro 6.0 An update that has seven fixes can now be installed. ## Description: This update for libzypp, zypper fixes the following issues: Security issue fixed: * invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY- CACHE-01] (bsc#1274625). * hasCredentials() requires both username AND password to be non-empty (bsc#1273242). * GPG Key hints in repoindex.xml require at least a long id to allow auto- import (bsc#1271730). Non security issues fixed: * Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). * Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). * zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). * Zypper patch doesn't give enough details about conflicts (bsc#1277790). Changes for libzypp: * Update to version 17.38.15: * Prevent libgpgme from launching gpg-agents; we don't need them. * defaultLoadSystem: Hand out the ZYpp::Ptr as return value. * Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) * zypp: Improve Testcase Loading for MCP Tools. * spec: Remove useless %bcond visibility_hidden (is always ON in cmake) Changes for zypper: * Update to version 1.14.101. ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-890 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * zypper-debuginfo-1.14.101-1.1 * libzypp-debugsource-17.38.15-1.1 * libzypp-17.38.15-1.1 * zypper-1.14.101-1.1 * libzypp-debuginfo-17.38.15-1.1 * zypper-debugsource-1.14.101-1.1 * SUSE Linux Micro 6.0 (noarch) * zypper-needs-restarting-1.14.101-1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1257249 * https://bugzilla.suse.com/show_bug.cgi?id=1271730 * https://bugzilla.suse.com/show_bug.cgi?id=1272534 * https://bugzilla.suse.com/show_bug.cgi?id=1273242 * https://bugzilla.suse.com/show_bug.cgi?id=1274091 * https://bugzilla.suse.com/show_bug.cgi?id=1274625 * https://bugzilla.suse.com/show_bug.cgi?id=1277790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:41:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:41:15 -0000 Subject: SUSE-SU-2026:23546-1: important: Security update for helm Message-ID: <178940767506.576.13777280081518342560@5ac198222802> # Security update for helm Announcement ID: SUSE-SU-2026:23546-1 Release Date: 2026-09-09T12:04:57Z Rating: important References: * bsc#1278270 * bsc#1278273 * bsc#1278688 Cross-References: * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for helm fixes the following issues: * CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1278270). * CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1278273). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing `:authority` and `Host` headers in gRPC-Go xDS servers (bsc#1278688). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-889 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * helm-3.21.3-3.1 * helm-debuginfo-3.21.3-3.1 * SUSE Linux Micro 6.0 (noarch) * helm-bash-completion-3.21.3-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1278270 * https://bugzilla.suse.com/show_bug.cgi?id=1278273 * https://bugzilla.suse.com/show_bug.cgi?id=1278688 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:42:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:42:22 -0000 Subject: SUSE-SU-2026:4172-1: important: Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise 15 SP7) Message-ID: <178940774234.576.1262252857238401017@5ac198222802> # Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:4172-1 Release Date: 2026-09-14T10:03:54Z Rating: important References: * bsc#1271543 * bsc#1271867 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-64530 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-64600 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64530 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64530 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64600 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64600 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64600 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.67 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64530: net/sched: cls_api: Handle TC_ACT_CONSUMED in tcf_qevent_hand (bsc#1271867). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-64600: xfs: resample the data fork mapping after cycling ILOCK (RefluXFS) (bsc#1271543). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-4172 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_67-rt-2-150700.2.1 * kernel-livepatch-6_4_0-150700_7_67-rt-debuginfo-2-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_18-debugsource-2-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64530.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-64600.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1271543 * https://bugzilla.suse.com/show_bug.cgi?id=1271867 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:43:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:43:06 -0000 Subject: SUSE-SU-2026:4170-1: important: Security update for the Linux Kernel RT (Live Patch 17 for SUSE Linux Enterprise 15 SP7) Message-ID: <178940778645.576.439631109734039185@5ac198222802> # Security update for the Linux Kernel RT (Live Patch 17 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:4170-1 Release Date: 2026-09-14T09:34:37Z Rating: important References: * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.62 fixes various security issues: The following security issues were fixed: * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-4170 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_62-rt-4-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_17-debugsource-4-150700.2.1 * kernel-livepatch-6_4_0-150700_7_62-rt-debuginfo-4-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:43:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:43:46 -0000 Subject: SUSE-SU-2026:4168-1: important: Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise 15 SP7) Message-ID: <178940782676.576.2743779337484586988@5ac198222802> # Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:4168-1 Release Date: 2026-09-14T09:34:28Z Rating: important References: * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.72 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-4168 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_72-rt-debuginfo-2-150700.2.1 * kernel-livepatch-6_4_0-150700_7_72-rt-2-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_19-debugsource-2-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:44:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:44:32 -0000 Subject: SUSE-SU-2026:4162-1: important: Security update for the Linux Kernel RT (Live Patch 16 for SUSE Linux Enterprise 15 SP7) Message-ID: <178940787216.576.12868707099031463378@5ac198222802> # Security update for the Linux Kernel RT (Live Patch 16 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:4162-1 Release Date: 2026-09-14T10:03:58Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.7.59 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-4162 SUSE-SLE- Module-Live-Patching-15-SP7-2026-4171 SUSE-SLE-Module-Live- Patching-15-SP7-2026-4157 SUSE-SLE-Module-Live-Patching-15-SP7-2026-4163 SUSE- SLE-Module-Live-Patching-15-SP7-2026-4173 SUSE-SLE-Module-Live- Patching-15-SP7-2026-4160 SUSE-SLE-Module-Live-Patching-15-SP7-2026-4161 SUSE- SLE-Module-Live-Patching-15-SP7-2026-4169 SUSE-SLE-Module-Live- Patching-15-SP7-2026-4166 SUSE-SLE-Module-Live-Patching-15-SP7-2026-4158 SUSE- SLE-Module-Live-Patching-15-SP7-2026-4159 SUSE-SLE-Module-Live- Patching-15-SP7-2026-4164 SUSE-SLE-Module-Live-Patching-15-SP7-2026-4165 SUSE- SLE-Module-Live-Patching-15-SP7-2026-4167 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (x86_64) * kernel-livepatch-6_4_0-150700_7_59-rt-5-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_6-debugsource-13-150700.2.1 * kernel-livepatch-6_4_0-150700_7_19-rt-debuginfo-14-150700.2.1 * kernel-livepatch-6_4_0-150700_7_34-rt-debuginfo-9-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_15-debugsource-5-150700.2.1 * kernel-livepatch-6_4_0-150700_7_13-rt-17-150700.2.1 * kernel-livepatch-6_4_0-150700_7_13-rt-debuginfo-17-150700.2.1 * kernel-livepatch-6_4_0-150700_7_40-rt-debuginfo-8-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_16-debugsource-5-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_12-debugsource-8-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_5-debugsource-14-150700.2.1 * kernel-livepatch-6_4_0-150700_7_37-rt-9-150700.2.1 * kernel-livepatch-6_4_0-150700_7_37-rt-debuginfo-9-150700.2.1 * kernel-livepatch-6_4_0-150700_7_19-rt-14-150700.2.1 * kernel-livepatch-6_4_0-150700_7_31-rt-11-150700.2.1 * kernel-livepatch-6_4_0-150700_7_54-rt-debuginfo-5-150700.2.1 * kernel-livepatch-6_4_0-150700_7_25-rt-12-150700.2.1 * kernel-livepatch-6_4_0-150700_7_44-rt-debuginfo-7-150700.2.1 * kernel-livepatch-6_4_0-150700_7_28-rt-12-150700.2.1 * kernel-livepatch-6_4_0-150700_7_28-rt-debuginfo-12-150700.2.1 * kernel-livepatch-6_4_0-150700_7_31-rt-debuginfo-11-150700.2.1 * kernel-livepatch-6_4_0-150700_7_40-rt-8-150700.2.1 * kernel-livepatch-6_4_0-150700_7_54-rt-5-150700.2.1 * kernel-livepatch-6_4_0-150700_7_25-rt-debuginfo-12-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_7-debugsource-12-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_13-debugsource-7-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_4-debugsource-17-150700.2.1 * kernel-livepatch-6_4_0-150700_7_59-rt-debuginfo-5-150700.2.1 * kernel-livepatch-6_4_0-150700_7_34-rt-9-150700.2.1 * kernel-livepatch-6_4_0-150700_7_51-rt-debuginfo-6-150700.2.1 * kernel-livepatch-6_4_0-150700_7_22-rt-debuginfo-13-150700.2.1 * kernel-livepatch-6_4_0-150700_7_16-rt-debuginfo-17-150700.2.1 * kernel-livepatch-6_4_0-150700_7_51-rt-6-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_8-debugsource-12-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_10-debugsource-9-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_14-debugsource-6-150700.2.1 * kernel-livepatch-6_4_0-150700_7_44-rt-7-150700.2.1 * kernel-livepatch-6_4_0-150700_7_22-rt-13-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_9-debugsource-11-150700.2.1 * kernel-livepatch-6_4_0-150700_7_16-rt-17-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_3-debugsource-17-150700.2.1 * kernel-livepatch-SLE15-SP7-RT_Update_11-debugsource-9-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:45:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:45:11 -0000 Subject: SUSE-SU-2026:4176-1: important: Security update for acl, attr Message-ID: <178940791112.576.2798582272352132370@5ac198222802> # Security update for acl, attr Announcement ID: SUSE-SU-2026:4176-1 Release Date: 2026-09-14T10:30:57Z Rating: important References: * bsc#1268867 * jsc#PED-16501 Cross-References: * CVE-2026-54369 * CVE-2026-54370 * CVE-2026-54371 CVSS scores: * CVE-2026-54369 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-54369 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54369 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54369 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54369 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54370 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-54370 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54370 ( NVD ): 7.2 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54370 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54371 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-54371 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54371 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54371 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54371 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities and contains one feature can now be installed. ## Description: This update for acl, attr fixes the following issue: * CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: * Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: * The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. * When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. * When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. * When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: * When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ("Too many levels of symbolic links") error will result instead. * acl_delete_entry() now verifies that the specified entry belongs to the specified acl. * Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. * Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. * When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. * setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. * setfacl --restore accidentally called chmod() when in --test mode. It no longer does. * When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. * When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. * The -h (--no-dereference) option of getfattr prevented getfattr from recursing into "symbolic link directories". This is wrong. When dirlink is a symbolic link that refers to a directory, "getfattr -Rh dirlink" will now visit that directory. The -P (--physical) option can be used to prevent that. * Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: * Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: * The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. * When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. * When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. * When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: * When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ("Too many levels of symbolic links") error will result instead. * acl_delete_entry() now verifies that the specified entry belongs to the specified acl. * Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. * Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. * When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. * setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. * setfacl --restore accidentally called chmod() when in --test mode. It no longer does. * When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. * When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. * The -h (--no-dereference) option of getfattr prevented getfattr from recursing into "symbolic link directories". This is wrong. When dirlink is a symbolic link that refers to a directory, "getfattr -Rh dirlink" will now visit that directory. The -P (--physical) option can be used to prevent that. * Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent * update to 2.5.2: * attr: eliminate a dead store in attr_copy_action() * libattr: Set symbol versions for legacy syscalls via attribute or asm * exports: use LGPL for library code * documentation updates * translation updates (Polish, Dutch, Gregorian, French) * build system updates ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4176 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4176 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4176 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4176 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4176 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4176 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4176 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4176 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4176 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4176 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4176 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4176 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4176 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4176 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4176 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4176 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libattr-devel-2.6.0-150000.4.3.1 * libacl1-2.4.0-150000.4.6.1 * libattr1-2.6.0-150000.4.3.1 * libattr1-debuginfo-2.6.0-150000.4.3.1 * libacl-devel-2.4.0-150000.4.6.1 * attr-debugsource-2.6.0-150000.4.3.1 * attr-2.6.0-150000.4.3.1 * acl-debugsource-2.4.0-150000.4.6.1 * acl-debuginfo-2.4.0-150000.4.6.1 * attr-debuginfo-2.6.0-150000.4.3.1 * acl-2.4.0-150000.4.6.1 * libacl1-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * libattr1-32bit-debuginfo-2.6.0-150000.4.3.1 * libacl1-32bit-2.4.0-150000.4.6.1 * libattr1-32bit-2.6.0-150000.4.3.1 * libacl1-32bit-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libattr-devel-2.6.0-150000.4.3.1 * libacl1-2.4.0-150000.4.6.1 * libattr1-2.6.0-150000.4.3.1 * libattr1-debuginfo-2.6.0-150000.4.3.1 * libacl-devel-2.4.0-150000.4.6.1 * attr-debugsource-2.6.0-150000.4.3.1 * attr-2.6.0-150000.4.3.1 * acl-debugsource-2.4.0-150000.4.6.1 * acl-debuginfo-2.4.0-150000.4.6.1 * attr-debuginfo-2.6.0-150000.4.3.1 * acl-2.4.0-150000.4.6.1 * libacl1-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * libattr1-32bit-debuginfo-2.6.0-150000.4.3.1 * libacl1-32bit-2.4.0-150000.4.6.1 * libattr1-32bit-2.6.0-150000.4.3.1 * libacl1-32bit-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libattr-devel-2.6.0-150000.4.3.1 * libacl1-2.4.0-150000.4.6.1 * libattr1-2.6.0-150000.4.3.1 * libattr1-debuginfo-2.6.0-150000.4.3.1 * libacl-devel-2.4.0-150000.4.6.1 * attr-debugsource-2.6.0-150000.4.3.1 * attr-2.6.0-150000.4.3.1 * acl-debugsource-2.4.0-150000.4.6.1 * acl-debuginfo-2.4.0-150000.4.6.1 * attr-debuginfo-2.6.0-150000.4.3.1 * acl-2.4.0-150000.4.6.1 * libacl1-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * libattr1-32bit-debuginfo-2.6.0-150000.4.3.1 * libacl1-32bit-2.4.0-150000.4.6.1 * libattr1-32bit-2.6.0-150000.4.3.1 * libacl1-32bit-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libacl1-2.4.0-150000.4.6.1 * libattr1-2.6.0-150000.4.3.1 * libattr1-debuginfo-2.6.0-150000.4.3.1 * attr-debugsource-2.6.0-150000.4.3.1 * attr-2.6.0-150000.4.3.1 * acl-debugsource-2.4.0-150000.4.6.1 * acl-debuginfo-2.4.0-150000.4.6.1 * attr-debuginfo-2.6.0-150000.4.3.1 * acl-2.4.0-150000.4.6.1 * libacl1-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libacl1-2.4.0-150000.4.6.1 * libattr1-2.6.0-150000.4.3.1 * libattr1-debuginfo-2.6.0-150000.4.3.1 * attr-debugsource-2.6.0-150000.4.3.1 * attr-2.6.0-150000.4.3.1 * acl-debugsource-2.4.0-150000.4.6.1 * acl-debuginfo-2.4.0-150000.4.6.1 * attr-debuginfo-2.6.0-150000.4.3.1 * acl-2.4.0-150000.4.6.1 * libacl1-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libattr-devel-2.6.0-150000.4.3.1 * libacl1-2.4.0-150000.4.6.1 * libattr1-2.6.0-150000.4.3.1 * libattr1-debuginfo-2.6.0-150000.4.3.1 * libacl-devel-2.4.0-150000.4.6.1 * attr-debugsource-2.6.0-150000.4.3.1 * attr-2.6.0-150000.4.3.1 * acl-debugsource-2.4.0-150000.4.6.1 * acl-debuginfo-2.4.0-150000.4.6.1 * attr-debuginfo-2.6.0-150000.4.3.1 * acl-2.4.0-150000.4.6.1 * libacl1-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * libattr1-32bit-debuginfo-2.6.0-150000.4.3.1 * libacl1-32bit-2.4.0-150000.4.6.1 * libattr1-32bit-2.6.0-150000.4.3.1 * libacl1-32bit-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libattr-devel-2.6.0-150000.4.3.1 * libacl1-2.4.0-150000.4.6.1 * libattr1-2.6.0-150000.4.3.1 * libattr1-debuginfo-2.6.0-150000.4.3.1 * libacl-devel-2.4.0-150000.4.6.1 * attr-debugsource-2.6.0-150000.4.3.1 * attr-2.6.0-150000.4.3.1 * acl-debugsource-2.4.0-150000.4.6.1 * acl-debuginfo-2.4.0-150000.4.6.1 * attr-debuginfo-2.6.0-150000.4.3.1 * acl-2.4.0-150000.4.6.1 * libacl1-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * libattr1-32bit-debuginfo-2.6.0-150000.4.3.1 * libacl1-32bit-2.4.0-150000.4.6.1 * libattr1-32bit-2.6.0-150000.4.3.1 * libacl1-32bit-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libattr-devel-2.6.0-150000.4.3.1 * libacl1-2.4.0-150000.4.6.1 * libattr1-2.6.0-150000.4.3.1 * libattr1-debuginfo-2.6.0-150000.4.3.1 * libacl-devel-2.4.0-150000.4.6.1 * attr-debugsource-2.6.0-150000.4.3.1 * attr-2.6.0-150000.4.3.1 * acl-debugsource-2.4.0-150000.4.6.1 * acl-debuginfo-2.4.0-150000.4.6.1 * attr-debuginfo-2.6.0-150000.4.3.1 * acl-2.4.0-150000.4.6.1 * libacl1-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * libattr1-32bit-debuginfo-2.6.0-150000.4.3.1 * libacl1-32bit-2.4.0-150000.4.6.1 * libattr1-32bit-2.6.0-150000.4.3.1 * libacl1-32bit-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libacl1-2.4.0-150000.4.6.1 * libattr1-2.6.0-150000.4.3.1 * libattr1-debuginfo-2.6.0-150000.4.3.1 * attr-debugsource-2.6.0-150000.4.3.1 * attr-2.6.0-150000.4.3.1 * acl-debugsource-2.4.0-150000.4.6.1 * acl-debuginfo-2.4.0-150000.4.6.1 * attr-debuginfo-2.6.0-150000.4.3.1 * acl-2.4.0-150000.4.6.1 * libacl1-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libacl1-2.4.0-150000.4.6.1 * libattr1-2.6.0-150000.4.3.1 * libattr1-debuginfo-2.6.0-150000.4.3.1 * attr-debugsource-2.6.0-150000.4.3.1 * attr-2.6.0-150000.4.3.1 * acl-debugsource-2.4.0-150000.4.6.1 * acl-debuginfo-2.4.0-150000.4.6.1 * attr-debuginfo-2.6.0-150000.4.3.1 * acl-2.4.0-150000.4.6.1 * libacl1-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libattr-devel-2.6.0-150000.4.3.1 * libacl1-2.4.0-150000.4.6.1 * libattr1-2.6.0-150000.4.3.1 * libattr1-debuginfo-2.6.0-150000.4.3.1 * libacl-devel-2.4.0-150000.4.6.1 * attr-debugsource-2.6.0-150000.4.3.1 * attr-2.6.0-150000.4.3.1 * acl-debugsource-2.4.0-150000.4.6.1 * acl-debuginfo-2.4.0-150000.4.6.1 * attr-debuginfo-2.6.0-150000.4.3.1 * acl-2.4.0-150000.4.6.1 * libacl1-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libattr1-32bit-debuginfo-2.6.0-150000.4.3.1 * libacl1-32bit-2.4.0-150000.4.6.1 * libattr1-32bit-2.6.0-150000.4.3.1 * libacl1-32bit-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libacl1-2.4.0-150000.4.6.1 * libattr1-2.6.0-150000.4.3.1 * libattr1-debuginfo-2.6.0-150000.4.3.1 * attr-debugsource-2.6.0-150000.4.3.1 * attr-2.6.0-150000.4.3.1 * acl-debugsource-2.4.0-150000.4.6.1 * acl-debuginfo-2.4.0-150000.4.6.1 * attr-debuginfo-2.6.0-150000.4.3.1 * acl-2.4.0-150000.4.6.1 * libacl1-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libattr-devel-2.6.0-150000.4.3.1 * libacl1-2.4.0-150000.4.6.1 * libattr1-2.6.0-150000.4.3.1 * libattr1-debuginfo-2.6.0-150000.4.3.1 * libacl-devel-2.4.0-150000.4.6.1 * attr-debugsource-2.6.0-150000.4.3.1 * attr-2.6.0-150000.4.3.1 * acl-debugsource-2.4.0-150000.4.6.1 * acl-debuginfo-2.4.0-150000.4.6.1 * attr-debuginfo-2.6.0-150000.4.3.1 * acl-2.4.0-150000.4.6.1 * libacl1-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * libattr1-32bit-debuginfo-2.6.0-150000.4.3.1 * libacl1-32bit-2.4.0-150000.4.6.1 * libattr1-32bit-2.6.0-150000.4.3.1 * libacl1-32bit-debuginfo-2.4.0-150000.4.6.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libattr-devel-2.6.0-150000.4.3.1 * libacl1-2.4.0-150000.4.6.1 * libattr1-2.6.0-150000.4.3.1 * libattr1-debuginfo-2.6.0-150000.4.3.1 * libacl-devel-2.4.0-150000.4.6.1 * attr-debugsource-2.6.0-150000.4.3.1 * attr-2.6.0-150000.4.3.1 * acl-debugsource-2.4.0-150000.4.6.1 * acl-debuginfo-2.4.0-150000.4.6.1 * attr-debuginfo-2.6.0-150000.4.3.1 * acl-2.4.0-150000.4.6.1 * libacl1-debuginfo-2.4.0-150000.4.6.1 * Basesystem Module 15-SP7 (x86_64) * libattr1-32bit-debuginfo-2.6.0-150000.4.3.1 * libacl1-32bit-2.4.0-150000.4.6.1 * libattr1-32bit-2.6.0-150000.4.3.1 * libacl1-32bit-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libattr-devel-2.6.0-150000.4.3.1 * libacl1-2.4.0-150000.4.6.1 * libattr1-2.6.0-150000.4.3.1 * libattr1-debuginfo-2.6.0-150000.4.3.1 * libacl-devel-2.4.0-150000.4.6.1 * attr-debugsource-2.6.0-150000.4.3.1 * attr-2.6.0-150000.4.3.1 * acl-debugsource-2.4.0-150000.4.6.1 * acl-debuginfo-2.4.0-150000.4.6.1 * attr-debuginfo-2.6.0-150000.4.3.1 * acl-2.4.0-150000.4.6.1 * libacl1-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * libattr1-32bit-debuginfo-2.6.0-150000.4.3.1 * libacl1-32bit-2.4.0-150000.4.6.1 * libattr1-32bit-2.6.0-150000.4.3.1 * libacl1-32bit-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libattr-devel-2.6.0-150000.4.3.1 * libacl1-2.4.0-150000.4.6.1 * libattr1-2.6.0-150000.4.3.1 * libattr1-debuginfo-2.6.0-150000.4.3.1 * libacl-devel-2.4.0-150000.4.6.1 * attr-debugsource-2.6.0-150000.4.3.1 * attr-2.6.0-150000.4.3.1 * acl-debugsource-2.4.0-150000.4.6.1 * acl-debuginfo-2.4.0-150000.4.6.1 * attr-debuginfo-2.6.0-150000.4.3.1 * acl-2.4.0-150000.4.6.1 * libacl1-debuginfo-2.4.0-150000.4.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libattr1-32bit-debuginfo-2.6.0-150000.4.3.1 * libacl1-32bit-2.4.0-150000.4.6.1 * libattr1-32bit-2.6.0-150000.4.3.1 * libacl1-32bit-debuginfo-2.4.0-150000.4.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54369.html * https://www.suse.com/security/cve/CVE-2026-54370.html * https://www.suse.com/security/cve/CVE-2026-54371.html * https://bugzilla.suse.com/show_bug.cgi?id=1268867 * https://jira.suse.com/browse/PED-16501 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:45:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:45:55 -0000 Subject: SUSE-SU-2026:4175-1: important: Security update for helm Message-ID: <178940795553.576.14849856929565158947@5ac198222802> # Security update for helm Announcement ID: SUSE-SU-2026:4175-1 Release Date: 2026-09-14T10:28:52Z Rating: important References: * bsc#1276644 * bsc#1277949 * bsc#1278270 * bsc#1278273 * bsc#1278688 Cross-References: * CVE-2026-37236 * CVE-2026-41178 * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-37236 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-37236 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-37236 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Containers Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves five vulnerabilities can now be installed. ## Description: This update for helm fixes the following issues: * CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST request through the X-HTTP-Method- Override header and bypass established access control (bsc#1277949). * CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276644). * CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1278270). * CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1278273). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing `:authority` and `Host` headers in gRPC-Go xDS servers (bsc#1278688). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4175 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4175 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4175 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4175 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4175 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4175 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4175 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4175 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4175 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-4175 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4175 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4175 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4175 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * helm-3.21.3-150000.1.96.1 * helm-debuginfo-3.21.3-150000.1.96.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * helm-zsh-completion-3.21.3-150000.1.96.1 * helm-bash-completion-3.21.3-150000.1.96.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * helm-3.21.3-150000.1.96.1 * helm-debuginfo-3.21.3-150000.1.96.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * helm-zsh-completion-3.21.3-150000.1.96.1 * helm-bash-completion-3.21.3-150000.1.96.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * helm-3.21.3-150000.1.96.1 * helm-debuginfo-3.21.3-150000.1.96.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * helm-zsh-completion-3.21.3-150000.1.96.1 * helm-bash-completion-3.21.3-150000.1.96.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * helm-3.21.3-150000.1.96.1 * helm-debuginfo-3.21.3-150000.1.96.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * helm-zsh-completion-3.21.3-150000.1.96.1 * helm-bash-completion-3.21.3-150000.1.96.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * helm-3.21.3-150000.1.96.1 * helm-debuginfo-3.21.3-150000.1.96.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * helm-zsh-completion-3.21.3-150000.1.96.1 * helm-bash-completion-3.21.3-150000.1.96.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * helm-3.21.3-150000.1.96.1 * helm-debuginfo-3.21.3-150000.1.96.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * helm-zsh-completion-3.21.3-150000.1.96.1 * helm-bash-completion-3.21.3-150000.1.96.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * helm-3.21.3-150000.1.96.1 * helm-debuginfo-3.21.3-150000.1.96.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * helm-zsh-completion-3.21.3-150000.1.96.1 * helm-bash-completion-3.21.3-150000.1.96.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * helm-3.21.3-150000.1.96.1 * helm-debuginfo-3.21.3-150000.1.96.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * helm-bash-completion-3.21.3-150000.1.96.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * helm-3.21.3-150000.1.96.1 * helm-debuginfo-3.21.3-150000.1.96.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * helm-zsh-completion-3.21.3-150000.1.96.1 * helm-bash-completion-3.21.3-150000.1.96.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * helm-3.21.3-150000.1.96.1 * helm-debuginfo-3.21.3-150000.1.96.1 * Containers Module 15-SP7 (noarch) * helm-zsh-completion-3.21.3-150000.1.96.1 * helm-bash-completion-3.21.3-150000.1.96.1 * SUSE Package Hub 15 15-SP7 (noarch) * helm-fish-completion-3.21.3-150000.1.96.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * helm-3.21.3-150000.1.96.1 * helm-debuginfo-3.21.3-150000.1.96.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * helm-zsh-completion-3.21.3-150000.1.96.1 * helm-bash-completion-3.21.3-150000.1.96.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * helm-3.21.3-150000.1.96.1 * helm-debuginfo-3.21.3-150000.1.96.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * helm-zsh-completion-3.21.3-150000.1.96.1 * helm-bash-completion-3.21.3-150000.1.96.1 ## References: * https://www.suse.com/security/cve/CVE-2026-37236.html * https://www.suse.com/security/cve/CVE-2026-41178.html * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1276644 * https://bugzilla.suse.com/show_bug.cgi?id=1277949 * https://bugzilla.suse.com/show_bug.cgi?id=1278270 * https://bugzilla.suse.com/show_bug.cgi?id=1278273 * https://bugzilla.suse.com/show_bug.cgi?id=1278688 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:46:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:46:51 -0000 Subject: SUSE-SU-2026:4174-1: important: Security update for python39.SUSE_SLE-15-SP3_Update Message-ID: <178940801108.576.9895612362509028782@5ac198222802> # Security update for python39.SUSE_SLE-15-SP3_Update Announcement ID: SUSE-SU-2026:4174-1 Release Date: 2026-09-14T10:26:53Z Rating: important References: * bsc#1211301 * bsc#1262429 * bsc#1267581 * bsc#1267821 * bsc#1269066 * bsc#1269788 * bsc#1269959 * bsc#1271192 * bsc#1273090 * bsc#1273091 * bsc#1273094 * bsc#1274743 * bsc#1276903 * bsc#1277271 Cross-References: * CVE-2026-0864 * CVE-2026-11972 * CVE-2026-13346 * CVE-2026-15308 * CVE-2026-1703 * CVE-2026-3219 * CVE-2026-3276 * CVE-2026-4360 * CVE-2026-7774 CVSS scores: * CVE-2026-0864 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0864 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0864 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11972 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11972 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-15308 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15308 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3276 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3276 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4360 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4360 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-7774 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-7774 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves nine vulnerabilities and has five security fixes can now be installed. ## Description: This update for python39.SUSE_SLE-15-SP3_Update fixes the following issues: Security issues fixed: * CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066). * CVE-2026-1703: files may be extracted outside the installation directory when installing and extracting maliciously crafted wheel archives (bsc#1274743). * CVE-2026-3219: pip doesn't reject concatenated ZIP (bsc#1262429). * CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted Unicode input (bsc#1267581). * CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959). * CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory (bsc#1267821). * CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788). * CVE-2026-13346: Arbitrary file installation via malicious package indexes (bsc#1273090 bsc#1273091 bsc#1273094). * CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192). Non security issues fixed: * crypto-policies: Extend the crypto-policies support for mozilla-nss, openjdk, krb5, bind, stunnel, openssh, libssh and more packages (bsc#1211301). * Update bundled pip wheels to pip-20.0.2-py2.py3-none-any.whl ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-4174 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4174 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4174 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * libpython3_9-1_0-3.9.25-150300.4.109.1 * python39-curses-3.9.25-150300.4.109.1 * python39-dbm-3.9.25-150300.4.109.1 * python39-dbm-debuginfo-3.9.25-150300.4.109.1 * python39-idle-3.9.25-150300.4.109.1 * python39-tk-debuginfo-3.9.25-150300.4.109.1 * python39-testsuite-debuginfo-3.9.25-150300.4.109.1 * python39-tk-3.9.25-150300.4.109.1 * python39-debugsource-3.9.25-150300.4.109.1 * python39-base-3.9.25-150300.4.109.1 * python39-testsuite-3.9.25-150300.4.109.1 * python39-debuginfo-3.9.25-150300.4.109.1 * libpython3_9-1_0-debuginfo-3.9.25-150300.4.109.1 * python39-core-debugsource-3.9.25-150300.4.109.1 * python39-tools-3.9.25-150300.4.109.1 * python39-3.9.25-150300.4.109.1 * python39-doc-3.9.25-150300.4.109.1 * python39-curses-debuginfo-3.9.25-150300.4.109.1 * python39-doc-devhelp-3.9.25-150300.4.109.1 * python39-base-debuginfo-3.9.25-150300.4.109.1 * python39-devel-3.9.25-150300.4.109.1 * openSUSE Leap 15.3 (x86_64) * python39-32bit-debuginfo-3.9.25-150300.4.109.1 * python39-base-32bit-debuginfo-3.9.25-150300.4.109.1 * libpython3_9-1_0-32bit-debuginfo-3.9.25-150300.4.109.1 * python39-base-32bit-3.9.25-150300.4.109.1 * python39-32bit-3.9.25-150300.4.109.1 * libpython3_9-1_0-32bit-3.9.25-150300.4.109.1 * openSUSE Leap 15.3 (aarch64_ilp32) * python39-64bit-3.9.25-150300.4.109.1 * libpython3_9-1_0-64bit-3.9.25-150300.4.109.1 * python39-64bit-debuginfo-3.9.25-150300.4.109.1 * python39-base-64bit-3.9.25-150300.4.109.1 * libpython3_9-1_0-64bit-debuginfo-3.9.25-150300.4.109.1 * python39-base-64bit-debuginfo-3.9.25-150300.4.109.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * python39-base-3.9.25-150300.4.109.1 * python39-3.9.25-150300.4.109.1 * libpython3_9-1_0-3.9.25-150300.4.109.1 * python39-curses-3.9.25-150300.4.109.1 * python39-dbm-3.9.25-150300.4.109.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * python39-base-3.9.25-150300.4.109.1 * python39-3.9.25-150300.4.109.1 * libpython3_9-1_0-3.9.25-150300.4.109.1 * python39-curses-3.9.25-150300.4.109.1 * python39-dbm-3.9.25-150300.4.109.1 ## References: * https://www.suse.com/security/cve/CVE-2026-0864.html * https://www.suse.com/security/cve/CVE-2026-11972.html * https://www.suse.com/security/cve/CVE-2026-13346.html * https://www.suse.com/security/cve/CVE-2026-15308.html * https://www.suse.com/security/cve/CVE-2026-1703.html * https://www.suse.com/security/cve/CVE-2026-3219.html * https://www.suse.com/security/cve/CVE-2026-3276.html * https://www.suse.com/security/cve/CVE-2026-4360.html * https://www.suse.com/security/cve/CVE-2026-7774.html * https://bugzilla.suse.com/show_bug.cgi?id=1211301 * https://bugzilla.suse.com/show_bug.cgi?id=1262429 * https://bugzilla.suse.com/show_bug.cgi?id=1267581 * https://bugzilla.suse.com/show_bug.cgi?id=1267821 * https://bugzilla.suse.com/show_bug.cgi?id=1269066 * https://bugzilla.suse.com/show_bug.cgi?id=1269788 * https://bugzilla.suse.com/show_bug.cgi?id=1269959 * https://bugzilla.suse.com/show_bug.cgi?id=1271192 * https://bugzilla.suse.com/show_bug.cgi?id=1273090 * https://bugzilla.suse.com/show_bug.cgi?id=1273091 * https://bugzilla.suse.com/show_bug.cgi?id=1273094 * https://bugzilla.suse.com/show_bug.cgi?id=1274743 * https://bugzilla.suse.com/show_bug.cgi?id=1276903 * https://bugzilla.suse.com/show_bug.cgi?id=1277271 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 17:48:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 17:48:03 -0000 Subject: SUSE-SU-2026:4156-1: important: Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen Message-ID: <178940808304.576.2303194318139922114@5ac198222802> # Security update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen Announcement ID: SUSE-SU-2026:4156-1 Release Date: 2026-09-14T09:08:12Z Rating: important References: * bsc#1226112 * bsc#1262698 * bsc#1262701 * bsc#1266262 * bsc#1266263 * bsc#1271649 * bsc#1272772 * bsc#1272773 * bsc#1272774 * bsc#1273243 * bsc#1274867 * bsc#1278001 * bsc#1279863 Cross-References: * CVE-2026-16349 * CVE-2026-16350 * CVE-2026-16351 * CVE-2026-16352 * CVE-2026-16353 * CVE-2026-16354 * CVE-2026-16355 * CVE-2026-16356 * CVE-2026-16357 * CVE-2026-16358 * CVE-2026-16359 * CVE-2026-16360 * CVE-2026-16362 * CVE-2026-16363 * CVE-2026-16364 * CVE-2026-16365 * CVE-2026-16366 * CVE-2026-16367 * CVE-2026-16368 * CVE-2026-16369 * CVE-2026-16370 * CVE-2026-16371 * CVE-2026-16372 * CVE-2026-16373 * CVE-2026-16374 * CVE-2026-16375 * CVE-2026-16376 * CVE-2026-16377 * CVE-2026-16378 * CVE-2026-16379 * CVE-2026-16380 * CVE-2026-16381 * CVE-2026-16382 * CVE-2026-16383 * CVE-2026-16384 * CVE-2026-16385 * CVE-2026-16386 * CVE-2026-16387 * CVE-2026-16388 * CVE-2026-16389 * CVE-2026-16390 * CVE-2026-16391 * CVE-2026-16392 * CVE-2026-16393 * CVE-2026-16394 * CVE-2026-16395 * CVE-2026-16396 * CVE-2026-16397 * CVE-2026-16398 * CVE-2026-16399 * CVE-2026-16400 * CVE-2026-16401 * CVE-2026-16402 * CVE-2026-16403 * CVE-2026-16404 * CVE-2026-16405 * CVE-2026-16406 * CVE-2026-16407 * CVE-2026-16408 * CVE-2026-16409 * CVE-2026-16410 * CVE-2026-16411 * CVE-2026-16412 * CVE-2026-74934 * CVE-2026-74935 * CVE-2026-74936 * CVE-2026-74937 * CVE-2026-74938 * CVE-2026-74939 * CVE-2026-74940 * CVE-2026-74941 * CVE-2026-74942 * CVE-2026-74943 * CVE-2026-74944 * CVE-2026-74945 * CVE-2026-74946 * CVE-2026-74947 * CVE-2026-74948 * CVE-2026-74949 * CVE-2026-74950 * CVE-2026-74952 * CVE-2026-74953 * CVE-2026-74954 * CVE-2026-74955 * CVE-2026-74956 * CVE-2026-74957 * CVE-2026-74958 * CVE-2026-74959 * CVE-2026-74960 * CVE-2026-74961 * CVE-2026-74962 * CVE-2026-74963 * CVE-2026-74964 * CVE-2026-74965 * CVE-2026-74966 * CVE-2026-74967 * CVE-2026-74968 * CVE-2026-74969 * CVE-2026-74970 * CVE-2026-74971 * CVE-2026-74972 * CVE-2026-74973 * CVE-2026-74974 * CVE-2026-74976 * CVE-2026-74977 * CVE-2026-74978 * CVE-2026-74979 * CVE-2026-74981 * CVE-2026-74982 * CVE-2026-74983 * CVE-2026-74984 * CVE-2026-74985 * CVE-2026-74986 * CVE-2026-74987 * CVE-2026-74988 * CVE-2026-74990 * CVE-2026-75874 * CVE-2026-84118 * CVE-2026-84119 * CVE-2026-84120 * CVE-2026-84121 * CVE-2026-84122 * CVE-2026-84123 * CVE-2026-84124 * CVE-2026-84125 * CVE-2026-84129 * CVE-2026-84130 * CVE-2026-84131 * CVE-2026-84132 * CVE-2026-84133 * CVE-2026-84134 * CVE-2026-84136 * CVE-2026-84137 * CVE-2026-84139 * CVE-2026-84140 * CVE-2026-84141 * CVE-2026-84143 * CVE-2026-84144 * CVE-2026-84145 CVSS scores: * CVE-2026-16349 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-16349 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16350 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16350 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16351 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-16351 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16352 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16352 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16353 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16353 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16354 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16356 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16357 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16358 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16359 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16360 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16362 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16363 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16364 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16365 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16366 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16367 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-16368 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16369 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16370 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16371 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16372 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16373 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16374 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16375 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16376 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16377 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16378 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16379 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16380 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16381 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16382 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16384 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16385 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16386 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16387 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16388 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16389 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16390 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16391 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16392 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-16393 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-16394 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16395 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16396 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16397 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-16398 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16399 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16400 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16401 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16403 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-16404 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:N * CVE-2026-16405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16406 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16407 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16408 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16409 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16410 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16411 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16412 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74934 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74934 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74935 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74935 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74936 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74936 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74936 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74937 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74938 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74938 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74939 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74940 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74940 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74941 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74942 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74943 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74943 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74944 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74944 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74945 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-74946 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74947 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74948 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-74949 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74950 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74952 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74953 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-74955 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74956 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74957 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74958 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-74959 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74960 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74961 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74962 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74963 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-74963 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74964 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74965 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74966 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-74967 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74968 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74969 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74970 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74971 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-74972 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-74973 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74974 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74976 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-74977 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74978 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74979 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74981 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74982 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74983 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74984 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74985 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74986 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74987 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74988 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74990 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74990 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-75874 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-84118 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84118 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84119 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-84119 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-84120 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84120 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84121 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-84121 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-84122 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84122 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84123 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84123 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84124 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84124 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84125 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84125 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84129 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84130 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84131 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84131 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84132 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84133 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84134 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-84136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84137 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-84137 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84139 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-84139 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84140 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84140 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84141 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84141 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84144 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84145 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84145 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 139 vulnerabilities can now be installed. ## Description: This update for MozillaFirefox, MozillaFirefox-branding-SLE, mozilla-nspr, mozilla-nss, rust-cbindgen fixes the following issues: Changes in MozillaFirefox: Firefox Extended Support Release 153.2.0 ESR * Fixed: Various security fixes. MFSA 2026-85 (bsc#1278001): * CVE-2026-75874: Sandbox escape in the Remote Settings Client component * CVE-2026-84118: Use-after-free in the JavaScript: GC component * CVE-2026-84119: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120: Use-after-free in the Audio/Video component * CVE-2026-84121: Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122: Use-after-free in the Audio/Video component * CVE-2026-84123: Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124: Use-after-free in the DOM: Core & HTML component * CVE-2026-84125: Use-after-free in the DOM: Core & HTML component * CVE-2026-74952: Privilege escalation in the Application Update component * CVE-2026-84129: Site isolation issue in the DOM: Navigation component * CVE-2026-84130: Information disclosure in the Graphics: WebGPU component * CVE-2026-84131: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132: Information disclosure in the Networking: HTTP component * CVE-2026-84133: Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134: Other issue in the Profile Backup component * CVE-2026-84136: Other issue in the DOM: Navigation component * CVE-2026-84137: Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139: Clickjacking issue in the DOM: Events component * CVE-2026-84140: Site isolation issue in the DOM: Navigation component * CVE-2026-84141: Integer overflow in the Graphics: ImageLib component * CVE-2026-84143: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144: Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145: Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 * Fixed: Various security fixes. MFSA 2026-77 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937: Use-after-free in the JavaScript: GC component * CVE-2026-74938: Mitigation bypass in the JavaScript: GC component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after- free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947: Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950: Privilege escalation in the Downloads API component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74954: Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955: Privilege escalation in the Request Handling component * CVE-2026-74956: Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74958: Information disclosure in the WebRTC component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74961: Side-channel in the Web Audio component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same- origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74966: Information disclosure in the Form Autofill component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968: Site isolation issue in the Graphics: WebRender component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970: Site isolation issue in the Graphics component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use- after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977: Integer overflow in the Graphics component * CVE-2026-74978: Clickjacking issue in the Widget component * CVE-2026-74979: Mitigation bypass in the Add-ons Manager component * CVE-2026-74981: Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982: Denial-of-service in the Widget component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984: Race condition in the JavaScript Engine component * CVE-2026-74985: Privilege escalation in the Enterprise Policies component * CVE-2026-74986: Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74988: Internally found bugs fixed in Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * Firefox Extended Support Release 153.0esr ESR * New: ## General * Firefox now includes a new profile management system that helps you separate your online life into distinct profiles for work, school, vacation planning, or whatever you choose. Profiles can be customized with names, avatars, and color themes while keeping tabs, bookmarks, passwords, and browsing history separate. Built-in profile backup and restore also makes it easier to migrate to a new device or recover your browsing data. * Split View lets you view two webpages side-by-side in a single browser window, with additional options to quickly open links in Split View, rearrange pages, and search open tabs. * The Firefox address bar has gained several new capabilities, including built-in unit and time zone conversion, quick actions such as muting all browser audio, and direct search results as you type. * Firefox now supports copying links directly to highlighted text on a webpage for easier sharing. * Firefox Settings has been redesigned with improved organization and navigation, making it easier to find and customize browser preferences. * New: ## AI Firefox introduced several new AI-powered features, including on- device tab organization, AI-assisted link previews, integrated AI search, and centralized controls for managing AI features. Whenever possible, these features perform processing locally to help protect user privacy. * New: ## Sidebar and Tabs * Firefox continues to improve tab management with enhancements to vertical tabs, tab groups, and the sidebar. * Tab groups have gained numerous usability improvements, including better support for collapsed groups, previews of grouped tabs, and additional organization options. * Passwords can now be accessed directly from the Firefox sidebar without opening a separate tab. * Firefox now supports copying links from one or multiple background tabs directly from the tab context menu, and multiple tabs can be copied or shared in a single action. * A Send Tab toolbar button is now available through Customize Toolbar. * New: ## Security & Privacy * Firefox has significantly expanded Fingerprinting Protection, making it harder for websites to uniquely identify users in both Standard and Strict Enhanced Tracking Protection modes. * Enhanced Tracking Protection includes stronger protections against bounce tracking and additional safeguards that restrict websites from accessing local network resources without user permission. * Firefox now uses Safe Browsing V5 for phishing and malware protection. * Firefox Password Manager now uses stronger AES-256 encryption to protect stored logins on disk. * Private Browsing has been enhanced with new controls, including the ability to instantly end a private browsing session and temporarily relax tracker blocking for individual sites when needed for compatibility. * New: ## Translations * Firefox has expanded on-device translation support with many additional languages and continued improvements to translation quality. * A dedicated translations page now provides an easy way to perform real-time translations directly within Firefox. * New: ## Accessibility * Firefox continues to improve accessibility with enhanced support for assistive technologies, including Windows UI Automation, improved keyboard navigation, more accessible date and time controls, and better support for mathematical content in PDFs. * New: ## Windows * Firefox now supports installing websites as standalone web apps pinned to the Windows taskbar. * Firefox web apps are also available for Microsoft Store installations. * Firefox now better integrates with Windows location permissions when websites request geolocation access. * New: ## macOS * Firefox now uses a dedicated GPU process by default, improving stability by allowing graphics failures to recover without restarting the browser. * WebGPU is now enabled by default on Apple Silicon Macs. * New: ## Linux * Firefox now supports native fractional scaling on Wayland, improving rendering on high-DPI displays. * Firefox no longer requires a restart after package manager updates and uses less memory on Linux. * Firefox now supports the XDG Base Directory Specification and ships with RPM packages for Red Hat, Fedora, openSUSE, and other RPM-based distributions. * HTML5: - Firefox now supports the View Transitions API for creating smooth animated transitions between application views. * WebGPU support has expanded across supported platforms, including Windows and Apple Silicon Macs. * Added support for several modern web platform APIs, improving compatibility with modern web applications. Notable additions include the Navigation API, URLPattern, Trusted Types, Sanitizer API, and Prioritized Task Scheduling. * Enterprise: - Enterprise administrators can now centrally manage Firefox's Generative AI features through enterprise policy. * Fixed a performance regression affecting native messaging, improving responsiveness for enterprise extensions that communicate with external applications. * Enterprise policy documentation has moved to https://firefox-admin-docs.mozilla.org/. * Fixed: Various security fixes. MFSA 2026-68 (bsc#1271649): * CVE-2026-16349: Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350: Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362: Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351: Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16363: JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364: Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365: Privilege escalation in the DOM: Workers component * CVE-2026-16366: Privilege escalation in the DOM: Navigation component * CVE-2026-16353: Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354: Information disclosure in the Graphics: ImageLib component * CVE-2026-16367: Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368: Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369: Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356: Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357: Incorrect boundary conditions in the Graphics component * CVE-2026-16370: Mitigation bypass in the DOM: Networking component * CVE-2026-16371: Privilege escalation in the DOM: Navigation component * CVE-2026-16372: Privilege escalation in the DOM: Content Processes component * CVE-2026-16373: Information disclosure in the Privacy component in Firefox for Android * CVE-2026-16374: Information disclosure in the Framework component in DevTools * CVE-2026-16375: Site isolation issue in the Networking: HTTP component * CVE-2026-16376: Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377: Mitigation bypass in the PDF Viewer component * CVE-2026-16378: Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379: Privilege escalation in the DOM: Content Processes component * CVE-2026-16358: Site isolation issue in the Graphics: WebRender component * CVE-2026-16380: Mitigation bypass in the Networking component * CVE-2026-16381: Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383: Mitigation bypass in the DOM: Networking component * CVE-2026-16384: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386: Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387: Site isolation issue in the Networking component * CVE-2026-16388: Sandbox escape in the DOM: Networking component * CVE-2026-16389: Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390: Mitigation bypass in the Enterprise Policies component * CVE-2026-16391: Information disclosure in the Storage: IndexedDB component * CVE-2026-16392: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393: Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359: Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394: Mitigation bypass in the DOM: Security component * CVE-2026-16395: Integer overflow in the Audio/Video component * CVE-2026-16396: Privilege escalation in WebExtensions * CVE-2026-16397: Clickjacking issue in the WebExtensions component in Firefox for Android * CVE-2026-16398: Site isolation issue in the Graphics component * CVE-2026-16399: Site isolation issue in the DOM: Navigation component * CVE-2026-16400: Information disclosure in the DOM: Security component * CVE-2026-16401: Privilege escalation in the Data Loss Prevention component * CVE-2026-16402: Integer overflow in the Graphics: ImageLib component * CVE-2026-16403: Spoofing issue in the Address Bar component * CVE-2026-16404: Spoofing issue in Firefox for Android * CVE-2026-16405: Information disclosure in the Networking: WebSockets component * CVE-2026-16406: Mitigation bypass in the Networking component * CVE-2026-16407: Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408: Integer overflow in the Audio/Video: Playback component * CVE-2026-16409: Invalid pointer in the Security: PSM component * CVE-2026-16410: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411: Memory safety bugs fixed in Firefox 153 * CVE-2026-16412: Memory safety bugs fixed in Firefox ESR 140.13 and Firefox 153 * CVE-2026-16360: Memory safety bugs fixed in Firefox ESR 115.38, Firefox ESR 140.13 and Firefox 153 * Fixed: Various security fixes. MFSA 2026-76 (bsc#1274867): * CVE-2026-74934: Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935: Privilege escalation in the DOM: Networking component * CVE-2026-74936: Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74939: Privilege escalation in the DOM: Navigation component * CVE-2026-74940: Use-after-free in the Graphics: Text component * CVE-2026-74941: Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942: Privilege escalation in the Remote Settings Client component * CVE-2026-74943: Use-after-free in the Graphics: ImageLib component * CVE-2026-74944: Use-after-free in the DOM: Core & HTML component * CVE-2026-74945: Information disclosure in the Graphics: Text component * CVE-2026-74946: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74948: Information disclosure in the Graphics component * CVE-2026-74949: Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74953: Privilege escalation in the Networking: Cookies component * CVE-2026-74957: Mitigation bypass in the Safe Browsing component * CVE-2026-74959: Mitigation bypass in the Storage: Cache API component * CVE-2026-74960: Site isolation issue in the WebExtensions component * CVE-2026-74962: Site isolation issue in the Networking: Cookies component * CVE-2026-74963: Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964: Integer overflow in the Graphics component * CVE-2026-74965: Privilege escalation in the Shell Integration component * CVE-2026-74967: Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74969: Use-after-free in the Layout: Text and Fonts component * CVE-2026-74971: Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972: Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973: Race condition, use-after-free in the Graphics component * CVE-2026-74974: Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976: JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74983: Mitigation bypass in the Data Loss Prevention component * CVE-2026-74987: Internally found bugs fixed in Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 * CVE-2026-74990: Internally found bugs fixed in Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.1 and Firefox 154 Changes in rust-cbindgen: * Update to version v0.29.4+git0: * Bump version. * tests: Add some tests for constant enums. * ir: Add support for arrays. * ir: Allow constant literals with enum variants. * ir: Use Path for ConstExprs. * Bump version to 0.29.3 and update CHANGES doc * tests: Fix tests with modern gcc. * Use C++ fixed-type enumeration syntax under C23 (or higher) as well * Allow `pub` access to `ReprType` fields * Update to version 0.29.2+git0: * ci: Add a meta job to block the merge queue on it. * Check for CMSE ABI's as well * Fix doc attribute parsing to properly handle block comments * Expose the line_endings config option to use with the builder * fix env in workflow file * use env to pass output parameters * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Update to version 0.29.2+git0: * Explicitly request serde's std features to avoid issues with newer toml versions. * Account for master -> main rename. * Update changelog and bump version. * enum: Track dependencies properly in enumerations. * Allow must_use if a reason is specified * constant: Handle cfg in associated constants. * tests: Add a test for bitflags + disjoint cfg. * Remove "display" feature from the toml crate * DOC: Add metatensor * Fix #1085 - Incorrect detection of duplicated constants * chore: More clippy fixes. * docs: Correct after_include type in example config * cargo update * cfg: Remove another clippy warning. * Fix `clippy::uninlined_format_args` * Update toml to 0.9 * Release 0.29.0 * Support no-export annotation for statics and functions. * conditional fields of constexpr literal structs * Add LiteralStructField * Github action: Add aarch64 to deploy * Add rename rule for generated associated constant * Upgrade heck to 0.5 * Add support for an optional nullable attribute * docs.md: Fix deprecated_with_note and deprecated_variant_with_note being spelled as 'notes' * Fix generic with "void" default * The return of Cast is simplified * Added tests for as keyword inside array into structs * Fixed error generation of structures using the keyword of as inside arrays * Added test for unsafe(no_mangle) attribute * Added tests for unsafe methotd's atributs * Fixed handling of trait methods containing the unsafe attribute * Rename -Zparse-only * Release 0.28.0 * tests: Fix symbol file and tests. * Appease clippy. * tests: Run rustfmt. Changes in mozilla-nspr: \- update to NSPR 4.39 * Improved error handling in PR_CreateThread on Windows * Cleanup and Type-cast fixes for prtime * Remove unused prstreams C++ wrapper from NSPR * Memory poisoning and Arena redzone fixes * Removed emacs/vim modelines and .cvsignore files * Added .editorconfig \- update to version 4.38.2 * Fixed a syntax error in test file parsetm.c, which was introduced in 4.38.1 \- update to version 4.38.1 * Incorrect time value produced by PR_ParseTimeString and PR_ParseTimeStringToExplodedTime if input string doesn't specify seconds. \- update to version 4.38 * Removed support for HPUX and _PR_POLL_WITH_SELECT * Fixed a bug in pt_TCP_SendTo on macOS * Ensure parameter passed to isalpha() is unsigned char \- update to version 4.37 * PR_GetUniqueIdentity asserts on the 32767th call * error LNK2019: unresolved external symbol _InterlockedCompareExchange * initclk deadline elapsed macOS * Remove prwin.h (formerly known as prwin16.h) * Use builtin atomic functions on RISC-V32/64 * PR_FormatTimeUSEnglish() doesn't support "%e" format specifier Changes in MozillaFirefox-branding-SLE: * use suse_version for SLE16 (bsc#1273243) * chage version to 153 * Switch to using xdg-desktop-portal file picker everywhere for SLE-16 and later (bsc#1226112) Changes in mozilla-nss: * Fix potential crash in FIPS checks on PBKDF2 password checking (boo#1279863) * Fix upper bound to allow FIPS approval for P-521. * Approve HKDF and key concatenation in the context of TLS. This enables approved TLS 1.3 channels with PQC (bsc#1262698). * Don't consider unapproved algorithms for TLS 1.3 in FIPS mode. * Mark TLS 1.2 KDF without extended master secret non-approved for FIPS (bsc#1266262). * Add patch to prefer any hybrid PQC and send at most one hybrid key share (bsc#1262698). * Add a notice to the module ID when it's in non-FIPS mode (bsc#1266263). * Import ML-DSA implementation and related PQC fixes from upstream (bsc#1262698, bsc#1272772). * Add power-on self-tests (KATs) for ML-KEM and ML-DSA (bsc#1272773). * Add zeroization for ML-KEM, ported from upstream (bsc#1272774). * Add zeroization for ML-DSA (bsc#1272774). * nss-ml-dsa-test-fixes.patch: Add ML-DSA robustness and test fixes. * Add PQC algorithms to approved list. Increase approved symmetric keygen floor to 112 bits (bsc#1262698). Approve non-NSS-aliased TLS 1.2 mechanisms (bsc#1266262). * Apply jitter enablement unconditionally (bsc#1262701). * update to NSS 3.125 * Set nssckbi version to 2.88. * Add Cybertrust Japan SecureSign Root CA16. * Remove Email Trust bit from TrustAsia Global Root CA G3 and G4. * Remove Entrust Root Certification Authority. * Remove SecureSign Root CA12. * Initialize ssl3.hs.echOuterExtensions in ssl_NewSocket. * replace references to nss-dev/nss with mozilla/nss. * limit recursion depth in CMS decoder. * clamp input.len to testString size in pk11_mergeSecretKey. * NULL pointer dereference in CERT_MergeExtensions. * CERT_DecodeAVAValue ? Integer Overflow in Output Buffer Sizing. * fix two integer overflows on LLP64 systems. * Modify an assertion in ssl3_ClientSendAppProtoXtn. * Import RSA-PSS PKCS#8 private keys. * Add EC Derive fuzz target. * Update fuzz/config/tstclnt_arguments.py. * Add DSAU fuzz target. * Update ASN1 mutators for fuzzing. * Update TLS mutators for fuzzing. * Update TLS certs for fuzzing. * Update TLS config for fuzzing. * Extend QuickDER fuzz target. * Extend PKCS12 fuzz target. * Extend PKCS8 fuzz target. * Extend certDN fuzz target. * Update ASN1 fuzz target. * Extend PKCS7 fuzz target. * Bounds-check wrap index in PK11_GetWrapKey to match PK11_SetWrapKey. * Adding a guard against integer overflow in AESKeyWrap_EncryptKWP. * Add an integer overflow guard in UpdateBase64Decoder. * Void out the fd.release in reconfig tests. * make sftk_FindAttribute return a copy. * Converted nss parameter schema from voluptuous to msgspec. * bmo#311577 - drop slot monitor in PK11_ResetToken before calling PK11_InitToken. * adjust the code to use nspr from github. * avoid deadlock when PK11_IsLoggedIn is called from PK11_DoPassword. * test pk11auth.c functions with a non-threadsafe module. * bmo#311577 - PK11_InitPin sets slot->lastLoginCheck without holding the slot monitor. * reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * validate encoded EC params length and tag in SECKEY_ECParamsToKeySize/BasePointOrderLen. * guard space subtraction in ssl_CallCustomExtensionSenders. * rewrite labelLen bound in tls13_HkdfExpandLabelGeneral to avoid unsigned overflow. * bound usageCount in PK11_UnwrapPrivKey to keyTemplate capacity. * Set tail pointer to null in static slot lists when deallocating. * avoid leaving a dangling ss->sec.ci.sid on allocation failure. * guard against integer overflow in CERT_Hexify. * Reject empty SECItem inputs in sftk_IsSafePrime before indexing data[len-1]. * NUL-terminate within filename field in jar_listtar to bound the filename scan. * Widen CERT_FormatName length accumulator from unsigned to size_t. * Bound IKE PRF nonce lengths to prevent CK_ULONG to unsigned int truncation. * Drop companion arrays on length mismatch in NSS_CMSArray_Sort instead of asserting. * Operate on a NUL-terminated copy in jar_parse_any to keep manifest scans bounded. * Reject MD2 contexts with unusedBuffer > MD2_BUFSIZE in Update and End. * Reserve NUL terminator for CKA_NSS_URL in nssCKObject_GetAttributes. * Guard padding read against empty output in SEC_PKCS7DecryptContents. * Guard against keySize overflow in IKE PRF/PRF+ output sizing. * Allocate values array when overwriting an empty CMS attribute. * Validate CKA_TOKEN attribute size in nssCKFWObject_SetAttribute. * Validate CKA_CERTIFICATE_TYPE ulValueLen in nss_cert_type_from_ck_attrib. * Handle zero-length input in PrepareBitStringForEncoding. * Length-check raw_manifest before PORT_Strncasecmp prefix dispatch in JAR_parse_manifest. * Reject CKA_NSS_MODULE_SPEC values that aren?t NUL-terminated within ulValueLen. * Reject negative PR_Read returns in JAR_digest_file and jar_create_pk7. * Update Bogo tests to 3fff7111b0eca817466e121059cb4e8b67ade35b. * doc: import NSS:TryServer wiki page in the tree. * improve PK11 URI tests. * avoid nested attributeLock acquisition in sftk_CopyObject. * doc: fix a typo in ?Community ? Network Security Services (NSS)?. * acquire RWLock before key copies in ssl_SetSelfEncryptKeyPair. * Reject empty nickname in PK11_TraverseCertsForNicknameInSlot. * require non-null session pointer in sftk_GetContext. * set session->lastOpWasFIPS while holding session reference. * atomically claim object removal in sftk_DeleteObject. * atomically swap session search in NSC_FindObjects*. * atomically install session contexts in C_*Init. * hold session reference for context lifetime in C_*Update. * align softoken session lock with head-bucket hash. * restore reference counting for SFTKSession. * update to NSS 3.124 * Add test for PKCS7 digest array alignment * Add test for rejection of excessively large ASN.1 SEQUENCE OF in quickder * Add test for CMS content size validation * Add regression tests for DSAU signature decoding * Add test for S/MIME profile lookup on temp certs * Test case for post-handshake auth and many certificate requests * Add test for intra-arena ASan redzones * update nss_status flags one at a time * add defensive info->len check in PK11_HPKE_SetupS and PK11_HPKE_SetupR * avoid PORT_Strdup in ssl_DecodeResumptionToken * add runtime check on decoded resumption token session id * improve mach try error handling * clang format * add comprehensive SECItem and SECItemArray tests * add bugzilla_cf_status_nss.py script * regenerate some recent release notes * fix bug list output by release note and email scripts * test removal from trust domain email cache * fix "testing if key corruption is detected in attribute" failures with sqlite-3.53.0 * build sqlite3 shell for Windows CI runners * avoid race with module unloading in NSSTrustDomain_FindTokensByURI * add ImportEd25519WithNonEmptyAlgorithmParams test * add CLAUDE.md and .mcp.json * add a mach try command * remove dead condition in sec_asn1d_check_and_subtract_length * avoid integer truncation in nssCKObject_GetAttributes * add defensive input validation to sftk_compute_ANSI_X9_63_kdf * avoid refcount over-release in nssTokenObjectCache error path [@ nssToken_Destroy] * sdb: enforce that metaData's id key is unique when reading * improve handling of escape sequences in pk11uri_ParseAttributes * use correct data for ID comparison in transfer_uri_certs_to_collection * fix truncation of ulValueLen in sdb_FindObjectsInit * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * set previous-nss-release for abicheck * Skip `PR_Sleep` yield for non-blocking sockets in `ssl3_SendApplicationData` * consistently protect PK11SlotInfo::maxKeyCount with freeListLock * Remove CRMF from testing and manifests * Remove unused RSA blind signature implementation from freebl * update to NSS 3.123.1 * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * update to NSS 3.123 * https://groups.google.com/a/mozilla.org/g/dev-tech-crypto/c/AW6VHkn6E0o * update to NSS 3.122.2: * reject DTLS 1.3 Server Hello after HVR without capping ss->vrange.max * update to NSS 3.122.1 * improve error handling in PK11_ImportPrivateKeyInfoAndReturnKey. * Improving the allocation of S/MIME DecryptSymKey. * store email on subject cache_entry in NSS trust domain. * Heap use-after-free in cert_VerifyCertChainOld via dangling certsList[] entry on NameConstraints violation. * Improve size calculations in CMS content buffering. * avoid integer overflow while escaping RFC822 Names. * Reject excessively large ASN.1 SEQUENCE OF in quickder. * Deep copy profile data in CERT_FindSMimeProfile. * Improve input validation in DSAU signature decoding. * avoid integer overflow in RSA_EMSAEncodePSS. * Add a maximum cert uncompressed len and tests. * Clarify extension negotiation mechanism for TLS Handshakes. * make ss->ssl3.hs.cookie an owned-copy of the cookie. * update to NSS 3.122 * ensure permittedSubtrees don't match wildcards that could be outside the permitted tree. * run mach doc-lint from generate_release_doc.py. * Fix integer underflow in tls13_AEAD when ciphertext is shorter than tag. * tls13_CopyEchConfigs uses PR_LIST_TAIL instead of loop variable. * fix cipher spec count intermittent CI failures. * fix Mlkem768x25519ShareDamager intermittent CI failures. * lint the legacy documentation. * lint the NSS 3.112.3 release notes. * add a doc-lint CI job. * Add more useful coverage reports to CI and fail if new commit isn't tested. * wrong alert for malformed TLS 1.3 Finished. * Swap order of asserts and state check. * set correct value of unused curve parameters in tls13_HandleKeyShare. * GCM needs to check for various limits in FIPS mode. * Get Key Length not working from ED and Montgomery keys. * Not all ike modes are FIPS approved. Adjust the indicators when they aren't. * fix intermittent ssl.sh test failures on windows runners. * FIPS indicators on HKDF needs to be restricted to TLS usage. * Generate keys not getting indicators. * improve error handling in smime_init_once. * Detect CPU features on OpenBSD using elf_aux_info. * RSA_EMSAEncodePSS should validate the length of mHash. * more robustly distinguish SFTKSessionObject and SFTKTokenObjects. * fix missing .S file error in Solaris Makefile builds. * fix memory leak in NSC_GenerateKey error path. * Missing SECFailure return after FATAL_ERROR in tls13_HandleEncryptedExtensions. * release xmit buf lock on dtls13_MaybeSendKeyUpdate error paths. * release 1stHandshakeLock on SSL_ResetHandshake error path. * avoid null deref in mp_div_d sign normalization. * Temp private key lifecycle is broken. * protect rwSessionCount with slotLock. * Remove invalid PORT_Free(). * Fix intermittent ClientGreaseKeyShare test failure. * Fix kCtxStr len passed to tls_SignOrVerifyUpdate. * patch upstream acvp-rust during checkout to avoid build failures. * update acvp Dockerfile. * CKA_PARAM_SET missing from the CK_ULONG list in softoken. * CKA_SEED missing from isPrivate in the database. * update abicheck expectation for __nss_InitLock. * taskcluster: set NSS_DISABLE_LIBPKIX=1 in test env for static builds. * tests: fix setup_policy to use ROOTCERTSFILE for root cert module path. * tests: fix selfserv/httpserv PID handling and wait exit code for MSYS_NT. * tests: add native_path helper for cross-platform path conversion. * tstclnt, strsclnt: avoid DNS lookup for loopback addresses on Windows. * avoid platform GCM for x64 iOS emulator builds. * remove lock instrumentation feature. * Move FIPS indicator structures out of fips_algorithms.h. * all.sh is failing in FIPS SSL test in main tree. * fix memory leaks in crmf tests. * fix unsatisfiable condition in lg_getTrust. * allow selfserv makefile build to use system zlib. * Add allocation limit to pkcs12 decoding. * Add text/html single-line example emails to NSS S/SMIME CMS tests. * Rebase patches nss-fips-aes-gcm-restrict.patch and nss-fips-approved-crypto- non-ec.patch due to upstreamed FIPS patches * update to NSS 3.121 * update vendored zlib to v1.3.2. * Revert the unnecessary changes to intel-gcm-wrap.gyp. * Use C fallback for AES-GCM on MinGW builds. * fix ML-KEM PCT. * Extend NSS Fuzzing docs. * avoid integer overflow in platform-independent ghash. * Fix errant whitespace in OISTE Server Root RSA G1 nickname. * fix build with glibc-2.43 assignment discards 'const' qualifier from pointer. * add gcm.gyp dependency for Solaris SPARC builds. * Set nssckbi version to 2.84. * Add e-Szigno TLS Root CA 2023 to NSS. * allow manual selection of CPU_ARCH=x86_64 and ppc64 in coreconf/Darwin.mk. * Update cryptofuzz version. * Paranoia assert. * Darwin compatibility for intel-aes.S and intel-gcm.S. * rename intel-{aes,gcm}.s to .S. * rename C files for platform-specific ghash implementations. * simplify compilation of platform-specific GCM and GHASH. * FORWARD_NULL null deref of worker in p7decode.c (sec_pkcs7_decoder_abort_digests). * Out-of-Bounds Read in ML-DSA Private Key Parsing (zero-length privateKey). * update to NSS 3.120.1 * no upstream releasenotes * update to NSS 3.120 * Fix docs generation bug. * CID 1678226: Dereferencing null pointer plaintext.data(). * Run PKCS12 fuzz target with --fuzz=tls in CI. * Allowing RT be started several times. * move linux decision and build tasks to d2g worker pools. * Revert back to original naming scheme of tarballs * update to NSS 3.119.1 * restore coreconf/Darwin.mk behavior for intel archs * update to NSS 3.119 * Fix ml-dsa return value for SECKEY_PrivateKeyStrengthInBits. * Make sure we don't accept ECH if the HRR cookie is ill-formatted. * Add a pkcs12 fuzzer with crypto stubbed out. * handle errors while setting sanitizers cflags in build. * Ignore IVs for AES KW. * Update Cryptofuzz version. * Fix incorrect logic for SNI selection when ECH is available but disabled. * fix forwarding of sqlite_libs in sqlite.gyp. * fix CPU_ARCH setting for arm64 makefile builds. * remove unused calcThreads variable from cmd/rsaperf. * Solving the incorrect tests introduced by extending EKU. * Memory leaks in pkcs12 and pkcs7 decoders. * Extending parsing with Microsoft Document Signing EKU. * Extending parsing with Adobe Document Signing EKU. * Extending pkix parsing with document signing EKUs. * fix compilation failure on ia32. * use hardware x64 GCM in static builds. * separate ppc sha512 library from ppc gcm library. * simplify cross-compilation from build.sh. * use clang's integrated assembler. * remove unused MP_IS_LITTLE_ENDIAN defines. * fix logic for disabling altivec in gyp builds. * free digest objects in SEC_PKCS7DecoderFinish if they haven't already been freed. * Add TLS interoperability tests with openssl and gnutls. * Ensure we don't send a DTLS1.3 cookie after DTLS1.2 HelloVerifyRequest. * add failure checks to pk11_mergeTrust() . * pk11wrap selects incorrect slot for CKM_ML_KEM*. * Adjusted for changed naming scheme of tarballs for this release by upstream * update to NSS 3.118.1 * pk11wrap selects incorrect slot for CKM_ML_KEM* * update to NSS 3.118 * Remove four Commscope root certificates from NSS * fix try pushes with --nspr-patch to actually apply the patch * Support for NIST Curves compressed points * Destroy certificate on error paths * Move NSS DB password hash away from SHA-1 * support secp384r1mlkem1024 * vendor latest ML-KEM code from libcrux * add mlk-kem-1024 tests * use the correct directory for FStar_UInt_8_16_32_64.h in source consistency test * Move scripts to python3 * add mlkem1024 support in freebl * support secp256r1mlkem768 * Make mlkem768x25519 the default * ML-DSA SGN and VFY interfaces * Align FIPS interfaces count with array * Ensure CKK_ML_KEM has derive CK_FALSE * Add script for tagging an NSS release * Remove the globals from nss-release-helper.py * Add release helper command for generating the release index * Add release helper command for generating a release note * Add release helper command for freezing a branch * update to NSS 3.117 * fix memory leak in secasn1decode_unittest.cc * Add OISTE roots * Add runbook for certdata.txt changes * dbtool: close databases before shutdown * SEC_ASN1Decode* should ensure it has read as many bytes as each length field indicates * don?t flush base64 when buffer is null * Set use_pkcs5_pbkd2_params2_only=1 for fuzzing builds * mozilla::pkix: recognize the qcStatements extension for QWACs * Fix a big-endian-problematic cast in zlib calls * Revert removing out/ directory after ossfuzz build * Add Cryptofuzz to OSS-Fuzz build * Add PKCS#11 trust tests * final disable dsa patch cert.sh * ml-dsa: move tls 1.3 to use streaming signatures * ml-dsa: Prep Create a FindOidTagByString function * ml-dsa: softoken changes * ml-dsa: der key decode * ml-dsa: Prep colapse the overuse of keyType outside of pk11wrap and cryptohi * ml-dsa: Prep Create a CreateSignatureAlgorithmID function * update to NSS 3.116 * disable DSA in NSS script tests * Disabling of some algorithms: generic cert.sh * Need to update to new mechanisms * Add ML-DSA public key printing support in NSS command-line utilities * note embedded scts before revocation checks are performed * Add support for ML-DSA keys and mechanisms in PKCS#11 interface * Add support for ML-DSA key type and public key structure * Enable ML-DSA integration via OIDs support and SECMOD flag * disable kyber * Implement PKCS #11 v3.2 PQ functions (use verify signature) * Disable dsa - gtests * make group and scheme support in test tools generic * Create GH workflow to automatically close PRs * Disable dsa - base code * Disabling of some algorithms: remove dsa from pk11_mode * Disable seed and RC2 bug fixes * restore support for finding certificates by decoded serial number * avoid CKR_BUFFER_TO_SMALL error in trust lookups * lib/softtoken/{sdb.c,sftkdbti.h}: Align sftkdb_known_attributes_size type * Use PKCS #11 v3.2 KEM mechanisms and functions * update to NSS 3.115.1 * restore support for finding certificates by decoded serial number. * avoid CKR_BUFFER_TO_SMALL error in trust lookups. * update to NSS 3.115 * CID 1648399 - Resource leak in shlibsign.c * CKA_SEED needs to be marked as a private attribute * Fix bad syntax on Windows in softoken_gtest.cc * Key private/public/secret keys by key type in softoken keydb * add PK11_HPKE_GetSharedSecret to abi-check expected report * remove NetscapeStepUpMatchesServerAuth from mozpkix TrustDomain * Fixup ABI * add ECH_SECRET and ECH_CONFIG to SSLKEYLOG for both client and server * ECH fuzz target * Implement PKCS #11 v3.2 FIPS indicator and validation objects * remove expired explicitly distrusted DigiNotar lookalike root * Implement PKCS #11 v3.2 functions * update to NSS 3.114 * NSS 3.114 source distribution should include NSPR 4.37 * Prevent leaks during pkcs12 decoding * Remove redundant assert in p7local.c * Bump nssckbi version to 2.80 * Remove expired Baltimore CyberTrust Root * Add TrustAsia Dedicated Roots to NSS * Add SwissSign 2022 Roots to NSS * Add backwards compatibility for CK_PKCS5_PBKD2_PARAMS * Implement PKCS #11 v3.2 trust objects in softoken * Implement PKCS #11 v3.2 trust objects - nss proper * remove dead code in ssl3con.c * DTLS (excl DTLS1.3) Changing Holddown timer logic * Bump nssckbi version to 2.79 * remove unneccessary assertion * Update mechanisms for Softoken PCT * convert Chunghwa Telecom ePKI Root removal to a distrust after * Ensure ssl_HaveRecvBufLock and friends respect opt.noLocks * use -O2 for asan build * Fix leaking locks when toggling SSL_NO_LOCKS * remove out-of-function semicolon * Extend pkcs8 fuzz target * Extend pkcs7 fuzz target * Remove unused assignment to pageno * Remove unused assignment to nextChunk * don't run commands as part of shell `local` declarations * fix sanitizer setup * don't silence ssl_gtests output when running with coverage * Release docs and housekeeping * migrate to new linux tester pool * rebase FIPS patches to adjust for upstream FIPS work * update to NSS 3.113 * Fix alias for mac workers on try. * bmo#198090 - Part 1: Use AES in the SDR (NSS) r=simonf,nss-reviewers,rrelyea * Bump nssckbi version to 2.78. * Turn off Websites Trust Bit for Chunghwa Telecom ePKI Root in FF 141. * fix frame pointers in intel-gcm.s. * Typo in release notes for NSS 101.4. * Improve nss-release-helper.py. * shlibsign is broken in System FIPS mode. * Need up update NSS for PKCS 3.1: Move IPSEC to 3.1 * PKCS #11 v3.2 header files. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4156 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4156 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4156 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4156 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4156 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4156 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4156 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4156 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4156 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4156 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4156 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4156 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4156 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4156 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4156 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4156 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4156 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4156 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * mozilla-nss-sysinit-3.125-150400.3.74.1 * MozillaFirefox-debuginfo-153.2.0-150400.157.5.1 * mozilla-nss-3.125-150400.3.74.1 * libsoftokn3-debuginfo-3.125-150400.3.74.1 * MozillaFirefox-debugsource-153.2.0-150400.157.5.1 * MozillaFirefox-153.2.0-150400.157.5.1 * mozilla-nss-certs-debuginfo-3.125-150400.3.74.1 * libfreebl3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debuginfo-3.125-150400.3.74.1 * mozilla-nspr-devel-4.39-150400.12.3.1 * mozilla-nss-tools-3.125-150400.3.74.1 * mozilla-nspr-debugsource-4.39-150400.12.3.1 * mozilla-nspr-debuginfo-4.39-150400.12.3.1 * mozilla-nss-debugsource-3.125-150400.3.74.1 * MozillaFirefox-translations-other-153.2.0-150400.157.5.1 * mozilla-nss-sysinit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-certs-3.125-150400.3.74.1 * mozilla-nspr-4.39-150400.12.3.1 * MozillaFirefox-translations-common-153.2.0-150400.157.5.1 * MozillaFirefox-branding-SLE-153-150400.14.3.1 * libfreebl3-3.125-150400.3.74.1 * mozilla-nss-tools-debuginfo-3.125-150400.3.74.1 * libsoftokn3-3.125-150400.3.74.1 * mozilla-nss-devel-3.125-150400.3.74.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * mozilla-nspr-32bit-debuginfo-4.39-150400.12.3.1 * libsoftokn3-32bit-debuginfo-3.125-150400.3.74.1 * libfreebl3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-3.125-150400.3.74.1 * libsoftokn3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-3.125-150400.3.74.1 * mozilla-nspr-32bit-4.39-150400.12.3.1 * libfreebl3-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-debuginfo-3.125-150400.3.74.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * MozillaFirefox-devel-153.2.0-150400.157.5.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * mozilla-nss-sysinit-3.125-150400.3.74.1 * MozillaFirefox-debuginfo-153.2.0-150400.157.5.1 * mozilla-nss-3.125-150400.3.74.1 * libsoftokn3-debuginfo-3.125-150400.3.74.1 * MozillaFirefox-debugsource-153.2.0-150400.157.5.1 * MozillaFirefox-153.2.0-150400.157.5.1 * mozilla-nss-certs-debuginfo-3.125-150400.3.74.1 * libfreebl3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debuginfo-3.125-150400.3.74.1 * mozilla-nspr-devel-4.39-150400.12.3.1 * mozilla-nss-tools-3.125-150400.3.74.1 * mozilla-nspr-debugsource-4.39-150400.12.3.1 * mozilla-nspr-debuginfo-4.39-150400.12.3.1 * mozilla-nss-debugsource-3.125-150400.3.74.1 * MozillaFirefox-translations-other-153.2.0-150400.157.5.1 * mozilla-nss-sysinit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-certs-3.125-150400.3.74.1 * mozilla-nspr-4.39-150400.12.3.1 * MozillaFirefox-translations-common-153.2.0-150400.157.5.1 * MozillaFirefox-branding-SLE-153-150400.14.3.1 * libfreebl3-3.125-150400.3.74.1 * mozilla-nss-tools-debuginfo-3.125-150400.3.74.1 * libsoftokn3-3.125-150400.3.74.1 * mozilla-nss-devel-3.125-150400.3.74.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * MozillaFirefox-devel-153.2.0-150400.157.5.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (x86_64) * mozilla-nspr-32bit-debuginfo-4.39-150400.12.3.1 * libsoftokn3-32bit-debuginfo-3.125-150400.3.74.1 * libfreebl3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-3.125-150400.3.74.1 * libsoftokn3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-3.125-150400.3.74.1 * mozilla-nspr-32bit-4.39-150400.12.3.1 * libfreebl3-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-debuginfo-3.125-150400.3.74.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * mozilla-nss-sysinit-3.125-150400.3.74.1 * MozillaFirefox-debuginfo-153.2.0-150400.157.5.1 * mozilla-nss-3.125-150400.3.74.1 * libsoftokn3-debuginfo-3.125-150400.3.74.1 * MozillaFirefox-debugsource-153.2.0-150400.157.5.1 * MozillaFirefox-153.2.0-150400.157.5.1 * mozilla-nss-certs-debuginfo-3.125-150400.3.74.1 * libfreebl3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debuginfo-3.125-150400.3.74.1 * mozilla-nspr-devel-4.39-150400.12.3.1 * mozilla-nss-tools-3.125-150400.3.74.1 * mozilla-nspr-debugsource-4.39-150400.12.3.1 * mozilla-nspr-debuginfo-4.39-150400.12.3.1 * mozilla-nss-debugsource-3.125-150400.3.74.1 * MozillaFirefox-translations-other-153.2.0-150400.157.5.1 * mozilla-nss-sysinit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-certs-3.125-150400.3.74.1 * mozilla-nspr-4.39-150400.12.3.1 * MozillaFirefox-translations-common-153.2.0-150400.157.5.1 * MozillaFirefox-branding-SLE-153-150400.14.3.1 * libfreebl3-3.125-150400.3.74.1 * mozilla-nss-tools-debuginfo-3.125-150400.3.74.1 * libsoftokn3-3.125-150400.3.74.1 * mozilla-nss-devel-3.125-150400.3.74.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (x86_64) * mozilla-nspr-32bit-debuginfo-4.39-150400.12.3.1 * libsoftokn3-32bit-debuginfo-3.125-150400.3.74.1 * libfreebl3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-3.125-150400.3.74.1 * libsoftokn3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-3.125-150400.3.74.1 * mozilla-nspr-32bit-4.39-150400.12.3.1 * libfreebl3-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-debuginfo-3.125-150400.3.74.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * MozillaFirefox-devel-153.2.0-150400.157.5.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * mozilla-nss-sysinit-3.125-150400.3.74.1 * mozilla-nss-3.125-150400.3.74.1 * libsoftokn3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-certs-debuginfo-3.125-150400.3.74.1 * libfreebl3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debuginfo-3.125-150400.3.74.1 * mozilla-nspr-devel-4.39-150400.12.3.1 * mozilla-nss-tools-3.125-150400.3.74.1 * mozilla-nspr-debugsource-4.39-150400.12.3.1 * mozilla-nspr-debuginfo-4.39-150400.12.3.1 * rust-cbindgen-debuginfo-0.29.4+git0-150400.11.3.2 * mozilla-nss-debugsource-3.125-150400.3.74.1 * mozilla-nss-sysinit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-certs-3.125-150400.3.74.1 * rust-cbindgen-0.29.4+git0-150400.11.3.2 * rust-cbindgen-debugsource-0.29.4+git0-150400.11.3.2 * mozilla-nspr-4.39-150400.12.3.1 * MozillaFirefox-branding-SLE-153-150400.14.3.1 * libfreebl3-3.125-150400.3.74.1 * mozilla-nss-tools-debuginfo-3.125-150400.3.74.1 * libsoftokn3-3.125-150400.3.74.1 * mozilla-nss-devel-3.125-150400.3.74.1 * openSUSE Leap 15.4 (x86_64) * mozilla-nspr-32bit-debuginfo-4.39-150400.12.3.1 * libsoftokn3-32bit-debuginfo-3.125-150400.3.74.1 * libfreebl3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-3.125-150400.3.74.1 * libsoftokn3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-sysinit-32bit-3.125-150400.3.74.1 * mozilla-nss-32bit-3.125-150400.3.74.1 * mozilla-nspr-32bit-4.39-150400.12.3.1 * mozilla-nss-sysinit-32bit-debuginfo-3.125-150400.3.74.1 * libfreebl3-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-debuginfo-3.125-150400.3.74.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libsoftokn3-64bit-3.125-150400.3.74.1 * mozilla-nspr-64bit-4.39-150400.12.3.1 * mozilla-nss-certs-64bit-debuginfo-3.125-150400.3.74.1 * mozilla-nspr-64bit-debuginfo-4.39-150400.12.3.1 * mozilla-nss-sysinit-64bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-certs-64bit-3.125-150400.3.74.1 * mozilla-nss-sysinit-64bit-3.125-150400.3.74.1 * libsoftokn3-64bit-debuginfo-3.125-150400.3.74.1 * libfreebl3-64bit-debuginfo-3.125-150400.3.74.1 * libfreebl3-64bit-3.125-150400.3.74.1 * mozilla-nss-64bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-64bit-3.125-150400.3.74.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-common-153.2.0-150400.157.5.1 * MozillaFirefox-debuginfo-153.2.0-150400.157.5.1 * MozillaFirefox-translations-other-153.2.0-150400.157.5.1 * MozillaFirefox-debugsource-153.2.0-150400.157.5.1 * MozillaFirefox-153.2.0-150400.157.5.1 * MozillaFirefox-branding-upstream-153.2.0-150400.157.5.1 * openSUSE Leap 15.4 (noarch) * MozillaFirefox-devel-153.2.0-150400.157.5.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * mozilla-nspr-debuginfo-4.39-150400.12.3.1 * mozilla-nss-certs-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debugsource-3.125-150400.3.74.1 * libfreebl3-3.125-150400.3.74.1 * mozilla-nss-3.125-150400.3.74.1 * libsoftokn3-debuginfo-3.125-150400.3.74.1 * libfreebl3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debuginfo-3.125-150400.3.74.1 * mozilla-nss-tools-debuginfo-3.125-150400.3.74.1 * mozilla-nss-tools-3.125-150400.3.74.1 * mozilla-nss-certs-3.125-150400.3.74.1 * libsoftokn3-3.125-150400.3.74.1 * mozilla-nspr-4.39-150400.12.3.1 * mozilla-nspr-debugsource-4.39-150400.12.3.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * mozilla-nspr-debuginfo-4.39-150400.12.3.1 * mozilla-nss-certs-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debugsource-3.125-150400.3.74.1 * libfreebl3-3.125-150400.3.74.1 * mozilla-nss-3.125-150400.3.74.1 * libsoftokn3-debuginfo-3.125-150400.3.74.1 * libfreebl3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debuginfo-3.125-150400.3.74.1 * mozilla-nss-tools-debuginfo-3.125-150400.3.74.1 * mozilla-nss-tools-3.125-150400.3.74.1 * mozilla-nss-certs-3.125-150400.3.74.1 * libsoftokn3-3.125-150400.3.74.1 * mozilla-nspr-4.39-150400.12.3.1 * mozilla-nspr-debugsource-4.39-150400.12.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * mozilla-nss-sysinit-3.125-150400.3.74.1 * MozillaFirefox-debuginfo-153.2.0-150400.157.5.1 * mozilla-nss-3.125-150400.3.74.1 * libsoftokn3-debuginfo-3.125-150400.3.74.1 * MozillaFirefox-debugsource-153.2.0-150400.157.5.1 * MozillaFirefox-153.2.0-150400.157.5.1 * mozilla-nss-certs-debuginfo-3.125-150400.3.74.1 * libfreebl3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debuginfo-3.125-150400.3.74.1 * mozilla-nspr-devel-4.39-150400.12.3.1 * mozilla-nss-tools-3.125-150400.3.74.1 * mozilla-nspr-debugsource-4.39-150400.12.3.1 * mozilla-nspr-debuginfo-4.39-150400.12.3.1 * mozilla-nss-debugsource-3.125-150400.3.74.1 * MozillaFirefox-translations-other-153.2.0-150400.157.5.1 * mozilla-nss-sysinit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-certs-3.125-150400.3.74.1 * mozilla-nspr-4.39-150400.12.3.1 * MozillaFirefox-translations-common-153.2.0-150400.157.5.1 * MozillaFirefox-branding-SLE-153-150400.14.3.1 * libfreebl3-3.125-150400.3.74.1 * mozilla-nss-tools-debuginfo-3.125-150400.3.74.1 * libsoftokn3-3.125-150400.3.74.1 * mozilla-nss-devel-3.125-150400.3.74.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * mozilla-nspr-32bit-debuginfo-4.39-150400.12.3.1 * libsoftokn3-32bit-debuginfo-3.125-150400.3.74.1 * libfreebl3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-3.125-150400.3.74.1 * libsoftokn3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-3.125-150400.3.74.1 * mozilla-nspr-32bit-4.39-150400.12.3.1 * libfreebl3-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-debuginfo-3.125-150400.3.74.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * MozillaFirefox-devel-153.2.0-150400.157.5.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * mozilla-nss-sysinit-3.125-150400.3.74.1 * MozillaFirefox-debuginfo-153.2.0-150400.157.5.1 * mozilla-nss-3.125-150400.3.74.1 * libsoftokn3-debuginfo-3.125-150400.3.74.1 * MozillaFirefox-debugsource-153.2.0-150400.157.5.1 * MozillaFirefox-153.2.0-150400.157.5.1 * mozilla-nss-certs-debuginfo-3.125-150400.3.74.1 * libfreebl3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debuginfo-3.125-150400.3.74.1 * mozilla-nspr-devel-4.39-150400.12.3.1 * mozilla-nss-tools-3.125-150400.3.74.1 * mozilla-nspr-debugsource-4.39-150400.12.3.1 * mozilla-nspr-debuginfo-4.39-150400.12.3.1 * mozilla-nss-debugsource-3.125-150400.3.74.1 * MozillaFirefox-translations-other-153.2.0-150400.157.5.1 * mozilla-nss-sysinit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-certs-3.125-150400.3.74.1 * mozilla-nspr-4.39-150400.12.3.1 * MozillaFirefox-translations-common-153.2.0-150400.157.5.1 * MozillaFirefox-branding-SLE-153-150400.14.3.1 * libfreebl3-3.125-150400.3.74.1 * mozilla-nss-tools-debuginfo-3.125-150400.3.74.1 * libsoftokn3-3.125-150400.3.74.1 * mozilla-nss-devel-3.125-150400.3.74.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * MozillaFirefox-devel-153.2.0-150400.157.5.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (x86_64) * mozilla-nspr-32bit-debuginfo-4.39-150400.12.3.1 * libsoftokn3-32bit-debuginfo-3.125-150400.3.74.1 * libfreebl3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-3.125-150400.3.74.1 * libsoftokn3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-3.125-150400.3.74.1 * mozilla-nspr-32bit-4.39-150400.12.3.1 * libfreebl3-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-debuginfo-3.125-150400.3.74.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * mozilla-nss-sysinit-3.125-150400.3.74.1 * MozillaFirefox-debuginfo-153.2.0-150400.157.5.1 * mozilla-nss-3.125-150400.3.74.1 * libsoftokn3-debuginfo-3.125-150400.3.74.1 * MozillaFirefox-debugsource-153.2.0-150400.157.5.1 * MozillaFirefox-153.2.0-150400.157.5.1 * mozilla-nss-certs-debuginfo-3.125-150400.3.74.1 * libfreebl3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debuginfo-3.125-150400.3.74.1 * mozilla-nspr-devel-4.39-150400.12.3.1 * mozilla-nss-tools-3.125-150400.3.74.1 * mozilla-nspr-debugsource-4.39-150400.12.3.1 * mozilla-nspr-debuginfo-4.39-150400.12.3.1 * mozilla-nss-debugsource-3.125-150400.3.74.1 * MozillaFirefox-translations-other-153.2.0-150400.157.5.1 * mozilla-nss-sysinit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-certs-3.125-150400.3.74.1 * mozilla-nspr-4.39-150400.12.3.1 * MozillaFirefox-translations-common-153.2.0-150400.157.5.1 * MozillaFirefox-branding-SLE-153-150400.14.3.1 * libfreebl3-3.125-150400.3.74.1 * mozilla-nss-tools-debuginfo-3.125-150400.3.74.1 * libsoftokn3-3.125-150400.3.74.1 * mozilla-nss-devel-3.125-150400.3.74.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (x86_64) * mozilla-nspr-32bit-debuginfo-4.39-150400.12.3.1 * libsoftokn3-32bit-debuginfo-3.125-150400.3.74.1 * libfreebl3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-3.125-150400.3.74.1 * libsoftokn3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-3.125-150400.3.74.1 * mozilla-nspr-32bit-4.39-150400.12.3.1 * libfreebl3-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-debuginfo-3.125-150400.3.74.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * MozillaFirefox-devel-153.2.0-150400.157.5.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * mozilla-nspr-debuginfo-4.39-150400.12.3.1 * mozilla-nss-certs-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debugsource-3.125-150400.3.74.1 * libfreebl3-3.125-150400.3.74.1 * mozilla-nss-3.125-150400.3.74.1 * libsoftokn3-debuginfo-3.125-150400.3.74.1 * libfreebl3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debuginfo-3.125-150400.3.74.1 * mozilla-nss-tools-debuginfo-3.125-150400.3.74.1 * mozilla-nss-tools-3.125-150400.3.74.1 * mozilla-nss-certs-3.125-150400.3.74.1 * libsoftokn3-3.125-150400.3.74.1 * mozilla-nspr-4.39-150400.12.3.1 * mozilla-nspr-debugsource-4.39-150400.12.3.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * mozilla-nspr-debuginfo-4.39-150400.12.3.1 * mozilla-nss-certs-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debugsource-3.125-150400.3.74.1 * libfreebl3-3.125-150400.3.74.1 * mozilla-nss-3.125-150400.3.74.1 * libsoftokn3-debuginfo-3.125-150400.3.74.1 * libfreebl3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debuginfo-3.125-150400.3.74.1 * mozilla-nss-tools-debuginfo-3.125-150400.3.74.1 * mozilla-nss-tools-3.125-150400.3.74.1 * mozilla-nss-certs-3.125-150400.3.74.1 * libsoftokn3-3.125-150400.3.74.1 * mozilla-nspr-4.39-150400.12.3.1 * mozilla-nspr-debugsource-4.39-150400.12.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * mozilla-nss-sysinit-3.125-150400.3.74.1 * MozillaFirefox-debuginfo-153.2.0-150400.157.5.1 * mozilla-nss-3.125-150400.3.74.1 * libsoftokn3-debuginfo-3.125-150400.3.74.1 * MozillaFirefox-debugsource-153.2.0-150400.157.5.1 * MozillaFirefox-153.2.0-150400.157.5.1 * mozilla-nss-certs-debuginfo-3.125-150400.3.74.1 * libfreebl3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debuginfo-3.125-150400.3.74.1 * mozilla-nspr-devel-4.39-150400.12.3.1 * mozilla-nss-tools-3.125-150400.3.74.1 * mozilla-nspr-debugsource-4.39-150400.12.3.1 * mozilla-nspr-debuginfo-4.39-150400.12.3.1 * mozilla-nss-debugsource-3.125-150400.3.74.1 * MozillaFirefox-translations-other-153.2.0-150400.157.5.1 * mozilla-nss-sysinit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-certs-3.125-150400.3.74.1 * mozilla-nspr-4.39-150400.12.3.1 * MozillaFirefox-translations-common-153.2.0-150400.157.5.1 * MozillaFirefox-branding-SLE-153-150400.14.3.1 * libfreebl3-3.125-150400.3.74.1 * mozilla-nss-tools-debuginfo-3.125-150400.3.74.1 * libsoftokn3-3.125-150400.3.74.1 * mozilla-nss-devel-3.125-150400.3.74.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * mozilla-nspr-32bit-debuginfo-4.39-150400.12.3.1 * libsoftokn3-32bit-debuginfo-3.125-150400.3.74.1 * libfreebl3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-3.125-150400.3.74.1 * libsoftokn3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-3.125-150400.3.74.1 * mozilla-nspr-32bit-4.39-150400.12.3.1 * libfreebl3-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-debuginfo-3.125-150400.3.74.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * MozillaFirefox-devel-153.2.0-150400.157.5.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * mozilla-nspr-debuginfo-4.39-150400.12.3.1 * mozilla-nss-certs-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debugsource-3.125-150400.3.74.1 * libfreebl3-3.125-150400.3.74.1 * mozilla-nss-3.125-150400.3.74.1 * libsoftokn3-debuginfo-3.125-150400.3.74.1 * libfreebl3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debuginfo-3.125-150400.3.74.1 * mozilla-nss-tools-debuginfo-3.125-150400.3.74.1 * mozilla-nss-tools-3.125-150400.3.74.1 * mozilla-nss-certs-3.125-150400.3.74.1 * libsoftokn3-3.125-150400.3.74.1 * mozilla-nspr-4.39-150400.12.3.1 * mozilla-nspr-debugsource-4.39-150400.12.3.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * mozilla-nss-sysinit-3.125-150400.3.74.1 * MozillaFirefox-debuginfo-153.2.0-150400.157.5.1 * mozilla-nss-3.125-150400.3.74.1 * libsoftokn3-debuginfo-3.125-150400.3.74.1 * MozillaFirefox-debugsource-153.2.0-150400.157.5.1 * MozillaFirefox-153.2.0-150400.157.5.1 * mozilla-nss-certs-debuginfo-3.125-150400.3.74.1 * libfreebl3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debuginfo-3.125-150400.3.74.1 * mozilla-nspr-devel-4.39-150400.12.3.1 * mozilla-nss-tools-3.125-150400.3.74.1 * mozilla-nspr-debugsource-4.39-150400.12.3.1 * mozilla-nspr-debuginfo-4.39-150400.12.3.1 * mozilla-nss-debugsource-3.125-150400.3.74.1 * MozillaFirefox-translations-other-153.2.0-150400.157.5.1 * mozilla-nss-sysinit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-certs-3.125-150400.3.74.1 * mozilla-nspr-4.39-150400.12.3.1 * MozillaFirefox-translations-common-153.2.0-150400.157.5.1 * MozillaFirefox-branding-SLE-153-150400.14.3.1 * libfreebl3-3.125-150400.3.74.1 * mozilla-nss-tools-debuginfo-3.125-150400.3.74.1 * libsoftokn3-3.125-150400.3.74.1 * mozilla-nss-devel-3.125-150400.3.74.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (x86_64) * mozilla-nspr-32bit-debuginfo-4.39-150400.12.3.1 * libsoftokn3-32bit-debuginfo-3.125-150400.3.74.1 * libfreebl3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-3.125-150400.3.74.1 * libsoftokn3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-3.125-150400.3.74.1 * mozilla-nspr-32bit-4.39-150400.12.3.1 * libfreebl3-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-debuginfo-3.125-150400.3.74.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * MozillaFirefox-devel-153.2.0-150400.157.5.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * mozilla-nss-sysinit-3.125-150400.3.74.1 * mozilla-nspr-debuginfo-4.39-150400.12.3.1 * mozilla-nss-certs-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debugsource-3.125-150400.3.74.1 * libfreebl3-3.125-150400.3.74.1 * mozilla-nss-3.125-150400.3.74.1 * libsoftokn3-debuginfo-3.125-150400.3.74.1 * libfreebl3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debuginfo-3.125-150400.3.74.1 * mozilla-nspr-devel-4.39-150400.12.3.1 * mozilla-nss-sysinit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-tools-debuginfo-3.125-150400.3.74.1 * mozilla-nss-tools-3.125-150400.3.74.1 * mozilla-nss-certs-3.125-150400.3.74.1 * libsoftokn3-3.125-150400.3.74.1 * mozilla-nspr-4.39-150400.12.3.1 * mozilla-nss-devel-3.125-150400.3.74.1 * mozilla-nspr-debugsource-4.39-150400.12.3.1 * Basesystem Module 15-SP7 (x86_64) * mozilla-nspr-32bit-debuginfo-4.39-150400.12.3.1 * libsoftokn3-32bit-debuginfo-3.125-150400.3.74.1 * libfreebl3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-3.125-150400.3.74.1 * libsoftokn3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-3.125-150400.3.74.1 * mozilla-nspr-32bit-4.39-150400.12.3.1 * libfreebl3-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-debuginfo-3.125-150400.3.74.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-common-153.2.0-150400.157.5.1 * MozillaFirefox-debuginfo-153.2.0-150400.157.5.1 * MozillaFirefox-branding-SLE-153-150400.14.3.1 * MozillaFirefox-translations-other-153.2.0-150400.157.5.1 * MozillaFirefox-debugsource-153.2.0-150400.157.5.1 * MozillaFirefox-153.2.0-150400.157.5.1 * Desktop Applications Module 15-SP7 (noarch) * MozillaFirefox-devel-153.2.0-150400.157.5.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * mozilla-nss-sysinit-3.125-150400.3.74.1 * MozillaFirefox-debuginfo-153.2.0-150400.157.5.1 * mozilla-nss-3.125-150400.3.74.1 * libsoftokn3-debuginfo-3.125-150400.3.74.1 * MozillaFirefox-debugsource-153.2.0-150400.157.5.1 * MozillaFirefox-153.2.0-150400.157.5.1 * mozilla-nss-certs-debuginfo-3.125-150400.3.74.1 * libfreebl3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debuginfo-3.125-150400.3.74.1 * mozilla-nspr-devel-4.39-150400.12.3.1 * mozilla-nss-tools-3.125-150400.3.74.1 * mozilla-nspr-debugsource-4.39-150400.12.3.1 * mozilla-nspr-debuginfo-4.39-150400.12.3.1 * mozilla-nss-debugsource-3.125-150400.3.74.1 * MozillaFirefox-translations-other-153.2.0-150400.157.5.1 * mozilla-nss-sysinit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-certs-3.125-150400.3.74.1 * mozilla-nspr-4.39-150400.12.3.1 * MozillaFirefox-translations-common-153.2.0-150400.157.5.1 * MozillaFirefox-branding-SLE-153-150400.14.3.1 * libfreebl3-3.125-150400.3.74.1 * mozilla-nss-tools-debuginfo-3.125-150400.3.74.1 * libsoftokn3-3.125-150400.3.74.1 * mozilla-nss-devel-3.125-150400.3.74.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (x86_64) * mozilla-nspr-32bit-debuginfo-4.39-150400.12.3.1 * libsoftokn3-32bit-debuginfo-3.125-150400.3.74.1 * libfreebl3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-3.125-150400.3.74.1 * libsoftokn3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-3.125-150400.3.74.1 * mozilla-nspr-32bit-4.39-150400.12.3.1 * libfreebl3-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-debuginfo-3.125-150400.3.74.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * MozillaFirefox-devel-153.2.0-150400.157.5.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * mozilla-nss-sysinit-3.125-150400.3.74.1 * MozillaFirefox-debuginfo-153.2.0-150400.157.5.1 * mozilla-nss-3.125-150400.3.74.1 * libsoftokn3-debuginfo-3.125-150400.3.74.1 * MozillaFirefox-debugsource-153.2.0-150400.157.5.1 * MozillaFirefox-153.2.0-150400.157.5.1 * mozilla-nss-certs-debuginfo-3.125-150400.3.74.1 * libfreebl3-debuginfo-3.125-150400.3.74.1 * mozilla-nss-debuginfo-3.125-150400.3.74.1 * mozilla-nspr-devel-4.39-150400.12.3.1 * mozilla-nss-tools-3.125-150400.3.74.1 * mozilla-nspr-debugsource-4.39-150400.12.3.1 * mozilla-nspr-debuginfo-4.39-150400.12.3.1 * mozilla-nss-debugsource-3.125-150400.3.74.1 * MozillaFirefox-translations-other-153.2.0-150400.157.5.1 * mozilla-nss-sysinit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-certs-3.125-150400.3.74.1 * mozilla-nspr-4.39-150400.12.3.1 * MozillaFirefox-translations-common-153.2.0-150400.157.5.1 * MozillaFirefox-branding-SLE-153-150400.14.3.1 * libfreebl3-3.125-150400.3.74.1 * mozilla-nss-tools-debuginfo-3.125-150400.3.74.1 * libsoftokn3-3.125-150400.3.74.1 * mozilla-nss-devel-3.125-150400.3.74.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * MozillaFirefox-devel-153.2.0-150400.157.5.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * mozilla-nspr-32bit-debuginfo-4.39-150400.12.3.1 * libsoftokn3-32bit-debuginfo-3.125-150400.3.74.1 * libfreebl3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-3.125-150400.3.74.1 * libsoftokn3-32bit-3.125-150400.3.74.1 * mozilla-nss-certs-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-3.125-150400.3.74.1 * mozilla-nspr-32bit-4.39-150400.12.3.1 * libfreebl3-32bit-debuginfo-3.125-150400.3.74.1 * mozilla-nss-32bit-debuginfo-3.125-150400.3.74.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16349.html * https://www.suse.com/security/cve/CVE-2026-16350.html * https://www.suse.com/security/cve/CVE-2026-16351.html * https://www.suse.com/security/cve/CVE-2026-16352.html * https://www.suse.com/security/cve/CVE-2026-16353.html * https://www.suse.com/security/cve/CVE-2026-16354.html * https://www.suse.com/security/cve/CVE-2026-16355.html * https://www.suse.com/security/cve/CVE-2026-16356.html * https://www.suse.com/security/cve/CVE-2026-16357.html * https://www.suse.com/security/cve/CVE-2026-16358.html * https://www.suse.com/security/cve/CVE-2026-16359.html * https://www.suse.com/security/cve/CVE-2026-16360.html * https://www.suse.com/security/cve/CVE-2026-16362.html * https://www.suse.com/security/cve/CVE-2026-16363.html * https://www.suse.com/security/cve/CVE-2026-16364.html * https://www.suse.com/security/cve/CVE-2026-16365.html * https://www.suse.com/security/cve/CVE-2026-16366.html * https://www.suse.com/security/cve/CVE-2026-16367.html * https://www.suse.com/security/cve/CVE-2026-16368.html * https://www.suse.com/security/cve/CVE-2026-16369.html * https://www.suse.com/security/cve/CVE-2026-16370.html * https://www.suse.com/security/cve/CVE-2026-16371.html * https://www.suse.com/security/cve/CVE-2026-16372.html * https://www.suse.com/security/cve/CVE-2026-16373.html * https://www.suse.com/security/cve/CVE-2026-16374.html * https://www.suse.com/security/cve/CVE-2026-16375.html * https://www.suse.com/security/cve/CVE-2026-16376.html * https://www.suse.com/security/cve/CVE-2026-16377.html * https://www.suse.com/security/cve/CVE-2026-16378.html * https://www.suse.com/security/cve/CVE-2026-16379.html * https://www.suse.com/security/cve/CVE-2026-16380.html * https://www.suse.com/security/cve/CVE-2026-16381.html * https://www.suse.com/security/cve/CVE-2026-16382.html * https://www.suse.com/security/cve/CVE-2026-16383.html * https://www.suse.com/security/cve/CVE-2026-16384.html * https://www.suse.com/security/cve/CVE-2026-16385.html * https://www.suse.com/security/cve/CVE-2026-16386.html * https://www.suse.com/security/cve/CVE-2026-16387.html * https://www.suse.com/security/cve/CVE-2026-16388.html * https://www.suse.com/security/cve/CVE-2026-16389.html * https://www.suse.com/security/cve/CVE-2026-16390.html * https://www.suse.com/security/cve/CVE-2026-16391.html * https://www.suse.com/security/cve/CVE-2026-16392.html * https://www.suse.com/security/cve/CVE-2026-16393.html * https://www.suse.com/security/cve/CVE-2026-16394.html * https://www.suse.com/security/cve/CVE-2026-16395.html * https://www.suse.com/security/cve/CVE-2026-16396.html * https://www.suse.com/security/cve/CVE-2026-16397.html * https://www.suse.com/security/cve/CVE-2026-16398.html * https://www.suse.com/security/cve/CVE-2026-16399.html * https://www.suse.com/security/cve/CVE-2026-16400.html * https://www.suse.com/security/cve/CVE-2026-16401.html * https://www.suse.com/security/cve/CVE-2026-16402.html * https://www.suse.com/security/cve/CVE-2026-16403.html * https://www.suse.com/security/cve/CVE-2026-16404.html * https://www.suse.com/security/cve/CVE-2026-16405.html * https://www.suse.com/security/cve/CVE-2026-16406.html * https://www.suse.com/security/cve/CVE-2026-16407.html * https://www.suse.com/security/cve/CVE-2026-16408.html * https://www.suse.com/security/cve/CVE-2026-16409.html * https://www.suse.com/security/cve/CVE-2026-16410.html * https://www.suse.com/security/cve/CVE-2026-16411.html * https://www.suse.com/security/cve/CVE-2026-16412.html * https://www.suse.com/security/cve/CVE-2026-74934.html * https://www.suse.com/security/cve/CVE-2026-74935.html * https://www.suse.com/security/cve/CVE-2026-74936.html * https://www.suse.com/security/cve/CVE-2026-74937.html * https://www.suse.com/security/cve/CVE-2026-74938.html * https://www.suse.com/security/cve/CVE-2026-74939.html * https://www.suse.com/security/cve/CVE-2026-74940.html * https://www.suse.com/security/cve/CVE-2026-74941.html * https://www.suse.com/security/cve/CVE-2026-74942.html * https://www.suse.com/security/cve/CVE-2026-74943.html * https://www.suse.com/security/cve/CVE-2026-74944.html * https://www.suse.com/security/cve/CVE-2026-74945.html * https://www.suse.com/security/cve/CVE-2026-74946.html * https://www.suse.com/security/cve/CVE-2026-74947.html * https://www.suse.com/security/cve/CVE-2026-74948.html * https://www.suse.com/security/cve/CVE-2026-74949.html * https://www.suse.com/security/cve/CVE-2026-74950.html * https://www.suse.com/security/cve/CVE-2026-74952.html * https://www.suse.com/security/cve/CVE-2026-74953.html * https://www.suse.com/security/cve/CVE-2026-74954.html * https://www.suse.com/security/cve/CVE-2026-74955.html * https://www.suse.com/security/cve/CVE-2026-74956.html * https://www.suse.com/security/cve/CVE-2026-74957.html * https://www.suse.com/security/cve/CVE-2026-74958.html * https://www.suse.com/security/cve/CVE-2026-74959.html * https://www.suse.com/security/cve/CVE-2026-74960.html * https://www.suse.com/security/cve/CVE-2026-74961.html * https://www.suse.com/security/cve/CVE-2026-74962.html * https://www.suse.com/security/cve/CVE-2026-74963.html * https://www.suse.com/security/cve/CVE-2026-74964.html * https://www.suse.com/security/cve/CVE-2026-74965.html * https://www.suse.com/security/cve/CVE-2026-74966.html * https://www.suse.com/security/cve/CVE-2026-74967.html * https://www.suse.com/security/cve/CVE-2026-74968.html * https://www.suse.com/security/cve/CVE-2026-74969.html * https://www.suse.com/security/cve/CVE-2026-74970.html * https://www.suse.com/security/cve/CVE-2026-74971.html * https://www.suse.com/security/cve/CVE-2026-74972.html * https://www.suse.com/security/cve/CVE-2026-74973.html * https://www.suse.com/security/cve/CVE-2026-74974.html * https://www.suse.com/security/cve/CVE-2026-74976.html * https://www.suse.com/security/cve/CVE-2026-74977.html * https://www.suse.com/security/cve/CVE-2026-74978.html * https://www.suse.com/security/cve/CVE-2026-74979.html * https://www.suse.com/security/cve/CVE-2026-74981.html * https://www.suse.com/security/cve/CVE-2026-74982.html * https://www.suse.com/security/cve/CVE-2026-74983.html * https://www.suse.com/security/cve/CVE-2026-74984.html * https://www.suse.com/security/cve/CVE-2026-74985.html * https://www.suse.com/security/cve/CVE-2026-74986.html * https://www.suse.com/security/cve/CVE-2026-74987.html * https://www.suse.com/security/cve/CVE-2026-74988.html * https://www.suse.com/security/cve/CVE-2026-74990.html * https://www.suse.com/security/cve/CVE-2026-75874.html * https://www.suse.com/security/cve/CVE-2026-84118.html * https://www.suse.com/security/cve/CVE-2026-84119.html * https://www.suse.com/security/cve/CVE-2026-84120.html * https://www.suse.com/security/cve/CVE-2026-84121.html * https://www.suse.com/security/cve/CVE-2026-84122.html * https://www.suse.com/security/cve/CVE-2026-84123.html * https://www.suse.com/security/cve/CVE-2026-84124.html * https://www.suse.com/security/cve/CVE-2026-84125.html * https://www.suse.com/security/cve/CVE-2026-84129.html * https://www.suse.com/security/cve/CVE-2026-84130.html * https://www.suse.com/security/cve/CVE-2026-84131.html * https://www.suse.com/security/cve/CVE-2026-84132.html * https://www.suse.com/security/cve/CVE-2026-84133.html * https://www.suse.com/security/cve/CVE-2026-84134.html * https://www.suse.com/security/cve/CVE-2026-84136.html * https://www.suse.com/security/cve/CVE-2026-84137.html * https://www.suse.com/security/cve/CVE-2026-84139.html * https://www.suse.com/security/cve/CVE-2026-84140.html * https://www.suse.com/security/cve/CVE-2026-84141.html * https://www.suse.com/security/cve/CVE-2026-84143.html * https://www.suse.com/security/cve/CVE-2026-84144.html * https://www.suse.com/security/cve/CVE-2026-84145.html * https://bugzilla.suse.com/show_bug.cgi?id=1226112 * https://bugzilla.suse.com/show_bug.cgi?id=1262698 * https://bugzilla.suse.com/show_bug.cgi?id=1262701 * https://bugzilla.suse.com/show_bug.cgi?id=1266262 * https://bugzilla.suse.com/show_bug.cgi?id=1266263 * https://bugzilla.suse.com/show_bug.cgi?id=1271649 * https://bugzilla.suse.com/show_bug.cgi?id=1272772 * https://bugzilla.suse.com/show_bug.cgi?id=1272773 * https://bugzilla.suse.com/show_bug.cgi?id=1272774 * https://bugzilla.suse.com/show_bug.cgi?id=1273243 * https://bugzilla.suse.com/show_bug.cgi?id=1274867 * https://bugzilla.suse.com/show_bug.cgi?id=1278001 * https://bugzilla.suse.com/show_bug.cgi?id=1279863 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:30:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:30:51 -0000 Subject: SUSE-SU-2026:23687-1: important: Security update for the Linux Kernel RT (Live Patch 3 for SUSE Linux Enterprise 16) Message-ID: <178941785177.21511.7681927622370910662@b9be41dc2e4b> # Security update for the Linux Kernel RT (Live Patch 3 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23687-1 Release Date: 2026-09-13T12:45:12Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.8.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1678 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_8-rt-12-160000.1.1 * kernel-livepatch-6_12_0-160000_8-rt-debuginfo-12-160000.1.1 * kernel-livepatch-SLE16-RT_Update_3-debugsource-12-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:31:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:31:37 -0000 Subject: SUSE-SU-2026:23686-1: important: Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise 16) Message-ID: <178941789754.21511.17968510617846671399@b9be41dc2e4b> # Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23686-1 Release Date: 2026-09-12T11:19:11Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.32.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1673 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_32-rt-7-160000.1.1 * kernel-livepatch-6_12_0-160000_32-rt-debuginfo-7-160000.1.1 * kernel-livepatch-SLE16-RT_Update_11-debugsource-7-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:32:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:32:22 -0000 Subject: SUSE-SU-2026:23685-1: important: Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise 16) Message-ID: <178941794211.21511.1320115008751131945@b9be41dc2e4b> # Security update for the Linux Kernel RT (Live Patch 10 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23685-1 Release Date: 2026-09-12T11:19:11Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.31.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1672 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-SLE16-RT_Update_10-debugsource-7-160000.1.1 * kernel-livepatch-6_12_0-160000_31-rt-debuginfo-7-160000.1.1 * kernel-livepatch-6_12_0-160000_31-rt-7-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:33:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:33:07 -0000 Subject: SUSE-SU-2026:23684-1: important: Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise 16) Message-ID: <178941798740.21511.7064785880562281207@b9be41dc2e4b> # Security update for the Linux Kernel RT (Live Patch 9 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23684-1 Release Date: 2026-09-12T11:19:11Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.30.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1671 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_30-rt-debuginfo-7-160000.1.1 * kernel-livepatch-6_12_0-160000_30-rt-7-160000.1.1 * kernel-livepatch-SLE16-RT_Update_9-debugsource-7-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:33:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:33:52 -0000 Subject: SUSE-SU-2026:23683-1: important: Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise 16) Message-ID: <178941803280.21511.8037106091800191765@b9be41dc2e4b> # Security update for the Linux Kernel RT (Live Patch 8 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23683-1 Release Date: 2026-09-12T11:19:11Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.29.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1670 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_29-rt-debuginfo-8-160000.1.1 * kernel-livepatch-6_12_0-160000_29-rt-8-160000.1.1 * kernel-livepatch-SLE16-RT_Update_8-debugsource-8-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:34:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:34:37 -0000 Subject: SUSE-SU-2026:23682-1: important: Security update for the Linux Kernel RT (Live Patch 7 for SUSE Linux Enterprise 16) Message-ID: <178941807755.21511.5972000082386358476@b9be41dc2e4b> # Security update for the Linux Kernel RT (Live Patch 7 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23682-1 Release Date: 2026-09-12T11:19:11Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.28.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1669 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_28-rt-debuginfo-9-160000.1.1 * kernel-livepatch-SLE16-RT_Update_7-debugsource-9-160000.1.1 * kernel-livepatch-6_12_0-160000_28-rt-9-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:35:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:35:22 -0000 Subject: SUSE-SU-2026:23681-1: important: Security update for the Linux Kernel RT (Live Patch 6 for SUSE Linux Enterprise 16) Message-ID: <178941812281.21511.12961386651794809675@b9be41dc2e4b> # Security update for the Linux Kernel RT (Live Patch 6 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23681-1 Release Date: 2026-09-12T11:19:11Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.27.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1668 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_27-rt-10-160000.1.1 * kernel-livepatch-SLE16-RT_Update_6-debugsource-10-160000.1.1 * kernel-livepatch-6_12_0-160000_27-rt-debuginfo-10-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:36:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:36:07 -0000 Subject: SUSE-SU-2026:23680-1: important: Security update for the Linux Kernel RT (Live Patch 5 for SUSE Linux Enterprise 16) Message-ID: <178941816747.21511.10248851909019363022@b9be41dc2e4b> # Security update for the Linux Kernel RT (Live Patch 5 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23680-1 Release Date: 2026-09-12T11:19:11Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.26.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1667 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_26-rt-11-160000.1.1 * kernel-livepatch-SLE16-RT_Update_5-debugsource-11-160000.1.1 * kernel-livepatch-6_12_0-160000_26-rt-debuginfo-11-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:36:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:36:52 -0000 Subject: SUSE-SU-2026:23679-1: important: Security update for the Linux Kernel RT (Live Patch 4 for SUSE Linux Enterprise 16) Message-ID: <178941821294.21511.4667358220068095975@b9be41dc2e4b> # Security update for the Linux Kernel RT (Live Patch 4 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23679-1 Release Date: 2026-09-12T11:19:11Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.9.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1666 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_9-rt-debuginfo-12-160000.1.1 * kernel-livepatch-6_12_0-160000_9-rt-12-160000.1.1 * kernel-livepatch-SLE16-RT_Update_4-debugsource-12-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:37:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:37:38 -0000 Subject: SUSE-SU-2026:23678-1: important: Security update for the Linux Kernel RT (Live Patch 2 for SUSE Linux Enterprise 16) Message-ID: <178941825863.21511.5199539829236732474@b9be41dc2e4b> # Security update for the Linux Kernel RT (Live Patch 2 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23678-1 Release Date: 2026-09-12T11:19:11Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.7.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1665 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_7-rt-13-160000.1.1 * kernel-livepatch-SLE16-RT_Update_2-debugsource-13-160000.1.1 * kernel-livepatch-6_12_0-160000_7-rt-debuginfo-13-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:38:23 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:38:23 -0000 Subject: SUSE-SU-2026:23677-1: important: Security update for the Linux Kernel RT (Live Patch 1 for SUSE Linux Enterprise 16) Message-ID: <178941830353.21511.9522100089847026587@b9be41dc2e4b> # Security update for the Linux Kernel RT (Live Patch 1 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23677-1 Release Date: 2026-09-12T11:19:11Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.6.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1664 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-SLE16-RT_Update_1-debugsource-15-160000.1.1 * kernel-livepatch-6_12_0-160000_6-rt-debuginfo-15-160000.1.1 * kernel-livepatch-6_12_0-160000_6-rt-15-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:39:08 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:39:08 -0000 Subject: SUSE-SU-2026:23676-1: important: Security update for the Linux Kernel RT (Live Patch 0 for SUSE Linux Enterprise 16) Message-ID: <178941834864.21511.6291638411014237506@b9be41dc2e4b> # Security update for the Linux Kernel RT (Live Patch 0 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23676-1 Release Date: 2026-09-12T11:19:11Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.5.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1663 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_5-rt-16-160000.3.4 * kernel-livepatch-6_12_0-160000_5-rt-debuginfo-16-160000.3.4 * kernel-livepatch-SLE16-RT_Update_0-debugsource-16-160000.3.4 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:39:48 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:39:48 -0000 Subject: SUSE-SU-2026:23675-1: important: Security update for the Linux Kernel RT (Live Patch 16 for SUSE Linux Enterprise 16) Message-ID: <178941838840.21511.6065925724491183374@b9be41dc2e4b> # Security update for the Linux Kernel RT (Live Patch 16 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23675-1 Release Date: 2026-09-12T11:17:46Z Rating: important References: * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.37.1 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1677 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_37-rt-2-160000.1.1 * kernel-livepatch-SLE16-RT_Update_16-debugsource-2-160000.1.1 * kernel-livepatch-6_12_0-160000_37-rt-debuginfo-2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:40:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:40:31 -0000 Subject: SUSE-SU-2026:23674-1: important: Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise 16) Message-ID: <178941843184.21511.10955610699149313413@b9be41dc2e4b> # Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23674-1 Release Date: 2026-09-12T11:17:46Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.35.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1676 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_35-rt-5-160000.1.1 * kernel-livepatch-6_12_0-160000_35-rt-debuginfo-5-160000.1.1 * kernel-livepatch-SLE16-RT_Update_14-debugsource-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:41:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:41:16 -0000 Subject: SUSE-SU-2026:23673-1: important: Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise 16) Message-ID: <178941847668.21511.8354568505291244532@b9be41dc2e4b> # Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23673-1 Release Date: 2026-09-12T11:17:46Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.34.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1675 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_34-rt-debuginfo-5-160000.1.1 * kernel-livepatch-6_12_0-160000_34-rt-5-160000.1.1 * kernel-livepatch-SLE16-RT_Update_13-debugsource-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:42:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:42:01 -0000 Subject: SUSE-SU-2026:23672-1: important: Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise 16) Message-ID: <178941852141.21511.5478098451652745122@b9be41dc2e4b> # Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23672-1 Release Date: 2026-09-12T11:17:45Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.33.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1674 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_33-rt-debuginfo-5-160000.1.1 * kernel-livepatch-6_12_0-160000_33-rt-5-160000.1.1 * kernel-livepatch-SLE16-RT_Update_12-debugsource-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:42:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:42:41 -0000 Subject: SUSE-SU-2026:23671-1: moderate: Security update for jq Message-ID: <178941856104.21511.13310999898474811711@b9be41dc2e4b> # Security update for jq Announcement ID: SUSE-SU-2026:23671-1 Release Date: 2026-09-11T14:59:34Z Rating: moderate References: * bsc#1265071 * bsc#1269221 Cross-References: * CVE-2026-43895 * CVE-2026-47770 CVSS scores: * CVE-2026-43895 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43895 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-43895 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-47770 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-47770 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47770 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for jq fixes the following issues: * CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure (bsc#1265071). * CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1662 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * jq-1.7.1-160000.5.1 * jq-debugsource-1.7.1-160000.5.1 * libjq1-debuginfo-1.7.1-160000.5.1 * jq-debuginfo-1.7.1-160000.5.1 * libjq1-1.7.1-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43895.html * https://www.suse.com/security/cve/CVE-2026-47770.html * https://bugzilla.suse.com/show_bug.cgi?id=1265071 * https://bugzilla.suse.com/show_bug.cgi?id=1269221 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:43:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:43:19 -0000 Subject: SUSE-SU-2026:23670-1: important: Security update for acl, attr Message-ID: <178941859933.21511.15548953280712973147@b9be41dc2e4b> # Security update for acl, attr Announcement ID: SUSE-SU-2026:23670-1 Release Date: 2026-09-11T11:56:09Z Rating: important References: * bsc#1268867 * jsc#PED-16501 Cross-References: * CVE-2026-54369 * CVE-2026-54370 * CVE-2026-54371 CVSS scores: * CVE-2026-54369 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-54369 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54369 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54369 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54369 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54370 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-54370 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54370 ( NVD ): 7.2 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54370 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54371 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-54371 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54371 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54371 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54371 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities and contains one feature can now be installed. ## Description: This update for acl, attr fixes the following issue: * CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: * Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: * The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. * When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. * When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. * When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: * When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ("Too many levels of symbolic links") error will result instead. * acl_delete_entry() now verifies that the specified entry belongs to the specified acl. * Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. * Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. * When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. * setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. * setfacl --restore accidentally called chmod() when in --test mode. It no longer does. * When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. * When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. * The -h (--no-dereference) option of getfattr prevented getfattr from recursing into "symbolic link directories". This is wrong. When dirlink is a symbolic link that refers to a directory, "getfattr -Rh dirlink" will now visit that directory. The -P (--physical) option can be used to prevent that. * Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: * Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: * The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. * When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. * When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. * When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: * When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ("Too many levels of symbolic links") error will result instead. * acl_delete_entry() now verifies that the specified entry belongs to the specified acl. * Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. * Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. * When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. * setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. * setfacl --restore accidentally called chmod() when in --test mode. It no longer does. * When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. * When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. * The -h (--no-dereference) option of getfattr prevented getfattr from recursing into "symbolic link directories". This is wrong. When dirlink is a symbolic link that refers to a directory, "getfattr -Rh dirlink" will now visit that directory. The -P (--physical) option can be used to prevent that. * Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1661 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libacl1-2.4.0-160000.1.1 * attr-2.6.0-160000.1.1 * acl-debugsource-2.4.0-160000.1.1 * libattr1-debuginfo-2.6.0-160000.1.1 * acl-debuginfo-2.4.0-160000.1.1 * attr-debugsource-2.6.0-160000.1.1 * libacl1-debuginfo-2.4.0-160000.1.1 * libattr1-2.6.0-160000.1.1 * acl-2.4.0-160000.1.1 * attr-debuginfo-2.6.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54369.html * https://www.suse.com/security/cve/CVE-2026-54370.html * https://www.suse.com/security/cve/CVE-2026-54371.html * https://bugzilla.suse.com/show_bug.cgi?id=1268867 * https://jira.suse.com/browse/PED-16501 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:44:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:44:51 -0000 Subject: SUSE-SU-2026:4180-1: important: Security update for clamav Message-ID: <178941869142.21511.2147693669845407302@b9be41dc2e4b> # Security update for clamav Announcement ID: SUSE-SU-2026:4180-1 Release Date: 2026-09-14T14:49:34Z Rating: important References: * bsc#1271922 * bsc#1274597 * bsc#1274598 * bsc#1274599 * bsc#1274600 * bsc#1274601 * bsc#1274602 * bsc#1274603 Cross-References: * CVE-2025-8088 * CVE-2026-20337 * CVE-2026-20338 * CVE-2026-20339 * CVE-2026-20345 * CVE-2026-20346 * CVE-2026-20347 * CVE-2026-20348 * CVE-2026-46671 CVSS scores: * CVE-2025-8088 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8088 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-20337 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20337 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20337 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20338 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20338 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20338 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20339 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20339 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20339 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20345 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20345 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20346 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20346 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20346 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20347 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20347 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20347 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20348 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20348 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20348 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46671 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-46671 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves nine vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues: * CVE-2026-20337: Improper boundary checks for content in zip archive parser (bsc#1274597). * CVE-2026-20338: invalid free due to bad ownership handling when merging ZIP catalogue records (bsc#1274598). * CVE-2026-20339: integer overflow in the PESpin unpacker leads to undersized allocation and heap out-of-bounds write (bsc#1274599). * CVE-2026-20345: out-of-bounds read/write via indexing error when converting GPT partition names (bsc#1274600). * CVE-2026-20346: integer underflow when parsing malformed PDF hex strings causes a crash (bsc#1274601). * CVE-2026-20347: integer overflow and undefined behavior when scanning malformed Mach-O files causes a crash (bsc#1274602). * CVE-2026-20348: improper size handling in the XAR parser allows excessive allocation and scan-limit bypass (bsc#1274603). * CVE-2026-46671: onenote_parser: Path traversal in `Parser:parse_notebook` allows reading files outside the notebook directory (bsc#1271922). * CVE-2025-8088: ejects path separators in NTFS alternate data stream names to prevent extraction outside ClamAV's temporary scan directory on Windows. Changes for clamav: Update to 1.5.4: * Fixed thread-safety issues in the clamd STATS command that could disclose process memory or crash the daemon while scans and STATS requests run concurrently. Also fixed partial socket-write handling used for large STATS responses. * FreeBSD: Restored support for safe quarantine move and remove actions while preserving protection against source-path replacement races. * Fixed an OpenSSL library-context leak in legacy hashing helpers when a requested message digest cannot be fetched, such as when the default provider is unavailable in a FIPS-enabled environment. * Upgraded the Rust crossbeam-epoch dependency to resolve the RUSTSEC-2026-0204 advisory. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4180 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4180 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4180 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4180 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * clamav-debugsource-1.5.4-150600.18.31.1 * clamav-debuginfo-1.5.4-150600.18.31.1 * libclammspack0-debuginfo-1.5.4-150600.18.31.1 * libclamav12-1.5.4-150600.18.31.1 * libclammspack0-1.5.4-150600.18.31.1 * clamav-milter-1.5.4-150600.18.31.1 * clamav-devel-1.5.4-150600.18.31.1 * libclamav12-debuginfo-1.5.4-150600.18.31.1 * libclamunrar12-debuginfo-1.5.4-150600.18.31.1 * libfreshclam4-debuginfo-1.5.4-150600.18.31.1 * libfreshclam4-1.5.4-150600.18.31.1 * clamav-milter-debuginfo-1.5.4-150600.18.31.1 * clamav-1.5.4-150600.18.31.1 * libclamunrar12-1.5.4-150600.18.31.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * clamav-docs-html-1.5.4-150600.18.31.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * clamav-debugsource-1.5.4-150600.18.31.1 * clamav-debuginfo-1.5.4-150600.18.31.1 * libclammspack0-debuginfo-1.5.4-150600.18.31.1 * libclamav12-1.5.4-150600.18.31.1 * libclammspack0-1.5.4-150600.18.31.1 * clamav-milter-1.5.4-150600.18.31.1 * clamav-devel-1.5.4-150600.18.31.1 * libclamav12-debuginfo-1.5.4-150600.18.31.1 * libclamunrar12-debuginfo-1.5.4-150600.18.31.1 * libfreshclam4-debuginfo-1.5.4-150600.18.31.1 * libfreshclam4-1.5.4-150600.18.31.1 * clamav-milter-debuginfo-1.5.4-150600.18.31.1 * clamav-1.5.4-150600.18.31.1 * libclamunrar12-1.5.4-150600.18.31.1 * openSUSE Leap 15.6 (noarch) * clamav-docs-html-1.5.4-150600.18.31.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * clamav-debugsource-1.5.4-150600.18.31.1 * clamav-debuginfo-1.5.4-150600.18.31.1 * libclammspack0-debuginfo-1.5.4-150600.18.31.1 * libclamav12-1.5.4-150600.18.31.1 * libclammspack0-1.5.4-150600.18.31.1 * clamav-milter-1.5.4-150600.18.31.1 * clamav-devel-1.5.4-150600.18.31.1 * libclamav12-debuginfo-1.5.4-150600.18.31.1 * libclamunrar12-debuginfo-1.5.4-150600.18.31.1 * libfreshclam4-debuginfo-1.5.4-150600.18.31.1 * libfreshclam4-1.5.4-150600.18.31.1 * clamav-milter-debuginfo-1.5.4-150600.18.31.1 * clamav-1.5.4-150600.18.31.1 * libclamunrar12-1.5.4-150600.18.31.1 * Basesystem Module 15-SP7 (noarch) * clamav-docs-html-1.5.4-150600.18.31.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * clamav-debugsource-1.5.4-150600.18.31.1 * clamav-debuginfo-1.5.4-150600.18.31.1 * libclammspack0-debuginfo-1.5.4-150600.18.31.1 * libclamav12-1.5.4-150600.18.31.1 * libclammspack0-1.5.4-150600.18.31.1 * clamav-milter-1.5.4-150600.18.31.1 * clamav-devel-1.5.4-150600.18.31.1 * libclamav12-debuginfo-1.5.4-150600.18.31.1 * libclamunrar12-debuginfo-1.5.4-150600.18.31.1 * libfreshclam4-debuginfo-1.5.4-150600.18.31.1 * libfreshclam4-1.5.4-150600.18.31.1 * clamav-milter-debuginfo-1.5.4-150600.18.31.1 * clamav-1.5.4-150600.18.31.1 * libclamunrar12-1.5.4-150600.18.31.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * clamav-docs-html-1.5.4-150600.18.31.1 ## References: * https://www.suse.com/security/cve/CVE-2025-8088.html * https://www.suse.com/security/cve/CVE-2026-20337.html * https://www.suse.com/security/cve/CVE-2026-20338.html * https://www.suse.com/security/cve/CVE-2026-20339.html * https://www.suse.com/security/cve/CVE-2026-20345.html * https://www.suse.com/security/cve/CVE-2026-20346.html * https://www.suse.com/security/cve/CVE-2026-20347.html * https://www.suse.com/security/cve/CVE-2026-20348.html * https://www.suse.com/security/cve/CVE-2026-46671.html * https://bugzilla.suse.com/show_bug.cgi?id=1271922 * https://bugzilla.suse.com/show_bug.cgi?id=1274597 * https://bugzilla.suse.com/show_bug.cgi?id=1274598 * https://bugzilla.suse.com/show_bug.cgi?id=1274599 * https://bugzilla.suse.com/show_bug.cgi?id=1274600 * https://bugzilla.suse.com/show_bug.cgi?id=1274601 * https://bugzilla.suse.com/show_bug.cgi?id=1274602 * https://bugzilla.suse.com/show_bug.cgi?id=1274603 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:45:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:45:55 -0000 Subject: SUSE-SU-2026:4179-1: important: Security update for clamav Message-ID: <178941875540.21511.4244298101006151282@b9be41dc2e4b> # Security update for clamav Announcement ID: SUSE-SU-2026:4179-1 Release Date: 2026-09-14T14:48:53Z Rating: important References: * bsc#1271922 * bsc#1274597 * bsc#1274598 * bsc#1274599 * bsc#1274600 * bsc#1274601 * bsc#1274602 * bsc#1274603 Cross-References: * CVE-2025-8088 * CVE-2026-20337 * CVE-2026-20338 * CVE-2026-20339 * CVE-2026-20345 * CVE-2026-20346 * CVE-2026-20347 * CVE-2026-20348 * CVE-2026-46671 CVSS scores: * CVE-2025-8088 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8088 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-20337 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20337 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20337 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20338 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20338 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20338 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20339 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20339 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20339 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20345 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20345 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20346 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20346 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20346 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20347 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20347 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20347 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20348 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20348 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20348 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46671 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-46671 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves nine vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues: * CVE-2026-20337: Improper boundary checks for content in zip archive parser (bsc#1274597). * CVE-2026-20338: invalid free due to bad ownership handling when merging ZIP catalogue records (bsc#1274598). * CVE-2026-20339: integer overflow in the PESpin unpacker leads to undersized allocation and heap out-of-bounds write (bsc#1274599). * CVE-2026-20345: out-of-bounds read/write via indexing error when converting GPT partition names (bsc#1274600). * CVE-2026-20346: integer underflow when parsing malformed PDF hex strings causes a crash (bsc#1274601). * CVE-2026-20347: integer overflow and undefined behavior when scanning malformed Mach-O files causes a crash (bsc#1274602). * CVE-2026-20348: improper size handling in the XAR parser allows excessive allocation and scan-limit bypass (bsc#1274603). * CVE-2026-46671: onenote_parser: Path traversal in `Parser:parse_notebook` allows reading files outside the notebook directory (bsc#1271922). * CVE-2025-8088: rejects path separators in NTFS alternate data stream names to prevent extraction outside ClamAV's temporary scan directory on Windows. Changes for clamav: Update to 1.5.4: * Fixed thread-safety issues in the clamd STATS command that could disclose process memory or crash the daemon while scans and STATS requests run concurrently. Also fixed partial socket-write handling used for large STATS responses. * FreeBSD: Restored support for safe quarantine move and remove actions while preserving protection against source-path replacement races. * Fixed an OpenSSL library-context leak in legacy hashing helpers when a requested message digest cannot be fetched, such as when the default provider is unavailable in a FIPS-enabled environment. * Upgraded the Rust crossbeam-epoch dependency to resolve the RUSTSEC-2026-0204 advisory. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4179 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4179 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libclamav12-debuginfo-1.5.4-3.59.1 * libclamunrar12-1.5.4-3.59.1 * libfreshclam4-debuginfo-1.5.4-3.59.1 * libclamav12-1.5.4-3.59.1 * clamav-milter-debuginfo-1.5.4-3.59.1 * libclammspack0-debuginfo-1.5.4-3.59.1 * clamav-debugsource-1.5.4-3.59.1 * clamav-milter-1.5.4-3.59.1 * libclamunrar12-debuginfo-1.5.4-3.59.1 * clamav-devel-1.5.4-3.59.1 * libclammspack0-1.5.4-3.59.1 * clamav-1.5.4-3.59.1 * clamav-debuginfo-1.5.4-3.59.1 * libfreshclam4-1.5.4-3.59.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * clamav-docs-html-1.5.4-3.59.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libclamav12-debuginfo-1.5.4-3.59.1 * libclamunrar12-1.5.4-3.59.1 * libfreshclam4-debuginfo-1.5.4-3.59.1 * libclamav12-1.5.4-3.59.1 * clamav-milter-debuginfo-1.5.4-3.59.1 * libclammspack0-debuginfo-1.5.4-3.59.1 * clamav-debugsource-1.5.4-3.59.1 * clamav-milter-1.5.4-3.59.1 * libclamunrar12-debuginfo-1.5.4-3.59.1 * clamav-devel-1.5.4-3.59.1 * libclammspack0-1.5.4-3.59.1 * clamav-1.5.4-3.59.1 * clamav-debuginfo-1.5.4-3.59.1 * libfreshclam4-1.5.4-3.59.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * clamav-docs-html-1.5.4-3.59.1 ## References: * https://www.suse.com/security/cve/CVE-2025-8088.html * https://www.suse.com/security/cve/CVE-2026-20337.html * https://www.suse.com/security/cve/CVE-2026-20338.html * https://www.suse.com/security/cve/CVE-2026-20339.html * https://www.suse.com/security/cve/CVE-2026-20345.html * https://www.suse.com/security/cve/CVE-2026-20346.html * https://www.suse.com/security/cve/CVE-2026-20347.html * https://www.suse.com/security/cve/CVE-2026-20348.html * https://www.suse.com/security/cve/CVE-2026-46671.html * https://bugzilla.suse.com/show_bug.cgi?id=1271922 * https://bugzilla.suse.com/show_bug.cgi?id=1274597 * https://bugzilla.suse.com/show_bug.cgi?id=1274598 * https://bugzilla.suse.com/show_bug.cgi?id=1274599 * https://bugzilla.suse.com/show_bug.cgi?id=1274600 * https://bugzilla.suse.com/show_bug.cgi?id=1274601 * https://bugzilla.suse.com/show_bug.cgi?id=1274602 * https://bugzilla.suse.com/show_bug.cgi?id=1274603 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:46:39 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:46:39 -0000 Subject: SUSE-SU-2026:4178-1: important: Security update for google-cloud-sap-agent Message-ID: <178941879909.21511.11997189577274769268@b9be41dc2e4b> # Security update for google-cloud-sap-agent Announcement ID: SUSE-SU-2026:4178-1 Release Date: 2026-09-14T14:48:31Z Rating: important References: * bsc#1210938 * bsc#1272128 * bsc#1278987 * bsc#1279201 * bsc#1279304 Cross-References: * CVE-2026-56852 * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84445 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves four vulnerabilities and has one security fix can now be installed. ## Description: This update for google-cloud-sap-agent fixes the following issues: Security issues fixed: * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272128). * CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279304). * CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279201). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278987). Non security issue fixed: * re-enable stripping and debuginfo (bsc#1210938). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2026-4178 ## Package List: * Public Cloud Module 12 (aarch64 ppc64le s390x x86_64) * google-cloud-sap-agent-3.15-6.81.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56852.html * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1210938 * https://bugzilla.suse.com/show_bug.cgi?id=1272128 * https://bugzilla.suse.com/show_bug.cgi?id=1278987 * https://bugzilla.suse.com/show_bug.cgi?id=1279201 * https://bugzilla.suse.com/show_bug.cgi?id=1279304 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 14 20:47:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 14 Sep 2026 20:47:51 -0000 Subject: SUSE-SU-2026:23585-1: important: Security update for openssl-3-x86_64-v3-livepatches Message-ID: <178941887169.21511.54476290087301821@b9be41dc2e4b> # Security update for openssl-3-x86_64-v3-livepatches Announcement ID: SUSE-SU-2026:23585-1 Release Date: 2026-08-31T07:42:43Z Rating: important References: * bsc#1271712 * bsc#1271713 * bsc#1274788 * bsc#1274790 * bsc#1274792 * bsc#1275133 * bsc#1275143 * bsc#1275145 Cross-References: * CVE-2026-14457 * CVE-2026-63072 * CVE-2026-63076 CVSS scores: * CVE-2026-14457 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-14457 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities and has five fixes can now be installed. ## Description: This update for openssl-3-x86_64-v3-livepatches fixes the following issues: * HollowByte: DoS vector against OpenSSL TLS ClientHello via remote, attacker- controlled memory allocations (bsc#1271713, bsc#1271712). * CVE-2026-14457: RPK server signature algorithm selection can dereference a missing certificate (bsc#1275145, bsc#1274792). * CVE-2026-63072: heap buffer overflow in CMS key unwrapping (bsc#1275133, bsc#1274788). * CVE-2026-63076: invalid pointer dereference in CMP server via crafted `protectionAlg` (bsc#1275143, bsc#1274790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1565 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1565 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * openssl-3-x86_64-v3-livepatches-0.6-160000.1.1 * openssl-3-x86_64-v3-livepatches-debugsource-0.6-160000.1.1 * openssl-3-x86_64-v3-livepatches-debuginfo-0.6-160000.1.1 * SUSE Linux Enterprise Server 16.0 (x86_64) * openssl-3-x86_64-v3-livepatches-0.6-160000.1.1 * openssl-3-x86_64-v3-livepatches-debugsource-0.6-160000.1.1 * openssl-3-x86_64-v3-livepatches-debuginfo-0.6-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14457.html * https://www.suse.com/security/cve/CVE-2026-63072.html * https://www.suse.com/security/cve/CVE-2026-63076.html * https://bugzilla.suse.com/show_bug.cgi?id=1271712 * https://bugzilla.suse.com/show_bug.cgi?id=1271713 * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1274790 * https://bugzilla.suse.com/show_bug.cgi?id=1274792 * https://bugzilla.suse.com/show_bug.cgi?id=1275133 * https://bugzilla.suse.com/show_bug.cgi?id=1275143 * https://bugzilla.suse.com/show_bug.cgi?id=1275145 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 15 12:30:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 15 Sep 2026 12:30:46 -0000 Subject: SUSE-SU-2026:4183-1: important: Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise 15 SP7) Message-ID: <178947544679.1625.12220374820460100272@55cee2c216ba> # Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:4183-1 Release Date: 2026-09-15T07:33:58Z Rating: important References: * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.78 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-4183 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4183 * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-4184 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_130-default-debuginfo-2-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_30-debugsource-2-150600.2.1 * kernel-livepatch-6_4_0-150600_23_130-default-2-150600.2.1 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_130-default-debuginfo-2-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_30-debugsource-2-150600.2.1 * kernel-livepatch-6_4_0-150600_23_130-default-2-150600.2.1 * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_78-default-2-150700.2.1 * kernel-livepatch-6_4_0-150700_53_78-default-debuginfo-2-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_20-debugsource-2-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 15 12:31:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 15 Sep 2026 12:31:46 -0000 Subject: SUSE-SU-2026:4182-1: important: Security update for perl-Protocol-HTTP2 Message-ID: <178947550615.1625.12212290714172360910@55cee2c216ba> # Security update for perl-Protocol-HTTP2 Announcement ID: SUSE-SU-2026:4182-1 Release Date: 2026-09-15T06:35:22Z Rating: important References: * bsc#1279629 Cross-References: * CVE-2026-16028 CVSS scores: * CVE-2026-16028 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-16028 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16028 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for perl-Protocol-HTTP2 fixes the following issue: * CVE-2026-16028: memory exhaustion leading to denial of service due to closed streams never being removed by `stream_state` from the connection stream table (bsc#1279629). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4182 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4182 ## Package List: * openSUSE Leap 15.6 (noarch) * perl-Protocol-HTTP2-1.10-150600.3.6.1 * SUSE Package Hub 15 15-SP7 (noarch) * perl-Protocol-HTTP2-1.10-150600.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-16028.html * https://bugzilla.suse.com/show_bug.cgi?id=1279629 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 15 12:32:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 15 Sep 2026 12:32:43 -0000 Subject: SUSE-SU-2026:4181-1: moderate: Security update for NetworkManager Message-ID: <178947556304.1625.10084839946850424631@55cee2c216ba> # Security update for NetworkManager Announcement ID: SUSE-SU-2026:4181-1 Release Date: 2026-09-15T06:35:06Z Rating: moderate References: * bsc#1257359 * bsc#1267696 Cross-References: * CVE-2025-9615 * CVE-2026-10805 CVSS scores: * CVE-2025-9615 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2025-9615 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-10805 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-10805 ( NVD ): 6.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for NetworkManager fixes the following issues: * CVE-2025-9615: avoid non-admin user using other users' certificate (bsc#1257359). * CVE-2026-10805: Local privilege escalation via malformed MUD URLs in dhclient backend (bsc#1267696). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4181 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libnm-util2-debuginfo-1.0.12-13.17.1 * typelib-1_0-NM-1_0-1.0.12-13.17.1 * libnm-util2-1.0.12-13.17.1 * libnm-glib-vpn1-debuginfo-1.0.12-13.17.1 * typelib-1_0-NetworkManager-1_0-1.0.12-13.17.1 * libnm-glib4-1.0.12-13.17.1 * NetworkManager-devel-1.0.12-13.17.1 * libnm0-1.0.12-13.17.1 * typelib-1_0-NMClient-1_0-1.0.12-13.17.1 * NetworkManager-debugsource-1.0.12-13.17.1 * libnm-glib4-debuginfo-1.0.12-13.17.1 * NetworkManager-debuginfo-1.0.12-13.17.1 * libnm0-debuginfo-1.0.12-13.17.1 * libnm-glib-vpn1-1.0.12-13.17.1 ## References: * https://www.suse.com/security/cve/CVE-2025-9615.html * https://www.suse.com/security/cve/CVE-2026-10805.html * https://bugzilla.suse.com/show_bug.cgi?id=1257359 * https://bugzilla.suse.com/show_bug.cgi?id=1267696 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 15 16:30:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 15 Sep 2026 16:30:41 -0000 Subject: SUSE-SU-2026:4185-1: important: Security update for the Linux Kernel (Live Patch 44 for SUSE Linux Enterprise 15 SP5) Message-ID: <178948984108.30454.3373832736404069655@b9be41dc2e4b> # Security update for the Linux Kernel (Live Patch 44 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:4185-1 Release Date: 2026-09-15T08:33:51Z Rating: important References: * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.182 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-4185 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-4185 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_44-debugsource-2-150500.2.1 * kernel-livepatch-5_14_21-150500_55_182-default-debuginfo-2-150500.2.1 * kernel-livepatch-5_14_21-150500_55_182-default-2-150500.2.1 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_44-debugsource-2-150500.2.1 * kernel-livepatch-5_14_21-150500_55_182-default-debuginfo-2-150500.2.1 * kernel-livepatch-5_14_21-150500_55_182-default-2-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 15 20:30:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 15 Sep 2026 20:30:36 -0000 Subject: SUSE-SU-2026:4193-1: important: Security update for the Linux Kernel (Live Patch 58 for SUSE Linux Enterprise 15 SP4) Message-ID: <178950423673.2274.11230811100165374960@c4bba689c63a> # Security update for the Linux Kernel (Live Patch 58 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:4193-1 Release Date: 2026-09-15T13:04:43Z Rating: important References: * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.235 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-4193 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4193 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_58-debugsource-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_235-default-debuginfo-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_235-default-2-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_58-debugsource-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_235-default-debuginfo-2-150400.2.1 * kernel-livepatch-5_14_21-150400_24_235-default-2-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 15 20:31:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 15 Sep 2026 20:31:36 -0000 Subject: SUSE-SU-2026:4192-1: important: Security update for the Linux Kernel (Live Patch 86 for SUSE Linux Enterprise 12 SP5) Message-ID: <178950429610.2274.15046605958039211704@c4bba689c63a> # Security update for the Linux Kernel (Live Patch 86 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:4192-1 Release Date: 2026-09-15T13:04:19Z Rating: important References: * bsc#1275458 Cross-References: * CVE-2026-64423 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.323 fixes one security issue: The following security issue was fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-4192 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_323-default-2-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 15 20:32:26 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 15 Sep 2026 20:32:26 -0000 Subject: SUSE-SU-2026:4195-1: important: Security update for libpcap Message-ID: <178950434635.2274.17110687169276812302@c4bba689c63a> # Security update for libpcap Announcement ID: SUSE-SU-2026:4195-1 Release Date: 2026-09-15T14:28:55Z Rating: important References: * bsc#1279584 * bsc#1279588 * bsc#1279593 * bsc#1279595 * bsc#1279782 * bsc#1279783 * bsc#1279784 Cross-References: * CVE-2026-0799 * CVE-2026-18238 * CVE-2026-18313 * CVE-2026-31911 * CVE-2026-31912 * CVE-2026-6244 * CVE-2026-6554 CVSS scores: * CVE-2026-0799 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-0799 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-0799 ( NVD ): 8.7 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H * CVE-2026-18238 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-18238 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-18238 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N * CVE-2026-18313 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-18313 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-18313 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-31911 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31911 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31911 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31912 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6244 ( SUSE ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6244 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6554 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-6554 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6554 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves seven vulnerabilities can now be installed. ## Description: This update for libpcap fixes the following issues: * CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a scratch memory register and allows for OOB access (bsc#1279782). * CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero (bsc#1279595). * CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584). * CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly validates its headers and allows for an OOB access (bsc#1279783). * CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ` message received from the client and never frees the memory (bsc#1279784). * CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588). * CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff (bsc#1279593). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4195 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4195 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4195 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4195 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4195 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4195 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4195 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4195 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4195 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4195 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4195 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4195 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4195 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4195 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libpcap-debugsource-1.10.1-150400.3.12.1 * libpcap1-1.10.1-150400.3.12.1 * libpcap-devel-1.10.1-150400.3.12.1 * libpcap1-debuginfo-1.10.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libpcap-debugsource-1.10.1-150400.3.12.1 * libpcap1-1.10.1-150400.3.12.1 * libpcap-devel-1.10.1-150400.3.12.1 * libpcap1-debuginfo-1.10.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libpcap-debugsource-1.10.1-150400.3.12.1 * libpcap1-1.10.1-150400.3.12.1 * libpcap-devel-1.10.1-150400.3.12.1 * libpcap1-debuginfo-1.10.1-150400.3.12.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libpcap1-debuginfo-1.10.1-150400.3.12.1 * libpcap-debugsource-1.10.1-150400.3.12.1 * libpcap-devel-1.10.1-150400.3.12.1 * libpcap1-1.10.1-150400.3.12.1 * libpcap-devel-static-1.10.1-150400.3.12.1 * openSUSE Leap 15.4 (x86_64) * libpcap-devel-32bit-1.10.1-150400.3.12.1 * libpcap1-32bit-debuginfo-1.10.1-150400.3.12.1 * libpcap1-32bit-1.10.1-150400.3.12.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libpcap-devel-64bit-1.10.1-150400.3.12.1 * libpcap1-64bit-1.10.1-150400.3.12.1 * libpcap1-64bit-debuginfo-1.10.1-150400.3.12.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libpcap-debugsource-1.10.1-150400.3.12.1 * libpcap1-1.10.1-150400.3.12.1 * libpcap1-debuginfo-1.10.1-150400.3.12.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libpcap-debugsource-1.10.1-150400.3.12.1 * libpcap1-1.10.1-150400.3.12.1 * libpcap1-debuginfo-1.10.1-150400.3.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libpcap-debugsource-1.10.1-150400.3.12.1 * libpcap1-1.10.1-150400.3.12.1 * libpcap-devel-1.10.1-150400.3.12.1 * libpcap1-debuginfo-1.10.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libpcap-debugsource-1.10.1-150400.3.12.1 * libpcap1-1.10.1-150400.3.12.1 * libpcap-devel-1.10.1-150400.3.12.1 * libpcap1-debuginfo-1.10.1-150400.3.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libpcap-debugsource-1.10.1-150400.3.12.1 * libpcap1-1.10.1-150400.3.12.1 * libpcap-devel-1.10.1-150400.3.12.1 * libpcap1-debuginfo-1.10.1-150400.3.12.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libpcap-debugsource-1.10.1-150400.3.12.1 * libpcap1-1.10.1-150400.3.12.1 * libpcap1-debuginfo-1.10.1-150400.3.12.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libpcap-debugsource-1.10.1-150400.3.12.1 * libpcap1-1.10.1-150400.3.12.1 * libpcap1-debuginfo-1.10.1-150400.3.12.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libpcap-debugsource-1.10.1-150400.3.12.1 * libpcap1-1.10.1-150400.3.12.1 * libpcap1-debuginfo-1.10.1-150400.3.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libpcap-debugsource-1.10.1-150400.3.12.1 * libpcap1-1.10.1-150400.3.12.1 * libpcap-devel-1.10.1-150400.3.12.1 * libpcap1-debuginfo-1.10.1-150400.3.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libpcap-debugsource-1.10.1-150400.3.12.1 * libpcap1-1.10.1-150400.3.12.1 * libpcap-devel-1.10.1-150400.3.12.1 * libpcap1-debuginfo-1.10.1-150400.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-0799.html * https://www.suse.com/security/cve/CVE-2026-18238.html * https://www.suse.com/security/cve/CVE-2026-18313.html * https://www.suse.com/security/cve/CVE-2026-31911.html * https://www.suse.com/security/cve/CVE-2026-31912.html * https://www.suse.com/security/cve/CVE-2026-6244.html * https://www.suse.com/security/cve/CVE-2026-6554.html * https://bugzilla.suse.com/show_bug.cgi?id=1279584 * https://bugzilla.suse.com/show_bug.cgi?id=1279588 * https://bugzilla.suse.com/show_bug.cgi?id=1279593 * https://bugzilla.suse.com/show_bug.cgi?id=1279595 * https://bugzilla.suse.com/show_bug.cgi?id=1279782 * https://bugzilla.suse.com/show_bug.cgi?id=1279783 * https://bugzilla.suse.com/show_bug.cgi?id=1279784 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 15 20:33:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 15 Sep 2026 20:33:28 -0000 Subject: SUSE-SU-2026:4194-1: important: Security update for libpcap Message-ID: <178950440895.2274.3923670068694208805@c4bba689c63a> # Security update for libpcap Announcement ID: SUSE-SU-2026:4194-1 Release Date: 2026-09-15T14:27:54Z Rating: important References: * bsc#1279584 * bsc#1279588 * bsc#1279593 * bsc#1279595 * bsc#1279782 * bsc#1279783 * bsc#1279784 Cross-References: * CVE-2026-0799 * CVE-2026-18238 * CVE-2026-18313 * CVE-2026-31911 * CVE-2026-31912 * CVE-2026-6244 * CVE-2026-6554 CVSS scores: * CVE-2026-0799 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-0799 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-0799 ( NVD ): 8.7 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H * CVE-2026-18238 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-18238 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-18238 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N * CVE-2026-18313 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-18313 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-18313 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-31911 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31911 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31911 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31912 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6244 ( SUSE ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6244 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6554 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-6554 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6554 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves seven vulnerabilities can now be installed. ## Description: This update for libpcap fixes the following issues: * CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a scratch memory register and allows for OOB access (bsc#1279782). * CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero (bsc#1279595). * CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584). * CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly validates its headers and allows for an OOB access (bsc#1279783). * CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ` message received from the client and never frees the memory (bsc#1279784). * CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588). * CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff (bsc#1279593). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4194 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4194 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4194 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libpcap1-debuginfo-1.10.4-150600.3.12.1 * libpcap-debugsource-1.10.4-150600.3.12.1 * libpcap-devel-1.10.4-150600.3.12.1 * libpcap1-1.10.4-150600.3.12.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libpcap-debugsource-1.10.4-150600.3.12.1 * libpcap-devel-static-1.10.4-150600.3.12.1 * libpcap1-debuginfo-1.10.4-150600.3.12.1 * libpcap-devel-1.10.4-150600.3.12.1 * libpcap1-1.10.4-150600.3.12.1 * openSUSE Leap 15.6 (x86_64) * libpcap-devel-32bit-1.10.4-150600.3.12.1 * libpcap1-32bit-1.10.4-150600.3.12.1 * libpcap1-32bit-debuginfo-1.10.4-150600.3.12.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libpcap-devel-64bit-1.10.4-150600.3.12.1 * libpcap1-64bit-1.10.4-150600.3.12.1 * libpcap1-64bit-debuginfo-1.10.4-150600.3.12.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libpcap1-debuginfo-1.10.4-150600.3.12.1 * libpcap-debugsource-1.10.4-150600.3.12.1 * libpcap-devel-1.10.4-150600.3.12.1 * libpcap1-1.10.4-150600.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-0799.html * https://www.suse.com/security/cve/CVE-2026-18238.html * https://www.suse.com/security/cve/CVE-2026-18313.html * https://www.suse.com/security/cve/CVE-2026-31911.html * https://www.suse.com/security/cve/CVE-2026-31912.html * https://www.suse.com/security/cve/CVE-2026-6244.html * https://www.suse.com/security/cve/CVE-2026-6554.html * https://bugzilla.suse.com/show_bug.cgi?id=1279584 * https://bugzilla.suse.com/show_bug.cgi?id=1279588 * https://bugzilla.suse.com/show_bug.cgi?id=1279593 * https://bugzilla.suse.com/show_bug.cgi?id=1279595 * https://bugzilla.suse.com/show_bug.cgi?id=1279782 * https://bugzilla.suse.com/show_bug.cgi?id=1279783 * https://bugzilla.suse.com/show_bug.cgi?id=1279784 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 15 20:34:26 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 15 Sep 2026 20:34:26 -0000 Subject: SUSE-SU-2026:4191-1: important: Security update for python-GitPython Message-ID: <178950446683.2274.1771304337030548955@c4bba689c63a> # Security update for python-GitPython Announcement ID: SUSE-SU-2026:4191-1 Release Date: 2026-09-15T12:36:10Z Rating: important References: * bsc#1279905 * bsc#1279906 * bsc#1279907 Cross-References: * CVE-2026-87817 * CVE-2026-87818 * CVE-2026-87819 CVSS scores: * CVE-2026-87817 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-87817 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-87817 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-87817 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-87818 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-87818 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-87818 ( NVD ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-87818 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-87819 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-87819 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-87819 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * Python 3 Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for python-GitPython fixes the following issues: * CVE-2026-87817: failure to properly validade the git directory location allows attackers to impersonate the git directory using tracked files and execute arbitrary code by placing pre-commit hooks in the tracked hooks directory (bsc#1279905). * CVE-2026-87818: failure to restrict the `--no-index` option in the high- level diff API allows attackers to read arbitrary filesystem paths as repository operands and create content-dependent Boolean oracles (bsc#1279906). * CVE-2026-87819: quadratic backtracking in the `Actor.name_email_regex` regular expression allows attackers to cause CPU exhaustion and a DoS via a commit with a malformed author field (bsc#1279907). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4191 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4191 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4191 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4191 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4191 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4191 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4191 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4191 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4191 * Python 3 Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Python3-15-SP7-2026-4191 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4191 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4191 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.11.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.11.1 * openSUSE Leap 15.4 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.11.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.11.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.11.1 * Python 3 Module 15-SP7 (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.11.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.11.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * python311-GitPython-3.1.34.1693646983.2a2ae77-150400.9.11.1 ## References: * https://www.suse.com/security/cve/CVE-2026-87817.html * https://www.suse.com/security/cve/CVE-2026-87818.html * https://www.suse.com/security/cve/CVE-2026-87819.html * https://bugzilla.suse.com/show_bug.cgi?id=1279905 * https://bugzilla.suse.com/show_bug.cgi?id=1279906 * https://bugzilla.suse.com/show_bug.cgi?id=1279907 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 15 20:35:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 15 Sep 2026 20:35:32 -0000 Subject: SUSE-SU-2026:4190-1: important: Security update for the Linux Kernel Message-ID: <178950453292.2274.14451707647203071791@c4bba689c63a> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:4190-1 Release Date: 2026-09-15T12:34:16Z Rating: important References: * bsc#1267369 * bsc#1269159 * bsc#1269306 * bsc#1269655 * bsc#1272385 * bsc#1273869 * bsc#1274888 * bsc#1275161 * bsc#1278294 Cross-References: * CVE-2026-46116 * CVE-2026-52955 * CVE-2026-53059 * CVE-2026-53163 * CVE-2026-63887 * CVE-2026-68121 * CVE-2026-68202 * CVE-2026-72389 * CVE-2026-80580 CVSS scores: * CVE-2026-46116 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-46116 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46116 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52955 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52955 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53059 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53059 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53059 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63887 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63887 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63887 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68121 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68121 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68202 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72389 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80580 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80580 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80580 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 11 SP4 * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE An update that solves nine vulnerabilities can now be installed. ## Description: The SUSE Linux Enterprise 11 SP4 kernel was updated to fix various security issues: The following security issues were fixed: * CVE-2026-46116: xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete (bsc#1267369). * CVE-2026-52955: libceph: Fix potential out-of-bounds access in crush_decode() (bsc#1269159). * CVE-2026-53059: dm mirror log: clear log bits up to BITS_PER_LONG boundary (bsc#1269655). * CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). * CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). * CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). * CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). * CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). * CVE-2026-80580: fbdev: bound mode sysfs output to the sysfs buffer (bsc#1278294). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2026-4190 * SUSE Linux Enterprise Server 11 SP4 zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2026-4190 ## Package List: * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE (nosrc x86_64) * kernel-xen-3.0.101-108.220.1 * kernel-trace-3.0.101-108.220.1 * kernel-ec2-3.0.101-108.220.1 * kernel-default-3.0.101-108.220.1 * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE (x86_64) * kernel-ec2-debugsource-3.0.101-108.220.1 * kernel-trace-debuginfo-3.0.101-108.220.1 * kernel-trace-debugsource-3.0.101-108.220.1 * kernel-trace-devel-debuginfo-3.0.101-108.220.1 * kernel-ec2-devel-debuginfo-3.0.101-108.220.1 * kernel-xen-base-3.0.101-108.220.1 * kernel-source-3.0.101-108.220.1 * kernel-default-base-3.0.101-108.220.1 * kernel-xen-debugsource-3.0.101-108.220.1 * kernel-default-devel-debuginfo-3.0.101-108.220.1 * kernel-default-debuginfo-3.0.101-108.220.1 * kernel-xen-debuginfo-3.0.101-108.220.1 * kernel-ec2-devel-3.0.101-108.220.1 * kernel-default-debugsource-3.0.101-108.220.1 * kernel-xen-devel-3.0.101-108.220.1 * kernel-ec2-debuginfo-3.0.101-108.220.1 * kernel-trace-devel-3.0.101-108.220.1 * kernel-xen-devel-debuginfo-3.0.101-108.220.1 * kernel-ec2-base-3.0.101-108.220.1 * kernel-syms-3.0.101-108.220.1 * kernel-default-devel-3.0.101-108.220.1 * kernel-trace-base-3.0.101-108.220.1 * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE (noarch nosrc) * kernel-docs-3.0.101-108.220.1 * SUSE Linux Enterprise Server 11 SP4 (nosrc x86_64) * kernel-xen-3.0.101-108.220.1 * kernel-trace-3.0.101-108.220.1 * kernel-ec2-3.0.101-108.220.1 * kernel-default-3.0.101-108.220.1 * SUSE Linux Enterprise Server 11 SP4 (x86_64) * kernel-ec2-debugsource-3.0.101-108.220.1 * kernel-trace-debuginfo-3.0.101-108.220.1 * kernel-trace-debugsource-3.0.101-108.220.1 * kernel-trace-devel-debuginfo-3.0.101-108.220.1 * kernel-ec2-devel-debuginfo-3.0.101-108.220.1 * kernel-xen-base-3.0.101-108.220.1 * kernel-source-3.0.101-108.220.1 * kernel-default-base-3.0.101-108.220.1 * kernel-xen-debugsource-3.0.101-108.220.1 * kernel-default-devel-debuginfo-3.0.101-108.220.1 * kernel-default-debuginfo-3.0.101-108.220.1 * kernel-xen-debuginfo-3.0.101-108.220.1 * kernel-ec2-devel-3.0.101-108.220.1 * kernel-default-debugsource-3.0.101-108.220.1 * kernel-xen-devel-3.0.101-108.220.1 * kernel-ec2-debuginfo-3.0.101-108.220.1 * kernel-trace-devel-3.0.101-108.220.1 * kernel-xen-devel-debuginfo-3.0.101-108.220.1 * kernel-ec2-base-3.0.101-108.220.1 * kernel-syms-3.0.101-108.220.1 * kernel-default-devel-3.0.101-108.220.1 * kernel-trace-base-3.0.101-108.220.1 * SUSE Linux Enterprise Server 11 SP4 (noarch nosrc) * kernel-docs-3.0.101-108.220.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46116.html * https://www.suse.com/security/cve/CVE-2026-52955.html * https://www.suse.com/security/cve/CVE-2026-53059.html * https://www.suse.com/security/cve/CVE-2026-53163.html * https://www.suse.com/security/cve/CVE-2026-63887.html * https://www.suse.com/security/cve/CVE-2026-68121.html * https://www.suse.com/security/cve/CVE-2026-68202.html * https://www.suse.com/security/cve/CVE-2026-72389.html * https://www.suse.com/security/cve/CVE-2026-80580.html * https://bugzilla.suse.com/show_bug.cgi?id=1267369 * https://bugzilla.suse.com/show_bug.cgi?id=1269159 * https://bugzilla.suse.com/show_bug.cgi?id=1269306 * https://bugzilla.suse.com/show_bug.cgi?id=1269655 * https://bugzilla.suse.com/show_bug.cgi?id=1272385 * https://bugzilla.suse.com/show_bug.cgi?id=1273869 * https://bugzilla.suse.com/show_bug.cgi?id=1274888 * https://bugzilla.suse.com/show_bug.cgi?id=1275161 * https://bugzilla.suse.com/show_bug.cgi?id=1278294 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 15 20:36:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 15 Sep 2026 20:36:18 -0000 Subject: SUSE-SU-2026:4189-1: moderate: Security update for python310 Message-ID: <178950457800.2274.11275598325364880429@c4bba689c63a> # Security update for python310 Announcement ID: SUSE-SU-2026:4189-1 Release Date: 2026-09-15T12:33:40Z Rating: moderate References: * bsc#1257599 * bsc#1262467 * bsc#1263083 * bsc#1273091 * bsc#1276903 * bsc#1277271 Cross-References: * CVE-2026-13346 * CVE-2026-1703 * CVE-2026-3219 * CVE-2026-6019 CVSS scores: * CVE-2026-13346 ( SUSE ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-13346 ( SUSE ): 4.2 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:N/I:H/A:N * CVE-2026-13346 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-13346 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-1703 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-1703 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-1703 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3219 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3219 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-3219 ( NVD ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( SUSE ): 3.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N * CVE-2026-6019 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6019 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.4 An update that solves four vulnerabilities and has two security fixes can now be installed. ## Description: This update for python310 fixes the following issues: Security issues fixed: * CVE-2026-1703: files may be extracted outside the installation directory when installing and extracting maliciously crafted wheel archives (bsc#1257599). * CVE-2026-3219: pip doesn't reject concatenated ZIP (bsc#1262467) * CVE-2026-13346: Arbitrary file installation via malicious package indexes (bsc#1273091). * CVE-2026-6019: Fixed regression introduced in fix that does not handle non- ascii chars correctly in `http.cookies` (bsc#1263083). Non security issue fixed: * [sle15spx][python3.6.15]"Error: Command '['/root/data/myenv/bin/python3.6', '-Im', 'ensurepip', '\--upgrade', '\-- default-pip']' returned non-zero exit status 1." (bsc#1277271). * Update bundled pip wheels to pip-20.0.2-py2.py3-none-any.whl patched from SUSE:SLE-15-SP4:Update/python3-pip ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4189 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * python310-base-3.10.20-150400.4.121.1 * python310-idle-3.10.20-150400.4.121.1 * python310-tools-3.10.20-150400.4.121.1 * python310-core-debugsource-3.10.20-150400.4.121.1 * python310-testsuite-3.10.20-150400.4.121.1 * python310-base-debuginfo-3.10.20-150400.4.121.1 * python310-curses-debuginfo-3.10.20-150400.4.121.1 * libpython3_10-1_0-debuginfo-3.10.20-150400.4.121.1 * python310-debugsource-3.10.20-150400.4.121.1 * python310-tk-3.10.20-150400.4.121.1 * python310-doc-devhelp-3.10.20-150400.4.121.1 * python310-3.10.20-150400.4.121.1 * libpython3_10-1_0-3.10.20-150400.4.121.1 * python310-curses-3.10.20-150400.4.121.1 * python310-tk-debuginfo-3.10.20-150400.4.121.1 * python310-devel-3.10.20-150400.4.121.1 * python310-dbm-debuginfo-3.10.20-150400.4.121.1 * python310-doc-3.10.20-150400.4.121.1 * python310-debuginfo-3.10.20-150400.4.121.1 * python310-dbm-3.10.20-150400.4.121.1 * python310-testsuite-debuginfo-3.10.20-150400.4.121.1 * openSUSE Leap 15.4 (x86_64) * python310-base-32bit-debuginfo-3.10.20-150400.4.121.1 * libpython3_10-1_0-32bit-debuginfo-3.10.20-150400.4.121.1 * libpython3_10-1_0-32bit-3.10.20-150400.4.121.1 * python310-32bit-debuginfo-3.10.20-150400.4.121.1 * python310-32bit-3.10.20-150400.4.121.1 * python310-base-32bit-3.10.20-150400.4.121.1 * openSUSE Leap 15.4 (aarch64_ilp32) * python310-64bit-3.10.20-150400.4.121.1 * python310-base-64bit-debuginfo-3.10.20-150400.4.121.1 * libpython3_10-1_0-64bit-debuginfo-3.10.20-150400.4.121.1 * python310-64bit-debuginfo-3.10.20-150400.4.121.1 * python310-base-64bit-3.10.20-150400.4.121.1 * libpython3_10-1_0-64bit-3.10.20-150400.4.121.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13346.html * https://www.suse.com/security/cve/CVE-2026-1703.html * https://www.suse.com/security/cve/CVE-2026-3219.html * https://www.suse.com/security/cve/CVE-2026-6019.html * https://bugzilla.suse.com/show_bug.cgi?id=1257599 * https://bugzilla.suse.com/show_bug.cgi?id=1262467 * https://bugzilla.suse.com/show_bug.cgi?id=1263083 * https://bugzilla.suse.com/show_bug.cgi?id=1273091 * https://bugzilla.suse.com/show_bug.cgi?id=1276903 * https://bugzilla.suse.com/show_bug.cgi?id=1277271 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 15 20:37:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 15 Sep 2026 20:37:19 -0000 Subject: SUSE-SU-2026:4188-1: important: Security update for libpcap Message-ID: <178950463939.2274.3958776114372743174@c4bba689c63a> # Security update for libpcap Announcement ID: SUSE-SU-2026:4188-1 Release Date: 2026-09-15T12:33:16Z Rating: important References: * bsc#1279584 * bsc#1279588 * bsc#1279593 * bsc#1279595 * bsc#1279782 * bsc#1279783 * bsc#1279784 Cross-References: * CVE-2026-0799 * CVE-2026-18238 * CVE-2026-18313 * CVE-2026-31911 * CVE-2026-31912 * CVE-2026-6244 * CVE-2026-6554 CVSS scores: * CVE-2026-0799 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-0799 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-0799 ( NVD ): 8.7 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H * CVE-2026-18238 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-18238 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-18238 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N * CVE-2026-18313 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-18313 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-18313 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-31911 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31911 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31911 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31912 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6244 ( SUSE ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6244 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6554 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-6554 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6554 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves seven vulnerabilities can now be installed. ## Description: This update for libpcap fixes the following issues: * CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a scratch memory register and allows for OOB access (bsc#1279782). * CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero (bsc#1279595). * CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584). * CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly validates its headers and allows for an OOB access (bsc#1279783). * CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ` message received from the client and never frees the memory (bsc#1279784). * CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588). * CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff (bsc#1279593). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4188 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4188 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libpcap1-debuginfo-1.10.5-150700.3.13.1 * libpcap-debugsource-1.10.5-150700.3.13.1 * libpcap1-1.10.5-150700.3.13.1 * libpcap-devel-1.10.5-150700.3.13.1 * SUSE Package Hub 15 15-SP7 (x86_64) * libpcap1-32bit-debuginfo-1.10.5-150700.3.13.1 * libpcap1-32bit-1.10.5-150700.3.13.1 ## References: * https://www.suse.com/security/cve/CVE-2026-0799.html * https://www.suse.com/security/cve/CVE-2026-18238.html * https://www.suse.com/security/cve/CVE-2026-18313.html * https://www.suse.com/security/cve/CVE-2026-31911.html * https://www.suse.com/security/cve/CVE-2026-31912.html * https://www.suse.com/security/cve/CVE-2026-6244.html * https://www.suse.com/security/cve/CVE-2026-6554.html * https://bugzilla.suse.com/show_bug.cgi?id=1279584 * https://bugzilla.suse.com/show_bug.cgi?id=1279588 * https://bugzilla.suse.com/show_bug.cgi?id=1279593 * https://bugzilla.suse.com/show_bug.cgi?id=1279595 * https://bugzilla.suse.com/show_bug.cgi?id=1279782 * https://bugzilla.suse.com/show_bug.cgi?id=1279783 * https://bugzilla.suse.com/show_bug.cgi?id=1279784 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 15 20:37:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 15 Sep 2026 20:37:58 -0000 Subject: SUSE-SU-2026:4187-1: moderate: Security update for 389-ds Message-ID: <178950467811.2274.6033843578106516828@c4bba689c63a> # Security update for 389-ds Announcement ID: SUSE-SU-2026:4187-1 Release Date: 2026-09-15T12:32:54Z Rating: moderate References: * bsc#1268065 Cross-References: * CVE-2026-11785 CVSS scores: * CVE-2026-11785 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-11785 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-11785 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for 389-ds fixes the following issue: * CVE-2026-11785: type confusion in the SSO token handler can cause partial stack address information disclosure (bsc#1268065). Changes for 389-ds: * Update to version 2.0.20~git94.63d290b04: * Issue 7774 - Add backport action (#7775) * Issue 7733 - Typo about nsuniqueid in tombstone_to_conflict (#7734) * Issue 7688 - BUG - partial address leak in sso token (#7689) * Issue 7560 - lib389 - Add helper function for checking ASAN files ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4187 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * 389-ds-debugsource-2.0.20~git94.63d290b04-150400.3.54.2 * 389-ds-snmp-2.0.20~git94.63d290b04-150400.3.54.2 * 389-ds-devel-2.0.20~git94.63d290b04-150400.3.54.2 * 389-ds-2.0.20~git94.63d290b04-150400.3.54.2 * 389-ds-snmp-debuginfo-2.0.20~git94.63d290b04-150400.3.54.2 * 389-ds-debuginfo-2.0.20~git94.63d290b04-150400.3.54.2 * libsvrcore0-debuginfo-2.0.20~git94.63d290b04-150400.3.54.2 * lib389-2.0.20~git94.63d290b04-150400.3.54.2 * libsvrcore0-2.0.20~git94.63d290b04-150400.3.54.2 ## References: * https://www.suse.com/security/cve/CVE-2026-11785.html * https://bugzilla.suse.com/show_bug.cgi?id=1268065 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:30:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:30:44 -0000 Subject: SUSE-SU-2026:23729-1: important: Security update for google-cloud-sap-agent Message-ID: <178957624413.26114.13621082068768245778@b9be41dc2e4b> # Security update for google-cloud-sap-agent Announcement ID: SUSE-SU-2026:23729-1 Release Date: 2026-09-14T08:49:02Z Rating: important References: * bsc#1210938 * bsc#1272128 * bsc#1278987 * bsc#1279201 * bsc#1279304 Cross-References: * CVE-2026-56852 * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84445 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities and has one fix can now be installed. ## Description: This update for google-cloud-sap-agent fixes the following issues: Security issues fixed: * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272128). * CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279304). * CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279201). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278987). Non security issue fixed: * re-enable stripping and debuginfo (bsc#1210938). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1679 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * google-cloud-sap-agent-3.15-160000.4.1 * google-cloud-sap-agent-debuginfo-3.15-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56852.html * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1210938 * https://bugzilla.suse.com/show_bug.cgi?id=1272128 * https://bugzilla.suse.com/show_bug.cgi?id=1278987 * https://bugzilla.suse.com/show_bug.cgi?id=1279201 * https://bugzilla.suse.com/show_bug.cgi?id=1279304 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:31:24 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:31:24 -0000 Subject: SUSE-SU-2026:23728-1: moderate: Security update for jq Message-ID: <178957628403.26114.2200466256089004123@b9be41dc2e4b> # Security update for jq Announcement ID: SUSE-SU-2026:23728-1 Release Date: 2026-09-11T14:59:34Z Rating: moderate References: * bsc#1265071 * bsc#1269221 Cross-References: * CVE-2026-43895 * CVE-2026-47770 CVSS scores: * CVE-2026-43895 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43895 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-43895 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-47770 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-47770 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47770 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for jq fixes the following issues: * CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure (bsc#1265071). * CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1662 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1662 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * jq-1.7.1-160000.5.1 * jq-debugsource-1.7.1-160000.5.1 * libjq1-debuginfo-1.7.1-160000.5.1 * jq-debuginfo-1.7.1-160000.5.1 * libjq1-1.7.1-160000.5.1 * libjq-devel-1.7.1-160000.5.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * jq-1.7.1-160000.5.1 * jq-debugsource-1.7.1-160000.5.1 * libjq1-debuginfo-1.7.1-160000.5.1 * jq-debuginfo-1.7.1-160000.5.1 * libjq1-1.7.1-160000.5.1 * libjq-devel-1.7.1-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43895.html * https://www.suse.com/security/cve/CVE-2026-47770.html * https://bugzilla.suse.com/show_bug.cgi?id=1265071 * https://bugzilla.suse.com/show_bug.cgi?id=1269221 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:32:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:32:11 -0000 Subject: SUSE-SU-2026:23727-1: important: Security update for clamav Message-ID: <178957633145.26114.2327448948254379347@b9be41dc2e4b> # Security update for clamav Announcement ID: SUSE-SU-2026:23727-1 Release Date: 2026-09-11T12:10:01Z Rating: important References: * bsc#1271922 * bsc#1274597 * bsc#1274598 * bsc#1274599 * bsc#1274600 * bsc#1274601 * bsc#1274602 * bsc#1274603 Cross-References: * CVE-2025-8088 * CVE-2026-20337 * CVE-2026-20338 * CVE-2026-20339 * CVE-2026-20345 * CVE-2026-20346 * CVE-2026-20347 * CVE-2026-20348 * CVE-2026-46671 CVSS scores: * CVE-2025-8088 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8088 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-20337 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20337 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20337 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20338 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20338 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20338 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20339 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20339 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20339 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20345 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20345 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20346 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20346 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20346 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20347 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20347 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20347 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20348 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20348 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20348 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46671 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-46671 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves nine vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues: * CVE-2026-20337: Improper boundary checks for content in zip archive parser (bsc#1274597). * CVE-2026-20338: invalid free due to bad ownership handling when merging ZIP catalogue records (bsc#1274598). * CVE-2026-20339: integer overflow in the PESpin unpacker leads to undersized allocation and heap out-of-bounds write (bsc#1274599). * CVE-2026-20345: out-of-bounds read/write via indexing error when converting GPT partition names (bsc#1274600). * CVE-2026-20346: integer underflow when parsing malformed PDF hex strings causes a crash (bsc#1274601). * CVE-2026-20347: integer overflow and undefined behavior when scanning malformed Mach-O files causes a crash (bsc#1274602). * CVE-2026-20348: improper size handling in the XAR parser allows excessive allocation and scan-limit bypass (bsc#1274603). * CVE-2026-46671: onenote_parser: Path traversal in `Parser:parse_notebook` allows reading files outside the notebook directory (bsc#1271922). * CVE-2025-8088: rejects path separators in NTFS alternate data stream names to prevent extraction outside ClamAV's temporary scan directory on Windows. Changes for clamav: Update to 1.5.4: * Fixed thread-safety issues in the clamd STATS command that could disclose process memory or crash the daemon while scans and STATS requests run concurrently. Also fixed partial socket-write handling used for large STATS responses. * FreeBSD: Restored support for safe quarantine move and remove actions while preserving protection against source-path replacement races. * Fixed an OpenSSL library-context leak in legacy hashing helpers when a requested message digest cannot be fetched, such as when the default provider is unavailable in a FIPS-enabled environment. * Upgraded the Rust crossbeam-epoch dependency to resolve the RUSTSEC-2026-0204 advisory. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1660 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1660 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * clamav-milter-debuginfo-1.5.4-160000.1.1 * clamav-milter-1.5.4-160000.1.1 * clamav-devel-1.5.4-160000.1.1 * clamav-debuginfo-1.5.4-160000.1.1 * libclammspack0-1.5.4-160000.1.1 * libfreshclam4-1.5.4-160000.1.1 * libclammspack0-debuginfo-1.5.4-160000.1.1 * libfreshclam4-debuginfo-1.5.4-160000.1.1 * libclamav12-debuginfo-1.5.4-160000.1.1 * clamav-debugsource-1.5.4-160000.1.1 * libclamav12-1.5.4-160000.1.1 * clamav-1.5.4-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * clamav-docs-html-1.5.4-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * clamav-milter-debuginfo-1.5.4-160000.1.1 * clamav-milter-1.5.4-160000.1.1 * clamav-devel-1.5.4-160000.1.1 * clamav-debuginfo-1.5.4-160000.1.1 * libclammspack0-1.5.4-160000.1.1 * libfreshclam4-1.5.4-160000.1.1 * libclammspack0-debuginfo-1.5.4-160000.1.1 * libfreshclam4-debuginfo-1.5.4-160000.1.1 * libclamav12-debuginfo-1.5.4-160000.1.1 * clamav-debugsource-1.5.4-160000.1.1 * libclamav12-1.5.4-160000.1.1 * clamav-1.5.4-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * clamav-docs-html-1.5.4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-8088.html * https://www.suse.com/security/cve/CVE-2026-20337.html * https://www.suse.com/security/cve/CVE-2026-20338.html * https://www.suse.com/security/cve/CVE-2026-20339.html * https://www.suse.com/security/cve/CVE-2026-20345.html * https://www.suse.com/security/cve/CVE-2026-20346.html * https://www.suse.com/security/cve/CVE-2026-20347.html * https://www.suse.com/security/cve/CVE-2026-20348.html * https://www.suse.com/security/cve/CVE-2026-46671.html * https://bugzilla.suse.com/show_bug.cgi?id=1271922 * https://bugzilla.suse.com/show_bug.cgi?id=1274597 * https://bugzilla.suse.com/show_bug.cgi?id=1274598 * https://bugzilla.suse.com/show_bug.cgi?id=1274599 * https://bugzilla.suse.com/show_bug.cgi?id=1274600 * https://bugzilla.suse.com/show_bug.cgi?id=1274601 * https://bugzilla.suse.com/show_bug.cgi?id=1274602 * https://bugzilla.suse.com/show_bug.cgi?id=1274603 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:32:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:32:50 -0000 Subject: SUSE-SU-2026:23726-1: important: Security update for acl, attr Message-ID: <178957637042.26114.11795443892641105065@b9be41dc2e4b> # Security update for acl, attr Announcement ID: SUSE-SU-2026:23726-1 Release Date: 2026-09-11T11:56:09Z Rating: important References: * bsc#1268867 * jsc#PED-16501 Cross-References: * CVE-2026-54369 * CVE-2026-54370 * CVE-2026-54371 CVSS scores: * CVE-2026-54369 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-54369 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54369 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54369 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54369 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54370 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-54370 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54370 ( NVD ): 7.2 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54370 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54371 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-54371 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54371 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54371 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54371 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities and contains one feature can now be installed. ## Description: This update for acl, attr fixes the following issue: * CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: * Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: * The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. * When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. * When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. * When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: * When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ("Too many levels of symbolic links") error will result instead. * acl_delete_entry() now verifies that the specified entry belongs to the specified acl. * Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. * Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. * When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. * setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. * setfacl --restore accidentally called chmod() when in --test mode. It no longer does. * When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. * When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. * The -h (--no-dereference) option of getfattr prevented getfattr from recursing into "symbolic link directories". This is wrong. When dirlink is a symbolic link that refers to a directory, "getfattr -Rh dirlink" will now visit that directory. The -P (--physical) option can be used to prevent that. * Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: * Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: * The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. * When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. * When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. * When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: * When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ("Too many levels of symbolic links") error will result instead. * acl_delete_entry() now verifies that the specified entry belongs to the specified acl. * Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. * Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. * When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. * setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. * setfacl --restore accidentally called chmod() when in --test mode. It no longer does. * When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. * When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. * The -h (--no-dereference) option of getfattr prevented getfattr from recursing into "symbolic link directories". This is wrong. When dirlink is a symbolic link that refers to a directory, "getfattr -Rh dirlink" will now visit that directory. The -P (--physical) option can be used to prevent that. * Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1661 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1661 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libacl1-2.4.0-160000.1.1 * libattr-devel-static-2.6.0-160000.1.1 * libacl-devel-2.4.0-160000.1.1 * libattr-devel-2.6.0-160000.1.1 * attr-2.6.0-160000.1.1 * acl-debugsource-2.4.0-160000.1.1 * libattr1-debuginfo-2.6.0-160000.1.1 * acl-debuginfo-2.4.0-160000.1.1 * attr-debugsource-2.6.0-160000.1.1 * libacl1-debuginfo-2.4.0-160000.1.1 * libattr1-2.6.0-160000.1.1 * acl-2.4.0-160000.1.1 * attr-debuginfo-2.6.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libacl1-2.4.0-160000.1.1 * libattr-devel-static-2.6.0-160000.1.1 * libacl-devel-2.4.0-160000.1.1 * libattr-devel-2.6.0-160000.1.1 * attr-2.6.0-160000.1.1 * acl-debugsource-2.4.0-160000.1.1 * libattr1-debuginfo-2.6.0-160000.1.1 * acl-debuginfo-2.4.0-160000.1.1 * attr-debugsource-2.6.0-160000.1.1 * libacl1-debuginfo-2.4.0-160000.1.1 * libattr1-2.6.0-160000.1.1 * acl-2.4.0-160000.1.1 * attr-debuginfo-2.6.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54369.html * https://www.suse.com/security/cve/CVE-2026-54370.html * https://www.suse.com/security/cve/CVE-2026-54371.html * https://bugzilla.suse.com/show_bug.cgi?id=1268867 * https://jira.suse.com/browse/PED-16501 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:33:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:33:51 -0000 Subject: SUSE-SU-2026:23724-1: important: Security update for ansible-core Message-ID: <178957643181.26114.2978932565846713522@b9be41dc2e4b> # Security update for ansible-core Announcement ID: SUSE-SU-2026:23724-1 Release Date: 2026-09-10T13:02:09Z Rating: important References: * bsc#1272369 Cross-References: * CVE-2026-11332 * CVE-2026-16493 CVSS scores: * CVE-2026-11332 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11332 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11332 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16493 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16493 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for ansible-core fixes the following issues: * CVE-2026-16493: argument injection in ansible-galaxy collection install via git clone (bsc#1272369). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1657 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1657 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * ansible-core-2.18.3-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * ansible-core-2.18.3-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11332.html * https://www.suse.com/security/cve/CVE-2026-16493.html * https://bugzilla.suse.com/show_bug.cgi?id=1272369 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:34:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:34:55 -0000 Subject: SUSE-SU-2026:23722-1: moderate: Security update for python-jwcrypto Message-ID: <178957649525.26114.11176348640447292586@b9be41dc2e4b> # Security update for python-jwcrypto Announcement ID: SUSE-SU-2026:23722-1 Release Date: 2026-09-10T09:38:19Z Rating: moderate References: * bsc#1277639 * bsc#1278707 Cross-References: * CVE-2026-80179 * CVE-2026-84185 CVSS scores: * CVE-2026-80179 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-80179 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-80179 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84185 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84185 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-84185 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-jwcrypto fixes the following issues: * CVE-2026-80179: denial of service via malformed JWE tokens (bsc#1277639). * CVE-2026-84185: general JSON JWS kid binding bypass during JWKSet verification (bsc#1278707). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1655 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1655 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * python313-jwcrypto-1.5.6-160000.4.1 * SUSE Linux Enterprise Server 16.0 (noarch) * python313-jwcrypto-1.5.6-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-80179.html * https://www.suse.com/security/cve/CVE-2026-84185.html * https://bugzilla.suse.com/show_bug.cgi?id=1277639 * https://bugzilla.suse.com/show_bug.cgi?id=1278707 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:36:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:36:09 -0000 Subject: SUSE-SU-2026:23720-1: important: Security update for tomcat Message-ID: <178957656933.26114.4962979617091421523@b9be41dc2e4b> # Security update for tomcat Announcement ID: SUSE-SU-2026:23720-1 Release Date: 2026-09-09T14:18:23Z Rating: important References: * bsc#1273150 * bsc#1276893 * bsc#1276894 * bsc#1276895 * bsc#1276896 * bsc#1276897 * bsc#1276898 * bsc#1276899 * bsc#1276900 * bsc#1276901 * bsc#1276902 Cross-References: * CVE-2026-32990 * CVE-2026-65182 * CVE-2026-65183 * CVE-2026-65637 * CVE-2026-65905 * CVE-2026-65927 * CVE-2026-66299 * CVE-2026-66422 * CVE-2026-68525 * CVE-2026-68569 * CVE-2026-68763 * CVE-2026-73180 CVSS scores: * CVE-2026-32990 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-65182 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65182 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-65182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-65183 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65183 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65637 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65637 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65637 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65905 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65905 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-65905 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65927 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65927 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-66299 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-66422 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-66422 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-66422 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-68525 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68525 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68525 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68569 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68569 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68569 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68763 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68763 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68763 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73180 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-73180 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-73180 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 12 vulnerabilities can now be installed. ## Description: This update for tomcat fixes the following issues: * CVE-2026-65182: Bypass longest prefix security constraint (bsc#1276893). * CVE-2026-65183: TOCTOU when setting specific permissions for Unix Domain Sockets (bsc#1276894). * CVE-2026-65637: HTTP/2 no-authority bypass of strict SNI validation - fix incomplete (bsc#1276895). * CVE-2026-65905: Limited replay attack possible with DIGEST authentication (bsc#1276896). * CVE-2026-65927: RewriteValve [N] restarts at the second rule and may bypass access control (bsc#1276897). * CVE-2026-66299: memory exhaustion via maliciously slow clients due to the WebSocket chat example providing an unbounded buffer for undelivered messages (bsc#1273150). * CVE-2026-66422: Servlet role references can bypass declarative role constraints (bsc#1276898). * CVE-2026-68525: Redirect after FORM auth may bypass method specific constraints (bsc#1276899). * CVE-2026-68569: Principal lookup can fail open in some cases (bsc#1276900). * CVE-2026-68763: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset (bsc#1276901). * CVE-2026-73180: Authenticated WebSocket session survives end of HTTP session (bsc#1276902). Changes for tomcat: * Update to Tomcat 9.0.121 * Catalina * Fix: Ensure that a login-config conflict when merging web.xml fragments triggers a deployment failure. (markt) * Code: Remove unnecessary calls to String.intern() in the parsing of configuration files. (markt) * Fix: Extend sessionAttributeValueClassNameFilter to include filtering of dynamic proxy interface classes. (markt) * Fix: Attempt to use rollback when persisting user data to the DataSourceUserDatabase fails and improve error reporting. (remm) * Fix: 70143: Handle InvalidFileNameException when parsing parts to rethrow it as an IllegalStateException as mandated by the Servlet specification. (remm) * Fix: Add missing reason to the JsonErrorReportValve. (remm) * Fix: evaluation of the N and C flags for rewrite rules. (remm) * Fix: qsd flag should always discard the original query string when rewriting. (remm) * Fix: Add appropriate escaping for context path, current directory name and parent directory name for directory listings produced by the default servlet. Ensure XML escaping is used with XML output. (markt) * Fix: When processing certificate subject names and issuer names within RewriteValve rules, always use the RFC 2253 format name. (markt) * Fix: the incorrect rejection of requests using digest authentication when the client provided nonce count is at the upper boundary of the window (markt). * Update: Separate the Context role mapping from the Servlet specification security-role-ref. (remm) * Fix: Handle the case where the JNDIRealm is configured to perform role searches with userRoleAttribute but the attribute is not available or not configured for the current user. (markt) * Fix: Improve handling of session attribute addition concurrent with session expiration. An application will now either see a successful addition followed by expiration or the addition will not succeed. It is no longer possible for the session to expire and the addition to succeed. This is of particular not for attributes that implement HttpSessionBindingListener. (markt) * Fix: Add a new attribute to the Context, urlPatternsProvidedInDecodedForm. This attribute controls whether URLs and URL patterns provided in the deployment descriptor (web.xml), annotations and/or their programmatic equivalents are treated as being provided in URL-encoded form (i.e. using %nn encoding) or in decoded form. The Servlet specification requires that they are provided in decoded form. However, Tomcat has historically treated them as if they are provided in encoded form. In Tomcat 12, they will always be treated as if they are provided in decoded form. This setting enables migration from encoded form to decoded form on an application by application basis. This attribute will be removed in Tomcat 12 where it will effectively be hard-coded to true. (markt) * Fix: Ensure the security constraint with the longest matching path is selected when more than one constraint matches the request path. (markt) * Fix: If the request saved by FORM authentication uses a method other than GET, ensure that the security constraints are re-assessed after the saved request is restored and before it is processed. Custom Authenticator implementations that extend FormAuthenticator and override doAuthenticate() and/or restoreRequest() will require modification. (markt) * Fix: Various improvements to the DataSourceRealm. A failure to connect to the database or an exception during either user or role lookup will now result in an authentication failure rather than a partially populated Principal. For CLIENT-CERT and SPNEGO authentication, the user must exist in the database for authentication to succeed. (markt) * Coyote * Update: Add utility AutoCloseable URLConnection wrapper, and use it to cleanup existing code patterns. (remm/markt) * Fix: When processing an HTTP upgrade from HTTP/1.1 to HTTP/2, ensure that all the HTTP/1.1 data has been processed before switching protocols. (markt) * Fix: Require every HTTP/2 request to provide an authority (either an :authority pseudo header or a Host header). (markt) * Fix: Register the use of an HTTP/2 stream identifier earlier so that there is no possibility of a re-used stream identifier being accepted, regardless of how early in the HEADERS frame processing an error is detected. (markt) * Add: new attributes (unixDomainSocketParentPermissions and unixDomainSocketParentOwner) to the NIO connector to provide additional control over the security of Unix Domain Sockets. Additional checks (enabled by default) have also been added for the directory where the Unix Domain Socket will be created.(markt) * Fix: an allocation leak in the HTTP/2 backlog tracking when a stream is reset. (markt) * Jasper * Fix: Ensure internal state is reset before re-using ELParser. (markt) * WebSocket * Add: a limit (defaults to 8KB) on the size of the HTTP response headers accepted during a WebSocket HTTP upgrade. This is configured via the org.apache.tomcat.websocket.MAX_HTTP_RESPONSE_HEADER_BYTES user property. (markt) * Fix: Improve URI template matching for WebSocket end points. Trailing slashes are now significant both for template definitions and URIs considered for potential matches to those URIs. Note that this means if a URI template ends in a variable without a trailing slash, that variable might be expanded to the empty string. (markt) * Fix: Account for session ID changes when tracking WebSocket connections for closure because they were created under an authenticated HTTP session that has since ended. (markt) * Web applications * Fix: Documentation: Better sample httpd configuration for use with SSLValve and add a note that the exact configuration required will depend on the overall httpd configuration. (markt) * Fix: Examples: Limit the buffering of messages in the WebSocket chat example to prevent a malicious client triggering excessive memory usage that could lead to a DoS. (markt) * Fix: Documentation: Expand the description of the %S (session ID) access log pattern token. (markt) * Fix: Manager: Use reflection to load clustering classes in sessionsList.jsp so the sessions list page renders correctly when clustering JARs are not present. (csutherl) * Other * Update: Maven Resolver Ant Tasks to 1.6.1. (rjung) * Update: Objenesis to 3.6. (markt) * Update: JSign to 7.5. (markt) * Update: Bouncy Castle to 1.85. (markt) * Add: Improvements to French translations. (remm) * Add: Improvements to Japanese translations provided by tak7iji. (markt) * Cluster * Add: Change the default encryptionAlgorithm for the EncryptInterceptor to AES/GCM/NoPadding. This is a breaking change for the EncryptInterceptor. (markt) * Add: Expand the documentation for the EncryptInterceptor to be more explicit regarding the security weaknesses of some supported algorithms. Also explicitly state that the replay protection is only effective for non- malleable algorithms. (markt) * Add: Expand the Javadoc for the DNSMembershipProvider in particular explaining its behaviour and providing configuration advice if control more over cluster membership is required. (markt) * jdbc-pool * Fix: 70164: Correct the documentation for the testOnBorrow attribute. Pull request #1033 provided by Kohei Tamura. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1651 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1651 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * tomcat-servlet-4_0-api-9.0.121-160000.1.1 * tomcat-jsvc-9.0.121-160000.1.1 * tomcat-docs-webapp-9.0.121-160000.1.1 * tomcat-9.0.121-160000.1.1 * tomcat-lib-9.0.121-160000.1.1 * tomcat-embed-9.0.121-160000.1.1 * tomcat-webapps-9.0.121-160000.1.1 * tomcat-admin-webapps-9.0.121-160000.1.1 * tomcat-jsp-2_3-api-9.0.121-160000.1.1 * tomcat-javadoc-9.0.121-160000.1.1 * tomcat-el-3_0-api-9.0.121-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * tomcat-servlet-4_0-api-9.0.121-160000.1.1 * tomcat-jsvc-9.0.121-160000.1.1 * tomcat-docs-webapp-9.0.121-160000.1.1 * tomcat-9.0.121-160000.1.1 * tomcat-lib-9.0.121-160000.1.1 * tomcat-embed-9.0.121-160000.1.1 * tomcat-webapps-9.0.121-160000.1.1 * tomcat-admin-webapps-9.0.121-160000.1.1 * tomcat-jsp-2_3-api-9.0.121-160000.1.1 * tomcat-javadoc-9.0.121-160000.1.1 * tomcat-el-3_0-api-9.0.121-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32990.html * https://www.suse.com/security/cve/CVE-2026-65182.html * https://www.suse.com/security/cve/CVE-2026-65183.html * https://www.suse.com/security/cve/CVE-2026-65637.html * https://www.suse.com/security/cve/CVE-2026-65905.html * https://www.suse.com/security/cve/CVE-2026-65927.html * https://www.suse.com/security/cve/CVE-2026-66299.html * https://www.suse.com/security/cve/CVE-2026-66422.html * https://www.suse.com/security/cve/CVE-2026-68525.html * https://www.suse.com/security/cve/CVE-2026-68569.html * https://www.suse.com/security/cve/CVE-2026-68763.html * https://www.suse.com/security/cve/CVE-2026-73180.html * https://bugzilla.suse.com/show_bug.cgi?id=1273150 * https://bugzilla.suse.com/show_bug.cgi?id=1276893 * https://bugzilla.suse.com/show_bug.cgi?id=1276894 * https://bugzilla.suse.com/show_bug.cgi?id=1276895 * https://bugzilla.suse.com/show_bug.cgi?id=1276896 * https://bugzilla.suse.com/show_bug.cgi?id=1276897 * https://bugzilla.suse.com/show_bug.cgi?id=1276898 * https://bugzilla.suse.com/show_bug.cgi?id=1276899 * https://bugzilla.suse.com/show_bug.cgi?id=1276900 * https://bugzilla.suse.com/show_bug.cgi?id=1276901 * https://bugzilla.suse.com/show_bug.cgi?id=1276902 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:37:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:37:31 -0000 Subject: SUSE-SU-2026:23717-1: moderate: Security update for opensc Message-ID: <178957665170.26114.16065010418862953990@b9be41dc2e4b> # Security update for opensc Announcement ID: SUSE-SU-2026:23717-1 Release Date: 2026-09-09T14:08:11Z Rating: moderate References: * bsc#1266964 Cross-References: * CVE-2026-40510 CVSS scores: * CVE-2026-40510 ( SUSE ): 4.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-40510 ( SUSE ): 5.7 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-40510 ( NVD ): 1.0 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40510 ( NVD ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-40510 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for opensc fixes the following issue: * CVE-2026-40510: stack buffer overflow in `piv_process_history()` allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device (bsc#1266964). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1648 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1648 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * opensc-0.26.1-160000.4.1 * opensc-debuginfo-0.26.1-160000.4.1 * opensc-debugsource-0.26.1-160000.4.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * opensc-0.26.1-160000.4.1 * opensc-debuginfo-0.26.1-160000.4.1 * opensc-debugsource-0.26.1-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40510.html * https://bugzilla.suse.com/show_bug.cgi?id=1266964 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:38:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:38:33 -0000 Subject: SUSE-SU-2026:23715-1: moderate: Security update for libcupsfilters Message-ID: <178957671345.26114.13343579364191027586@b9be41dc2e4b> # Security update for libcupsfilters Announcement ID: SUSE-SU-2026:23715-1 Release Date: 2026-09-09T13:12:21Z Rating: moderate References: * bsc#1273145 * bsc#1273146 Cross-References: * CVE-2026-64611 * CVE-2026-64612 CVSS scores: * CVE-2026-64611 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64611 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64611 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64612 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64612 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64612 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for libcupsfilters fixes the following issues: * CVE-2026-64611: infinite-loop CPU-exhaustion DoS in cfIEEE1284NormalizeMakeModel on empty MDL field (bsc#1273145). * CVE-2026-64612: malformed PNG aborts CUPS image filter process (bsc#1273146). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1646 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1646 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libcupsfilters2-debuginfo-2.1.1-160000.3.1 * libcupsfilters-2.1.1-160000.3.1 * libcupsfilters2-2.1.1-160000.3.1 * libcupsfilters-devel-2.1.1-160000.3.1 * libcupsfilters-debugsource-2.1.1-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libcupsfilters2-debuginfo-2.1.1-160000.3.1 * libcupsfilters-2.1.1-160000.3.1 * libcupsfilters2-2.1.1-160000.3.1 * libcupsfilters-devel-2.1.1-160000.3.1 * libcupsfilters-debugsource-2.1.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64611.html * https://www.suse.com/security/cve/CVE-2026-64612.html * https://bugzilla.suse.com/show_bug.cgi?id=1273145 * https://bugzilla.suse.com/show_bug.cgi?id=1273146 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:39:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:39:54 -0000 Subject: SUSE-SU-2026:23712-1: low: Security update for govulncheck-vulndb Message-ID: <178957679422.26114.14143631537480107178@b9be41dc2e4b> # Security update for govulncheck-vulndb Announcement ID: SUSE-SU-2026:23712-1 Release Date: 2026-09-08T16:52:09Z Rating: low References: * jsc#PED-11136 Cross-References: * CVE-2026-20909 * CVE-2026-22547 * CVE-2026-24690 * CVE-2026-25712 * CVE-2026-25718 * CVE-2026-26232 * CVE-2026-26247 * CVE-2026-26307 * CVE-2026-27657 * CVE-2026-27878 * CVE-2026-28705 * CVE-2026-54746 * CVE-2026-54754 * CVE-2026-54755 * CVE-2026-54766 * CVE-2026-55064 * CVE-2026-55065 * CVE-2026-55066 * CVE-2026-55067 * CVE-2026-55068 * CVE-2026-55108 * CVE-2026-55245 * CVE-2026-55484 * CVE-2026-55569 * CVE-2026-55588 * CVE-2026-55621 * CVE-2026-55622 * CVE-2026-55678 * CVE-2026-55761 * CVE-2026-55763 * CVE-2026-55764 * CVE-2026-55784 * CVE-2026-55785 * CVE-2026-55834 * CVE-2026-55873 * CVE-2026-55874 * CVE-2026-56854 * CVE-2026-56855 * CVE-2026-78662 CVSS scores: * CVE-2026-20909 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-22547 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-24690 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-25712 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-25718 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-26232 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-26247 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-26307 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27657 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-27878 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28705 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-54746 ( NVD ): 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L * CVE-2026-54754 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H * CVE-2026-54755 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H * CVE-2026-54766 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55064 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-55065 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-55066 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N * CVE-2026-55067 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N * CVE-2026-55068 ( NVD ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55108 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H * CVE-2026-55245 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55484 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55569 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L * CVE-2026-55588 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55621 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-55622 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-55678 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55761 ( NVD ): 7.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55761 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-55763 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55764 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55784 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55785 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-55834 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-55873 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-55874 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-56854 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56854 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56854 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56855 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78662 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78662 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78662 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 39 vulnerabilities and contains one feature can now be installed. ## Description: This update for govulncheck-vulndb fixes the following issues: * Update to version 0.0.20260902T191204 2026-09-02T19:12:04Z (jsc#PED-11136). Go CVE Numbering Authority IDs added or updated with aliases: * GO-2026-6305 CVE-2026-55834 GHSA-2wvm-8mvp-22qv * GO-2026-6306 CVE-2026-55064 GHSA-44v6-7fxq- vgf4 * GO-2026-6307 CVE-2026-55067 GHSA-569v-q83c-3j3g * GO-2026-6308 CVE-2026-55066 GHSA-5pg6-m483-7vrg * GO-2026-6309 CVE-2026-54746 GHSA-8x7x-83cf-c3pg * GO-2026-6310 CVE-2026-54755 GHSA-cgc5-v3f2-8m2v * GO-2026-6311 CVE-2026-54766 GHSA-f27p-pw2p-9pr4 * GO-2026-6312 CVE-2026-55108 GHSA-fmgp-q6jx-gg3x * GO-2026-6313 CVE-2026-55065 GHSA-gg93-x632-9ccv * GO-2026-6314 CVE-2026-55569 GHSA-mf5c-hw34-4hpp * GO-2026-6315 CVE-2026-54754 GHSA-p7gw-2pcp-5pf8 * GO-2026-6316 CVE-2026-55068 GHSA-x8mj-6p3q-g5pp * GO-2026-6317 CVE-2026-55588 GHSA-298f-872v-2rcx * GO-2026-6318 CVE-2026-55621 GHSA-64f3-v33m-w89f * GO-2026-6319 CVE-2026-55622 GHSA-c9f5-j9c3-mhrg * GO-2026-6320 CVE-2026-55245 GHSA-w98g-5w9p-p3rc * GO-2026-6321 CVE-2026-55484 GHSA-hr6j-w4mw-g9mj * GO-2026-6322 CVE-2026-55678 GHSA-p378-jp5r-gpgw * GO-2026-6323 CVE-2026-55763 GHSA-v358-wf77-39xv * GO-2026-6324 CVE-2026-55761 GHSA-x626-fcwx-f5pc * GO-2026-6325 CVE-2026-27878 GHSA-6xff-cpcq-vpw2 * GO-2026-6326 CVE-2026-55784 GHSA-334q-h5g3-fpxv * GO-2026-6327 CVE-2026-55874 GHSA-56wq-x3wv-3ff4 * GO-2026-6328 CVE-2026-55785 GHSA-fp46-6vfw-gc9c * GO-2026-6329 CVE-2026-55873 GHSA-hgpf-8634-g44c * GO-2026-6330 CVE-2026-55764 GHSA-mrpp-v6pg-p54x * GO-2026-6333 CVE-2026-25712 GHSA-37w2-86g3-h4qh * GO-2026-6334 CVE-2026-24690 GHSA-47rq-xp99-92mx * GO-2026-6335 CVE-2026-27657 GHSA-4c8f-3m6h-m56r * GO-2026-6336 CVE-2026-26232 GHSA-5v69-g2m3-3hq3 * GO-2026-6337 CVE-2026-28705 GHSA-7jvx-g65v-r899 * GO-2026-6338 CVE-2026-22547 GHSA-922f-hfwp-p56f * GO-2026-6339 CVE-2026-20909 GHSA-fhq3-p242-2qpf * GO-2026-6340 CVE-2026-25718 GHSA-h697-89cp-24q8 * GO-2026-6341 CVE-2026-26307 GHSA-h9c5-x7g8-4q7f * GO-2026-6342 CVE-2026-26247 GHSA-m5ch-ppfx-xv3v * GO-2026-6354 CVE-2026-78662 * GO-2026-6355 CVE-2026-56855 * Update to version 0.0.20260828T144745 2026-08-28T14:47:45Z. * GO-2026-6303 CVE-2026-56854 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1643 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1643 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * govulncheck-vulndb-0.0.20260902T191204-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * govulncheck-vulndb-0.0.20260902T191204-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20909.html * https://www.suse.com/security/cve/CVE-2026-22547.html * https://www.suse.com/security/cve/CVE-2026-24690.html * https://www.suse.com/security/cve/CVE-2026-25712.html * https://www.suse.com/security/cve/CVE-2026-25718.html * https://www.suse.com/security/cve/CVE-2026-26232.html * https://www.suse.com/security/cve/CVE-2026-26247.html * https://www.suse.com/security/cve/CVE-2026-26307.html * https://www.suse.com/security/cve/CVE-2026-27657.html * https://www.suse.com/security/cve/CVE-2026-27878.html * https://www.suse.com/security/cve/CVE-2026-28705.html * https://www.suse.com/security/cve/CVE-2026-54746.html * https://www.suse.com/security/cve/CVE-2026-54754.html * https://www.suse.com/security/cve/CVE-2026-54755.html * https://www.suse.com/security/cve/CVE-2026-54766.html * https://www.suse.com/security/cve/CVE-2026-55064.html * https://www.suse.com/security/cve/CVE-2026-55065.html * https://www.suse.com/security/cve/CVE-2026-55066.html * https://www.suse.com/security/cve/CVE-2026-55067.html * https://www.suse.com/security/cve/CVE-2026-55068.html * https://www.suse.com/security/cve/CVE-2026-55108.html * https://www.suse.com/security/cve/CVE-2026-55245.html * https://www.suse.com/security/cve/CVE-2026-55484.html * https://www.suse.com/security/cve/CVE-2026-55569.html * https://www.suse.com/security/cve/CVE-2026-55588.html * https://www.suse.com/security/cve/CVE-2026-55621.html * https://www.suse.com/security/cve/CVE-2026-55622.html * https://www.suse.com/security/cve/CVE-2026-55678.html * https://www.suse.com/security/cve/CVE-2026-55761.html * https://www.suse.com/security/cve/CVE-2026-55763.html * https://www.suse.com/security/cve/CVE-2026-55764.html * https://www.suse.com/security/cve/CVE-2026-55784.html * https://www.suse.com/security/cve/CVE-2026-55785.html * https://www.suse.com/security/cve/CVE-2026-55834.html * https://www.suse.com/security/cve/CVE-2026-55873.html * https://www.suse.com/security/cve/CVE-2026-55874.html * https://www.suse.com/security/cve/CVE-2026-56854.html * https://www.suse.com/security/cve/CVE-2026-56855.html * https://www.suse.com/security/cve/CVE-2026-78662.html * https://jira.suse.com/browse/PED-11136 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:40:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:40:45 -0000 Subject: SUSE-SU-2026:23711-1: important: Security update for tomcat10 Message-ID: <178957684556.26114.5263871886777495337@b9be41dc2e4b> # Security update for tomcat10 Announcement ID: SUSE-SU-2026:23711-1 Release Date: 2026-09-08T15:47:18Z Rating: important References: * bsc#1273150 * bsc#1276893 * bsc#1276894 * bsc#1276895 * bsc#1276896 * bsc#1276897 * bsc#1276898 * bsc#1276899 * bsc#1276900 * bsc#1276901 * bsc#1276902 Cross-References: * CVE-2026-32990 * CVE-2026-65182 * CVE-2026-65183 * CVE-2026-65637 * CVE-2026-65905 * CVE-2026-65927 * CVE-2026-66299 * CVE-2026-66422 * CVE-2026-68525 * CVE-2026-68569 * CVE-2026-68763 * CVE-2026-73180 CVSS scores: * CVE-2026-32990 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-65182 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65182 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-65182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-65183 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65183 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65637 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65637 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65637 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65905 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65905 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-65905 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65927 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65927 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-66299 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-66422 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-66422 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-66422 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-68525 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68525 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68525 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68569 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68569 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68569 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68763 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68763 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68763 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73180 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-73180 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-73180 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 12 vulnerabilities can now be installed. ## Description: This update for tomcat10 fixes the following issues: * CVE-2026-65182: Bypass longest prefix security constraint (bsc#1276893). * CVE-2026-65183: TOCTOU when setting specific permissions for Unix Domain Sockets (bsc#1276894). * CVE-2026-65637: HTTP/2 no-authority bypass of strict SNI validation - fix incomplete (bsc#1276895). * CVE-2026-65905: Limited replay attack possible with DIGEST authentication (bsc#1276896). * CVE-2026-65927: RewriteValve [N] restarts at the second rule and may bypass access control (bsc#1276897). * CVE-2026-66299: memory exhaustion via maliciously slow clients due to the WebSocket chat example providing an unbounded buffer for undelivered messages (bsc#1273150). * CVE-2026-66422: Servlet role references can bypass declarative role constraints (bsc#1276898). * CVE-2026-68525: Redirect after FORM auth may bypass method specific constraints (bsc#1276899). * CVE-2026-68569: Principal lookup can fail open in some cases (bsc#1276900). * CVE-2026-68763: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset (bsc#1276901). * CVE-2026-73180: Authenticated WebSocket session survives end of HTTP session (bsc#1276902). Changes for tomcat10: * Update to Tomcat 10.1.59 * Catalina * Fix: Ensure that a login-config conflict when merging web.xml fragments triggers a deployment failure. (markt) * Code: Remove unnecessary calls to String.intern() in the parsing of configuration files. (markt) * Fix: Extend sessionAttributeValueClassNameFilter to include filtering of dynamic proxy interface classes. (markt) * Fix: Attempt to use rollback when persisting user data to the DataSourceUserDatabase fails and improve error reporting. (remm) * Fix: 70143: Handle InvalidFileNameException when parsing parts to rethrow it as an IllegalStateException as mandated by the Servlet specification. (remm) * Fix: Add missing reason to the JsonErrorReportValve. (remm) * Fix: evaluation of the N and C flags for rewrite rules. (remm) * Fix: qsd flag should always discard the original query string when rewriting. (remm) * Fix: Add appropriate escaping for context path, current directory name and parent directory name for directory listings produced by the default servlet. Ensure XML escaping is used with XML output. (markt) * Fix: When processing certificate subject names and issuer names within RewriteValve rules, always use the RFC 2253 format name. (markt) * Fix: the incorrect rejection of requests using digest authentication when the client provided nonce count is at the upper boundary of the window (markt). * Update: Separate the Context role mapping from the Servlet specification security-role-ref. (remm) * Fix: Handle the case where the JNDIRealm is configured to perform role searches with userRoleAttribute but the attribute is not available or not configured for the current user. (markt) * Fix: Improve handling of session attribute addition concurrent with session expiration. An application will now either see a successful addition followed by expiration or the addition will not succeed. It is no longer possible for the session to expire and the addition to succeed. This is of particular not for attributes that implement HttpSessionBindingListener. (markt) * Fix: Add a new attribute to the Context, urlPatternsProvidedInDecodedForm. This attribute controls whether URLs and URL patterns provided in the deployment descriptor (web.xml), annotations and/or their programmatic equivalents are treated as being provided in URL-encoded form (i.e. using %nn encoding) or in decoded form. The Servlet specification requires that they are provided in decoded form. However, Tomcat has historically treated them as if they are provided in encoded form. In Tomcat 12, they will always be treated as if they are provided in decoded form. This setting enables migration from encoded form to decoded form on an application by application basis. This attribute will be removed in Tomcat 12 where it will effectively be hard-coded to true. (markt) * Fix: Ensure the security constraint with the longest matching path is selected when more than one constraint matches the request path. (markt) * Fix: If the request saved by FORM authentication uses a method other than GET, ensure that the security constraints are re-assessed after the saved request is restored and before it is processed. Custom Authenticator implementations that extend FormAuthenticator and override doAuthenticate() and/or restoreRequest() will require modification. (markt) * Fix: Various improvements to the DataSourceRealm. A failure to connect to the database or an exception during either user or role lookup will now result in an authentication failure rather than a partially populated Principal. For CLIENT-CERT and SPNEGO authentication, the user must exist in the database for authentication to succeed. (markt) * Fix: Improve the handling of AsyncContext.dispatch() when the Context attribute dispatchersUseEncodedPaths is set to false since the application has no control over the path used for the AsyncContext.dispatch(). Prior to this fix, paths containing literal '?' characters were truncated. (markt) * Fix: Ensure that capture groups from a RewriteCond always reflect the result of the current request. (markt) * Fix: async path building. (markt) * Coyote * Update: Add utility AutoCloseable URLConnection wrapper, and use it to cleanup existing code patterns. (remm/markt) * Fix: When processing an HTTP upgrade from HTTP/1.1 to HTTP/2, ensure that all the HTTP/1.1 data has been processed before switching protocols. (markt) * Fix: Require every HTTP/2 request to provide an authority (either an :authority pseudo header or a Host header). (markt) * Fix: Register the use of an HTTP/2 stream identifier earlier so that there is no possibility of a re-used stream identifier being accepted, regardless of how early in the HEADERS frame processing an error is detected. (markt) * Add: new attributes (unixDomainSocketParentPermissions and unixDomainSocketParentOwner) to the NIO connector to provide additional control over the security of Unix Domain Sockets. Additional checks (enabled by default) have also been added for the directory where the Unix Domain Socket will be created.(markt) * Fix: an allocation leak in the HTTP/2 backlog tracking when a stream is reset. (markt) * Fix: parsing of client certificates that specify more than one OCSP responder for configurations that use OpenSSL-FFM. (markt) * Jasper * Fix: Ensure internal state is reset before re-using ELParser. (markt) * WebSocket * Add: a limit (defaults to 8KB) on the size of the HTTP response headers accepted during a WebSocket HTTP upgrade. This is configured via the org.apache.tomcat.websocket.MAX_HTTP_RESPONSE_HEADER_BYTES user property. (markt) * Fix: Improve URI template matching for WebSocket end points. Trailing slashes are now significant both for template definitions and URIs considered for potential matches to those URIs. Note that this means if a URI template ends in a variable without a trailing slash, that variable might be expanded to the empty string. (markt) * Fix: Account for session ID changes when tracking WebSocket connections for closure because they were created under an authenticated HTTP session that has since ended. (markt) * Web applications * Fix: Documentation: Better sample httpd configuration for use with SSLValve and add a note that the exact configuration required will depend on the overall httpd configuration. (markt) * Fix: Examples: Limit the buffering of messages in the WebSocket chat example to prevent a malicious client triggering excessive memory usage that could lead to a DoS. (markt) * Fix: Documentation: Expand the description of the %S (session ID) access log pattern token. (markt) * Fix: Manager: Use reflection to load clustering classes in sessionsList.jsp so the sessions list page renders correctly when clustering JARs are not present. (csutherl) * Other * Update: Maven Resolver Ant Tasks to 1.6.1. (rjung) * Update: Objenesis to 3.6. (markt) * Update: JSign to 7.5. (markt) * Update: Bouncy Castle to 1.85. (markt) * Add: Improvements to French translations. (remm) * Add: Improvements to Japanese translations provided by tak7iji. (markt) * Cluster * Add: Change the default encryptionAlgorithm for the EncryptInterceptor to AES/GCM/NoPadding. This is a breaking change for the EncryptInterceptor. (markt) * Add: Expand the documentation for the EncryptInterceptor to be more explicit regarding the security weaknesses of some supported algorithms. Also explicitly state that the replay protection is only effective for non- malleable algorithms. (markt) * Add: Expand the Javadoc for the DNSMembershipProvider in particular explaining its behaviour and providing configuration advice if control more over cluster membership is required. (markt) * jdbc-pool * Fix: 70164: Correct the documentation for the testOnBorrow attribute. Pull request #1033 provided by Kohei Tamura. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1641 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1641 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * tomcat10-embed-10.1.59-160000.1.1 * tomcat10-admin-webapps-10.1.59-160000.1.1 * tomcat10-10.1.59-160000.1.1 * tomcat10-el-5_0-api-10.1.59-160000.1.1 * tomcat10-doc-10.1.59-160000.1.1 * tomcat10-jsvc-10.1.59-160000.1.1 * tomcat10-servlet-6_0-api-10.1.59-160000.1.1 * tomcat10-docs-webapp-10.1.59-160000.1.1 * tomcat10-jsp-3_1-api-10.1.59-160000.1.1 * tomcat10-lib-10.1.59-160000.1.1 * tomcat10-webapps-10.1.59-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * tomcat10-embed-10.1.59-160000.1.1 * tomcat10-admin-webapps-10.1.59-160000.1.1 * tomcat10-10.1.59-160000.1.1 * tomcat10-el-5_0-api-10.1.59-160000.1.1 * tomcat10-doc-10.1.59-160000.1.1 * tomcat10-jsvc-10.1.59-160000.1.1 * tomcat10-servlet-6_0-api-10.1.59-160000.1.1 * tomcat10-docs-webapp-10.1.59-160000.1.1 * tomcat10-jsp-3_1-api-10.1.59-160000.1.1 * tomcat10-lib-10.1.59-160000.1.1 * tomcat10-webapps-10.1.59-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32990.html * https://www.suse.com/security/cve/CVE-2026-65182.html * https://www.suse.com/security/cve/CVE-2026-65183.html * https://www.suse.com/security/cve/CVE-2026-65637.html * https://www.suse.com/security/cve/CVE-2026-65905.html * https://www.suse.com/security/cve/CVE-2026-65927.html * https://www.suse.com/security/cve/CVE-2026-66299.html * https://www.suse.com/security/cve/CVE-2026-66422.html * https://www.suse.com/security/cve/CVE-2026-68525.html * https://www.suse.com/security/cve/CVE-2026-68569.html * https://www.suse.com/security/cve/CVE-2026-68763.html * https://www.suse.com/security/cve/CVE-2026-73180.html * https://bugzilla.suse.com/show_bug.cgi?id=1273150 * https://bugzilla.suse.com/show_bug.cgi?id=1276893 * https://bugzilla.suse.com/show_bug.cgi?id=1276894 * https://bugzilla.suse.com/show_bug.cgi?id=1276895 * https://bugzilla.suse.com/show_bug.cgi?id=1276896 * https://bugzilla.suse.com/show_bug.cgi?id=1276897 * https://bugzilla.suse.com/show_bug.cgi?id=1276898 * https://bugzilla.suse.com/show_bug.cgi?id=1276899 * https://bugzilla.suse.com/show_bug.cgi?id=1276900 * https://bugzilla.suse.com/show_bug.cgi?id=1276901 * https://bugzilla.suse.com/show_bug.cgi?id=1276902 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:41:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:41:36 -0000 Subject: SUSE-SU-2026:23710-1: important: Security update for tomcat11 Message-ID: <178957689619.26114.4952734122324656689@b9be41dc2e4b> # Security update for tomcat11 Announcement ID: SUSE-SU-2026:23710-1 Release Date: 2026-09-08T15:45:34Z Rating: important References: * bsc#1273150 * bsc#1276893 * bsc#1276894 * bsc#1276895 * bsc#1276896 * bsc#1276897 * bsc#1276898 * bsc#1276899 * bsc#1276900 * bsc#1276901 * bsc#1276902 Cross-References: * CVE-2026-32990 * CVE-2026-65182 * CVE-2026-65183 * CVE-2026-65637 * CVE-2026-65905 * CVE-2026-65927 * CVE-2026-66299 * CVE-2026-66422 * CVE-2026-68525 * CVE-2026-68569 * CVE-2026-68763 * CVE-2026-73180 CVSS scores: * CVE-2026-32990 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-65182 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65182 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-65182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-65183 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65183 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65637 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65637 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65637 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65905 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65905 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-65905 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65927 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65927 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-66299 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-66422 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-66422 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-66422 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-68525 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68525 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68525 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68569 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68569 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68569 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68763 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68763 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68763 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73180 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-73180 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-73180 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 12 vulnerabilities can now be installed. ## Description: This update for tomcat11 fixes the following issues: * CVE-2026-65182: Bypass longest prefix security constraint (bsc#1276893). * CVE-2026-65183: TOCTOU when setting specific permissions for Unix Domain Sockets (bsc#1276894). * CVE-2026-65637: HTTP/2 no-authority bypass of strict SNI validation - fix incomplete (bsc#1276895). * CVE-2026-65905: Limited replay attack possible with DIGEST authentication (bsc#1276896). * CVE-2026-65927: RewriteValve [N] restarts at the second rule and may bypass access control (bsc#1276897). * CVE-2026-66299: memory exhaustion via maliciously slow clients due to the WebSocket chat example providing an unbounded buffer for undelivered messages (bsc#1273150). * CVE-2026-66422: Servlet role references can bypass declarative role constraints (bsc#1276898). * CVE-2026-68525: Redirect after FORM auth may bypass method specific constraints (bsc#1276899). * CVE-2026-68569: Principal lookup can fail open in some cases (bsc#1276900). * CVE-2026-68763: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset (bsc#1276901). * CVE-2026-73180: Authenticated WebSocket session survives end of HTTP session (bsc#1276902). Changes for tomcat11: * Update to Tomcat 11.0.25 * Catalina * Fix: Ensure that a login-config conflict when merging web.xml fragments triggers a deployment failure. (markt) * Code: Remove unnecessary calls to String.intern() in the parsing of configuration files. (markt) * Fix: Extend sessionAttributeValueClassNameFilter to include filtering of dynamic proxy interface classes. (markt) * Fix: Attempt to use rollback when persisting user data to the DataSourceUserDatabase fails and improve error reporting. (remm) * Fix: 70143: Handle InvalidFileNameException when parsing parts to rethrow it as an IllegalStateException as mandated by the Servlet specification. (remm) * Fix: Add missing reason to the JsonErrorReportValve. (remm) * Fix: evaluation of the N and C flags for rewrite rules. (remm) * Fix: qsd flag should always discard the original query string when rewriting. (remm) * Fix: Add appropriate escaping for context path, current directory name and parent directory name for directory listings produced by the default servlet. Ensure XML escaping is used with XML output. (markt) * Fix: When processing certificate subject names and issuer names within RewriteValve rules, always use the RFC 2253 format name. (markt) * Fix: the incorrect rejection of requests using digest authentication when the client provided nonce count is at the upper boundary of the window (markt). * Update: Separate the Context role mapping from the Servlet specification security-role-ref. (remm) * Fix: Handle the case where the JNDIRealm is configured to perform role searches with userRoleAttribute but the attribute is not available or not configured for the current user. (markt) * Fix: Improve handling of session attribute addition concurrent with session expiration. An application will now either see a successful addition followed by expiration or the addition will not succeed. It is no longer possible for the session to expire and the addition to succeed. This is of particular not for attributes that implement HttpSessionBindingListener. (markt) * Fix: Add a new attribute to the Context, urlPatternsProvidedInDecodedForm. This attribute controls whether URLs and URL patterns provided in the deployment descriptor (web.xml), annotations and/or their programmatic equivalents are treated as being provided in URL-encoded form (i.e. using %nn encoding) or in decoded form. The Servlet specification requires that they are provided in decoded form. However, Tomcat has historically treated them as if they are provided in encoded form. In Tomcat 12, they will always be treated as if they are provided in decoded form. This setting enables migration from encoded form to decoded form on an application by application basis. This attribute will be removed in Tomcat 12 where it will effectively be hard-coded to true. (markt) * Fix: Ensure the security constraint with the longest matching path is selected when more than one constraint matches the request path. (markt) * Fix: If the request saved by FORM authentication uses a method other than GET, ensure that the security constraints are re-assessed after the saved request is restored and before it is processed. Custom Authenticator implementations that extend FormAuthenticator and override doAuthenticate() and/or restoreRequest() will require modification. (markt) * Fix: Various improvements to the DataSourceRealm. A failure to connect to the database or an exception during either user or role lookup will now result in an authentication failure rather than a partially populated Principal. For CLIENT-CERT and SPNEGO authentication, the user must exist in the database for authentication to succeed. (markt) * Coyote * Update: Add utility AutoCloseable URLConnection wrapper, and use it to cleanup existing code patterns. (remm/markt) * Fix: When processing an HTTP upgrade from HTTP/1.1 to HTTP/2, ensure that all the HTTP/1.1 data has been processed before switching protocols. (markt) * Fix: Require every HTTP/2 request to provide an authority (either an :authority pseudo header or a Host header). (markt) * Fix: Register the use of an HTTP/2 stream identifier earlier so that there is no possibility of a re-used stream identifier being accepted, regardless of how early in the HEADERS frame processing an error is detected. (markt) * Add: new attributes (unixDomainSocketParentPermissions and unixDomainSocketParentOwner) to the NIO connector to provide additional control over the security of Unix Domain Sockets. Additional checks (enabled by default) have also been added for the directory where the Unix Domain Socket will be created.(markt) * Fix: an allocation leak in the HTTP/2 backlog tracking when a stream is reset. (markt) * Jasper * Fix: Ensure internal state is reset before re-using ELParser. (markt) * WebSocket * Add: a limit (defaults to 8KB) on the size of the HTTP response headers accepted during a WebSocket HTTP upgrade. This is configured via the org.apache.tomcat.websocket.MAX_HTTP_RESPONSE_HEADER_BYTES user property. (markt) * Fix: Improve URI template matching for WebSocket end points. Trailing slashes are now significant both for template definitions and URIs considered for potential matches to those URIs. Note that this means if a URI template ends in a variable without a trailing slash, that variable might be expanded to the empty string. (markt) * Fix: Account for session ID changes when tracking WebSocket connections for closure because they were created under an authenticated HTTP session that has since ended. (markt) * Web applications * Fix: 70160: Correct various references to the Servlet specification to use version 6.1. (markt) * Fix: Documentation: Better sample httpd configuration for use with SSLValve and add a note that the exact configuration required will depend on the overall httpd configuration. (markt) * Fix: Examples: Limit the buffering of messages in the WebSocket chat example to prevent a malicious client triggering excessive memory usage that could lead to a DoS. (markt) * Fix: Documentation: Expand the description of the %S (session ID) access log pattern token. (markt) * Fix: Manager: Use reflection to load clustering classes in sessionsList.jsp so the sessions list page renders correctly when clustering JARs are not present. (csutherl) * Other * Update: Maven Resolver Ant Tasks to 1.6.1. (rjung) * Update: Objenesis to 3.6. (markt) * Update: JSign to 7.5. (markt) * Update: Bouncy Castle to 1.85. (markt) * Add: Improvements to French translations. (remm) * Add: Improvements to Japanese translations provided by tak7iji. (markt) * Cluster * Add: Change the default encryptionAlgorithm for the EncryptInterceptor to AES/GCM/NoPadding. This is a breaking change for the EncryptInterceptor. (markt) * Add: Expand the documentation for the EncryptInterceptor to be more explicit regarding the security weaknesses of some supported algorithms. Also explicitly state that the replay protection is only effective for non- malleable algorithms. (markt) * Add: Expand the Javadoc for the DNSMembershipProvider in particular explaining its behaviour and providing configuration advice if control more over cluster membership is required. (markt) * jdbc-pool * Fix: 70164: Correct the documentation for the testOnBorrow attribute. Pull request #1033 provided by Kohei Tamura. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1642 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1642 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * tomcat11-el-6_0-api-11.0.25-160000.1.1 * tomcat11-embed-11.0.25-160000.1.1 * tomcat11-jsvc-11.0.25-160000.1.1 * tomcat11-docs-webapp-11.0.25-160000.1.1 * tomcat11-servlet-6_1-api-11.0.25-160000.1.1 * tomcat11-webapps-11.0.25-160000.1.1 * tomcat11-11.0.25-160000.1.1 * tomcat11-admin-webapps-11.0.25-160000.1.1 * tomcat11-lib-11.0.25-160000.1.1 * tomcat11-jsp-4_0-api-11.0.25-160000.1.1 * tomcat11-doc-11.0.25-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * tomcat11-el-6_0-api-11.0.25-160000.1.1 * tomcat11-embed-11.0.25-160000.1.1 * tomcat11-jsvc-11.0.25-160000.1.1 * tomcat11-docs-webapp-11.0.25-160000.1.1 * tomcat11-servlet-6_1-api-11.0.25-160000.1.1 * tomcat11-webapps-11.0.25-160000.1.1 * tomcat11-11.0.25-160000.1.1 * tomcat11-admin-webapps-11.0.25-160000.1.1 * tomcat11-lib-11.0.25-160000.1.1 * tomcat11-jsp-4_0-api-11.0.25-160000.1.1 * tomcat11-doc-11.0.25-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32990.html * https://www.suse.com/security/cve/CVE-2026-65182.html * https://www.suse.com/security/cve/CVE-2026-65183.html * https://www.suse.com/security/cve/CVE-2026-65637.html * https://www.suse.com/security/cve/CVE-2026-65905.html * https://www.suse.com/security/cve/CVE-2026-65927.html * https://www.suse.com/security/cve/CVE-2026-66299.html * https://www.suse.com/security/cve/CVE-2026-66422.html * https://www.suse.com/security/cve/CVE-2026-68525.html * https://www.suse.com/security/cve/CVE-2026-68569.html * https://www.suse.com/security/cve/CVE-2026-68763.html * https://www.suse.com/security/cve/CVE-2026-73180.html * https://bugzilla.suse.com/show_bug.cgi?id=1273150 * https://bugzilla.suse.com/show_bug.cgi?id=1276893 * https://bugzilla.suse.com/show_bug.cgi?id=1276894 * https://bugzilla.suse.com/show_bug.cgi?id=1276895 * https://bugzilla.suse.com/show_bug.cgi?id=1276896 * https://bugzilla.suse.com/show_bug.cgi?id=1276897 * https://bugzilla.suse.com/show_bug.cgi?id=1276898 * https://bugzilla.suse.com/show_bug.cgi?id=1276899 * https://bugzilla.suse.com/show_bug.cgi?id=1276900 * https://bugzilla.suse.com/show_bug.cgi?id=1276901 * https://bugzilla.suse.com/show_bug.cgi?id=1276902 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:42:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:42:22 -0000 Subject: SUSE-SU-2026:23709-1: critical: Security update for libzypp, zypper Message-ID: <178957694241.26114.529288402416571851@b9be41dc2e4b> # Security update for libzypp, zypper Announcement ID: SUSE-SU-2026:23709-1 Release Date: 2026-09-08T15:22:38Z Rating: critical References: * bsc#1257249 * bsc#1271730 * bsc#1272534 * bsc#1273242 * bsc#1274091 * bsc#1274625 * bsc#1277790 Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that has seven fixes can now be installed. ## Description: This update for libzypp, zypper fixes the following issues: Security issue fixed: * invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY- CACHE-01] (bsc#1274625). Non security issues fixed: * Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). * Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). * zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). * Zypper patch doesn't give enough details about conflicts (bsc#1277790). Changes for libzypp: Update to version 17.38.1: * Prevent libgpgme from launching gpg-agents; we don't need them. * defaultLoadSystem: Hand out the ZYpp::Ptr as return value. * Log all solver problem rules (bsc#1277790) The log contains the most relevant problem rule, but sometimes it helps to know all rules associated with this problem. zypper shows them on demand as 'detail'. The log now remembers them as well. * Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) * repoGpgCheck: Strictly follow the repo_gpgcheck setting (bsc#1274625) There's been a legacy exception for unsigned repositories which were explicitly accepted in the past. After switching the repo_gpgcheck from off to on, they were allowed to stay unsigned until a first signed version was retrieved. From there on the handling was strict. Now the handling is strict as soon as the repo_gpgcheck turned on. The next set of metadata retrieved must be signed. * Iniparser: each new file starts in the unnamed section (bsc#1272534) * Fix hasCredentials() to require both username AND password to be non-empty (bsc#1273242) This avoids an unnecessary 2nd 401 response sending just the username in case the username but no password is known. Now it immediately fetches the credentials from disk if no password is known. * GPG Key hints in repoindex.xml require at least a long id to allow auto- import (bsc#1271730) The short Id (32bit/8byte) is not considered to be a safe identifier for a gpg key. A long id (64bit/16byte) or even better the full fingerprint is needed to identify the key. * zypp: Improve Testcase Loading for MCP Tools. Changes for zypper: Update to version 1.14.99: * Show solver problem details per default in not-interactive mode (bsc#1277790) This way they see all details when capturing zypper's output because the (d)etail button can't be pressed in not-interactive mode. * Add --servicesd-dir global option to relocate /etc/zypp/services.d (bsc#1257249) * info: check for missing positional args before systemSetup (bsc#1274091) * Remove deprecated installRecommends option from zypper.conf. The system wide default for all libzypp based applications is defined in zypp.conf(5). It is not recommended to define this in zypper exclusively. ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1639 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1639 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libzypp-devel-17.38.15-160000.1.1 * zypper-debugsource-1.14.101-160000.1.1 * libzypp-debugsource-17.38.15-160000.1.1 * zypper-1.14.101-160000.1.1 * libzypp-17.38.15-160000.1.1 * libzypp-debuginfo-17.38.15-160000.1.1 * libzypp-devel-doc-17.38.15-160000.1.1 * zypper-debuginfo-1.14.101-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * zypper-needs-restarting-1.14.101-160000.1.1 * zypper-aptitude-1.14.101-160000.1.1 * zypper-log-1.14.101-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libzypp-devel-17.38.15-160000.1.1 * zypper-debugsource-1.14.101-160000.1.1 * libzypp-debugsource-17.38.15-160000.1.1 * zypper-1.14.101-160000.1.1 * libzypp-17.38.15-160000.1.1 * libzypp-debuginfo-17.38.15-160000.1.1 * libzypp-devel-doc-17.38.15-160000.1.1 * zypper-debuginfo-1.14.101-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * zypper-needs-restarting-1.14.101-160000.1.1 * zypper-aptitude-1.14.101-160000.1.1 * zypper-log-1.14.101-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1257249 * https://bugzilla.suse.com/show_bug.cgi?id=1271730 * https://bugzilla.suse.com/show_bug.cgi?id=1272534 * https://bugzilla.suse.com/show_bug.cgi?id=1273242 * https://bugzilla.suse.com/show_bug.cgi?id=1274091 * https://bugzilla.suse.com/show_bug.cgi?id=1274625 * https://bugzilla.suse.com/show_bug.cgi?id=1277790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:43:05 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:43:05 -0000 Subject: SUSE-SU-2026:23708-1: important: Security update for google-cloud-sap-agent Message-ID: <178957698557.26114.10144644350811613226@b9be41dc2e4b> # Security update for google-cloud-sap-agent Announcement ID: SUSE-SU-2026:23708-1 Release Date: 2026-09-14T08:32:36Z Rating: important References: * bsc#1210938 * bsc#1272128 * bsc#1278987 * bsc#1279201 * bsc#1279304 Cross-References: * CVE-2026-56852 * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84445 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 An update that solves four vulnerabilities and has one fix can now be installed. ## Description: This update for google-cloud-sap-agent fixes the following issues: Security issues fixed: * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272128). * CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279304). * CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279201). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278987). Non security issue fixed: * re-enable stripping and debuginfo (bsc#1210938). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1679 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 x86_64) * google-cloud-sap-agent-3.15-160000.4.1 * google-cloud-sap-agent-debuginfo-3.15-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56852.html * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1210938 * https://bugzilla.suse.com/show_bug.cgi?id=1272128 * https://bugzilla.suse.com/show_bug.cgi?id=1278987 * https://bugzilla.suse.com/show_bug.cgi?id=1279201 * https://bugzilla.suse.com/show_bug.cgi?id=1279304 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:43:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:43:45 -0000 Subject: SUSE-SU-2026:23707-1: moderate: Security update for jq Message-ID: <178957702527.26114.5436381749721467581@b9be41dc2e4b> # Security update for jq Announcement ID: SUSE-SU-2026:23707-1 Release Date: 2026-09-11T15:00:17Z Rating: moderate References: * bsc#1265071 * bsc#1269221 Cross-References: * CVE-2026-43895 * CVE-2026-47770 CVSS scores: * CVE-2026-43895 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43895 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-43895 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-47770 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-47770 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47770 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for jq fixes the following issues: * CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure (bsc#1265071). * CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1662 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * jq-1.7.1-160000.5.1 * jq-debugsource-1.7.1-160000.5.1 * libjq1-debuginfo-1.7.1-160000.5.1 * jq-debuginfo-1.7.1-160000.5.1 * libjq1-1.7.1-160000.5.1 * libjq-devel-1.7.1-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43895.html * https://www.suse.com/security/cve/CVE-2026-47770.html * https://bugzilla.suse.com/show_bug.cgi?id=1265071 * https://bugzilla.suse.com/show_bug.cgi?id=1269221 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:44:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:44:32 -0000 Subject: SUSE-SU-2026:23706-1: important: Security update for clamav Message-ID: <178957707241.26114.18382617643540587093@b9be41dc2e4b> # Security update for clamav Announcement ID: SUSE-SU-2026:23706-1 Release Date: 2026-09-11T12:01:10Z Rating: important References: * bsc#1271922 * bsc#1274597 * bsc#1274598 * bsc#1274599 * bsc#1274600 * bsc#1274601 * bsc#1274602 * bsc#1274603 Cross-References: * CVE-2025-8088 * CVE-2026-20337 * CVE-2026-20338 * CVE-2026-20339 * CVE-2026-20345 * CVE-2026-20346 * CVE-2026-20347 * CVE-2026-20348 * CVE-2026-46671 CVSS scores: * CVE-2025-8088 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8088 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-20337 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20337 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20337 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20338 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20338 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20338 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20339 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20339 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20339 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20345 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20345 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20346 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20346 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20346 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20347 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20347 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20347 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20348 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20348 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20348 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46671 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-46671 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Enterprise Server 16.0 An update that solves nine vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues: * CVE-2026-20337: Improper boundary checks for content in zip archive parser (bsc#1274597). * CVE-2026-20338: invalid free due to bad ownership handling when merging ZIP catalogue records (bsc#1274598). * CVE-2026-20339: integer overflow in the PESpin unpacker leads to undersized allocation and heap out-of-bounds write (bsc#1274599). * CVE-2026-20345: out-of-bounds read/write via indexing error when converting GPT partition names (bsc#1274600). * CVE-2026-20346: integer underflow when parsing malformed PDF hex strings causes a crash (bsc#1274601). * CVE-2026-20347: integer overflow and undefined behavior when scanning malformed Mach-O files causes a crash (bsc#1274602). * CVE-2026-20348: improper size handling in the XAR parser allows excessive allocation and scan-limit bypass (bsc#1274603). * CVE-2026-46671: onenote_parser: Path traversal in `Parser:parse_notebook` allows reading files outside the notebook directory (bsc#1271922). * CVE-2025-8088: rejects path separators in NTFS alternate data stream names to prevent extraction outside ClamAV's temporary scan directory on Windows. Changes for clamav: Update to 1.5.4: * Fixed thread-safety issues in the clamd STATS command that could disclose process memory or crash the daemon while scans and STATS requests run concurrently. Also fixed partial socket-write handling used for large STATS responses. * FreeBSD: Restored support for safe quarantine move and remove actions while preserving protection against source-path replacement races. * Fixed an OpenSSL library-context leak in legacy hashing helpers when a requested message digest cannot be fetched, such as when the default provider is unavailable in a FIPS-enabled environment. * Upgraded the Rust crossbeam-epoch dependency to resolve the RUSTSEC-2026-0204 advisory. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1660 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * clamav-milter-debuginfo-1.5.4-160000.1.1 * clamav-milter-1.5.4-160000.1.1 * clamav-devel-1.5.4-160000.1.1 * clamav-debuginfo-1.5.4-160000.1.1 * libclammspack0-1.5.4-160000.1.1 * libfreshclam4-1.5.4-160000.1.1 * libclammspack0-debuginfo-1.5.4-160000.1.1 * libfreshclam4-debuginfo-1.5.4-160000.1.1 * libclamav12-debuginfo-1.5.4-160000.1.1 * clamav-debugsource-1.5.4-160000.1.1 * libclamav12-1.5.4-160000.1.1 * clamav-1.5.4-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * clamav-docs-html-1.5.4-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-8088.html * https://www.suse.com/security/cve/CVE-2026-20337.html * https://www.suse.com/security/cve/CVE-2026-20338.html * https://www.suse.com/security/cve/CVE-2026-20339.html * https://www.suse.com/security/cve/CVE-2026-20345.html * https://www.suse.com/security/cve/CVE-2026-20346.html * https://www.suse.com/security/cve/CVE-2026-20347.html * https://www.suse.com/security/cve/CVE-2026-20348.html * https://www.suse.com/security/cve/CVE-2026-46671.html * https://bugzilla.suse.com/show_bug.cgi?id=1271922 * https://bugzilla.suse.com/show_bug.cgi?id=1274597 * https://bugzilla.suse.com/show_bug.cgi?id=1274598 * https://bugzilla.suse.com/show_bug.cgi?id=1274599 * https://bugzilla.suse.com/show_bug.cgi?id=1274600 * https://bugzilla.suse.com/show_bug.cgi?id=1274601 * https://bugzilla.suse.com/show_bug.cgi?id=1274602 * https://bugzilla.suse.com/show_bug.cgi?id=1274603 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:45:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:45:11 -0000 Subject: SUSE-SU-2026:23705-1: important: Security update for acl, attr Message-ID: <178957711136.26114.8388593613090755509@b9be41dc2e4b> # Security update for acl, attr Announcement ID: SUSE-SU-2026:23705-1 Release Date: 2026-09-11T11:45:57Z Rating: important References: * bsc#1268867 * jsc#PED-16501 Cross-References: * CVE-2026-54369 * CVE-2026-54370 * CVE-2026-54371 CVSS scores: * CVE-2026-54369 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-54369 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54369 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54369 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54369 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54370 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-54370 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54370 ( NVD ): 7.2 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54370 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54371 ( SUSE ): 8.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-54371 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54371 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54371 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-54371 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 An update that solves three vulnerabilities and contains one feature can now be installed. ## Description: This update for acl, attr fixes the following issue: * CVE-2026-54369,CVE-2026-54370,CVE-2026-54371: Symlink Traversal Privilege Escalation via getfattr/setfattr, getfacl/setfacl/chacl, libacl (bsc#1268867). Changes for acl: * Update to 2.4.0 (jsc#PED-16501): Major Issues Fixed: * The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. * When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. * When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. * When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: * When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ("Too many levels of symbolic links") error will result instead. * acl_delete_entry() now verifies that the specified entry belongs to the specified acl. * Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. * Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. * When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. * setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. * setfacl --restore accidentally called chmod() when in --test mode. It no longer does. * When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. * When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. * The -h (--no-dereference) option of getfattr prevented getfattr from recursing into "symbolic link directories". This is wrong. When dirlink is a symbolic link that refers to a directory, "getfattr -Rh dirlink" will now visit that directory. The -P (--physical) option can be used to prevent that. * Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent Changes for attr: * Update to 2.6.0 (jsc#PED-16501): Major Issues Fixed: * The libacl library functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() take a pathname argument and follow symbolic links. When a privileged user calls one of those functions, an attacker that controls a pathname component can replace a file or directory with a symbolic link and redirect the operation to a different file. This can lead to local privilege escalation. (CVE-2026-54369, bsc#1268867) The library functions cannot be fixed without breaking compatibility; the described behaviour is by design. Instead, version 2.4.0 of the acl package introduces the additional functions acl_get_file_at(), acl_set_file_at(), acl_extended_file_at(), and acl_delete_def_file_at(). These functions each take a dirfd file descriptor argument and an at_flags argument and accept the AT_SYMLINK_NOFOLLOW and AT_EMPTY_PATH flags. Use these functions to control when to follow symbolic links. (CVE-2026-54370, bsc#1268867) In addition, the libacl functions acl_get_fd(), acl_set_fd(), and acl_extended_fd() functions always operate on the access ACL; the library previously did not offer a way to operate on the default ACL of a directory file descriptor. The new functions remove that restriction. It will be up to each individual program to start using these new library functions where appropriate. * When walking directory trees, the getfacl, setfacl, chacl, and getfattr utilities constructed the full pathname of each file in the tree and use that pathname to access the file. When a privileged user used those utilities, an attacker that controlled a pathname component could replace a directory with a symbolic link and redirect the operation to a different file, leading to a local privilege escalation. (CVE-2026-54371, bsc#1268867) This is fixed by using directory file descriptors and operating relative to those directory file descriptors. * When resolving the final pathname component, the getfacl, setfacl, chacl, getfattr, and setfattr utilities in some cases used functions that resolve symbolic links. This includes the above mentioned libacl functions, but also stat(), chmod(), and chown(). This is fixed by using symlink-safe functions throughout the code. * When restoring a backup, the setfacl and setfattr utilities read the full pathnames of files from the backup. When those pathnames were resolved, pathname components that are symbolic links were traversed. An attacker that controlled a pathname component could replace it with a symbolic link, causing a privileged user to operate on a file other than the one intended. This could lead to the same kind of local privilege escalation as discussed before. This is fixed by using openat2(RESOLVE_NO_SYMLINKS) to resolve the directory components of a pathname, but see Compatibility Notes below for the details. Minor Issues Fixed: * When a symbolic link was specified on the command line but symbolic link traversal was disabled using option -P (--physical), the getfacl and setfacl utilities previously silently ignored the symlink. Now, an ELOOP ("Too many levels of symbolic links") error will result instead. * acl_delete_entry() now verifies that the specified entry belongs to the specified acl. * Numeric uids and gids that cannot be represented in types uid_t and gid_t are checked more carefully and invalid numbers are rejected. * Functions acl_get_file(), acl_get_file_at(), and acl_get_fd() will retry several times when the size of an ACL grows unexpectedly; previously, they only grew the allocated buffer once before giving up. * When passed a directory file descriptor, function perm_copy_fd() didn't copy the default ACL from one directory to the other. It now does. * setfacl --restore accidentally ignored leading whitespace in filenames. It no longer does. * setfacl --restore accidentally called chmod() when in --test mode. It no longer does. * When the setfattr --restore option was used multiple times, a buffer was accessed after being freed. This no longer happens. * When the setfattr -h (--no-dereference) option was given after --restore, it was ignored. Now, the options can be passed in any order. * The -h (--no-dereference) option of getfattr prevented getfattr from recursing into "symbolic link directories". This is wrong. When dirlink is a symbolic link that refers to a directory, "getfattr -Rh dirlink" will now visit that directory. The -P (--physical) option can be used to prevent that. * Similarly, when a symbolic link referring to a directory was specified on the getfacl or setfacl command line, the -R option did not cause that directory to be visited. This has been fixed so that those directories will now be visited. The -P (--physical) option can be used to prevent ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1661 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libacl1-2.4.0-160000.1.1 * libattr-devel-static-2.6.0-160000.1.1 * libacl-devel-2.4.0-160000.1.1 * libattr-devel-2.6.0-160000.1.1 * attr-2.6.0-160000.1.1 * acl-debugsource-2.4.0-160000.1.1 * libattr1-debuginfo-2.6.0-160000.1.1 * acl-debuginfo-2.4.0-160000.1.1 * attr-debugsource-2.6.0-160000.1.1 * libacl1-debuginfo-2.4.0-160000.1.1 * libattr1-2.6.0-160000.1.1 * acl-2.4.0-160000.1.1 * attr-debuginfo-2.6.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54369.html * https://www.suse.com/security/cve/CVE-2026-54370.html * https://www.suse.com/security/cve/CVE-2026-54371.html * https://bugzilla.suse.com/show_bug.cgi?id=1268867 * https://jira.suse.com/browse/PED-16501 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:45:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:45:50 -0000 Subject: SUSE-SU-2026:23704-1: important: Security update for ansible-core Message-ID: <178957715023.26114.11334932739036063977@b9be41dc2e4b> # Security update for ansible-core Announcement ID: SUSE-SU-2026:23704-1 Release Date: 2026-09-10T13:09:24Z Rating: important References: * bsc#1272369 Cross-References: * CVE-2026-11332 * CVE-2026-16493 CVSS scores: * CVE-2026-11332 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11332 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-11332 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16493 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16493 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for ansible-core fixes the following issues: * CVE-2026-16493: argument injection in ansible-galaxy collection install via git clone (bsc#1272369). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1657 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * ansible-core-2.18.3-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-11332.html * https://www.suse.com/security/cve/CVE-2026-16493.html * https://bugzilla.suse.com/show_bug.cgi?id=1272369 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:46:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:46:51 -0000 Subject: SUSE-SU-2026:23702-1: moderate: Security update for python-jwcrypto Message-ID: <178957721191.26114.6174463391678358827@b9be41dc2e4b> # Security update for python-jwcrypto Announcement ID: SUSE-SU-2026:23702-1 Release Date: 2026-09-10T09:40:10Z Rating: moderate References: * bsc#1277639 * bsc#1278707 Cross-References: * CVE-2026-80179 * CVE-2026-84185 CVSS scores: * CVE-2026-80179 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-80179 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-80179 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84185 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84185 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-84185 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for python-jwcrypto fixes the following issues: * CVE-2026-80179: denial of service via malformed JWE tokens (bsc#1277639). * CVE-2026-84185: general JSON JWS kid binding bypass during JWKSet verification (bsc#1278707). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1655 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * python313-jwcrypto-1.5.6-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-80179.html * https://www.suse.com/security/cve/CVE-2026-84185.html * https://bugzilla.suse.com/show_bug.cgi?id=1277639 * https://bugzilla.suse.com/show_bug.cgi?id=1278707 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:48:05 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:48:05 -0000 Subject: SUSE-SU-2026:23700-1: important: Security update for tomcat Message-ID: <178957728572.26114.7340438016409062897@b9be41dc2e4b> # Security update for tomcat Announcement ID: SUSE-SU-2026:23700-1 Release Date: 2026-09-09T14:14:08Z Rating: important References: * bsc#1273150 * bsc#1276893 * bsc#1276894 * bsc#1276895 * bsc#1276896 * bsc#1276897 * bsc#1276898 * bsc#1276899 * bsc#1276900 * bsc#1276901 * bsc#1276902 Cross-References: * CVE-2026-32990 * CVE-2026-65182 * CVE-2026-65183 * CVE-2026-65637 * CVE-2026-65905 * CVE-2026-65927 * CVE-2026-66299 * CVE-2026-66422 * CVE-2026-68525 * CVE-2026-68569 * CVE-2026-68763 * CVE-2026-73180 CVSS scores: * CVE-2026-32990 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-65182 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65182 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-65182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-65183 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65183 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65637 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65637 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65637 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65905 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65905 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-65905 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65927 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65927 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-66299 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-66422 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-66422 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-66422 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-68525 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68525 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68525 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68569 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68569 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68569 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68763 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68763 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68763 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73180 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-73180 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-73180 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 An update that solves 12 vulnerabilities can now be installed. ## Description: This update for tomcat fixes the following issues: * CVE-2026-65182: Bypass longest prefix security constraint (bsc#1276893). * CVE-2026-65183: TOCTOU when setting specific permissions for Unix Domain Sockets (bsc#1276894). * CVE-2026-65637: HTTP/2 no-authority bypass of strict SNI validation - fix incomplete (bsc#1276895). * CVE-2026-65905: Limited replay attack possible with DIGEST authentication (bsc#1276896). * CVE-2026-65927: RewriteValve [N] restarts at the second rule and may bypass access control (bsc#1276897). * CVE-2026-66299: memory exhaustion via maliciously slow clients due to the WebSocket chat example providing an unbounded buffer for undelivered messages (bsc#1273150). * CVE-2026-66422: Servlet role references can bypass declarative role constraints (bsc#1276898). * CVE-2026-68525: Redirect after FORM auth may bypass method specific constraints (bsc#1276899). * CVE-2026-68569: Principal lookup can fail open in some cases (bsc#1276900). * CVE-2026-68763: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset (bsc#1276901). * CVE-2026-73180: Authenticated WebSocket session survives end of HTTP session (bsc#1276902). Changes for tomcat: * Update to Tomcat 9.0.121 * Catalina * Fix: Ensure that a login-config conflict when merging web.xml fragments triggers a deployment failure. (markt) * Code: Remove unnecessary calls to String.intern() in the parsing of configuration files. (markt) * Fix: Extend sessionAttributeValueClassNameFilter to include filtering of dynamic proxy interface classes. (markt) * Fix: Attempt to use rollback when persisting user data to the DataSourceUserDatabase fails and improve error reporting. (remm) * Fix: 70143: Handle InvalidFileNameException when parsing parts to rethrow it as an IllegalStateException as mandated by the Servlet specification. (remm) * Fix: Add missing reason to the JsonErrorReportValve. (remm) * Fix: evaluation of the N and C flags for rewrite rules. (remm) * Fix: qsd flag should always discard the original query string when rewriting. (remm) * Fix: Add appropriate escaping for context path, current directory name and parent directory name for directory listings produced by the default servlet. Ensure XML escaping is used with XML output. (markt) * Fix: When processing certificate subject names and issuer names within RewriteValve rules, always use the RFC 2253 format name. (markt) * Fix: the incorrect rejection of requests using digest authentication when the client provided nonce count is at the upper boundary of the window (markt). * Update: Separate the Context role mapping from the Servlet specification security-role-ref. (remm) * Fix: Handle the case where the JNDIRealm is configured to perform role searches with userRoleAttribute but the attribute is not available or not configured for the current user. (markt) * Fix: Improve handling of session attribute addition concurrent with session expiration. An application will now either see a successful addition followed by expiration or the addition will not succeed. It is no longer possible for the session to expire and the addition to succeed. This is of particular not for attributes that implement HttpSessionBindingListener. (markt) * Fix: Add a new attribute to the Context, urlPatternsProvidedInDecodedForm. This attribute controls whether URLs and URL patterns provided in the deployment descriptor (web.xml), annotations and/or their programmatic equivalents are treated as being provided in URL-encoded form (i.e. using %nn encoding) or in decoded form. The Servlet specification requires that they are provided in decoded form. However, Tomcat has historically treated them as if they are provided in encoded form. In Tomcat 12, they will always be treated as if they are provided in decoded form. This setting enables migration from encoded form to decoded form on an application by application basis. This attribute will be removed in Tomcat 12 where it will effectively be hard-coded to true. (markt) * Fix: Ensure the security constraint with the longest matching path is selected when more than one constraint matches the request path. (markt) * Fix: If the request saved by FORM authentication uses a method other than GET, ensure that the security constraints are re-assessed after the saved request is restored and before it is processed. Custom Authenticator implementations that extend FormAuthenticator and override doAuthenticate() and/or restoreRequest() will require modification. (markt) * Fix: Various improvements to the DataSourceRealm. A failure to connect to the database or an exception during either user or role lookup will now result in an authentication failure rather than a partially populated Principal. For CLIENT-CERT and SPNEGO authentication, the user must exist in the database for authentication to succeed. (markt) * Coyote * Update: Add utility AutoCloseable URLConnection wrapper, and use it to cleanup existing code patterns. (remm/markt) * Fix: When processing an HTTP upgrade from HTTP/1.1 to HTTP/2, ensure that all the HTTP/1.1 data has been processed before switching protocols. (markt) * Fix: Require every HTTP/2 request to provide an authority (either an :authority pseudo header or a Host header). (markt) * Fix: Register the use of an HTTP/2 stream identifier earlier so that there is no possibility of a re-used stream identifier being accepted, regardless of how early in the HEADERS frame processing an error is detected. (markt) * Add: new attributes (unixDomainSocketParentPermissions and unixDomainSocketParentOwner) to the NIO connector to provide additional control over the security of Unix Domain Sockets. Additional checks (enabled by default) have also been added for the directory where the Unix Domain Socket will be created.(markt) * Fix: an allocation leak in the HTTP/2 backlog tracking when a stream is reset. (markt) * Jasper * Fix: Ensure internal state is reset before re-using ELParser. (markt) * WebSocket * Add: a limit (defaults to 8KB) on the size of the HTTP response headers accepted during a WebSocket HTTP upgrade. This is configured via the org.apache.tomcat.websocket.MAX_HTTP_RESPONSE_HEADER_BYTES user property. (markt) * Fix: Improve URI template matching for WebSocket end points. Trailing slashes are now significant both for template definitions and URIs considered for potential matches to those URIs. Note that this means if a URI template ends in a variable without a trailing slash, that variable might be expanded to the empty string. (markt) * Fix: Account for session ID changes when tracking WebSocket connections for closure because they were created under an authenticated HTTP session that has since ended. (markt) * Web applications * Fix: Documentation: Better sample httpd configuration for use with SSLValve and add a note that the exact configuration required will depend on the overall httpd configuration. (markt) * Fix: Examples: Limit the buffering of messages in the WebSocket chat example to prevent a malicious client triggering excessive memory usage that could lead to a DoS. (markt) * Fix: Documentation: Expand the description of the %S (session ID) access log pattern token. (markt) * Fix: Manager: Use reflection to load clustering classes in sessionsList.jsp so the sessions list page renders correctly when clustering JARs are not present. (csutherl) * Other * Update: Maven Resolver Ant Tasks to 1.6.1. (rjung) * Update: Objenesis to 3.6. (markt) * Update: JSign to 7.5. (markt) * Update: Bouncy Castle to 1.85. (markt) * Add: Improvements to French translations. (remm) * Add: Improvements to Japanese translations provided by tak7iji. (markt) * Cluster * Add: Change the default encryptionAlgorithm for the EncryptInterceptor to AES/GCM/NoPadding. This is a breaking change for the EncryptInterceptor. (markt) * Add: Expand the documentation for the EncryptInterceptor to be more explicit regarding the security weaknesses of some supported algorithms. Also explicitly state that the replay protection is only effective for non- malleable algorithms. (markt) * Add: Expand the Javadoc for the DNSMembershipProvider in particular explaining its behaviour and providing configuration advice if control more over cluster membership is required. (markt) * jdbc-pool * Fix: 70164: Correct the documentation for the testOnBorrow attribute. Pull request #1033 provided by Kohei Tamura. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1651 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * tomcat-servlet-4_0-api-9.0.121-160000.1.1 * tomcat-jsvc-9.0.121-160000.1.1 * tomcat-docs-webapp-9.0.121-160000.1.1 * tomcat-9.0.121-160000.1.1 * tomcat-lib-9.0.121-160000.1.1 * tomcat-embed-9.0.121-160000.1.1 * tomcat-webapps-9.0.121-160000.1.1 * tomcat-admin-webapps-9.0.121-160000.1.1 * tomcat-jsp-2_3-api-9.0.121-160000.1.1 * tomcat-javadoc-9.0.121-160000.1.1 * tomcat-el-3_0-api-9.0.121-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32990.html * https://www.suse.com/security/cve/CVE-2026-65182.html * https://www.suse.com/security/cve/CVE-2026-65183.html * https://www.suse.com/security/cve/CVE-2026-65637.html * https://www.suse.com/security/cve/CVE-2026-65905.html * https://www.suse.com/security/cve/CVE-2026-65927.html * https://www.suse.com/security/cve/CVE-2026-66299.html * https://www.suse.com/security/cve/CVE-2026-66422.html * https://www.suse.com/security/cve/CVE-2026-68525.html * https://www.suse.com/security/cve/CVE-2026-68569.html * https://www.suse.com/security/cve/CVE-2026-68763.html * https://www.suse.com/security/cve/CVE-2026-73180.html * https://bugzilla.suse.com/show_bug.cgi?id=1273150 * https://bugzilla.suse.com/show_bug.cgi?id=1276893 * https://bugzilla.suse.com/show_bug.cgi?id=1276894 * https://bugzilla.suse.com/show_bug.cgi?id=1276895 * https://bugzilla.suse.com/show_bug.cgi?id=1276896 * https://bugzilla.suse.com/show_bug.cgi?id=1276897 * https://bugzilla.suse.com/show_bug.cgi?id=1276898 * https://bugzilla.suse.com/show_bug.cgi?id=1276899 * https://bugzilla.suse.com/show_bug.cgi?id=1276900 * https://bugzilla.suse.com/show_bug.cgi?id=1276901 * https://bugzilla.suse.com/show_bug.cgi?id=1276902 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:49:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:49:27 -0000 Subject: SUSE-SU-2026:23697-1: moderate: Security update for opensc Message-ID: <178957736793.26114.2870292969873536863@b9be41dc2e4b> # Security update for opensc Announcement ID: SUSE-SU-2026:23697-1 Release Date: 2026-09-09T14:07:45Z Rating: moderate References: * bsc#1266964 Cross-References: * CVE-2026-40510 CVSS scores: * CVE-2026-40510 ( SUSE ): 4.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-40510 ( SUSE ): 5.7 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-40510 ( NVD ): 1.0 CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40510 ( NVD ): 3.8 CVSS:3.1/AV:P/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2026-40510 ( NVD ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for opensc fixes the following issue: * CVE-2026-40510: stack buffer overflow in `piv_process_history()` allows physically present attackers to trigger memory corruption by presenting a crafted PIV smart card or USB device (bsc#1266964). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1648 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * opensc-0.26.1-160000.4.1 * opensc-debuginfo-0.26.1-160000.4.1 * opensc-debugsource-0.26.1-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40510.html * https://bugzilla.suse.com/show_bug.cgi?id=1266964 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:50:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:50:30 -0000 Subject: SUSE-SU-2026:23695-1: moderate: Security update for libcupsfilters Message-ID: <178957743075.26114.411924011886422047@b9be41dc2e4b> # Security update for libcupsfilters Announcement ID: SUSE-SU-2026:23695-1 Release Date: 2026-09-09T13:16:45Z Rating: moderate References: * bsc#1273145 * bsc#1273146 Cross-References: * CVE-2026-64611 * CVE-2026-64612 CVSS scores: * CVE-2026-64611 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64611 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64611 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64612 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64612 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64612 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for libcupsfilters fixes the following issues: * CVE-2026-64611: infinite-loop CPU-exhaustion DoS in cfIEEE1284NormalizeMakeModel on empty MDL field (bsc#1273145). * CVE-2026-64612: malformed PNG aborts CUPS image filter process (bsc#1273146). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1646 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libcupsfilters2-debuginfo-2.1.1-160000.3.1 * libcupsfilters-2.1.1-160000.3.1 * libcupsfilters2-2.1.1-160000.3.1 * libcupsfilters-devel-2.1.1-160000.3.1 * libcupsfilters-debugsource-2.1.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64611.html * https://www.suse.com/security/cve/CVE-2026-64612.html * https://bugzilla.suse.com/show_bug.cgi?id=1273145 * https://bugzilla.suse.com/show_bug.cgi?id=1273146 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:51:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:51:52 -0000 Subject: SUSE-SU-2026:23692-1: low: Security update for govulncheck-vulndb Message-ID: <178957751200.26114.1819639900495390041@b9be41dc2e4b> # Security update for govulncheck-vulndb Announcement ID: SUSE-SU-2026:23692-1 Release Date: 2026-09-08T16:29:20Z Rating: low References: * jsc#PED-11136 Cross-References: * CVE-2026-20909 * CVE-2026-22547 * CVE-2026-24690 * CVE-2026-25712 * CVE-2026-25718 * CVE-2026-26232 * CVE-2026-26247 * CVE-2026-26307 * CVE-2026-27657 * CVE-2026-27878 * CVE-2026-28705 * CVE-2026-54746 * CVE-2026-54754 * CVE-2026-54755 * CVE-2026-54766 * CVE-2026-55064 * CVE-2026-55065 * CVE-2026-55066 * CVE-2026-55067 * CVE-2026-55068 * CVE-2026-55108 * CVE-2026-55245 * CVE-2026-55484 * CVE-2026-55569 * CVE-2026-55588 * CVE-2026-55621 * CVE-2026-55622 * CVE-2026-55678 * CVE-2026-55761 * CVE-2026-55763 * CVE-2026-55764 * CVE-2026-55784 * CVE-2026-55785 * CVE-2026-55834 * CVE-2026-55873 * CVE-2026-55874 * CVE-2026-56854 * CVE-2026-56855 * CVE-2026-78662 CVSS scores: * CVE-2026-20909 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-22547 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-24690 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-25712 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-25718 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-26232 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-26247 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-26307 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27657 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-27878 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-28705 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-54746 ( NVD ): 6.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:L * CVE-2026-54754 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H * CVE-2026-54755 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H * CVE-2026-54766 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55064 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-55065 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-55066 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N * CVE-2026-55067 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N * CVE-2026-55068 ( NVD ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55108 ( NVD ): 8.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:H * CVE-2026-55245 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55484 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55569 ( NVD ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L * CVE-2026-55588 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-55621 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-55622 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-55678 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55761 ( NVD ): 7.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55761 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-55763 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55764 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-55784 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-55785 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-55834 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-55873 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-55874 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-56854 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56854 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56854 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56855 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78662 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78662 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78662 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 An update that solves 39 vulnerabilities and contains one feature can now be installed. ## Description: This update for govulncheck-vulndb fixes the following issues: * Update to version 0.0.20260902T191204 2026-09-02T19:12:04Z (jsc#PED-11136). Go CVE Numbering Authority IDs added or updated with aliases: * GO-2026-6305 CVE-2026-55834 GHSA-2wvm-8mvp-22qv * GO-2026-6306 CVE-2026-55064 GHSA-44v6-7fxq- vgf4 * GO-2026-6307 CVE-2026-55067 GHSA-569v-q83c-3j3g * GO-2026-6308 CVE-2026-55066 GHSA-5pg6-m483-7vrg * GO-2026-6309 CVE-2026-54746 GHSA-8x7x-83cf-c3pg * GO-2026-6310 CVE-2026-54755 GHSA-cgc5-v3f2-8m2v * GO-2026-6311 CVE-2026-54766 GHSA-f27p-pw2p-9pr4 * GO-2026-6312 CVE-2026-55108 GHSA-fmgp-q6jx-gg3x * GO-2026-6313 CVE-2026-55065 GHSA-gg93-x632-9ccv * GO-2026-6314 CVE-2026-55569 GHSA-mf5c-hw34-4hpp * GO-2026-6315 CVE-2026-54754 GHSA-p7gw-2pcp-5pf8 * GO-2026-6316 CVE-2026-55068 GHSA-x8mj-6p3q-g5pp * GO-2026-6317 CVE-2026-55588 GHSA-298f-872v-2rcx * GO-2026-6318 CVE-2026-55621 GHSA-64f3-v33m-w89f * GO-2026-6319 CVE-2026-55622 GHSA-c9f5-j9c3-mhrg * GO-2026-6320 CVE-2026-55245 GHSA-w98g-5w9p-p3rc * GO-2026-6321 CVE-2026-55484 GHSA-hr6j-w4mw-g9mj * GO-2026-6322 CVE-2026-55678 GHSA-p378-jp5r-gpgw * GO-2026-6323 CVE-2026-55763 GHSA-v358-wf77-39xv * GO-2026-6324 CVE-2026-55761 GHSA-x626-fcwx-f5pc * GO-2026-6325 CVE-2026-27878 GHSA-6xff-cpcq-vpw2 * GO-2026-6326 CVE-2026-55784 GHSA-334q-h5g3-fpxv * GO-2026-6327 CVE-2026-55874 GHSA-56wq-x3wv-3ff4 * GO-2026-6328 CVE-2026-55785 GHSA-fp46-6vfw-gc9c * GO-2026-6329 CVE-2026-55873 GHSA-hgpf-8634-g44c * GO-2026-6330 CVE-2026-55764 GHSA-mrpp-v6pg-p54x * GO-2026-6333 CVE-2026-25712 GHSA-37w2-86g3-h4qh * GO-2026-6334 CVE-2026-24690 GHSA-47rq-xp99-92mx * GO-2026-6335 CVE-2026-27657 GHSA-4c8f-3m6h-m56r * GO-2026-6336 CVE-2026-26232 GHSA-5v69-g2m3-3hq3 * GO-2026-6337 CVE-2026-28705 GHSA-7jvx-g65v-r899 * GO-2026-6338 CVE-2026-22547 GHSA-922f-hfwp-p56f * GO-2026-6339 CVE-2026-20909 GHSA-fhq3-p242-2qpf * GO-2026-6340 CVE-2026-25718 GHSA-h697-89cp-24q8 * GO-2026-6341 CVE-2026-26307 GHSA-h9c5-x7g8-4q7f * GO-2026-6342 CVE-2026-26247 GHSA-m5ch-ppfx-xv3v * GO-2026-6354 CVE-2026-78662 * GO-2026-6355 CVE-2026-56855 * Update to version 0.0.20260828T144745 2026-08-28T14:47:45Z. * GO-2026-6303 CVE-2026-56854 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1643 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * govulncheck-vulndb-0.0.20260902T191204-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-20909.html * https://www.suse.com/security/cve/CVE-2026-22547.html * https://www.suse.com/security/cve/CVE-2026-24690.html * https://www.suse.com/security/cve/CVE-2026-25712.html * https://www.suse.com/security/cve/CVE-2026-25718.html * https://www.suse.com/security/cve/CVE-2026-26232.html * https://www.suse.com/security/cve/CVE-2026-26247.html * https://www.suse.com/security/cve/CVE-2026-26307.html * https://www.suse.com/security/cve/CVE-2026-27657.html * https://www.suse.com/security/cve/CVE-2026-27878.html * https://www.suse.com/security/cve/CVE-2026-28705.html * https://www.suse.com/security/cve/CVE-2026-54746.html * https://www.suse.com/security/cve/CVE-2026-54754.html * https://www.suse.com/security/cve/CVE-2026-54755.html * https://www.suse.com/security/cve/CVE-2026-54766.html * https://www.suse.com/security/cve/CVE-2026-55064.html * https://www.suse.com/security/cve/CVE-2026-55065.html * https://www.suse.com/security/cve/CVE-2026-55066.html * https://www.suse.com/security/cve/CVE-2026-55067.html * https://www.suse.com/security/cve/CVE-2026-55068.html * https://www.suse.com/security/cve/CVE-2026-55108.html * https://www.suse.com/security/cve/CVE-2026-55245.html * https://www.suse.com/security/cve/CVE-2026-55484.html * https://www.suse.com/security/cve/CVE-2026-55569.html * https://www.suse.com/security/cve/CVE-2026-55588.html * https://www.suse.com/security/cve/CVE-2026-55621.html * https://www.suse.com/security/cve/CVE-2026-55622.html * https://www.suse.com/security/cve/CVE-2026-55678.html * https://www.suse.com/security/cve/CVE-2026-55761.html * https://www.suse.com/security/cve/CVE-2026-55763.html * https://www.suse.com/security/cve/CVE-2026-55764.html * https://www.suse.com/security/cve/CVE-2026-55784.html * https://www.suse.com/security/cve/CVE-2026-55785.html * https://www.suse.com/security/cve/CVE-2026-55834.html * https://www.suse.com/security/cve/CVE-2026-55873.html * https://www.suse.com/security/cve/CVE-2026-55874.html * https://www.suse.com/security/cve/CVE-2026-56854.html * https://www.suse.com/security/cve/CVE-2026-56855.html * https://www.suse.com/security/cve/CVE-2026-78662.html * https://jira.suse.com/browse/PED-11136 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:52:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:52:43 -0000 Subject: SUSE-SU-2026:23691-1: important: Security update for tomcat11 Message-ID: <178957756340.26114.15534912829007886127@b9be41dc2e4b> # Security update for tomcat11 Announcement ID: SUSE-SU-2026:23691-1 Release Date: 2026-09-08T15:49:16Z Rating: important References: * bsc#1273150 * bsc#1276893 * bsc#1276894 * bsc#1276895 * bsc#1276896 * bsc#1276897 * bsc#1276898 * bsc#1276899 * bsc#1276900 * bsc#1276901 * bsc#1276902 Cross-References: * CVE-2026-32990 * CVE-2026-65182 * CVE-2026-65183 * CVE-2026-65637 * CVE-2026-65905 * CVE-2026-65927 * CVE-2026-66299 * CVE-2026-66422 * CVE-2026-68525 * CVE-2026-68569 * CVE-2026-68763 * CVE-2026-73180 CVSS scores: * CVE-2026-32990 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-65182 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65182 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-65182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-65183 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65183 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65637 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65637 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65637 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65905 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65905 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-65905 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65927 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65927 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-66299 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-66422 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-66422 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-66422 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-68525 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68525 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68525 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68569 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68569 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68569 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68763 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68763 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68763 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73180 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-73180 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-73180 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 An update that solves 12 vulnerabilities can now be installed. ## Description: This update for tomcat11 fixes the following issues: * CVE-2026-65182: Bypass longest prefix security constraint (bsc#1276893). * CVE-2026-65183: TOCTOU when setting specific permissions for Unix Domain Sockets (bsc#1276894). * CVE-2026-65637: HTTP/2 no-authority bypass of strict SNI validation - fix incomplete (bsc#1276895). * CVE-2026-65905: Limited replay attack possible with DIGEST authentication (bsc#1276896). * CVE-2026-65927: RewriteValve [N] restarts at the second rule and may bypass access control (bsc#1276897). * CVE-2026-66299: memory exhaustion via maliciously slow clients due to the WebSocket chat example providing an unbounded buffer for undelivered messages (bsc#1273150). * CVE-2026-66422: Servlet role references can bypass declarative role constraints (bsc#1276898). * CVE-2026-68525: Redirect after FORM auth may bypass method specific constraints (bsc#1276899). * CVE-2026-68569: Principal lookup can fail open in some cases (bsc#1276900). * CVE-2026-68763: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset (bsc#1276901). * CVE-2026-73180: Authenticated WebSocket session survives end of HTTP session (bsc#1276902). Changes for tomcat11: * Update to Tomcat 11.0.25 * Catalina * Fix: Ensure that a login-config conflict when merging web.xml fragments triggers a deployment failure. (markt) * Code: Remove unnecessary calls to String.intern() in the parsing of configuration files. (markt) * Fix: Extend sessionAttributeValueClassNameFilter to include filtering of dynamic proxy interface classes. (markt) * Fix: Attempt to use rollback when persisting user data to the DataSourceUserDatabase fails and improve error reporting. (remm) * Fix: 70143: Handle InvalidFileNameException when parsing parts to rethrow it as an IllegalStateException as mandated by the Servlet specification. (remm) * Fix: Add missing reason to the JsonErrorReportValve. (remm) * Fix: evaluation of the N and C flags for rewrite rules. (remm) * Fix: qsd flag should always discard the original query string when rewriting. (remm) * Fix: Add appropriate escaping for context path, current directory name and parent directory name for directory listings produced by the default servlet. Ensure XML escaping is used with XML output. (markt) * Fix: When processing certificate subject names and issuer names within RewriteValve rules, always use the RFC 2253 format name. (markt) * Fix: the incorrect rejection of requests using digest authentication when the client provided nonce count is at the upper boundary of the window (markt). * Update: Separate the Context role mapping from the Servlet specification security-role-ref. (remm) * Fix: Handle the case where the JNDIRealm is configured to perform role searches with userRoleAttribute but the attribute is not available or not configured for the current user. (markt) * Fix: Improve handling of session attribute addition concurrent with session expiration. An application will now either see a successful addition followed by expiration or the addition will not succeed. It is no longer possible for the session to expire and the addition to succeed. This is of particular not for attributes that implement HttpSessionBindingListener. (markt) * Fix: Add a new attribute to the Context, urlPatternsProvidedInDecodedForm. This attribute controls whether URLs and URL patterns provided in the deployment descriptor (web.xml), annotations and/or their programmatic equivalents are treated as being provided in URL-encoded form (i.e. using %nn encoding) or in decoded form. The Servlet specification requires that they are provided in decoded form. However, Tomcat has historically treated them as if they are provided in encoded form. In Tomcat 12, they will always be treated as if they are provided in decoded form. This setting enables migration from encoded form to decoded form on an application by application basis. This attribute will be removed in Tomcat 12 where it will effectively be hard-coded to true. (markt) * Fix: Ensure the security constraint with the longest matching path is selected when more than one constraint matches the request path. (markt) * Fix: If the request saved by FORM authentication uses a method other than GET, ensure that the security constraints are re-assessed after the saved request is restored and before it is processed. Custom Authenticator implementations that extend FormAuthenticator and override doAuthenticate() and/or restoreRequest() will require modification. (markt) * Fix: Various improvements to the DataSourceRealm. A failure to connect to the database or an exception during either user or role lookup will now result in an authentication failure rather than a partially populated Principal. For CLIENT-CERT and SPNEGO authentication, the user must exist in the database for authentication to succeed. (markt) * Coyote * Update: Add utility AutoCloseable URLConnection wrapper, and use it to cleanup existing code patterns. (remm/markt) * Fix: When processing an HTTP upgrade from HTTP/1.1 to HTTP/2, ensure that all the HTTP/1.1 data has been processed before switching protocols. (markt) * Fix: Require every HTTP/2 request to provide an authority (either an :authority pseudo header or a Host header). (markt) * Fix: Register the use of an HTTP/2 stream identifier earlier so that there is no possibility of a re-used stream identifier being accepted, regardless of how early in the HEADERS frame processing an error is detected. (markt) * Add: new attributes (unixDomainSocketParentPermissions and unixDomainSocketParentOwner) to the NIO connector to provide additional control over the security of Unix Domain Sockets. Additional checks (enabled by default) have also been added for the directory where the Unix Domain Socket will be created.(markt) * Fix: an allocation leak in the HTTP/2 backlog tracking when a stream is reset. (markt) * Jasper * Fix: Ensure internal state is reset before re-using ELParser. (markt) * WebSocket * Add: a limit (defaults to 8KB) on the size of the HTTP response headers accepted during a WebSocket HTTP upgrade. This is configured via the org.apache.tomcat.websocket.MAX_HTTP_RESPONSE_HEADER_BYTES user property. (markt) * Fix: Improve URI template matching for WebSocket end points. Trailing slashes are now significant both for template definitions and URIs considered for potential matches to those URIs. Note that this means if a URI template ends in a variable without a trailing slash, that variable might be expanded to the empty string. (markt) * Fix: Account for session ID changes when tracking WebSocket connections for closure because they were created under an authenticated HTTP session that has since ended. (markt) * Web applications * Fix: 70160: Correct various references to the Servlet specification to use version 6.1. (markt) * Fix: Documentation: Better sample httpd configuration for use with SSLValve and add a note that the exact configuration required will depend on the overall httpd configuration. (markt) * Fix: Examples: Limit the buffering of messages in the WebSocket chat example to prevent a malicious client triggering excessive memory usage that could lead to a DoS. (markt) * Fix: Documentation: Expand the description of the %S (session ID) access log pattern token. (markt) * Fix: Manager: Use reflection to load clustering classes in sessionsList.jsp so the sessions list page renders correctly when clustering JARs are not present. (csutherl) * Other * Update: Maven Resolver Ant Tasks to 1.6.1. (rjung) * Update: Objenesis to 3.6. (markt) * Update: JSign to 7.5. (markt) * Update: Bouncy Castle to 1.85. (markt) * Add: Improvements to French translations. (remm) * Add: Improvements to Japanese translations provided by tak7iji. (markt) * Cluster * Add: Change the default encryptionAlgorithm for the EncryptInterceptor to AES/GCM/NoPadding. This is a breaking change for the EncryptInterceptor. (markt) * Add: Expand the documentation for the EncryptInterceptor to be more explicit regarding the security weaknesses of some supported algorithms. Also explicitly state that the replay protection is only effective for non- malleable algorithms. (markt) * Add: Expand the Javadoc for the DNSMembershipProvider in particular explaining its behaviour and providing configuration advice if control more over cluster membership is required. (markt) * jdbc-pool * Fix: 70164: Correct the documentation for the testOnBorrow attribute. Pull request #1033 provided by Kohei Tamura. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1642 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * tomcat11-el-6_0-api-11.0.25-160000.1.1 * tomcat11-embed-11.0.25-160000.1.1 * tomcat11-jsvc-11.0.25-160000.1.1 * tomcat11-docs-webapp-11.0.25-160000.1.1 * tomcat11-servlet-6_1-api-11.0.25-160000.1.1 * tomcat11-webapps-11.0.25-160000.1.1 * tomcat11-11.0.25-160000.1.1 * tomcat11-admin-webapps-11.0.25-160000.1.1 * tomcat11-lib-11.0.25-160000.1.1 * tomcat11-jsp-4_0-api-11.0.25-160000.1.1 * tomcat11-doc-11.0.25-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32990.html * https://www.suse.com/security/cve/CVE-2026-65182.html * https://www.suse.com/security/cve/CVE-2026-65183.html * https://www.suse.com/security/cve/CVE-2026-65637.html * https://www.suse.com/security/cve/CVE-2026-65905.html * https://www.suse.com/security/cve/CVE-2026-65927.html * https://www.suse.com/security/cve/CVE-2026-66299.html * https://www.suse.com/security/cve/CVE-2026-66422.html * https://www.suse.com/security/cve/CVE-2026-68525.html * https://www.suse.com/security/cve/CVE-2026-68569.html * https://www.suse.com/security/cve/CVE-2026-68763.html * https://www.suse.com/security/cve/CVE-2026-73180.html * https://bugzilla.suse.com/show_bug.cgi?id=1273150 * https://bugzilla.suse.com/show_bug.cgi?id=1276893 * https://bugzilla.suse.com/show_bug.cgi?id=1276894 * https://bugzilla.suse.com/show_bug.cgi?id=1276895 * https://bugzilla.suse.com/show_bug.cgi?id=1276896 * https://bugzilla.suse.com/show_bug.cgi?id=1276897 * https://bugzilla.suse.com/show_bug.cgi?id=1276898 * https://bugzilla.suse.com/show_bug.cgi?id=1276899 * https://bugzilla.suse.com/show_bug.cgi?id=1276900 * https://bugzilla.suse.com/show_bug.cgi?id=1276901 * https://bugzilla.suse.com/show_bug.cgi?id=1276902 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:53:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:53:34 -0000 Subject: SUSE-SU-2026:23690-1: important: Security update for tomcat10 Message-ID: <178957761460.26114.14620500416866532803@b9be41dc2e4b> # Security update for tomcat10 Announcement ID: SUSE-SU-2026:23690-1 Release Date: 2026-09-08T15:49:16Z Rating: important References: * bsc#1273150 * bsc#1276893 * bsc#1276894 * bsc#1276895 * bsc#1276896 * bsc#1276897 * bsc#1276898 * bsc#1276899 * bsc#1276900 * bsc#1276901 * bsc#1276902 Cross-References: * CVE-2026-32990 * CVE-2026-65182 * CVE-2026-65183 * CVE-2026-65637 * CVE-2026-65905 * CVE-2026-65927 * CVE-2026-66299 * CVE-2026-66422 * CVE-2026-68525 * CVE-2026-68569 * CVE-2026-68763 * CVE-2026-73180 CVSS scores: * CVE-2026-32990 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-65182 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65182 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-65182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-65183 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65183 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65637 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65637 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65637 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65905 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65905 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-65905 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65927 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65927 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-66299 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-66422 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-66422 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-66422 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-68525 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68525 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68525 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68569 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68569 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68569 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68763 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68763 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68763 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73180 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-73180 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-73180 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise Server 16.0 An update that solves 12 vulnerabilities can now be installed. ## Description: This update for tomcat10 fixes the following issues: * CVE-2026-65182: Bypass longest prefix security constraint (bsc#1276893). * CVE-2026-65183: TOCTOU when setting specific permissions for Unix Domain Sockets (bsc#1276894). * CVE-2026-65637: HTTP/2 no-authority bypass of strict SNI validation - fix incomplete (bsc#1276895). * CVE-2026-65905: Limited replay attack possible with DIGEST authentication (bsc#1276896). * CVE-2026-65927: RewriteValve [N] restarts at the second rule and may bypass access control (bsc#1276897). * CVE-2026-66299: memory exhaustion via maliciously slow clients due to the WebSocket chat example providing an unbounded buffer for undelivered messages (bsc#1273150). * CVE-2026-66422: Servlet role references can bypass declarative role constraints (bsc#1276898). * CVE-2026-68525: Redirect after FORM auth may bypass method specific constraints (bsc#1276899). * CVE-2026-68569: Principal lookup can fail open in some cases (bsc#1276900). * CVE-2026-68763: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset (bsc#1276901). * CVE-2026-73180: Authenticated WebSocket session survives end of HTTP session (bsc#1276902). Changes for tomcat10: * Update to Tomcat 10.1.59 * Catalina * Fix: Ensure that a login-config conflict when merging web.xml fragments triggers a deployment failure. (markt) * Code: Remove unnecessary calls to String.intern() in the parsing of configuration files. (markt) * Fix: Extend sessionAttributeValueClassNameFilter to include filtering of dynamic proxy interface classes. (markt) * Fix: Attempt to use rollback when persisting user data to the DataSourceUserDatabase fails and improve error reporting. (remm) * Fix: 70143: Handle InvalidFileNameException when parsing parts to rethrow it as an IllegalStateException as mandated by the Servlet specification. (remm) * Fix: Add missing reason to the JsonErrorReportValve. (remm) * Fix: evaluation of the N and C flags for rewrite rules. (remm) * Fix: qsd flag should always discard the original query string when rewriting. (remm) * Fix: Add appropriate escaping for context path, current directory name and parent directory name for directory listings produced by the default servlet. Ensure XML escaping is used with XML output. (markt) * Fix: When processing certificate subject names and issuer names within RewriteValve rules, always use the RFC 2253 format name. (markt) * Fix: the incorrect rejection of requests using digest authentication when the client provided nonce count is at the upper boundary of the window (markt). * Update: Separate the Context role mapping from the Servlet specification security-role-ref. (remm) * Fix: Handle the case where the JNDIRealm is configured to perform role searches with userRoleAttribute but the attribute is not available or not configured for the current user. (markt) * Fix: Improve handling of session attribute addition concurrent with session expiration. An application will now either see a successful addition followed by expiration or the addition will not succeed. It is no longer possible for the session to expire and the addition to succeed. This is of particular not for attributes that implement HttpSessionBindingListener. (markt) * Fix: Add a new attribute to the Context, urlPatternsProvidedInDecodedForm. This attribute controls whether URLs and URL patterns provided in the deployment descriptor (web.xml), annotations and/or their programmatic equivalents are treated as being provided in URL-encoded form (i.e. using %nn encoding) or in decoded form. The Servlet specification requires that they are provided in decoded form. However, Tomcat has historically treated them as if they are provided in encoded form. In Tomcat 12, they will always be treated as if they are provided in decoded form. This setting enables migration from encoded form to decoded form on an application by application basis. This attribute will be removed in Tomcat 12 where it will effectively be hard-coded to true. (markt) * Fix: Ensure the security constraint with the longest matching path is selected when more than one constraint matches the request path. (markt) * Fix: If the request saved by FORM authentication uses a method other than GET, ensure that the security constraints are re-assessed after the saved request is restored and before it is processed. Custom Authenticator implementations that extend FormAuthenticator and override doAuthenticate() and/or restoreRequest() will require modification. (markt) * Fix: Various improvements to the DataSourceRealm. A failure to connect to the database or an exception during either user or role lookup will now result in an authentication failure rather than a partially populated Principal. For CLIENT-CERT and SPNEGO authentication, the user must exist in the database for authentication to succeed. (markt) * Fix: Improve the handling of AsyncContext.dispatch() when the Context attribute dispatchersUseEncodedPaths is set to false since the application has no control over the path used for the AsyncContext.dispatch(). Prior to this fix, paths containing literal '?' characters were truncated. (markt) * Fix: Ensure that capture groups from a RewriteCond always reflect the result of the current request. (markt) * Fix: async path building. (markt) * Coyote * Update: Add utility AutoCloseable URLConnection wrapper, and use it to cleanup existing code patterns. (remm/markt) * Fix: When processing an HTTP upgrade from HTTP/1.1 to HTTP/2, ensure that all the HTTP/1.1 data has been processed before switching protocols. (markt) * Fix: Require every HTTP/2 request to provide an authority (either an :authority pseudo header or a Host header). (markt) * Fix: Register the use of an HTTP/2 stream identifier earlier so that there is no possibility of a re-used stream identifier being accepted, regardless of how early in the HEADERS frame processing an error is detected. (markt) * Add: new attributes (unixDomainSocketParentPermissions and unixDomainSocketParentOwner) to the NIO connector to provide additional control over the security of Unix Domain Sockets. Additional checks (enabled by default) have also been added for the directory where the Unix Domain Socket will be created.(markt) * Fix: an allocation leak in the HTTP/2 backlog tracking when a stream is reset. (markt) * Fix: parsing of client certificates that specify more than one OCSP responder for configurations that use OpenSSL-FFM. (markt) * Jasper * Fix: Ensure internal state is reset before re-using ELParser. (markt) * WebSocket * Add: a limit (defaults to 8KB) on the size of the HTTP response headers accepted during a WebSocket HTTP upgrade. This is configured via the org.apache.tomcat.websocket.MAX_HTTP_RESPONSE_HEADER_BYTES user property. (markt) * Fix: Improve URI template matching for WebSocket end points. Trailing slashes are now significant both for template definitions and URIs considered for potential matches to those URIs. Note that this means if a URI template ends in a variable without a trailing slash, that variable might be expanded to the empty string. (markt) * Fix: Account for session ID changes when tracking WebSocket connections for closure because they were created under an authenticated HTTP session that has since ended. (markt) * Web applications * Fix: Documentation: Better sample httpd configuration for use with SSLValve and add a note that the exact configuration required will depend on the overall httpd configuration. (markt) * Fix: Examples: Limit the buffering of messages in the WebSocket chat example to prevent a malicious client triggering excessive memory usage that could lead to a DoS. (markt) * Fix: Documentation: Expand the description of the %S (session ID) access log pattern token. (markt) * Fix: Manager: Use reflection to load clustering classes in sessionsList.jsp so the sessions list page renders correctly when clustering JARs are not present. (csutherl) * Other * Update: Maven Resolver Ant Tasks to 1.6.1. (rjung) * Update: Objenesis to 3.6. (markt) * Update: JSign to 7.5. (markt) * Update: Bouncy Castle to 1.85. (markt) * Add: Improvements to French translations. (remm) * Add: Improvements to Japanese translations provided by tak7iji. (markt) * Cluster * Add: Change the default encryptionAlgorithm for the EncryptInterceptor to AES/GCM/NoPadding. This is a breaking change for the EncryptInterceptor. (markt) * Add: Expand the documentation for the EncryptInterceptor to be more explicit regarding the security weaknesses of some supported algorithms. Also explicitly state that the replay protection is only effective for non- malleable algorithms. (markt) * Add: Expand the Javadoc for the DNSMembershipProvider in particular explaining its behaviour and providing configuration advice if control more over cluster membership is required. (markt) * jdbc-pool * Fix: 70164: Correct the documentation for the testOnBorrow attribute. Pull request #1033 provided by Kohei Tamura. (markt) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1641 ## Package List: * SUSE Linux Enterprise Server 16.0 (noarch) * tomcat10-embed-10.1.59-160000.1.1 * tomcat10-admin-webapps-10.1.59-160000.1.1 * tomcat10-10.1.59-160000.1.1 * tomcat10-el-5_0-api-10.1.59-160000.1.1 * tomcat10-doc-10.1.59-160000.1.1 * tomcat10-jsvc-10.1.59-160000.1.1 * tomcat10-servlet-6_0-api-10.1.59-160000.1.1 * tomcat10-docs-webapp-10.1.59-160000.1.1 * tomcat10-jsp-3_1-api-10.1.59-160000.1.1 * tomcat10-lib-10.1.59-160000.1.1 * tomcat10-webapps-10.1.59-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-32990.html * https://www.suse.com/security/cve/CVE-2026-65182.html * https://www.suse.com/security/cve/CVE-2026-65183.html * https://www.suse.com/security/cve/CVE-2026-65637.html * https://www.suse.com/security/cve/CVE-2026-65905.html * https://www.suse.com/security/cve/CVE-2026-65927.html * https://www.suse.com/security/cve/CVE-2026-66299.html * https://www.suse.com/security/cve/CVE-2026-66422.html * https://www.suse.com/security/cve/CVE-2026-68525.html * https://www.suse.com/security/cve/CVE-2026-68569.html * https://www.suse.com/security/cve/CVE-2026-68763.html * https://www.suse.com/security/cve/CVE-2026-73180.html * https://bugzilla.suse.com/show_bug.cgi?id=1273150 * https://bugzilla.suse.com/show_bug.cgi?id=1276893 * https://bugzilla.suse.com/show_bug.cgi?id=1276894 * https://bugzilla.suse.com/show_bug.cgi?id=1276895 * https://bugzilla.suse.com/show_bug.cgi?id=1276896 * https://bugzilla.suse.com/show_bug.cgi?id=1276897 * https://bugzilla.suse.com/show_bug.cgi?id=1276898 * https://bugzilla.suse.com/show_bug.cgi?id=1276899 * https://bugzilla.suse.com/show_bug.cgi?id=1276900 * https://bugzilla.suse.com/show_bug.cgi?id=1276901 * https://bugzilla.suse.com/show_bug.cgi?id=1276902 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:54:20 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:54:20 -0000 Subject: SUSE-SU-2026:23689-1: critical: Security update for libzypp, zypper Message-ID: <178957766093.26114.3376023529421016487@b9be41dc2e4b> # Security update for libzypp, zypper Announcement ID: SUSE-SU-2026:23689-1 Release Date: 2026-09-08T15:42:08Z Rating: critical References: * bsc#1257249 * bsc#1271730 * bsc#1272534 * bsc#1273242 * bsc#1274091 * bsc#1274625 * bsc#1277790 Affected Products: * SUSE Linux Enterprise Server 16.0 An update that has seven fixes can now be installed. ## Description: This update for libzypp, zypper fixes the following issues: Security issue fixed: * invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY- CACHE-01] (bsc#1274625). Non security issues fixed: * Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). * Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). * zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). * Zypper patch doesn't give enough details about conflicts (bsc#1277790). Changes for libzypp: Update to version 17.38.1: * Prevent libgpgme from launching gpg-agents; we don't need them. * defaultLoadSystem: Hand out the ZYpp::Ptr as return value. * Log all solver problem rules (bsc#1277790) The log contains the most relevant problem rule, but sometimes it helps to know all rules associated with this problem. zypper shows them on demand as 'detail'. The log now remembers them as well. * Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) * repoGpgCheck: Strictly follow the repo_gpgcheck setting (bsc#1274625) There's been a legacy exception for unsigned repositories which were explicitly accepted in the past. After switching the repo_gpgcheck from off to on, they were allowed to stay unsigned until a first signed version was retrieved. From there on the handling was strict. Now the handling is strict as soon as the repo_gpgcheck turned on. The next set of metadata retrieved must be signed. * Iniparser: each new file starts in the unnamed section (bsc#1272534) * Fix hasCredentials() to require both username AND password to be non-empty (bsc#1273242) This avoids an unnecessary 2nd 401 response sending just the username in case the username but no password is known. Now it immediately fetches the credentials from disk if no password is known. * GPG Key hints in repoindex.xml require at least a long id to allow auto- import (bsc#1271730) The short Id (32bit/8byte) is not considered to be a safe identifier for a gpg key. A long id (64bit/16byte) or even better the full fingerprint is needed to identify the key. * zypp: Improve Testcase Loading for MCP Tools. Changes for zypper: Update to version 1.14.99: * Show solver problem details per default in not-interactive mode (bsc#1277790) This way they see all details when capturing zypper's output because the (d)etail button can't be pressed in not-interactive mode. * Add --servicesd-dir global option to relocate /etc/zypp/services.d (bsc#1257249) * info: check for missing positional args before systemSetup (bsc#1274091) * Remove deprecated installRecommends option from zypper.conf. The system wide default for all libzypp based applications is defined in zypp.conf(5). It is not recommended to define this in zypper exclusively. ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1639 ## Package List: * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * libzypp-devel-17.38.15-160000.1.1 * zypper-debugsource-1.14.101-160000.1.1 * libzypp-debugsource-17.38.15-160000.1.1 * zypper-1.14.101-160000.1.1 * libzypp-17.38.15-160000.1.1 * libzypp-debuginfo-17.38.15-160000.1.1 * libzypp-devel-doc-17.38.15-160000.1.1 * zypper-debuginfo-1.14.101-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * zypper-needs-restarting-1.14.101-160000.1.1 * zypper-aptitude-1.14.101-160000.1.1 * zypper-log-1.14.101-160000.1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1257249 * https://bugzilla.suse.com/show_bug.cgi?id=1271730 * https://bugzilla.suse.com/show_bug.cgi?id=1272534 * https://bugzilla.suse.com/show_bug.cgi?id=1273242 * https://bugzilla.suse.com/show_bug.cgi?id=1274091 * https://bugzilla.suse.com/show_bug.cgi?id=1274625 * https://bugzilla.suse.com/show_bug.cgi?id=1277790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:55:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:55:09 -0000 Subject: SUSE-SU-2026:23688-1: important: Security update for helm Message-ID: <178957770904.26114.2119292843042713710@b9be41dc2e4b> # Security update for helm Announcement ID: SUSE-SU-2026:23688-1 Release Date: 2026-09-08T14:27:43Z Rating: important References: * bsc#1270127 * bsc#1271660 * bsc#1272402 * bsc#1276514 * bsc#1276644 * bsc#1277949 * bsc#1278270 * bsc#1278273 * bsc#1278688 Cross-References: * CVE-2026-37236 * CVE-2026-41178 * CVE-2026-48978 * CVE-2026-50151 * CVE-2026-63308 * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-37236 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-37236 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-37236 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48978 ( SUSE ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-48978 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-48978 ( NVD ): 2.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-50151 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-50151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-63308 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-63308 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-63308 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-63308 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84445 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities and has one fix can now be installed. ## Security update for helm ### Description: This update for helm fixes the following issues: Update to version 3.21.1: * CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST request through the X-HTTP-Method- Override header and bypass established access control (bsc#1277949). * CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276644). * CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). * CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271660). * CVE-2026-63308: processing zero-length byte slices in template chart files can trigger an index out-of-range panic (bsc#1272402). * CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1278270). * CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1278273). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing `:authority` and `Host` headers in gRPC-Go xDS servers (bsc#1278688). * gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation (bsc#1276514). ## Security update for helm ### Description: This update for helm fixes the following issues: Update to version 3.21.1: * CVE-2026-37236: github.com/grpc-ecosystem/grpc-gateway/v2/runtime: client can override the HTTP method of a POST request through the X-HTTP-Method- Override header and bypass established access control (bsc#1277949). * CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276644). * CVE-2026-48978: oras.land/oras-go/v2/registry/remote/auth: Malicious registry can hijack Bearer token realm to exfiltrate credentials and refresh tokens (bsc#1270127). * CVE-2026-50151: oras-go: Credential forwarding via unvalidated Location header during blob upload (bsc#1271660). * CVE-2026-63308: processing zero-length byte slices in template chart files can trigger an index out-of-range panic (bsc#1272402). * CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1278270). * CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1278273). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing `:authority` and `Host` headers in gRPC-Go xDS servers (bsc#1278688). * gRPC-Go: several issues affecting the xDS RBAC authorization engine and the HTTP/2 transport server implementation (bsc#1276514). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1640 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1640 SUSE-SLES-16.0-1640 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * helm-debuginfo-3.21.3-160000.2.1 * helm-3.21.3-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * helm-fish-completion-3.21.3-160000.2.1 * helm-zsh-completion-3.21.3-160000.2.1 * helm-bash-completion-3.21.3-160000.2.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * helm-debuginfo-3.21.3-160000.2.1 * helm-3.21.3-160000.2.1 * SUSE Linux Enterprise Server 16.0 (noarch) * helm-fish-completion-3.21.3-160000.2.1 * helm-zsh-completion-3.21.3-160000.2.1 * helm-bash-completion-3.21.3-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-37236.html * https://www.suse.com/security/cve/CVE-2026-41178.html * https://www.suse.com/security/cve/CVE-2026-48978.html * https://www.suse.com/security/cve/CVE-2026-50151.html * https://www.suse.com/security/cve/CVE-2026-63308.html * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1270127 * https://bugzilla.suse.com/show_bug.cgi?id=1271660 * https://bugzilla.suse.com/show_bug.cgi?id=1272402 * https://bugzilla.suse.com/show_bug.cgi?id=1276514 * https://bugzilla.suse.com/show_bug.cgi?id=1276644 * https://bugzilla.suse.com/show_bug.cgi?id=1277949 * https://bugzilla.suse.com/show_bug.cgi?id=1278270 * https://bugzilla.suse.com/show_bug.cgi?id=1278273 * https://bugzilla.suse.com/show_bug.cgi?id=1278688 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:55:48 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:55:48 -0000 Subject: SUSE-SU-2026:4213-1: important: Security update for openvpn Message-ID: <178957774871.26114.51946033844025699@b9be41dc2e4b> # Security update for openvpn Announcement ID: SUSE-SU-2026:4213-1 Release Date: 2026-09-16T11:53:27Z Rating: important References: * bsc#1275310 * bsc#1279613 Cross-References: * CVE-2026-63650 * CVE-2026-84732 CVSS scores: * CVE-2026-63650 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-63650 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-63650 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84732 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84732 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for openvpn fixes the following issues: * CVE-2026-63650: OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field (bsc#1275310). * CVE-2026-84732: Remote Denial of Service via crafted ACK packets (bsc#1279613). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4213 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4213 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4213 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4213 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * openvpn-dco-2.6.10-150600.3.37.1 * openvpn-debuginfo-2.6.10-150600.3.37.1 * openvpn-dco-debuginfo-2.6.10-150600.3.37.1 * openvpn-auth-pam-plugin-debuginfo-2.6.10-150600.3.37.1 * openvpn-devel-2.6.10-150600.3.37.1 * openvpn-dco-debugsource-2.6.10-150600.3.37.1 * openvpn-2.6.10-150600.3.37.1 * openvpn-debugsource-2.6.10-150600.3.37.1 * openvpn-auth-pam-plugin-2.6.10-150600.3.37.1 * openvpn-dco-devel-2.6.10-150600.3.37.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * openvpn-dco-2.6.10-150600.3.37.1 * openvpn-debuginfo-2.6.10-150600.3.37.1 * openvpn-dco-debuginfo-2.6.10-150600.3.37.1 * openvpn-auth-pam-plugin-debuginfo-2.6.10-150600.3.37.1 * openvpn-devel-2.6.10-150600.3.37.1 * openvpn-dco-debugsource-2.6.10-150600.3.37.1 * openvpn-down-root-plugin-debuginfo-2.6.10-150600.3.37.1 * openvpn-2.6.10-150600.3.37.1 * openvpn-down-root-plugin-2.6.10-150600.3.37.1 * openvpn-debugsource-2.6.10-150600.3.37.1 * openvpn-auth-pam-plugin-2.6.10-150600.3.37.1 * openvpn-dco-devel-2.6.10-150600.3.37.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * openvpn-dco-2.6.10-150600.3.37.1 * openvpn-debuginfo-2.6.10-150600.3.37.1 * openvpn-dco-debuginfo-2.6.10-150600.3.37.1 * openvpn-auth-pam-plugin-debuginfo-2.6.10-150600.3.37.1 * openvpn-devel-2.6.10-150600.3.37.1 * openvpn-dco-debugsource-2.6.10-150600.3.37.1 * openvpn-2.6.10-150600.3.37.1 * openvpn-debugsource-2.6.10-150600.3.37.1 * openvpn-auth-pam-plugin-2.6.10-150600.3.37.1 * openvpn-dco-devel-2.6.10-150600.3.37.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * openvpn-dco-2.6.10-150600.3.37.1 * openvpn-debuginfo-2.6.10-150600.3.37.1 * openvpn-dco-debuginfo-2.6.10-150600.3.37.1 * openvpn-auth-pam-plugin-debuginfo-2.6.10-150600.3.37.1 * openvpn-devel-2.6.10-150600.3.37.1 * openvpn-dco-debugsource-2.6.10-150600.3.37.1 * openvpn-2.6.10-150600.3.37.1 * openvpn-debugsource-2.6.10-150600.3.37.1 * openvpn-auth-pam-plugin-2.6.10-150600.3.37.1 * openvpn-dco-devel-2.6.10-150600.3.37.1 ## References: * https://www.suse.com/security/cve/CVE-2026-63650.html * https://www.suse.com/security/cve/CVE-2026-84732.html * https://bugzilla.suse.com/show_bug.cgi?id=1275310 * https://bugzilla.suse.com/show_bug.cgi?id=1279613 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:56:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:56:55 -0000 Subject: SUSE-SU-2026:4212-1: important: Security update for distribution Message-ID: <178957781570.26114.9396579890675654314@b9be41dc2e4b> # Security update for distribution Announcement ID: SUSE-SU-2026:4212-1 Release Date: 2026-09-16T11:52:50Z Rating: important References: * bsc#1259718 * bsc#1260283 * bsc#1261793 * bsc#1262096 * bsc#1262951 * bsc#1265429 * bsc#1265788 * bsc#1266629 * bsc#1268884 * bsc#1272132 * jsc#PED-11728 * jsc#PED-14747 Cross-References: * CVE-2026-33186 * CVE-2026-33540 * CVE-2026-33814 * CVE-2026-34986 * CVE-2026-35172 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-41888 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 * CVE-2026-56852 CVSS scores: * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33540 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-33540 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-35172 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-35172 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-35172 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41888 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-41888 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-41888 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41888 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Containers Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 21 vulnerabilities and contains two features can now be installed. ## Description: This update for distribution fixes the following issues: Security issues fixed: * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260283). * CVE-2026-33540: information disclosure via improper validation of authentication realm URL (bsc#1261793). * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265788). * CVE-2026-34986: github.com/go-jose/go-jose/v4: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262951). * CVE-2026-35172: information disclosure via stale references after content deletion (bsc#1262096). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266629). * CVE-2026-39827,CVE-2026-39828,CVE-2026-39829,CVE-2026-39830,CVE-2026-39831, CVE-2026-39832,CVE-2026-39833,CVE-2026-39834,CVE-2026-39835,CVE-2026-42508, CVE-2026-46595,CVE-2026-46597,CVE-2026-46598: golang.org/x/crypto/ssh: multiple issues (bsc#1268884). * CVE-2026-41888: tag deletion bypasses the storage.delete.enabled configuration (bsc#1265429). * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272132). Changes for distribution: Update to 3.1.1: * Bounds-check the file basename in PurgeUploads Walk callback * Add S3 Express One Zone support to the S3 storage driver * Fix tag list endpoint in proxy mode * Clamp oversized `n` query parameter in proxy mode instead of returning 400 * See the full changelog below for the full list of changes. * internal/client/auth/challenge: cleanups and minor refactor * build(deps): bump go.opentelemetry.io/otel/exporters/otlp/otlplog/otlploghttp from 0.18.0 to 0.19.0 in the go_modules group across 1 directory * build(deps): bump go.opentelemetry.io/otel/exporters/otlp/otl ptrace/otlptracehttp from 1.42.0 to 1.43.0 in the go_modules group across 1 directory * build(deps): bump github/codeql-action from 4.34.1 to 4.35.1 * chore(build): Bump go version to latest * refactor: use slices.Backward to simplify the code * fix(proxy): fix tag list endpoint in proxy mode * Update docker-compose structure in deploying.md * build(deps): bump actions/upload-artifact from 7.0.0 to 7.0.1 * build(deps): bump actions/upload-pages-artifact from 4.0.0 to 5.0.0 * build(deps): bump docker/login-action from 4.0.0 to 4.1.0 * build(deps): bump docker/bake-action from 7.0.0 to 7.1.0 * fix(proxy): clamp oversized n query param instead of * feat(s3): add express zone one support to S3 driver * fix(storage): bounds-check the file basename in PurgeUploads Walk callback * chore(release): prepare for v3.1.1 release * Adds support for tag pagination * Fixes default credentials in Azure storage provider * Drops support for go1.23 and go1.24 and updates to go1.25 * docs: Update to refer to new image tag v3 * Fix default_credentials in azure storage provider * chore: make function comment match function name * build(deps): bump golang.org/x/net from 0.37.0 to 0.38.0 in the go_modules group across 1 directory * fix: implement JWK thumbprint for Ed25519 public keys * fix: Annotate code block from validation.indexes configuration docs * feat: extract redis config to separate struct * Fix: resolve issue #4478 by using a temporary file for non- append writes * build(deps): bump ossf/scorecard-action from 2.4.1 to 2.4.2 * docs: Add note about `OTEL_TRACES_EXPORTER` * fix: set OTEL traces to disabled by default * Fix markdown syntax for OTEL traces link in docs * Switch UUIDs to UUIDv7 * refactor: replace map iteration with maps.Copy/Clone * s3-aws: fix build for 386 * docs: Add OpenTelemetry links to quickstart docs * Fix S3 driver loglevel param * Fixed data race in TestSchedule test * Fixes #4683 - uses X/Y instead of Gx/Gy for thumbprint of ecdsa keys * build(deps): bump actions/checkout from 4 to 5 * Fix broken link to Docker Hub fair use policy * fix(registry/handlers/app): redis CAs * build(deps): bump actions/labeler from 5 to 6 * build(deps): bump actions/setup-go from 5 to 6 * build(deps): bump actions/upload-pages-artifact from 3 to 4 * build(deps): bump ossf/scorecard-action from 2.4.2 to 2.4.3 * build(deps): bump github/codeql-action from 3.26.5 to 4.30.7 * build(deps): bump github/codeql-action from 4.30.7 to 4.30.8 * chore: labeler: add area/client mapping for internal/client/** * client: add Accept headers to Exists() HEAD * feat(registry): Make graceful shutdown test robust * fix(registry): Correct log formatting for upstream challenge * build(deps): bump github/codeql-action from 4.30.8 to 4.30.9 * build(deps): bump github/codeql-action from 4.30.9 to 4.31.3 * refactor: remove redundant variable declarations in for loops * "should" -> "must" regarding redis eviction policy * build(deps): bump actions/checkout from 5 to 6 * Incorrect warning hint * Add return error when list object * build(deps): bump actions/checkout from 5.0.1 to 6.0.0 * build(deps): bump peter-evans/dockerhub-description from 4 to 5 * fix: Logging regression for manifest HEAD requests * Add boolean parsing util * Expose `useFIPSEndpoint` for S3 * Add Cloudfleet Container Registry to adopters * fix(ci): Fix broken Azure e2e storage tests * BUG: Fix notification filtering to work with actions when mediatypes is empty * build(deps): bump actions/checkout from 6.0.0 to 6.0.1 * build(deps): bump actions/upload-artifact from 4.6.2 to 6.0.0 * build(deps): bump github/codeql-action from 4.31.3 to 4.31.10 * build(deps): bump github/codeql-action from 4.31.10 to 4.32.2 * build(deps): bump actions/checkout from 6.0.1 to 6.0.2 * update golangci-lint to v2.9 and fix linting issues * update to go1.25.7, alpine 3.23, xx v1.9.0 * vendor: github.com/sirupsen/logrus v1.9.4 * vendor: update golang.org/x/* dependencies * vendor: github.com/docker/docker-credential-helpers v0.9.5 * vendor: github.com/opencontainers/image-spec v1.1.1 * vendor: github.com/klauspost/compress v1.18.4 * fix: prefer otel variables over hard coded service name * vendor: github.com/spf13/cobra v1.10.2 * vendor: github.com/bshuster-repo/logrus-logstash-hook v1.1.0 * fix: sync parent dir to ensure data is reliably stored * modernize code * vendor: github.com/docker/go-events 605354379745 * vendor: github.com/go-jose/go-jose/v4 v4.1.3 * build(deps): bump github/codeql-action from 4.32.2 to 4.32.5 * build(deps): bump docker/login-action from 3 to 4 * build(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 * build(deps): bump docker/setup-buildx-action from 3 to 4 * build(deps): bump docker/bake-action from 6 to 7 * build(deps): bump docker/metadata-action from 5 to 6 * fix: nil-check scheduler in `proxyingRegistry.Close()` * fix: set MD5 on GCS writer before first `Write` call in `putContent` * docs: pull through cache will pull from remote multiple times * Update s3.md regionendpoint option * chore(deps): Bump Go to latest 1.25 in CI workflows and go.mod * fix: correct Ed25519 JWK thumbprint `kty` from `"OTP"` to `"OKP"` * Update vacuum.go * Opt: refector tag list pagination support (stage 1) * Correctly match environment variables to YAML-inlined structs in configuration * Enable Redis TLS without client certificates * build(deps): bump actions/deploy-pages from 4 to 5 * build(deps): bump github/codeql-action from 4.32.5 to 4.34.1 * fix(registry/proxy): use detached context when flushing write buffer * ci: pin actions and apply zizmor auto-fixes * build(deps): bump actions/setup-go from 6.3.0 to 6.4.0 * build(deps): bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 in the go_modules group across 1 directory * chore(app): warn when partial TLS config is used in Redis * feat(registry): enhance authentication checks in htpasswd implementation * Opt: refactor tag list pagination support * build(deps): bump codecov/codecov-action from 5.5.4 to 6.0.0 * build(deps): bump actions/configure-pages from 5.0.0 to 6.0.0 * fix(vendor): fix broke vendor validation * chore(ci): Prep for v3.1 release * Update to version 3.1.0: * fix(vendor): fix broke vendpor validation * fix redis repo-scoped blob descriptor revocation * proxy: bind bearer realms to upstream trust boundary * restore directory ownership after last change * Move config files in systemd tmpfiles dir for immutable mode (jsc#PED-14747) * Add distribution-registry.tmpfiles * This is the first v3 stable release since `v2.8.3` which is a culmination of years of hard work of the container community and registry maintainers! * If you are upgrading from `v2.x` and have never used any of the release candidates, please familiarise yourselves with the `v2.x` deprecations properly. * oss and swift storage drivers are no longer supported * `docker/libtrust` has been replaced with `go-jose/go-jose` in https://github.com/distribution/distribution/pull/4096 * `client` is no longer supported as a standalone package in https://github.com/distribution/distribution/pull/4126 * the default configuration path has changed to `/etc/distribution/config.yml` * `ManifestBuilder` interface in 3886 * `manifest.Versioned` has been deprecated in favor of `oci.Versioned` in 3887 * `reference` package has been moved to github.com/distribution/reference in https://github.com/distribution/distribution/pull/4063 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4212 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4212 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4212 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4212 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4212 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4212 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4212 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4212 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4212 * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-4212 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4212 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4212 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * distribution-registry-3.1.1-150400.9.41.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * distribution-registry-3.1.1-150400.9.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * distribution-registry-3.1.1-150400.9.41.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * distribution-registry-3.1.1-150400.9.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * distribution-registry-3.1.1-150400.9.41.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * distribution-registry-3.1.1-150400.9.41.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * distribution-registry-3.1.1-150400.9.41.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * distribution-registry-3.1.1-150400.9.41.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * distribution-registry-3.1.1-150400.9.41.1 * Containers Module 15-SP7 (aarch64 ppc64le s390x x86_64) * distribution-registry-3.1.1-150400.9.41.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * distribution-registry-3.1.1-150400.9.41.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * distribution-registry-3.1.1-150400.9.41.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-33540.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-35172.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-41888.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://bugzilla.suse.com/show_bug.cgi?id=1259718 * https://bugzilla.suse.com/show_bug.cgi?id=1260283 * https://bugzilla.suse.com/show_bug.cgi?id=1261793 * https://bugzilla.suse.com/show_bug.cgi?id=1262096 * https://bugzilla.suse.com/show_bug.cgi?id=1262951 * https://bugzilla.suse.com/show_bug.cgi?id=1265429 * https://bugzilla.suse.com/show_bug.cgi?id=1265788 * https://bugzilla.suse.com/show_bug.cgi?id=1266629 * https://bugzilla.suse.com/show_bug.cgi?id=1268884 * https://bugzilla.suse.com/show_bug.cgi?id=1272132 * https://jira.suse.com/browse/PED-11728 * https://jira.suse.com/browse/PED-14747 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:57:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:57:51 -0000 Subject: SUSE-SU-2026:4211-1: important: Security update for kbd Message-ID: <178957787115.26114.1132646114279926944@b9be41dc2e4b> # Security update for kbd Announcement ID: SUSE-SU-2026:4211-1 Release Date: 2026-09-16T11:51:08Z Rating: important References: * bsc#1275441 Cross-References: * CVE-2026-72693 CVSS scores: * CVE-2026-72693 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72693 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for kbd fixes the following issue: * CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4211 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kbd-2.4.0-150700.15.10.1 * kbd-debugsource-2.4.0-150700.15.10.1 * kbd-debuginfo-2.4.0-150700.15.10.1 * Basesystem Module 15-SP7 (noarch) * kbd-legacy-2.4.0-150700.15.10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-72693.html * https://bugzilla.suse.com/show_bug.cgi?id=1275441 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:58:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:58:35 -0000 Subject: SUSE-SU-2026:4210-1: important: Security update for alloy Message-ID: <178957791583.26114.12600245923835474681@b9be41dc2e4b> # Security update for alloy Announcement ID: SUSE-SU-2026:4210-1 Release Date: 2026-09-16T11:50:54Z Rating: important References: * bsc#1263289 * bsc#1263324 * bsc#1264949 * bsc#1265542 * bsc#1265845 * bsc#1266654 Cross-References: * CVE-2026-10722 * CVE-2026-1229 * CVE-2026-33814 * CVE-2026-39821 * CVE-2026-41506 * CVE-2026-41606 * CVE-2026-41607 CVSS scores: * CVE-2026-10722 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-10722 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-10722 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-10722 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-10722 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-1229 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-1229 ( SUSE ): 7.0 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L * CVE-2026-1229 ( NVD ): 2.9 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:X/V:X/RE:X/U:Amber * CVE-2026-1229 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-41506 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-41506 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-41506 ( NVD ): 4.7 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N * CVE-2026-41506 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-41606 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41606 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41606 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41606 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-41607 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41607 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41607 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41607 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves seven vulnerabilities can now be installed. ## Description: This update for alloy fixes the following issues: * CVE-2026-1229: github.com/cloudflare/circl: the CombinedMult function in the ecc/p384 package produces an incorrect value for specific inputs (bsc#1265542). * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265845). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266654). * CVE-2026-41506: github.com/go-git/go-git/v5: HTTP authentication credential leak when following redirects during smart-HTTP clone and fetch operations (bsc#1264949). * CVE-2026-41606: github.com/apache/thrift: crafted nested messages in c_glib dispatch can lead to uncontrolled recursion and denial of service (bsc#1263324). * CVE-2026-41607: github.com/apache/thrift: crafted message with improper length validation can lead to an out-of-bounds read and potential information disclosure (bsc#1263289). Changes for alloy: * Update to version 1.18.0: * BREAKING: otelcol HTTP receivers default to idle_timeout="1m", read_header_timeout="1m", write_timeout="30s" to match upstream. Affects otlp, faro, jaeger, zipkin, influxdb, splunkhec, datadog and jaeger_remote_sampling. * Back off usage reporting on persistent failure * Fix Beyla glob parsing * Bump github.com/prometheus/procfs for XFS Collector fix * database_observability.mysql: Simplify denylist in-memory map * database_observability.postgres: Handle DSN with unix sockets * database_observability.postgres: Update collect intervals * database_observability: Explain-plan conditions now redact * Don't emit error log when remotecfg is unused * For a full list of changes, please refer to the CHANGELOG: https://github.com/grafana/alloy/blob/v1.18.0/CHANGELOG.md ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4210 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * alloy-debuginfo-1.18.0-150700.15.26.1 * alloy-1.18.0-150700.15.26.1 ## References: * https://www.suse.com/security/cve/CVE-2026-10722.html * https://www.suse.com/security/cve/CVE-2026-1229.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-41506.html * https://www.suse.com/security/cve/CVE-2026-41606.html * https://www.suse.com/security/cve/CVE-2026-41607.html * https://bugzilla.suse.com/show_bug.cgi?id=1263289 * https://bugzilla.suse.com/show_bug.cgi?id=1263324 * https://bugzilla.suse.com/show_bug.cgi?id=1264949 * https://bugzilla.suse.com/show_bug.cgi?id=1265542 * https://bugzilla.suse.com/show_bug.cgi?id=1265845 * https://bugzilla.suse.com/show_bug.cgi?id=1266654 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 16:59:24 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 16:59:24 -0000 Subject: SUSE-SU-2026:4209-1: important: Security update for containerized-data-importer Message-ID: <178957796402.26114.11178276999025446153@b9be41dc2e4b> # Security update for containerized-data-importer Announcement ID: SUSE-SU-2026:4209-1 Release Date: 2026-09-16T11:50:41Z Rating: important References: * bsc#1248946 * bsc#1262952 * bsc#1265799 * bsc#1266179 * bsc#1266639 * bsc#1267176 * bsc#1272064 * bsc#1276687 * bsc#1278621 Cross-References: * CVE-2025-58058 * CVE-2026-25680 * CVE-2026-25681 * CVE-2026-27136 * CVE-2026-33814 * CVE-2026-34986 * CVE-2026-39821 * CVE-2026-39827 * CVE-2026-39828 * CVE-2026-39829 * CVE-2026-39830 * CVE-2026-39831 * CVE-2026-39832 * CVE-2026-39833 * CVE-2026-39834 * CVE-2026-39835 * CVE-2026-41178 * CVE-2026-42502 * CVE-2026-42506 * CVE-2026-42508 * CVE-2026-46595 * CVE-2026-46597 * CVE-2026-46598 * CVE-2026-56852 * CVE-2026-56854 * CVE-2026-56855 * CVE-2026-78662 CVSS scores: * CVE-2025-58058 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2025-58058 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2025-58058 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-25680 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-25680 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-25680 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-25681 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-25681 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-25681 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-27136 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-27136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-33814 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33814 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-34986 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-34986 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39821 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39821 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39821 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39827 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39827 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39827 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39828 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39828 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39828 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-39828 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-39829 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39829 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39829 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39830 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39830 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-39830 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39831 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39831 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39831 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( SUSE ): 6.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N * CVE-2026-39832 ( SUSE ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39832 ( NVD ): 8.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N * CVE-2026-39833 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-39833 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39833 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-39834 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39834 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39834 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-39835 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-39835 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-39835 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-42502 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42502 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42502 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N * CVE-2026-42506 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42506 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-42508 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-42508 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-42508 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46595 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46595 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L * CVE-2026-46595 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-46597 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46597 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46597 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46598 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46598 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56854 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56854 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56854 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56855 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78662 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78662 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78662 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Containers Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 27 vulnerabilities can now be installed. ## Description: This update for containerized-data-importer fixes the following issues: * CVE-2025-58058: github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory (bsc#1248946). * CVE-2026-25680: golang.org/x/net/html: denial of service when parsing arbitrary HTML (bsc#1267176). * CVE-2026-25681: golang.org/x/net/html: incorrect handling of character references in DOCTYPE nodes (bsc#1267176). * CVE-2026-27136: golang.org/x/net/html: duplicate attributes can cause XSS (bsc#1267176). * CVE-2026-42502: golang.org/x/net/html: incorrect handling of HTML elements in foreign content (bsc#1267176). * CVE-2026-42506: golang.org/x/net/html: incorrect handling of namespaced elements in foreign content (bsc#1267176). * CVE-2026-33814: golang.org/x/net/http2: infinite loop in HTTP/2 transport when given bad SETTINGS_MAX_FRAME_SIZE (bsc#1265799). * CVE-2026-34986: github.com/go-jose/go-jose/v3: crafted JWE input with a missing encrypted key can lead to a denial of service (bsc#1262952). * CVE-2026-39821: golang.org/x/net/idna: failure to reject ASCII-only Punycode-encoded labels allows for validation bypass and privilege escalation (bsc#1266639). * CVE-2026-39827: golang.org/x/crypto/ssh: newChannel leak after Reject() (bsc#1266179). * CVE-2026-39828: golang.org/x/crypto/ssh: bypass of certificate restrictions (bsc#1266179). * CVE-2026-39829: golang.org/x/crypto/ssh: pathological RSA/DSA parameters may cause DoS (bsc#1266179). * CVE-2026-39830: golang.org/x/crypto/ssh: client can cause server deadlock on unexpected responses (bsc#1266179). * CVE-2026-39831: golang.org/x/crypto/ssh: bypass of FIDO/U2F security keys physical interaction (bsc#1266179). * CVE-2026-39832: golang.org/x/crypto/ssh: remote agent constraint extensions dropped (bsc#1266179). * CVE-2026-39833: golang.org/x/crypto/ssh: lifetime without confirm constraint (bsc#1266179). * CVE-2026-39834: golang.org/x/crypto/ssh: infinite loop on large channel writes (bsc#1266179). * CVE-2026-39835: golang.org/x/crypto/ssh: server panic during CheckHostKey/Authenticate (bsc#1266179). * CVE-2026-42508: golang.org/x/crypto/ssh: failure to enforce @revoked status (bsc#1266179). * CVE-2026-46595: golang.org/x/crypto/ssh: VerifiedPublicKeyCallback permissions skip enforcement (bsc#1266179). * CVE-2026-46597: golang.org/x/crypto/ssh: byte arithmetic causes underflow and panic (bsc#1266179). * CVE-2026-46598: golang.org/x/crypto/ssh: pathological inputs can lead to client panic (bsc#1266179). * CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276687). * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272064). * CVE-2026-56854: golang.org/x/crypto/ssh: source-address restriction bypassed in 5 callback families (bsc#1278621). * CVE-2026-56855: golang.org/x/crypto/ssh: prevent DoS on deadlocked established channel (bsc#1278621). * CVE-2026-78662: golang.org/x/crypto/ssh: prevent DoS on deadlocked undecided channel (bsc#1278621). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Containers Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Containers-15-SP7-2026-4209 ## Package List: * Containers Module 15-SP7 (aarch64 x86_64) * containerized-data-importer-manifests-1.64.0-150700.9.14.1 ## References: * https://www.suse.com/security/cve/CVE-2025-58058.html * https://www.suse.com/security/cve/CVE-2026-25680.html * https://www.suse.com/security/cve/CVE-2026-25681.html * https://www.suse.com/security/cve/CVE-2026-27136.html * https://www.suse.com/security/cve/CVE-2026-33814.html * https://www.suse.com/security/cve/CVE-2026-34986.html * https://www.suse.com/security/cve/CVE-2026-39821.html * https://www.suse.com/security/cve/CVE-2026-39827.html * https://www.suse.com/security/cve/CVE-2026-39828.html * https://www.suse.com/security/cve/CVE-2026-39829.html * https://www.suse.com/security/cve/CVE-2026-39830.html * https://www.suse.com/security/cve/CVE-2026-39831.html * https://www.suse.com/security/cve/CVE-2026-39832.html * https://www.suse.com/security/cve/CVE-2026-39833.html * https://www.suse.com/security/cve/CVE-2026-39834.html * https://www.suse.com/security/cve/CVE-2026-39835.html * https://www.suse.com/security/cve/CVE-2026-41178.html * https://www.suse.com/security/cve/CVE-2026-42502.html * https://www.suse.com/security/cve/CVE-2026-42506.html * https://www.suse.com/security/cve/CVE-2026-42508.html * https://www.suse.com/security/cve/CVE-2026-46595.html * https://www.suse.com/security/cve/CVE-2026-46597.html * https://www.suse.com/security/cve/CVE-2026-46598.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://www.suse.com/security/cve/CVE-2026-56854.html * https://www.suse.com/security/cve/CVE-2026-56855.html * https://www.suse.com/security/cve/CVE-2026-78662.html * https://bugzilla.suse.com/show_bug.cgi?id=1248946 * https://bugzilla.suse.com/show_bug.cgi?id=1262952 * https://bugzilla.suse.com/show_bug.cgi?id=1265799 * https://bugzilla.suse.com/show_bug.cgi?id=1266179 * https://bugzilla.suse.com/show_bug.cgi?id=1266639 * https://bugzilla.suse.com/show_bug.cgi?id=1267176 * https://bugzilla.suse.com/show_bug.cgi?id=1272064 * https://bugzilla.suse.com/show_bug.cgi?id=1276687 * https://bugzilla.suse.com/show_bug.cgi?id=1278621 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 17:00:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 17:00:11 -0000 Subject: SUSE-SU-2026:4208-1: important: Security update for clamav Message-ID: <178957801190.26114.11030378513010957527@b9be41dc2e4b> # Security update for clamav Announcement ID: SUSE-SU-2026:4208-1 Release Date: 2026-09-16T08:23:42Z Rating: important References: * bsc#1271922 * bsc#1274597 * bsc#1274598 * bsc#1274599 * bsc#1274600 * bsc#1274601 * bsc#1274602 * bsc#1274603 Cross-References: * CVE-2025-8088 * CVE-2026-20337 * CVE-2026-20338 * CVE-2026-20339 * CVE-2026-20345 * CVE-2026-20346 * CVE-2026-20347 * CVE-2026-20348 * CVE-2026-46671 CVSS scores: * CVE-2025-8088 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-8088 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-20337 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20337 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20337 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20338 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20338 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20338 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20339 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20339 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20339 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20345 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20345 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20345 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20346 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20346 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20346 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20347 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20347 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20347 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20348 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-20348 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-20348 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46671 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-46671 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves nine vulnerabilities can now be installed. ## Description: This update for clamav fixes the following issues: * CVE-2026-20337: Improper boundary checks for content in zip archive parser (bsc#1274597). * CVE-2026-20338: invalid free due to bad ownership handling when merging ZIP catalogue records (bsc#1274598). * CVE-2026-20339: integer overflow in the PESpin unpacker leads to undersized allocation and heap out-of-bounds write (bsc#1274599). * CVE-2026-20345: out-of-bounds read/write via indexing error when converting GPT partition names (bsc#1274600). * CVE-2026-20346: integer underflow when parsing malformed PDF hex strings causes a crash (bsc#1274601). * CVE-2026-20347: integer overflow and undefined behavior when scanning malformed Mach-O files causes a crash (bsc#1274602). * CVE-2026-20348: improper size handling in the XAR parser allows excessive allocation and scan-limit bypass (bsc#1274603). * CVE-2026-46671: onenote_parser: Path traversal in `Parser:parse_notebook` allows reading files outside the notebook directory (bsc#1271922). * CVE-2025-8088: rejects path separators in NTFS alternate data stream names to prevent extraction outside ClamAV's temporary scan directory on Windows. Changes for clamav: Update to 1.5.4: * Fixed thread-safety issues in the clamd STATS command that could disclose process memory or crash the daemon while scans and STATS requests run concurrently. Also fixed partial socket-write handling used for large STATS responses. * FreeBSD: Restored support for safe quarantine move and remove actions while preserving protection against source-path replacement races. * Fixed an OpenSSL library-context leak in legacy hashing helpers when a requested message digest cannot be fetched, such as when the default provider is unavailable in a FIPS-enabled environment. * Upgraded the Rust crossbeam-epoch dependency to resolve the RUSTSEC-2026-0204 advisory. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4208 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4208 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4208 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4208 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4208 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4208 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4208 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4208 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4208 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4208 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * clamav-debugsource-1.5.4-150400.13.11.1 * clamav-milter-1.5.4-150400.13.11.1 * clamav-devel-1.5.4-150400.13.11.1 * libclammspack0-debuginfo-1.5.4-150400.13.11.1 * libclamav12-debuginfo-1.5.4-150400.13.11.1 * clamav-milter-debuginfo-1.5.4-150400.13.11.1 * clamav-1.5.4-150400.13.11.1 * libclamav12-1.5.4-150400.13.11.1 * libclamunrar12-debuginfo-1.5.4-150400.13.11.1 * libclamunrar12-1.5.4-150400.13.11.1 * libfreshclam4-1.5.4-150400.13.11.1 * libfreshclam4-debuginfo-1.5.4-150400.13.11.1 * clamav-debuginfo-1.5.4-150400.13.11.1 * libclammspack0-1.5.4-150400.13.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * clamav-docs-html-1.5.4-150400.13.11.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * clamav-debugsource-1.5.4-150400.13.11.1 * clamav-milter-1.5.4-150400.13.11.1 * clamav-devel-1.5.4-150400.13.11.1 * libclammspack0-debuginfo-1.5.4-150400.13.11.1 * libclamav12-debuginfo-1.5.4-150400.13.11.1 * clamav-milter-debuginfo-1.5.4-150400.13.11.1 * clamav-1.5.4-150400.13.11.1 * libclamav12-1.5.4-150400.13.11.1 * libclamunrar12-debuginfo-1.5.4-150400.13.11.1 * libclamunrar12-1.5.4-150400.13.11.1 * libfreshclam4-1.5.4-150400.13.11.1 * libfreshclam4-debuginfo-1.5.4-150400.13.11.1 * clamav-debuginfo-1.5.4-150400.13.11.1 * libclammspack0-1.5.4-150400.13.11.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * clamav-docs-html-1.5.4-150400.13.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * clamav-debugsource-1.5.4-150400.13.11.1 * clamav-milter-1.5.4-150400.13.11.1 * clamav-devel-1.5.4-150400.13.11.1 * libclammspack0-debuginfo-1.5.4-150400.13.11.1 * libclamav12-debuginfo-1.5.4-150400.13.11.1 * clamav-milter-debuginfo-1.5.4-150400.13.11.1 * clamav-1.5.4-150400.13.11.1 * libclamav12-1.5.4-150400.13.11.1 * libclamunrar12-debuginfo-1.5.4-150400.13.11.1 * libclamunrar12-1.5.4-150400.13.11.1 * libfreshclam4-1.5.4-150400.13.11.1 * libfreshclam4-debuginfo-1.5.4-150400.13.11.1 * clamav-debuginfo-1.5.4-150400.13.11.1 * libclammspack0-1.5.4-150400.13.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * clamav-docs-html-1.5.4-150400.13.11.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * clamav-debugsource-1.5.4-150400.13.11.1 * clamav-milter-1.5.4-150400.13.11.1 * clamav-devel-1.5.4-150400.13.11.1 * libclammspack0-debuginfo-1.5.4-150400.13.11.1 * libclamav12-debuginfo-1.5.4-150400.13.11.1 * clamav-milter-debuginfo-1.5.4-150400.13.11.1 * clamav-1.5.4-150400.13.11.1 * libclamav12-1.5.4-150400.13.11.1 * libclamunrar12-debuginfo-1.5.4-150400.13.11.1 * libclamunrar12-1.5.4-150400.13.11.1 * libfreshclam4-1.5.4-150400.13.11.1 * libfreshclam4-debuginfo-1.5.4-150400.13.11.1 * clamav-debuginfo-1.5.4-150400.13.11.1 * libclammspack0-1.5.4-150400.13.11.1 * openSUSE Leap 15.4 (noarch) * clamav-docs-html-1.5.4-150400.13.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * clamav-debugsource-1.5.4-150400.13.11.1 * clamav-milter-1.5.4-150400.13.11.1 * clamav-devel-1.5.4-150400.13.11.1 * libclammspack0-debuginfo-1.5.4-150400.13.11.1 * libclamav12-debuginfo-1.5.4-150400.13.11.1 * clamav-milter-debuginfo-1.5.4-150400.13.11.1 * clamav-1.5.4-150400.13.11.1 * libclamav12-1.5.4-150400.13.11.1 * libclamunrar12-debuginfo-1.5.4-150400.13.11.1 * libclamunrar12-1.5.4-150400.13.11.1 * libfreshclam4-1.5.4-150400.13.11.1 * libfreshclam4-debuginfo-1.5.4-150400.13.11.1 * clamav-debuginfo-1.5.4-150400.13.11.1 * libclammspack0-1.5.4-150400.13.11.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * clamav-docs-html-1.5.4-150400.13.11.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * clamav-debugsource-1.5.4-150400.13.11.1 * clamav-milter-1.5.4-150400.13.11.1 * clamav-devel-1.5.4-150400.13.11.1 * libclammspack0-debuginfo-1.5.4-150400.13.11.1 * libclamav12-debuginfo-1.5.4-150400.13.11.1 * clamav-milter-debuginfo-1.5.4-150400.13.11.1 * clamav-1.5.4-150400.13.11.1 * libclamav12-1.5.4-150400.13.11.1 * libclamunrar12-debuginfo-1.5.4-150400.13.11.1 * libclamunrar12-1.5.4-150400.13.11.1 * libfreshclam4-1.5.4-150400.13.11.1 * libfreshclam4-debuginfo-1.5.4-150400.13.11.1 * clamav-debuginfo-1.5.4-150400.13.11.1 * libclammspack0-1.5.4-150400.13.11.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * clamav-docs-html-1.5.4-150400.13.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * clamav-debugsource-1.5.4-150400.13.11.1 * clamav-milter-1.5.4-150400.13.11.1 * clamav-devel-1.5.4-150400.13.11.1 * libclammspack0-debuginfo-1.5.4-150400.13.11.1 * libclamav12-debuginfo-1.5.4-150400.13.11.1 * clamav-milter-debuginfo-1.5.4-150400.13.11.1 * clamav-1.5.4-150400.13.11.1 * libclamav12-1.5.4-150400.13.11.1 * libclamunrar12-debuginfo-1.5.4-150400.13.11.1 * libclamunrar12-1.5.4-150400.13.11.1 * libfreshclam4-1.5.4-150400.13.11.1 * libfreshclam4-debuginfo-1.5.4-150400.13.11.1 * clamav-debuginfo-1.5.4-150400.13.11.1 * libclammspack0-1.5.4-150400.13.11.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * clamav-docs-html-1.5.4-150400.13.11.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * clamav-debugsource-1.5.4-150400.13.11.1 * libclammspack0-debuginfo-1.5.4-150400.13.11.1 * libclamav12-debuginfo-1.5.4-150400.13.11.1 * clamav-1.5.4-150400.13.11.1 * libclamav12-1.5.4-150400.13.11.1 * libclamunrar12-debuginfo-1.5.4-150400.13.11.1 * libclamunrar12-1.5.4-150400.13.11.1 * libfreshclam4-1.5.4-150400.13.11.1 * libfreshclam4-debuginfo-1.5.4-150400.13.11.1 * clamav-debuginfo-1.5.4-150400.13.11.1 * libclammspack0-1.5.4-150400.13.11.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * clamav-debugsource-1.5.4-150400.13.11.1 * clamav-milter-1.5.4-150400.13.11.1 * clamav-devel-1.5.4-150400.13.11.1 * libclammspack0-debuginfo-1.5.4-150400.13.11.1 * libclamav12-debuginfo-1.5.4-150400.13.11.1 * clamav-milter-debuginfo-1.5.4-150400.13.11.1 * clamav-1.5.4-150400.13.11.1 * libclamav12-1.5.4-150400.13.11.1 * libclamunrar12-debuginfo-1.5.4-150400.13.11.1 * libclamunrar12-1.5.4-150400.13.11.1 * libfreshclam4-1.5.4-150400.13.11.1 * libfreshclam4-debuginfo-1.5.4-150400.13.11.1 * clamav-debuginfo-1.5.4-150400.13.11.1 * libclammspack0-1.5.4-150400.13.11.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * clamav-docs-html-1.5.4-150400.13.11.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * clamav-debugsource-1.5.4-150400.13.11.1 * clamav-milter-1.5.4-150400.13.11.1 * clamav-devel-1.5.4-150400.13.11.1 * libclammspack0-debuginfo-1.5.4-150400.13.11.1 * libclamav12-debuginfo-1.5.4-150400.13.11.1 * clamav-milter-debuginfo-1.5.4-150400.13.11.1 * clamav-1.5.4-150400.13.11.1 * libclamav12-1.5.4-150400.13.11.1 * libclamunrar12-debuginfo-1.5.4-150400.13.11.1 * libclamunrar12-1.5.4-150400.13.11.1 * libfreshclam4-1.5.4-150400.13.11.1 * libfreshclam4-debuginfo-1.5.4-150400.13.11.1 * clamav-debuginfo-1.5.4-150400.13.11.1 * libclammspack0-1.5.4-150400.13.11.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * clamav-docs-html-1.5.4-150400.13.11.1 ## References: * https://www.suse.com/security/cve/CVE-2025-8088.html * https://www.suse.com/security/cve/CVE-2026-20337.html * https://www.suse.com/security/cve/CVE-2026-20338.html * https://www.suse.com/security/cve/CVE-2026-20339.html * https://www.suse.com/security/cve/CVE-2026-20345.html * https://www.suse.com/security/cve/CVE-2026-20346.html * https://www.suse.com/security/cve/CVE-2026-20347.html * https://www.suse.com/security/cve/CVE-2026-20348.html * https://www.suse.com/security/cve/CVE-2026-46671.html * https://bugzilla.suse.com/show_bug.cgi?id=1271922 * https://bugzilla.suse.com/show_bug.cgi?id=1274597 * https://bugzilla.suse.com/show_bug.cgi?id=1274598 * https://bugzilla.suse.com/show_bug.cgi?id=1274599 * https://bugzilla.suse.com/show_bug.cgi?id=1274600 * https://bugzilla.suse.com/show_bug.cgi?id=1274601 * https://bugzilla.suse.com/show_bug.cgi?id=1274602 * https://bugzilla.suse.com/show_bug.cgi?id=1274603 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 17:01:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 17:01:07 -0000 Subject: SUSE-SU-2026:4207-1: important: Security update for kbd Message-ID: <178957806734.26114.11078372579245457340@b9be41dc2e4b> # Security update for kbd Announcement ID: SUSE-SU-2026:4207-1 Release Date: 2026-09-16T08:22:45Z Rating: important References: * bsc#1275441 Cross-References: * CVE-2026-72693 CVSS scores: * CVE-2026-72693 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72693 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves one vulnerability can now be installed. ## Description: This update for kbd fixes the following issue: * CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4207 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4207 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4207 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4207 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4207 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4207 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4207 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4207 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4207 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4207 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4207 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4207 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4207 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4207 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4207 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4207 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * kbd-2.4.0-150400.5.12.1 * kbd-debuginfo-2.4.0-150400.5.12.1 * kbd-debugsource-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * kbd-legacy-2.4.0-150400.5.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * kbd-2.4.0-150400.5.12.1 * kbd-debuginfo-2.4.0-150400.5.12.1 * kbd-debugsource-2.4.0-150400.5.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * kbd-legacy-2.4.0-150400.5.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * kbd-2.4.0-150400.5.12.1 * kbd-debuginfo-2.4.0-150400.5.12.1 * kbd-debugsource-2.4.0-150400.5.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * kbd-legacy-2.4.0-150400.5.12.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * kbd-2.4.0-150400.5.12.1 * kbd-debuginfo-2.4.0-150400.5.12.1 * kbd-debugsource-2.4.0-150400.5.12.1 * openSUSE Leap 15.4 (noarch) * kbd-legacy-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * kbd-2.4.0-150400.5.12.1 * kbd-debuginfo-2.4.0-150400.5.12.1 * kbd-debugsource-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * kbd-legacy-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * kbd-2.4.0-150400.5.12.1 * kbd-debuginfo-2.4.0-150400.5.12.1 * kbd-debugsource-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * kbd-legacy-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * kbd-2.4.0-150400.5.12.1 * kbd-debuginfo-2.4.0-150400.5.12.1 * kbd-debugsource-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * kbd-legacy-2.4.0-150400.5.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * kbd-2.4.0-150400.5.12.1 * kbd-debuginfo-2.4.0-150400.5.12.1 * kbd-debugsource-2.4.0-150400.5.12.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * kbd-legacy-2.4.0-150400.5.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * kbd-2.4.0-150400.5.12.1 * kbd-debuginfo-2.4.0-150400.5.12.1 * kbd-debugsource-2.4.0-150400.5.12.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * kbd-legacy-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * kbd-2.4.0-150400.5.12.1 * kbd-debuginfo-2.4.0-150400.5.12.1 * kbd-debugsource-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * kbd-legacy-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * kbd-2.4.0-150400.5.12.1 * kbd-debuginfo-2.4.0-150400.5.12.1 * kbd-debugsource-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * kbd-legacy-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * kbd-2.4.0-150400.5.12.1 * kbd-debuginfo-2.4.0-150400.5.12.1 * kbd-debugsource-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * kbd-legacy-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * kbd-2.4.0-150400.5.12.1 * kbd-debuginfo-2.4.0-150400.5.12.1 * kbd-debugsource-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Micro 5.5 (noarch) * kbd-legacy-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * kbd-2.4.0-150400.5.12.1 * kbd-debuginfo-2.4.0-150400.5.12.1 * kbd-debugsource-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * kbd-legacy-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * kbd-2.4.0-150400.5.12.1 * kbd-debuginfo-2.4.0-150400.5.12.1 * kbd-debugsource-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * kbd-legacy-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * kbd-2.4.0-150400.5.12.1 * kbd-debuginfo-2.4.0-150400.5.12.1 * kbd-debugsource-2.4.0-150400.5.12.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * kbd-legacy-2.4.0-150400.5.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-72693.html * https://bugzilla.suse.com/show_bug.cgi?id=1275441 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 17:02:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 17:02:07 -0000 Subject: SUSE-SU-2026:4206-1: important: Security update for google-cloud-sap-agent Message-ID: <178957812786.26114.6318707260141482957@b9be41dc2e4b> # Security update for google-cloud-sap-agent Announcement ID: SUSE-SU-2026:4206-1 Release Date: 2026-09-16T08:21:12Z Rating: important References: * bsc#1210938 * bsc#1272128 * bsc#1278987 * bsc#1279201 * bsc#1279304 Cross-References: * CVE-2026-56852 * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84445 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves four vulnerabilities and has one security fix can now be installed. ## Description: This update for google-cloud-sap-agent fixes the following issues: Security issues fixed: * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272128). * CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279304). * CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279201). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278987). Non security issue fixed: * re-enable stripping and debuginfo (bsc#1210938). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-4206 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-4206 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-4206 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-4206 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * google-cloud-sap-agent-3.15-150100.3.87.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * google-cloud-sap-agent-3.15-150100.3.87.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * google-cloud-sap-agent-3.15-150100.3.87.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * google-cloud-sap-agent-3.15-150100.3.87.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56852.html * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1210938 * https://bugzilla.suse.com/show_bug.cgi?id=1272128 * https://bugzilla.suse.com/show_bug.cgi?id=1278987 * https://bugzilla.suse.com/show_bug.cgi?id=1279201 * https://bugzilla.suse.com/show_bug.cgi?id=1279304 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 17:02:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 17:02:46 -0000 Subject: SUSE-SU-2026:4205-1: low: Security update for lcms2 Message-ID: <178957816626.26114.2432847829534899321@b9be41dc2e4b> # Security update for lcms2 Announcement ID: SUSE-SU-2026:4205-1 Release Date: 2026-09-16T08:20:32Z Rating: low References: * bsc#1264994 Cross-References: * CVE-2026-41254 CVSS scores: * CVE-2026-41254 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-41254 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41254 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-41254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for lcms2 fixes the following issue: * CVE-2026-41254: Information disclosure or denial of service via integer overflow in CubeSize (bsc#1264994). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4205 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4205 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4205 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * liblcms2-2-debuginfo-2.15-150600.3.6.1 * lcms2-debuginfo-2.15-150600.3.6.1 * lcms2-2.15-150600.3.6.1 * liblcms2-2-2.15-150600.3.6.1 * lcms2-debugsource-2.15-150600.3.6.1 * liblcms2-devel-2.15-150600.3.6.1 * openSUSE Leap 15.6 (x86_64) * liblcms2-2-32bit-2.15-150600.3.6.1 * liblcms2-2-32bit-debuginfo-2.15-150600.3.6.1 * liblcms2-devel-32bit-2.15-150600.3.6.1 * openSUSE Leap 15.6 (aarch64_ilp32) * liblcms2-2-64bit-debuginfo-2.15-150600.3.6.1 * liblcms2-devel-64bit-2.15-150600.3.6.1 * liblcms2-2-64bit-2.15-150600.3.6.1 * openSUSE Leap 15.6 (noarch) * liblcms2-doc-2.15-150600.3.6.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * liblcms2-2-debuginfo-2.15-150600.3.6.1 * lcms2-debuginfo-2.15-150600.3.6.1 * liblcms2-2-2.15-150600.3.6.1 * liblcms2-devel-2.15-150600.3.6.1 * lcms2-debugsource-2.15-150600.3.6.1 * SUSE Package Hub 15 15-SP7 (x86_64) * liblcms2-2-32bit-2.15-150600.3.6.1 * liblcms2-2-32bit-debuginfo-2.15-150600.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41254.html * https://bugzilla.suse.com/show_bug.cgi?id=1264994 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 17:03:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 17:03:47 -0000 Subject: SUSE-SU-2026:4204-1: moderate: Security update for glibc Message-ID: <178957822785.26114.12693382576564121619@b9be41dc2e4b> # Security update for glibc Announcement ID: SUSE-SU-2026:4204-1 Release Date: 2026-09-16T08:20:11Z Rating: moderate References: * bsc#1274723 * bsc#1274726 * bsc#1276946 * bsc#1277262 * bsc#1277921 * bsc#1277922 Cross-References: * CVE-2026-18374 * CVE-2026-19542 * CVE-2026-6368 * CVE-2026-6791 * CVE-2026-77117 * CVE-2026-80489 CVSS scores: * CVE-2026-18374 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-18374 ( SUSE ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-18374 ( NVD ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-19542 ( SUSE ): 1.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-19542 ( SUSE ): 4.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2026-19542 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6368 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-6368 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green * CVE-2026-6791 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-6791 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-77117 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-77117 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-77117 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80489 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80489 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80489 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for glibc fixes the following issues: * CVE-2026-6368: wordexp WRDE_APPEND rollback restores stale we_wordv, leading to invalid free in wordfree (bsc#1274726). * CVE-2026-6791: wordexp: unbounded alloca (strndupa) in parse_tilde (bsc#1274723). * CVE-2026-18374: overflow in the fopen ccs extension (bsc#1277262). * CVE-2026-19542: Fix out-of-bounds array write in tdelete (bsc#1276946). * CVE-2026-77117: non-progress DoS in SHIFT_JISX0213 -> UCS-4 conversion state handling (bsc#1277921). * CVE-2026-80489: non-progress DoS in SHIFT_JISX0213 -> UCS-4 conversion state handling (bsc#1277922). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4204 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4204 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * nscd-debuginfo-2.22-114.52.2 * glibc-devel-static-2.22-114.52.2 * glibc-locale-2.22-114.52.2 * nscd-2.22-114.52.2 * glibc-locale-debuginfo-2.22-114.52.2 * glibc-2.22-114.52.2 * glibc-devel-debuginfo-2.22-114.52.2 * glibc-profile-2.22-114.52.2 * glibc-devel-2.22-114.52.2 * glibc-debugsource-2.22-114.52.2 * glibc-debuginfo-2.22-114.52.2 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * glibc-locale-32bit-2.22-114.52.2 * glibc-debuginfo-32bit-2.22-114.52.2 * glibc-profile-32bit-2.22-114.52.2 * glibc-32bit-2.22-114.52.2 * glibc-devel-debuginfo-32bit-2.22-114.52.2 * glibc-locale-debuginfo-32bit-2.22-114.52.2 * glibc-devel-32bit-2.22-114.52.2 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * glibc-i18ndata-2.22-114.52.2 * glibc-info-2.22-114.52.2 * glibc-html-2.22-114.52.2 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * nscd-debuginfo-2.22-114.52.2 * glibc-devel-static-2.22-114.52.2 * glibc-locale-32bit-2.22-114.52.2 * glibc-debuginfo-32bit-2.22-114.52.2 * glibc-locale-2.22-114.52.2 * nscd-2.22-114.52.2 * glibc-locale-debuginfo-2.22-114.52.2 * glibc-2.22-114.52.2 * glibc-profile-32bit-2.22-114.52.2 * glibc-devel-debuginfo-2.22-114.52.2 * glibc-32bit-2.22-114.52.2 * glibc-devel-debuginfo-32bit-2.22-114.52.2 * glibc-locale-debuginfo-32bit-2.22-114.52.2 * glibc-profile-2.22-114.52.2 * glibc-devel-2.22-114.52.2 * glibc-devel-32bit-2.22-114.52.2 * glibc-debugsource-2.22-114.52.2 * glibc-debuginfo-2.22-114.52.2 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * glibc-i18ndata-2.22-114.52.2 * glibc-info-2.22-114.52.2 * glibc-html-2.22-114.52.2 ## References: * https://www.suse.com/security/cve/CVE-2026-18374.html * https://www.suse.com/security/cve/CVE-2026-19542.html * https://www.suse.com/security/cve/CVE-2026-6368.html * https://www.suse.com/security/cve/CVE-2026-6791.html * https://www.suse.com/security/cve/CVE-2026-77117.html * https://www.suse.com/security/cve/CVE-2026-80489.html * https://bugzilla.suse.com/show_bug.cgi?id=1274723 * https://bugzilla.suse.com/show_bug.cgi?id=1274726 * https://bugzilla.suse.com/show_bug.cgi?id=1276946 * https://bugzilla.suse.com/show_bug.cgi?id=1277262 * https://bugzilla.suse.com/show_bug.cgi?id=1277921 * https://bugzilla.suse.com/show_bug.cgi?id=1277922 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 17:04:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 17:04:38 -0000 Subject: SUSE-SU-2026:4203-1: important: Security update for tomcat Message-ID: <178957827878.26114.8172805115098881459@b9be41dc2e4b> # Security update for tomcat Announcement ID: SUSE-SU-2026:4203-1 Release Date: 2026-09-16T08:19:51Z Rating: important References: * bsc#1273150 * bsc#1276893 * bsc#1276894 * bsc#1276895 * bsc#1276896 * bsc#1276897 * bsc#1276898 * bsc#1276899 * bsc#1276900 * bsc#1276901 * bsc#1276902 Cross-References: * CVE-2026-65182 * CVE-2026-65183 * CVE-2026-65637 * CVE-2026-65905 * CVE-2026-65927 * CVE-2026-66299 * CVE-2026-66422 * CVE-2026-68525 * CVE-2026-68569 * CVE-2026-68763 * CVE-2026-73180 CVSS scores: * CVE-2026-65182 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65182 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-65182 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-65183 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65183 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65637 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65637 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65637 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65905 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-65905 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-65905 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-65927 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-65927 ( SUSE ): 7.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-65927 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-66299 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-66299 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-66422 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-66422 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-66422 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-68525 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68525 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68525 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68569 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68569 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68569 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-68763 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68763 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68763 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-73180 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-73180 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-73180 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves 11 vulnerabilities can now be installed. ## Description: This update for tomcat fixes the following issues: * CVE-2026-65182: Apache Tomcat: Bypass longest prefix security constraint (bsc#1276893). * CVE-2026-65183: Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets (bsc#1276894). * CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - fix incomplete (bsc#1276895). * CVE-2026-65905: Apache Tomcat: Limited replay attack possible with DIGEST authentication (bsc#1276896). * CVE-2026-65927: Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control (bsc#1276897). * CVE-2026-66299: memory exhaustion via maliciously slow clients due to the WebSocket chat example providing an unbounded buffer for undelivered messages (bsc#1273150). * CVE-2026-66422: Apache Tomcat: Servlet role references can bypass declarative role constraints (bsc#1276898). * CVE-2026-68525: Apache Tomcat: Redirect after FORM auth may bypass method specific constraints (bsc#1276899). * CVE-2026-68569: Apache Tomcat: Principal lookup can fail open in some cases (bsc#1276900). * CVE-2026-68763: Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset (bsc#1276901). * CVE-2026-73180: Apache Tomcat: Authenticated WebSocket session survives end of HTTP session (bsc#1276902). Changes for tomcat: * Updated to version 9.0.121 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4203 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4203 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4203 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4203 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4203 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4203 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4203 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4203 * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-4203 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4203 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4203 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * tomcat-9.0.121-150200.120.1 * tomcat-el-3_0-api-9.0.121-150200.120.1 * tomcat-lib-9.0.121-150200.120.1 * tomcat-webapps-9.0.121-150200.120.1 * tomcat-servlet-4_0-api-9.0.121-150200.120.1 * tomcat-jsp-2_3-api-9.0.121-150200.120.1 * tomcat-admin-webapps-9.0.121-150200.120.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * tomcat-9.0.121-150200.120.1 * tomcat-el-3_0-api-9.0.121-150200.120.1 * tomcat-lib-9.0.121-150200.120.1 * tomcat-webapps-9.0.121-150200.120.1 * tomcat-servlet-4_0-api-9.0.121-150200.120.1 * tomcat-jsp-2_3-api-9.0.121-150200.120.1 * tomcat-admin-webapps-9.0.121-150200.120.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * tomcat-9.0.121-150200.120.1 * tomcat-el-3_0-api-9.0.121-150200.120.1 * tomcat-lib-9.0.121-150200.120.1 * tomcat-webapps-9.0.121-150200.120.1 * tomcat-servlet-4_0-api-9.0.121-150200.120.1 * tomcat-jsp-2_3-api-9.0.121-150200.120.1 * tomcat-admin-webapps-9.0.121-150200.120.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * tomcat-9.0.121-150200.120.1 * tomcat-el-3_0-api-9.0.121-150200.120.1 * tomcat-lib-9.0.121-150200.120.1 * tomcat-webapps-9.0.121-150200.120.1 * tomcat-servlet-4_0-api-9.0.121-150200.120.1 * tomcat-jsp-2_3-api-9.0.121-150200.120.1 * tomcat-admin-webapps-9.0.121-150200.120.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * tomcat-9.0.121-150200.120.1 * tomcat-el-3_0-api-9.0.121-150200.120.1 * tomcat-lib-9.0.121-150200.120.1 * tomcat-webapps-9.0.121-150200.120.1 * tomcat-servlet-4_0-api-9.0.121-150200.120.1 * tomcat-jsp-2_3-api-9.0.121-150200.120.1 * tomcat-admin-webapps-9.0.121-150200.120.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * tomcat-9.0.121-150200.120.1 * tomcat-el-3_0-api-9.0.121-150200.120.1 * tomcat-lib-9.0.121-150200.120.1 * tomcat-webapps-9.0.121-150200.120.1 * tomcat-servlet-4_0-api-9.0.121-150200.120.1 * tomcat-jsp-2_3-api-9.0.121-150200.120.1 * tomcat-admin-webapps-9.0.121-150200.120.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * tomcat-9.0.121-150200.120.1 * tomcat-el-3_0-api-9.0.121-150200.120.1 * tomcat-lib-9.0.121-150200.120.1 * tomcat-webapps-9.0.121-150200.120.1 * tomcat-servlet-4_0-api-9.0.121-150200.120.1 * tomcat-jsp-2_3-api-9.0.121-150200.120.1 * tomcat-admin-webapps-9.0.121-150200.120.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * tomcat-9.0.121-150200.120.1 * tomcat-el-3_0-api-9.0.121-150200.120.1 * tomcat-lib-9.0.121-150200.120.1 * tomcat-webapps-9.0.121-150200.120.1 * tomcat-servlet-4_0-api-9.0.121-150200.120.1 * tomcat-jsp-2_3-api-9.0.121-150200.120.1 * tomcat-admin-webapps-9.0.121-150200.120.1 * Web and Scripting Module 15-SP7 (noarch) * tomcat-9.0.121-150200.120.1 * tomcat-el-3_0-api-9.0.121-150200.120.1 * tomcat-lib-9.0.121-150200.120.1 * tomcat-webapps-9.0.121-150200.120.1 * tomcat-servlet-4_0-api-9.0.121-150200.120.1 * tomcat-jsp-2_3-api-9.0.121-150200.120.1 * tomcat-admin-webapps-9.0.121-150200.120.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * tomcat-9.0.121-150200.120.1 * tomcat-el-3_0-api-9.0.121-150200.120.1 * tomcat-lib-9.0.121-150200.120.1 * tomcat-webapps-9.0.121-150200.120.1 * tomcat-servlet-4_0-api-9.0.121-150200.120.1 * tomcat-jsp-2_3-api-9.0.121-150200.120.1 * tomcat-admin-webapps-9.0.121-150200.120.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * tomcat-9.0.121-150200.120.1 * tomcat-el-3_0-api-9.0.121-150200.120.1 * tomcat-lib-9.0.121-150200.120.1 * tomcat-webapps-9.0.121-150200.120.1 * tomcat-servlet-4_0-api-9.0.121-150200.120.1 * tomcat-jsp-2_3-api-9.0.121-150200.120.1 * tomcat-admin-webapps-9.0.121-150200.120.1 ## References: * https://www.suse.com/security/cve/CVE-2026-65182.html * https://www.suse.com/security/cve/CVE-2026-65183.html * https://www.suse.com/security/cve/CVE-2026-65637.html * https://www.suse.com/security/cve/CVE-2026-65905.html * https://www.suse.com/security/cve/CVE-2026-65927.html * https://www.suse.com/security/cve/CVE-2026-66299.html * https://www.suse.com/security/cve/CVE-2026-66422.html * https://www.suse.com/security/cve/CVE-2026-68525.html * https://www.suse.com/security/cve/CVE-2026-68569.html * https://www.suse.com/security/cve/CVE-2026-68763.html * https://www.suse.com/security/cve/CVE-2026-73180.html * https://bugzilla.suse.com/show_bug.cgi?id=1273150 * https://bugzilla.suse.com/show_bug.cgi?id=1276893 * https://bugzilla.suse.com/show_bug.cgi?id=1276894 * https://bugzilla.suse.com/show_bug.cgi?id=1276895 * https://bugzilla.suse.com/show_bug.cgi?id=1276896 * https://bugzilla.suse.com/show_bug.cgi?id=1276897 * https://bugzilla.suse.com/show_bug.cgi?id=1276898 * https://bugzilla.suse.com/show_bug.cgi?id=1276899 * https://bugzilla.suse.com/show_bug.cgi?id=1276900 * https://bugzilla.suse.com/show_bug.cgi?id=1276901 * https://bugzilla.suse.com/show_bug.cgi?id=1276902 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 17:05:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 17:05:18 -0000 Subject: SUSE-SU-2026:4202-1: important: Security update for corosync Message-ID: <178957831874.26114.18394915772091866584@b9be41dc2e4b> # Security update for corosync Announcement ID: SUSE-SU-2026:4202-1 Release Date: 2026-09-16T08:18:20Z Rating: important References: * bsc#1278738 * bsc#1278739 Cross-References: * CVE-2026-81665 * CVE-2026-81666 CVSS scores: * CVE-2026-81665 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-81665 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-81665 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-81666 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-81666 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-81666 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise High Availability Extension 15 SP4 * SUSE Linux Enterprise High Availability Extension 15 SP5 * SUSE Linux Enterprise High Availability Extension 15 SP6 * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves two vulnerabilities can now be installed. ## Description: This update for corosync fixes the following issues: * CVE-2026-81665: heap-based buffer overflow in totempg assembly buffer during fragmented message reassembly (bsc#1278738). * CVE-2026-81666: integer overflow in check_memb_commit_token_sanity may bypass message length validation on 32-bit systems (bsc#1278739). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-4202 * SUSE Linux Enterprise High Availability Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2026-4202 * SUSE Linux Enterprise High Availability Extension 15 SP5 zypper in -t patch SUSE-SLE-Product-HA-15-SP5-2026-4202 * SUSE Linux Enterprise High Availability Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2026-4202 * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2026-4202 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * libquorum5-2.4.6-150300.12.19.1 * libcorosync_common4-2.4.6-150300.12.19.1 * libtotem_pg5-debuginfo-2.4.6-150300.12.19.1 * libcmap4-debuginfo-2.4.6-150300.12.19.1 * corosync-qdevice-2.4.6-150300.12.19.1 * corosync-debugsource-2.4.6-150300.12.19.1 * libvotequorum8-debuginfo-2.4.6-150300.12.19.1 * libcorosync_common4-debuginfo-2.4.6-150300.12.19.1 * corosync-qnetd-debuginfo-2.4.6-150300.12.19.1 * libcpg4-2.4.6-150300.12.19.1 * corosync-debuginfo-2.4.6-150300.12.19.1 * libcmap4-2.4.6-150300.12.19.1 * corosync-qdevice-debuginfo-2.4.6-150300.12.19.1 * libvotequorum8-2.4.6-150300.12.19.1 * corosync-qnetd-2.4.6-150300.12.19.1 * corosync-testagents-debuginfo-2.4.6-150300.12.19.1 * libcfg6-debuginfo-2.4.6-150300.12.19.1 * libcorosync-devel-2.4.6-150300.12.19.1 * libcpg4-debuginfo-2.4.6-150300.12.19.1 * libtotem_pg5-2.4.6-150300.12.19.1 * corosync-2.4.6-150300.12.19.1 * libsam4-debuginfo-2.4.6-150300.12.19.1 * corosync-testagents-2.4.6-150300.12.19.1 * libsam4-2.4.6-150300.12.19.1 * libquorum5-debuginfo-2.4.6-150300.12.19.1 * libcfg6-2.4.6-150300.12.19.1 * openSUSE Leap 15.3 (x86_64) * libsam4-32bit-debuginfo-2.4.6-150300.12.19.1 * libcmap4-32bit-debuginfo-2.4.6-150300.12.19.1 * libvotequorum8-32bit-2.4.6-150300.12.19.1 * libcmap4-32bit-2.4.6-150300.12.19.1 * libcorosync_common4-32bit-2.4.6-150300.12.19.1 * libtotem_pg5-32bit-2.4.6-150300.12.19.1 * libvotequorum8-32bit-debuginfo-2.4.6-150300.12.19.1 * libcfg6-32bit-debuginfo-2.4.6-150300.12.19.1 * libcpg4-32bit-2.4.6-150300.12.19.1 * libcorosync_common4-32bit-debuginfo-2.4.6-150300.12.19.1 * libcpg4-32bit-debuginfo-2.4.6-150300.12.19.1 * libquorum5-32bit-2.4.6-150300.12.19.1 * libcfg6-32bit-2.4.6-150300.12.19.1 * libtotem_pg5-32bit-debuginfo-2.4.6-150300.12.19.1 * libquorum5-32bit-debuginfo-2.4.6-150300.12.19.1 * libsam4-32bit-2.4.6-150300.12.19.1 * openSUSE Leap 15.3 (aarch64_ilp32) * libcorosync_common4-64bit-debuginfo-2.4.6-150300.12.19.1 * libquorum5-64bit-debuginfo-2.4.6-150300.12.19.1 * libvotequorum8-64bit-debuginfo-2.4.6-150300.12.19.1 * libcfg6-64bit-2.4.6-150300.12.19.1 * libcorosync_common4-64bit-2.4.6-150300.12.19.1 * libcmap4-64bit-2.4.6-150300.12.19.1 * libcfg6-64bit-debuginfo-2.4.6-150300.12.19.1 * libcpg4-64bit-2.4.6-150300.12.19.1 * libquorum5-64bit-2.4.6-150300.12.19.1 * libsam4-64bit-debuginfo-2.4.6-150300.12.19.1 * libtotem_pg5-64bit-debuginfo-2.4.6-150300.12.19.1 * libtotem_pg5-64bit-2.4.6-150300.12.19.1 * libcpg4-64bit-debuginfo-2.4.6-150300.12.19.1 * libsam4-64bit-2.4.6-150300.12.19.1 * libcmap4-64bit-debuginfo-2.4.6-150300.12.19.1 * libvotequorum8-64bit-2.4.6-150300.12.19.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le s390x x86_64) * libquorum5-2.4.6-150300.12.19.1 * libcorosync_common4-2.4.6-150300.12.19.1 * libtotem_pg5-debuginfo-2.4.6-150300.12.19.1 * libcmap4-debuginfo-2.4.6-150300.12.19.1 * corosync-qdevice-2.4.6-150300.12.19.1 * corosync-debugsource-2.4.6-150300.12.19.1 * libvotequorum8-debuginfo-2.4.6-150300.12.19.1 * libcorosync_common4-debuginfo-2.4.6-150300.12.19.1 * corosync-qnetd-debuginfo-2.4.6-150300.12.19.1 * libcpg4-2.4.6-150300.12.19.1 * corosync-debuginfo-2.4.6-150300.12.19.1 * libcmap4-2.4.6-150300.12.19.1 * corosync-qdevice-debuginfo-2.4.6-150300.12.19.1 * libvotequorum8-2.4.6-150300.12.19.1 * corosync-qnetd-2.4.6-150300.12.19.1 * corosync-testagents-debuginfo-2.4.6-150300.12.19.1 * libcfg6-debuginfo-2.4.6-150300.12.19.1 * libcorosync-devel-2.4.6-150300.12.19.1 * libcpg4-debuginfo-2.4.6-150300.12.19.1 * libtotem_pg5-2.4.6-150300.12.19.1 * corosync-2.4.6-150300.12.19.1 * libsam4-debuginfo-2.4.6-150300.12.19.1 * corosync-testagents-2.4.6-150300.12.19.1 * libsam4-2.4.6-150300.12.19.1 * libquorum5-debuginfo-2.4.6-150300.12.19.1 * libcfg6-2.4.6-150300.12.19.1 * SUSE Linux Enterprise High Availability Extension 15 SP5 (aarch64 ppc64le s390x x86_64) * libquorum5-2.4.6-150300.12.19.1 * libcorosync_common4-2.4.6-150300.12.19.1 * libtotem_pg5-debuginfo-2.4.6-150300.12.19.1 * libcmap4-debuginfo-2.4.6-150300.12.19.1 * corosync-qdevice-2.4.6-150300.12.19.1 * corosync-debugsource-2.4.6-150300.12.19.1 * libvotequorum8-debuginfo-2.4.6-150300.12.19.1 * libcorosync_common4-debuginfo-2.4.6-150300.12.19.1 * corosync-qnetd-debuginfo-2.4.6-150300.12.19.1 * libcpg4-2.4.6-150300.12.19.1 * corosync-debuginfo-2.4.6-150300.12.19.1 * libcmap4-2.4.6-150300.12.19.1 * corosync-qdevice-debuginfo-2.4.6-150300.12.19.1 * libvotequorum8-2.4.6-150300.12.19.1 * corosync-qnetd-2.4.6-150300.12.19.1 * corosync-testagents-debuginfo-2.4.6-150300.12.19.1 * libcfg6-debuginfo-2.4.6-150300.12.19.1 * libcorosync-devel-2.4.6-150300.12.19.1 * libcpg4-debuginfo-2.4.6-150300.12.19.1 * libtotem_pg5-2.4.6-150300.12.19.1 * corosync-2.4.6-150300.12.19.1 * libsam4-debuginfo-2.4.6-150300.12.19.1 * corosync-testagents-2.4.6-150300.12.19.1 * libsam4-2.4.6-150300.12.19.1 * libquorum5-debuginfo-2.4.6-150300.12.19.1 * libcfg6-2.4.6-150300.12.19.1 * SUSE Linux Enterprise High Availability Extension 15 SP6 (aarch64 ppc64le s390x x86_64) * libquorum5-2.4.6-150300.12.19.1 * libcorosync_common4-2.4.6-150300.12.19.1 * libtotem_pg5-debuginfo-2.4.6-150300.12.19.1 * libcmap4-debuginfo-2.4.6-150300.12.19.1 * corosync-qdevice-2.4.6-150300.12.19.1 * corosync-debugsource-2.4.6-150300.12.19.1 * libvotequorum8-debuginfo-2.4.6-150300.12.19.1 * libcorosync_common4-debuginfo-2.4.6-150300.12.19.1 * corosync-qnetd-debuginfo-2.4.6-150300.12.19.1 * libcpg4-2.4.6-150300.12.19.1 * corosync-debuginfo-2.4.6-150300.12.19.1 * libcmap4-2.4.6-150300.12.19.1 * corosync-qdevice-debuginfo-2.4.6-150300.12.19.1 * libvotequorum8-2.4.6-150300.12.19.1 * corosync-qnetd-2.4.6-150300.12.19.1 * corosync-testagents-debuginfo-2.4.6-150300.12.19.1 * libcfg6-debuginfo-2.4.6-150300.12.19.1 * libcorosync-devel-2.4.6-150300.12.19.1 * libcpg4-debuginfo-2.4.6-150300.12.19.1 * libtotem_pg5-2.4.6-150300.12.19.1 * corosync-2.4.6-150300.12.19.1 * libsam4-debuginfo-2.4.6-150300.12.19.1 * corosync-testagents-2.4.6-150300.12.19.1 * libsam4-2.4.6-150300.12.19.1 * libquorum5-debuginfo-2.4.6-150300.12.19.1 * libcfg6-2.4.6-150300.12.19.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (aarch64 ppc64le s390x x86_64) * libquorum5-2.4.6-150300.12.19.1 * libcorosync_common4-2.4.6-150300.12.19.1 * libtotem_pg5-debuginfo-2.4.6-150300.12.19.1 * libcmap4-debuginfo-2.4.6-150300.12.19.1 * corosync-qdevice-2.4.6-150300.12.19.1 * corosync-debugsource-2.4.6-150300.12.19.1 * libvotequorum8-debuginfo-2.4.6-150300.12.19.1 * libcorosync_common4-debuginfo-2.4.6-150300.12.19.1 * corosync-qnetd-debuginfo-2.4.6-150300.12.19.1 * libcpg4-2.4.6-150300.12.19.1 * corosync-debuginfo-2.4.6-150300.12.19.1 * libcmap4-2.4.6-150300.12.19.1 * corosync-qdevice-debuginfo-2.4.6-150300.12.19.1 * libvotequorum8-2.4.6-150300.12.19.1 * corosync-qnetd-2.4.6-150300.12.19.1 * corosync-testagents-debuginfo-2.4.6-150300.12.19.1 * libcfg6-debuginfo-2.4.6-150300.12.19.1 * libcorosync-devel-2.4.6-150300.12.19.1 * libcpg4-debuginfo-2.4.6-150300.12.19.1 * libtotem_pg5-2.4.6-150300.12.19.1 * corosync-2.4.6-150300.12.19.1 * libsam4-debuginfo-2.4.6-150300.12.19.1 * corosync-testagents-2.4.6-150300.12.19.1 * libsam4-2.4.6-150300.12.19.1 * libquorum5-debuginfo-2.4.6-150300.12.19.1 * libcfg6-2.4.6-150300.12.19.1 ## References: * https://www.suse.com/security/cve/CVE-2026-81665.html * https://www.suse.com/security/cve/CVE-2026-81666.html * https://bugzilla.suse.com/show_bug.cgi?id=1278738 * https://bugzilla.suse.com/show_bug.cgi?id=1278739 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 17:06:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 17:06:27 -0000 Subject: SUSE-SU-2026:4201-1: important: Security update for pcre2 Message-ID: <178957838727.26114.17106655832933149011@b9be41dc2e4b> # Security update for pcre2 Announcement ID: SUSE-SU-2026:4201-1 Release Date: 2026-09-16T08:17:42Z Rating: important References: * bsc#1277707 * bsc#1277708 * bsc#1277709 * bsc#1277710 * bsc#1277711 * bsc#1277713 * bsc#1279893 * bsc#1280050 * bsc#1280051 * bsc#1280052 * bsc#1280053 * bsc#1280054 Cross-References: * CVE-2026-86145 * CVE-2026-89156 * CVE-2026-89157 * CVE-2026-89158 * CVE-2026-89160 * CVE-2026-89161 CVSS scores: * CVE-2026-86145 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-86145 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-86145 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-89156 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-89156 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-89156 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-89157 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-89157 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-89157 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-89158 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-89158 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-89158 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-89160 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-89160 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-89160 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-89161 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-89161 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-89161 ( NVD ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves six vulnerabilities and has six security fixes can now be installed. ## Description: This update for pcre2 fixes the following issues: * CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). * CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). * CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). * CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). * CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). * CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4201 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4201 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libpcre2-16-0-debuginfo-10.34-1.16.1 * pcre2-devel-10.34-1.16.1 * libpcre2-posix2-debuginfo-10.34-1.16.1 * libpcre2-32-0-10.34-1.16.1 * libpcre2-16-0-10.34-1.16.1 * libpcre2-32-0-debuginfo-10.34-1.16.1 * libpcre2-8-0-debuginfo-10.34-1.16.1 * libpcre2-posix2-10.34-1.16.1 * libpcre2-8-0-10.34-1.16.1 * pcre2-devel-static-10.34-1.16.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libpcre2-16-0-debuginfo-10.34-1.16.1 * pcre2-devel-10.34-1.16.1 * libpcre2-posix2-debuginfo-10.34-1.16.1 * libpcre2-32-0-10.34-1.16.1 * libpcre2-16-0-10.34-1.16.1 * libpcre2-32-0-debuginfo-10.34-1.16.1 * libpcre2-8-0-debuginfo-10.34-1.16.1 * libpcre2-posix2-10.34-1.16.1 * libpcre2-8-0-10.34-1.16.1 * pcre2-devel-static-10.34-1.16.1 ## References: * https://www.suse.com/security/cve/CVE-2026-86145.html * https://www.suse.com/security/cve/CVE-2026-89156.html * https://www.suse.com/security/cve/CVE-2026-89157.html * https://www.suse.com/security/cve/CVE-2026-89158.html * https://www.suse.com/security/cve/CVE-2026-89160.html * https://www.suse.com/security/cve/CVE-2026-89161.html * https://bugzilla.suse.com/show_bug.cgi?id=1277707 * https://bugzilla.suse.com/show_bug.cgi?id=1277708 * https://bugzilla.suse.com/show_bug.cgi?id=1277709 * https://bugzilla.suse.com/show_bug.cgi?id=1277710 * https://bugzilla.suse.com/show_bug.cgi?id=1277711 * https://bugzilla.suse.com/show_bug.cgi?id=1277713 * https://bugzilla.suse.com/show_bug.cgi?id=1279893 * https://bugzilla.suse.com/show_bug.cgi?id=1280050 * https://bugzilla.suse.com/show_bug.cgi?id=1280051 * https://bugzilla.suse.com/show_bug.cgi?id=1280052 * https://bugzilla.suse.com/show_bug.cgi?id=1280053 * https://bugzilla.suse.com/show_bug.cgi?id=1280054 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 16 17:07:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 16 Sep 2026 17:07:10 -0000 Subject: SUSE-SU-2026:4200-1: important: Security update for gvfs Message-ID: <178957843012.26114.17953931531150036166@b9be41dc2e4b> # Security update for gvfs Announcement ID: SUSE-SU-2026:4200-1 Release Date: 2026-09-16T08:17:25Z Rating: important References: * bsc#1278156 * bsc#1278157 * bsc#1278158 * bsc#1278159 Cross-References: * CVE-2026-84267 * CVE-2026-84268 * CVE-2026-84269 * CVE-2026-84270 CVSS scores: * CVE-2026-84267 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-84267 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-84267 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-84268 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-84268 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84268 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84269 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84269 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-84269 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-84270 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-84270 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84270 ( NVD ): 4.3 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves four vulnerabilities can now be installed. ## Description: This update for gvfs fixes the following issues: * CVE-2026-84267: `read_string()` allocates buffers withouth verifying that the buffer is completely filled when communicating with a malicious SFTP server, which can lead to uninitialized heap memory leaks (bsc#1278157). * CVE-2026-84268: `read_reply()` processes length that exceeds requested client size when communicating with a malicious SFTP server, which can lead to an OOB write (bsc#1278158). * CVE-2026-84269: DSI read path processes length that exceeds requested client size when communicating with a malicious AFP server, which can lead to an OOB memory access (bsc#1278159). * CVE-2026-84270: `do_read()` trusts the data length returned by a mounted MTP device and does not limit it to the original size requested by the client, which can lead to an OOB write (bsc#1278156). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4200 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4200 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gvfs-backends-1.28.3-18.12.1 * gvfs-debugsource-1.28.3-18.12.1 * gvfs-backend-samba-debuginfo-1.28.3-18.12.1 * gvfs-backend-samba-1.28.3-18.12.1 * gvfs-1.28.3-18.12.1 * gvfs-debuginfo-1.28.3-18.12.1 * gvfs-fuse-debuginfo-1.28.3-18.12.1 * gvfs-backends-debuginfo-1.28.3-18.12.1 * gvfs-fuse-1.28.3-18.12.1 * gvfs-devel-1.28.3-18.12.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * gvfs-lang-1.28.3-18.12.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * gvfs-backends-1.28.3-18.12.1 * gvfs-debugsource-1.28.3-18.12.1 * gvfs-backend-samba-debuginfo-1.28.3-18.12.1 * gvfs-backend-samba-1.28.3-18.12.1 * gvfs-1.28.3-18.12.1 * gvfs-debuginfo-1.28.3-18.12.1 * gvfs-fuse-debuginfo-1.28.3-18.12.1 * gvfs-backends-debuginfo-1.28.3-18.12.1 * gvfs-fuse-1.28.3-18.12.1 * gvfs-devel-1.28.3-18.12.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * gvfs-lang-1.28.3-18.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-84267.html * https://www.suse.com/security/cve/CVE-2026-84268.html * https://www.suse.com/security/cve/CVE-2026-84269.html * https://www.suse.com/security/cve/CVE-2026-84270.html * https://bugzilla.suse.com/show_bug.cgi?id=1278156 * https://bugzilla.suse.com/show_bug.cgi?id=1278157 * https://bugzilla.suse.com/show_bug.cgi?id=1278158 * https://bugzilla.suse.com/show_bug.cgi?id=1278159 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 08:30:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 08:30:41 -0000 Subject: SUSE-SU-2026:4215-1: important: Security update for the Linux Kernel (Live Patch 46 for SUSE Linux Enterprise 15 SP4) Message-ID: <178963384107.979.17118956824984721809@b9be41dc2e4b> # Security update for the Linux Kernel (Live Patch 46 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:4215-1 Release Date: 2026-09-16T15:34:23Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.184 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-4219 SUSE-SLE- Module-Live-Patching-15-SP4-2026-4218 SUSE-SLE-Module-Live- Patching-15-SP4-2026-4215 SUSE-SLE-Module-Live-Patching-15-SP4-2026-4214 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4219 SUSE-2026-4218 SUSE-2026-4215 SUSE-2026-4214 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_173-default-20-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_43-debugsource-20-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_44-debugsource-19-150400.2.1 * kernel-livepatch-5_14_21-150400_24_173-default-debuginfo-20-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-debuginfo-19-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-debuginfo-13-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-13-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-debuginfo-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-19-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_46-debugsource-13-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-17-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_45-debugsource-17-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_173-default-20-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_43-debugsource-20-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_44-debugsource-19-150400.2.1 * kernel-livepatch-5_14_21-150400_24_173-default-debuginfo-20-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-debuginfo-19-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-debuginfo-13-150400.2.1 * kernel-livepatch-5_14_21-150400_24_184-default-13-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-debuginfo-17-150400.2.1 * kernel-livepatch-5_14_21-150400_24_176-default-19-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_46-debugsource-13-150400.2.1 * kernel-livepatch-5_14_21-150400_24_179-default-17-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_45-debugsource-17-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 08:31:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 08:31:30 -0000 Subject: SUSE-SU-2026:4217-1: important: Security update for openvpn Message-ID: <178963389008.979.12444509127703338552@b9be41dc2e4b> # Security update for openvpn Announcement ID: SUSE-SU-2026:4217-1 Release Date: 2026-09-16T13:45:27Z Rating: important References: * bsc#1275310 * bsc#1279613 Cross-References: * CVE-2026-63650 * CVE-2026-84732 CVSS scores: * CVE-2026-63650 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-63650 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-63650 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84732 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84732 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for openvpn fixes the following issues: * CVE-2026-63650: OpenVPN 2.7_alpha1 through 2.7.5 using mbedTLS allows remote authenticated users to be misidentified by ignoring the configured X.509 username identity lookup field (bsc#1275310). * CVE-2026-84732: Remote Denial of Service via crafted ACK packets (bsc#1279613). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4217 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4217 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4217 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4217 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4217 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4217 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4217 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4217 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4217 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * openvpn-debuginfo-2.5.6-150400.3.28.1 * openvpn-debugsource-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-2.5.6-150400.3.28.1 * openvpn-2.5.6-150400.3.28.1 * openvpn-devel-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-debuginfo-2.5.6-150400.3.28.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * openvpn-debuginfo-2.5.6-150400.3.28.1 * openvpn-debugsource-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-2.5.6-150400.3.28.1 * openvpn-2.5.6-150400.3.28.1 * openvpn-devel-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-debuginfo-2.5.6-150400.3.28.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * openvpn-debuginfo-2.5.6-150400.3.28.1 * openvpn-debugsource-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-2.5.6-150400.3.28.1 * openvpn-2.5.6-150400.3.28.1 * openvpn-devel-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-debuginfo-2.5.6-150400.3.28.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * openvpn-debuginfo-2.5.6-150400.3.28.1 * openvpn-debugsource-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-2.5.6-150400.3.28.1 * openvpn-down-root-plugin-2.5.6-150400.3.28.1 * openvpn-2.5.6-150400.3.28.1 * openvpn-devel-2.5.6-150400.3.28.1 * openvpn-down-root-plugin-debuginfo-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-debuginfo-2.5.6-150400.3.28.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * openvpn-debuginfo-2.5.6-150400.3.28.1 * openvpn-debugsource-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-2.5.6-150400.3.28.1 * openvpn-2.5.6-150400.3.28.1 * openvpn-devel-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-debuginfo-2.5.6-150400.3.28.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * openvpn-debuginfo-2.5.6-150400.3.28.1 * openvpn-debugsource-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-2.5.6-150400.3.28.1 * openvpn-2.5.6-150400.3.28.1 * openvpn-devel-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-debuginfo-2.5.6-150400.3.28.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * openvpn-debuginfo-2.5.6-150400.3.28.1 * openvpn-debugsource-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-2.5.6-150400.3.28.1 * openvpn-2.5.6-150400.3.28.1 * openvpn-devel-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-debuginfo-2.5.6-150400.3.28.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * openvpn-debuginfo-2.5.6-150400.3.28.1 * openvpn-debugsource-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-2.5.6-150400.3.28.1 * openvpn-2.5.6-150400.3.28.1 * openvpn-devel-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-debuginfo-2.5.6-150400.3.28.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * openvpn-debuginfo-2.5.6-150400.3.28.1 * openvpn-debugsource-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-2.5.6-150400.3.28.1 * openvpn-2.5.6-150400.3.28.1 * openvpn-devel-2.5.6-150400.3.28.1 * openvpn-auth-pam-plugin-debuginfo-2.5.6-150400.3.28.1 ## References: * https://www.suse.com/security/cve/CVE-2026-63650.html * https://www.suse.com/security/cve/CVE-2026-84732.html * https://bugzilla.suse.com/show_bug.cgi?id=1275310 * https://bugzilla.suse.com/show_bug.cgi?id=1279613 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 08:32:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 08:32:27 -0000 Subject: SUSE-SU-2026:4216-1: moderate: Security update for cups Message-ID: <178963394758.979.8892823608207612303@b9be41dc2e4b> # Security update for cups Announcement ID: SUSE-SU-2026:4216-1 Release Date: 2026-09-16T13:44:41Z Rating: moderate References: * bsc#1279945 Cross-References: * CVE-2026-87875 CVSS scores: * CVE-2026-87875 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-87875 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-87875 ( NVD ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for cups fixes the following issue: * CVE-2026-87875,GHSA-559w-7676-3xrq: heap out-of-bounds read in `cupsUTF32ToUTF8()` due to missing source-length bound can be reached via the SNMP supply-description parsing (bsc#1279945). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4216 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * cups-devel-1.7.5-20.70.1 * cups-client-debuginfo-1.7.5-20.70.1 * cups-debugsource-1.7.5-20.70.1 * cups-1.7.5-20.70.1 * cups-libs-debuginfo-1.7.5-20.70.1 * cups-libs-1.7.5-20.70.1 * cups-libs-debuginfo-32bit-1.7.5-20.70.1 * cups-debuginfo-1.7.5-20.70.1 * cups-client-1.7.5-20.70.1 * cups-libs-32bit-1.7.5-20.70.1 ## References: * https://www.suse.com/security/cve/CVE-2026-87875.html * https://bugzilla.suse.com/show_bug.cgi?id=1279945 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 12:30:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 12:30:56 -0000 Subject: SUSE-SU-2026:4224-1: important: Security update for the Linux Kernel (Live Patch 32 for SUSE Linux Enterprise 15 SP5) Message-ID: <178964825611.4950.12625097208965400032@c4bba689c63a> # Security update for the Linux Kernel (Live Patch 32 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:4224-1 Release Date: 2026-09-17T05:34:16Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.127 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-4224 SUSE-SLE- Module-Live-Patching-15-SP4-2026-4220 SUSE-SLE-Module-Live- Patching-15-SP4-2026-4221 SUSE-SLE-Module-Live-Patching-15-SP4-2026-4222 SUSE- SLE-Module-Live-Patching-15-SP4-2026-4223 SUSE-SLE-Module-Live- Patching-15-SP4-2026-4225 SUSE-SLE-Module-Live-Patching-15-SP4-2026-4226 SUSE- SLE-Module-Live-Patching-15-SP4-2026-4227 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4224 SUSE-2026-4220 SUSE-2026-4221 SUSE-2026-4222 SUSE-2026-4223 SUSE-2026-4225 SUSE-2026-4226 SUSE-2026-4227 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-4228 SUSE-SLE- Module-Live-Patching-15-SP5-2026-4229 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-4228 SUSE-2026-4229 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_187-default-13-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-debuginfo-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-debuginfo-13-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_51-debugsource-8-150400.2.1 * kernel-livepatch-5_14_21-150400_24_194-default-debuginfo-11-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-debuginfo-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_47-debugsource-13-150400.2.1 * kernel-livepatch-5_14_21-150400_24_200-default-9-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_52-debugsource-7-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_49-debugsource-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_209-default-debuginfo-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_53-debugsource-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_219-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-8-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_54-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_200-default-debuginfo-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_219-default-5-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_50-debugsource-9-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_48-debugsource-11-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-debuginfo-8-150400.2.1 * kernel-livepatch-5_14_21-150400_24_209-default-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_194-default-11-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_187-default-13-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-debuginfo-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_187-default-debuginfo-13-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_51-debugsource-8-150400.2.1 * kernel-livepatch-5_14_21-150400_24_194-default-debuginfo-11-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-debuginfo-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_47-debugsource-13-150400.2.1 * kernel-livepatch-5_14_21-150400_24_200-default-9-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_52-debugsource-7-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_49-debugsource-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_197-default-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_209-default-debuginfo-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_214-default-6-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_53-debugsource-6-150400.2.1 * kernel-livepatch-5_14_21-150400_24_219-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-8-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_54-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_200-default-debuginfo-9-150400.2.1 * kernel-livepatch-5_14_21-150400_24_219-default-5-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_50-debugsource-9-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_48-debugsource-11-150400.2.1 * kernel-livepatch-5_14_21-150400_24_205-default-debuginfo-8-150400.2.1 * kernel-livepatch-5_14_21-150400_24_209-default-7-150400.2.1 * kernel-livepatch-5_14_21-150400_24_194-default-11-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_32-debugsource-13-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-16-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_31-debugsource-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_127-default-13-150500.2.1 * kernel-livepatch-5_14_21-150500_55_127-default-debuginfo-13-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-16-150500.2.1 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP5_Update_32-debugsource-13-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-16-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_31-debugsource-16-150500.2.1 * kernel-livepatch-5_14_21-150500_55_127-default-13-150500.2.1 * kernel-livepatch-5_14_21-150500_55_127-default-debuginfo-13-150500.2.1 * kernel-livepatch-5_14_21-150500_55_124-default-debuginfo-16-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 16:30:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 16:30:45 -0000 Subject: SUSE-SU-2026:4231-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP6) Message-ID: <178966264502.23775.3603339698245804199@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:4231-1 Release Date: 2026-09-17T10:33:58Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.73 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-4231 SUSE-SLE- Module-Live-Patching-15-SP5-2026-4232 SUSE-SLE-Module-Live- Patching-15-SP5-2026-4233 SUSE-SLE-Module-Live-Patching-15-SP5-2026-4235 SUSE- SLE-Module-Live-Patching-15-SP5-2026-4236 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-4231 SUSE-2026-4232 SUSE-2026-4233 SUSE-2026-4235 SUSE-2026-4236 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-4234 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4234 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_144-default-9-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_37-debugsource-9-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-13-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_36-debugsource-9-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-13-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-13-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_35-debugsource-12-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-13-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_34-debugsource-13-150500.2.1 * kernel-livepatch-5_14_21-150500_55_141-default-debuginfo-9-150500.2.1 * kernel-livepatch-5_14_21-150500_55_141-default-9-150500.2.1 * kernel-livepatch-5_14_21-150500_55_136-default-12-150500.2.1 * kernel-livepatch-5_14_21-150500_55_136-default-debuginfo-12-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_33-debugsource-13-150500.2.1 * kernel-livepatch-5_14_21-150500_55_144-default-debuginfo-9-150500.2.1 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_144-default-9-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_37-debugsource-9-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-13-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_36-debugsource-9-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-debuginfo-13-150500.2.1 * kernel-livepatch-5_14_21-150500_55_133-default-debuginfo-13-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_35-debugsource-12-150500.2.1 * kernel-livepatch-5_14_21-150500_55_130-default-13-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_34-debugsource-13-150500.2.1 * kernel-livepatch-5_14_21-150500_55_141-default-debuginfo-9-150500.2.1 * kernel-livepatch-5_14_21-150500_55_141-default-9-150500.2.1 * kernel-livepatch-5_14_21-150500_55_136-default-12-150500.2.1 * kernel-livepatch-5_14_21-150500_55_136-default-debuginfo-12-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_33-debugsource-13-150500.2.1 * kernel-livepatch-5_14_21-150500_55_144-default-debuginfo-9-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_16-debugsource-14-150600.2.1 * kernel-livepatch-6_4_0-150600_23_73-default-14-150600.2.1 * kernel-livepatch-6_4_0-150600_23_73-default-debuginfo-14-150600.2.1 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_16-debugsource-14-150600.2.1 * kernel-livepatch-6_4_0-150600_23_73-default-14-150600.2.1 * kernel-livepatch-6_4_0-150600_23_73-default-debuginfo-14-150600.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 16:31:40 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 16:31:40 -0000 Subject: SUSE-SU-2026:4242-1: important: Security update for openvpn Message-ID: <178966270099.23775.17933625545194282465@200ee98c8b1d> # Security update for openvpn Announcement ID: SUSE-SU-2026:4242-1 Release Date: 2026-09-17T11:49:21Z Rating: important References: * bsc#1279613 Cross-References: * CVE-2026-84732 CVSS scores: * CVE-2026-84732 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84732 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for openvpn fixes the following issue: * CVE-2026-84732: Remote Denial of Service via crafted ACK packets (bsc#1279613). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4242 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4242 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * openvpn-2.3.8-16.38.1 * openvpn-debugsource-2.3.8-16.38.1 * openvpn-debuginfo-2.3.8-16.38.1 * openvpn-auth-pam-plugin-2.3.8-16.38.1 * openvpn-auth-pam-plugin-debuginfo-2.3.8-16.38.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * openvpn-2.3.8-16.38.1 * openvpn-debugsource-2.3.8-16.38.1 * openvpn-debuginfo-2.3.8-16.38.1 * openvpn-auth-pam-plugin-2.3.8-16.38.1 * openvpn-auth-pam-plugin-debuginfo-2.3.8-16.38.1 ## References: * https://www.suse.com/security/cve/CVE-2026-84732.html * https://bugzilla.suse.com/show_bug.cgi?id=1279613 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 16:32:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 16:32:33 -0000 Subject: SUSE-SU-2026:4241-1: important: Security update for pcre2 Message-ID: <178966275350.23775.1355877104519262537@200ee98c8b1d> # Security update for pcre2 Announcement ID: SUSE-SU-2026:4241-1 Release Date: 2026-09-17T11:49:07Z Rating: important References: * bsc#1277707 * bsc#1277708 * bsc#1277709 * bsc#1277710 * bsc#1277711 * bsc#1277713 * bsc#1279893 * bsc#1280050 * bsc#1280051 * bsc#1280052 * bsc#1280053 * bsc#1280054 Cross-References: * CVE-2026-86145 * CVE-2026-89156 * CVE-2026-89157 * CVE-2026-89158 * CVE-2026-89160 * CVE-2026-89161 CVSS scores: * CVE-2026-86145 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-86145 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-86145 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-89156 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-89156 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-89156 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-89156 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-89157 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-89157 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-89157 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-89157 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-89158 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-89158 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-89158 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-89158 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-89160 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-89160 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-89160 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-89160 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-89161 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-89161 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-89161 ( NVD ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-89161 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities and has six security fixes can now be installed. ## Description: This update for pcre2 fixes the following issues: * CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). * CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). * CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). * CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). * CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). * CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4241 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4241 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4241 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4241 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libpcre2-8-0-10.42-150600.3.3.1 * pcre2-debugsource-10.42-150600.3.3.1 * libpcre2-16-0-10.42-150600.3.3.1 * libpcre2-32-0-debuginfo-10.42-150600.3.3.1 * libpcre2-posix3-10.42-150600.3.3.1 * libpcre2-16-0-debuginfo-10.42-150600.3.3.1 * libpcre2-8-0-debuginfo-10.42-150600.3.3.1 * pcre2-devel-10.42-150600.3.3.1 * pcre2-tools-10.42-150600.3.3.1 * libpcre2-32-0-10.42-150600.3.3.1 * pcre2-tools-debuginfo-10.42-150600.3.3.1 * libpcre2-posix3-debuginfo-10.42-150600.3.3.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libpcre2-8-0-32bit-debuginfo-10.42-150600.3.3.1 * libpcre2-8-0-32bit-10.42-150600.3.3.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libpcre2-8-0-10.42-150600.3.3.1 * pcre2-devel-static-10.42-150600.3.3.1 * pcre2-debugsource-10.42-150600.3.3.1 * libpcre2-16-0-10.42-150600.3.3.1 * libpcre2-32-0-debuginfo-10.42-150600.3.3.1 * libpcre2-posix3-10.42-150600.3.3.1 * libpcre2-16-0-debuginfo-10.42-150600.3.3.1 * libpcre2-8-0-debuginfo-10.42-150600.3.3.1 * pcre2-devel-10.42-150600.3.3.1 * pcre2-tools-10.42-150600.3.3.1 * libpcre2-32-0-10.42-150600.3.3.1 * pcre2-tools-debuginfo-10.42-150600.3.3.1 * libpcre2-posix3-debuginfo-10.42-150600.3.3.1 * openSUSE Leap 15.6 (x86_64) * libpcre2-16-0-32bit-10.42-150600.3.3.1 * libpcre2-16-0-32bit-debuginfo-10.42-150600.3.3.1 * libpcre2-32-0-32bit-10.42-150600.3.3.1 * libpcre2-posix3-32bit-10.42-150600.3.3.1 * libpcre2-posix3-32bit-debuginfo-10.42-150600.3.3.1 * libpcre2-8-0-32bit-debuginfo-10.42-150600.3.3.1 * libpcre2-32-0-32bit-debuginfo-10.42-150600.3.3.1 * libpcre2-8-0-32bit-10.42-150600.3.3.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libpcre2-32-0-64bit-debuginfo-10.42-150600.3.3.1 * libpcre2-8-0-64bit-debuginfo-10.42-150600.3.3.1 * libpcre2-8-0-64bit-10.42-150600.3.3.1 * libpcre2-posix3-64bit-10.42-150600.3.3.1 * libpcre2-16-0-64bit-debuginfo-10.42-150600.3.3.1 * libpcre2-posix3-64bit-debuginfo-10.42-150600.3.3.1 * libpcre2-32-0-64bit-10.42-150600.3.3.1 * libpcre2-16-0-64bit-10.42-150600.3.3.1 * openSUSE Leap 15.6 (noarch) * pcre2-doc-10.42-150600.3.3.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libpcre2-8-0-10.42-150600.3.3.1 * pcre2-debugsource-10.42-150600.3.3.1 * libpcre2-16-0-10.42-150600.3.3.1 * libpcre2-32-0-debuginfo-10.42-150600.3.3.1 * libpcre2-posix3-10.42-150600.3.3.1 * libpcre2-16-0-debuginfo-10.42-150600.3.3.1 * libpcre2-8-0-debuginfo-10.42-150600.3.3.1 * pcre2-devel-10.42-150600.3.3.1 * pcre2-tools-10.42-150600.3.3.1 * libpcre2-32-0-10.42-150600.3.3.1 * pcre2-tools-debuginfo-10.42-150600.3.3.1 * libpcre2-posix3-debuginfo-10.42-150600.3.3.1 * Basesystem Module 15-SP7 (x86_64) * libpcre2-8-0-32bit-debuginfo-10.42-150600.3.3.1 * libpcre2-8-0-32bit-10.42-150600.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libpcre2-8-0-10.42-150600.3.3.1 * pcre2-debugsource-10.42-150600.3.3.1 * libpcre2-16-0-10.42-150600.3.3.1 * libpcre2-32-0-debuginfo-10.42-150600.3.3.1 * libpcre2-posix3-10.42-150600.3.3.1 * libpcre2-16-0-debuginfo-10.42-150600.3.3.1 * libpcre2-8-0-debuginfo-10.42-150600.3.3.1 * pcre2-devel-10.42-150600.3.3.1 * pcre2-tools-10.42-150600.3.3.1 * libpcre2-32-0-10.42-150600.3.3.1 * pcre2-tools-debuginfo-10.42-150600.3.3.1 * libpcre2-posix3-debuginfo-10.42-150600.3.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libpcre2-8-0-32bit-debuginfo-10.42-150600.3.3.1 * libpcre2-8-0-32bit-10.42-150600.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-86145.html * https://www.suse.com/security/cve/CVE-2026-89156.html * https://www.suse.com/security/cve/CVE-2026-89157.html * https://www.suse.com/security/cve/CVE-2026-89158.html * https://www.suse.com/security/cve/CVE-2026-89160.html * https://www.suse.com/security/cve/CVE-2026-89161.html * https://bugzilla.suse.com/show_bug.cgi?id=1277707 * https://bugzilla.suse.com/show_bug.cgi?id=1277708 * https://bugzilla.suse.com/show_bug.cgi?id=1277709 * https://bugzilla.suse.com/show_bug.cgi?id=1277710 * https://bugzilla.suse.com/show_bug.cgi?id=1277711 * https://bugzilla.suse.com/show_bug.cgi?id=1277713 * https://bugzilla.suse.com/show_bug.cgi?id=1279893 * https://bugzilla.suse.com/show_bug.cgi?id=1280050 * https://bugzilla.suse.com/show_bug.cgi?id=1280051 * https://bugzilla.suse.com/show_bug.cgi?id=1280052 * https://bugzilla.suse.com/show_bug.cgi?id=1280053 * https://bugzilla.suse.com/show_bug.cgi?id=1280054 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 16:33:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 16:33:33 -0000 Subject: SUSE-SU-2026:4240-1: important: Security update for gvfs Message-ID: <178966281372.23775.17553524065125280006@200ee98c8b1d> # Security update for gvfs Announcement ID: SUSE-SU-2026:4240-1 Release Date: 2026-09-17T11:48:40Z Rating: important References: * bsc#1278156 * bsc#1278157 * bsc#1278158 * bsc#1278159 Cross-References: * CVE-2026-84267 * CVE-2026-84268 * CVE-2026-84269 * CVE-2026-84270 CVSS scores: * CVE-2026-84267 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-84267 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-84267 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-84268 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-84268 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84268 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84269 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84269 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-84269 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-84270 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-84270 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84270 ( NVD ): 4.3 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for gvfs fixes the following issues: * CVE-2026-84267: `read_string()` allocates buffers withouth verifying that the buffer is completely filled when communicating with a malicious SFTP server, which can lead to uninitialized heap memory leaks (bsc#1278157). * CVE-2026-84268: `read_reply()` processes length that exceeds requested client size when communicating with a malicious SFTP server, which can lead to an OOB write (bsc#1278158). * CVE-2026-84269: DSI read path processes length that exceeds requested client size when communicating with a malicious AFP server, which can lead to an OOB memory access (bsc#1278159). * CVE-2026-84270: `do_read()` trusts the data length returned by a mounted MTP device and does not limit it to the original size requested by the client, which can lead to an OOB write (bsc#1278156). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4240 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4240 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4240 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4240 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * gvfs-1.52.2-150600.3.9.1 * gvfs-backend-afc-debuginfo-1.52.2-150600.3.9.1 * gvfs-backends-debuginfo-1.52.2-150600.3.9.1 * gvfs-backend-samba-1.52.2-150600.3.9.1 * gvfs-debuginfo-1.52.2-150600.3.9.1 * gvfs-debugsource-1.52.2-150600.3.9.1 * gvfs-backend-samba-debuginfo-1.52.2-150600.3.9.1 * gvfs-backend-afc-1.52.2-150600.3.9.1 * gvfs-fuse-debuginfo-1.52.2-150600.3.9.1 * gvfs-backends-1.52.2-150600.3.9.1 * gvfs-fuse-1.52.2-150600.3.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * gvfs-lang-1.52.2-150600.3.9.1 * gvfs-devel-1.52.2-150600.3.9.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * gvfs-1.52.2-150600.3.9.1 * gvfs-backend-afc-debuginfo-1.52.2-150600.3.9.1 * gvfs-backends-debuginfo-1.52.2-150600.3.9.1 * gvfs-backend-samba-1.52.2-150600.3.9.1 * gvfs-debuginfo-1.52.2-150600.3.9.1 * gvfs-debugsource-1.52.2-150600.3.9.1 * gvfs-backend-samba-debuginfo-1.52.2-150600.3.9.1 * gvfs-backend-afc-1.52.2-150600.3.9.1 * gvfs-fuse-debuginfo-1.52.2-150600.3.9.1 * gvfs-backend-goa-1.52.2-150600.3.9.1 * gvfs-backends-1.52.2-150600.3.9.1 * gvfs-backend-goa-debuginfo-1.52.2-150600.3.9.1 * gvfs-fuse-1.52.2-150600.3.9.1 * openSUSE Leap 15.6 (x86_64) * gvfs-32bit-1.52.2-150600.3.9.1 * gvfs-32bit-debuginfo-1.52.2-150600.3.9.1 * openSUSE Leap 15.6 (aarch64_ilp32) * gvfs-64bit-debuginfo-1.52.2-150600.3.9.1 * gvfs-64bit-1.52.2-150600.3.9.1 * openSUSE Leap 15.6 (noarch) * gvfs-lang-1.52.2-150600.3.9.1 * gvfs-devel-1.52.2-150600.3.9.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * gvfs-1.52.2-150600.3.9.1 * gvfs-backend-afc-debuginfo-1.52.2-150600.3.9.1 * gvfs-backends-debuginfo-1.52.2-150600.3.9.1 * gvfs-backend-samba-1.52.2-150600.3.9.1 * gvfs-debuginfo-1.52.2-150600.3.9.1 * gvfs-debugsource-1.52.2-150600.3.9.1 * gvfs-backend-samba-debuginfo-1.52.2-150600.3.9.1 * gvfs-backend-afc-1.52.2-150600.3.9.1 * gvfs-fuse-debuginfo-1.52.2-150600.3.9.1 * gvfs-backends-1.52.2-150600.3.9.1 * gvfs-fuse-1.52.2-150600.3.9.1 * Desktop Applications Module 15-SP7 (noarch) * gvfs-lang-1.52.2-150600.3.9.1 * gvfs-devel-1.52.2-150600.3.9.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * gvfs-1.52.2-150600.3.9.1 * gvfs-backend-afc-debuginfo-1.52.2-150600.3.9.1 * gvfs-backends-debuginfo-1.52.2-150600.3.9.1 * gvfs-backend-samba-1.52.2-150600.3.9.1 * gvfs-debuginfo-1.52.2-150600.3.9.1 * gvfs-debugsource-1.52.2-150600.3.9.1 * gvfs-backend-samba-debuginfo-1.52.2-150600.3.9.1 * gvfs-backend-afc-1.52.2-150600.3.9.1 * gvfs-fuse-debuginfo-1.52.2-150600.3.9.1 * gvfs-backends-1.52.2-150600.3.9.1 * gvfs-fuse-1.52.2-150600.3.9.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * gvfs-lang-1.52.2-150600.3.9.1 * gvfs-devel-1.52.2-150600.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-84267.html * https://www.suse.com/security/cve/CVE-2026-84268.html * https://www.suse.com/security/cve/CVE-2026-84269.html * https://www.suse.com/security/cve/CVE-2026-84270.html * https://bugzilla.suse.com/show_bug.cgi?id=1278156 * https://bugzilla.suse.com/show_bug.cgi?id=1278157 * https://bugzilla.suse.com/show_bug.cgi?id=1278158 * https://bugzilla.suse.com/show_bug.cgi?id=1278159 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 16:34:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 16:34:37 -0000 Subject: SUSE-SU-2026:4239-1: important: Security update for libpcap Message-ID: <178966287779.23775.6380927850386938873@200ee98c8b1d> # Security update for libpcap Announcement ID: SUSE-SU-2026:4239-1 Release Date: 2026-09-17T11:48:13Z Rating: important References: * bsc#1279584 * bsc#1279588 * bsc#1279593 * bsc#1279595 * bsc#1279782 * bsc#1279783 Cross-References: * CVE-2026-0799 * CVE-2026-18238 * CVE-2026-31911 * CVE-2026-31912 * CVE-2026-6244 * CVE-2026-6554 CVSS scores: * CVE-2026-0799 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-0799 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-0799 ( NVD ): 8.7 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H * CVE-2026-18238 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-18238 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-18238 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N * CVE-2026-31911 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31911 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31911 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31912 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6244 ( SUSE ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6244 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6554 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-6554 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6554 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves six vulnerabilities can now be installed. ## Description: This update for libpcap fixes the following issues: * CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a scratch memory register and allows for OOB access (bsc#1279782). * CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero (bsc#1279595). * CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584). * CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly validates its headers and allows for an OOB access (bsc#1279783). * CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588). * CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff (bsc#1279593). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4239 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4239 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libpcap1-1.8.1-10.12.1 * libpcap1-debuginfo-1.8.1-10.12.1 * libpcap-debugsource-1.8.1-10.12.1 * libpcap-devel-1.8.1-10.12.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libpcap1-1.8.1-10.12.1 * libpcap1-debuginfo-1.8.1-10.12.1 * libpcap-debugsource-1.8.1-10.12.1 * libpcap-devel-1.8.1-10.12.1 ## References: * https://www.suse.com/security/cve/CVE-2026-0799.html * https://www.suse.com/security/cve/CVE-2026-18238.html * https://www.suse.com/security/cve/CVE-2026-31911.html * https://www.suse.com/security/cve/CVE-2026-31912.html * https://www.suse.com/security/cve/CVE-2026-6244.html * https://www.suse.com/security/cve/CVE-2026-6554.html * https://bugzilla.suse.com/show_bug.cgi?id=1279584 * https://bugzilla.suse.com/show_bug.cgi?id=1279588 * https://bugzilla.suse.com/show_bug.cgi?id=1279593 * https://bugzilla.suse.com/show_bug.cgi?id=1279595 * https://bugzilla.suse.com/show_bug.cgi?id=1279782 * https://bugzilla.suse.com/show_bug.cgi?id=1279783 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 16:35:21 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 16:35:21 -0000 Subject: SUSE-SU-2026:4238-1: important: Security update for gvfs Message-ID: <178966292121.23775.4467807990168999572@200ee98c8b1d> # Security update for gvfs Announcement ID: SUSE-SU-2026:4238-1 Release Date: 2026-09-17T11:48:00Z Rating: important References: * bsc#1278156 * bsc#1278157 * bsc#1278158 * bsc#1278159 Cross-References: * CVE-2026-84267 * CVE-2026-84268 * CVE-2026-84269 * CVE-2026-84270 CVSS scores: * CVE-2026-84267 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-84267 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-84267 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-84268 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-84268 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84268 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84269 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84269 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-84269 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-84270 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-84270 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84270 ( NVD ): 4.3 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves four vulnerabilities can now be installed. ## Description: This update for gvfs fixes the following issues: * CVE-2026-84267: `read_string()` allocates buffers withouth verifying that the buffer is completely filled when communicating with a malicious SFTP server, which can lead to uninitialized heap memory leaks (bsc#1278157). * CVE-2026-84268: `read_reply()` processes length that exceeds requested client size when communicating with a malicious SFTP server, which can lead to an OOB write (bsc#1278158). * CVE-2026-84269: DSI read path processes length that exceeds requested client size when communicating with a malicious AFP server, which can lead to an OOB memory access (bsc#1278159). * CVE-2026-84270: `do_read()` trusts the data length returned by a mounted MTP device and does not limit it to the original size requested by the client, which can lead to an OOB write (bsc#1278156). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4238 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4238 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4238 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4238 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4238 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4238 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4238 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4238 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4238 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * gvfs-devel-1.48.2-150400.4.15.1 * gvfs-backend-afc-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.15.1 * gvfs-1.48.2-150400.4.15.1 * gvfs-backends-debuginfo-1.48.2-150400.4.15.1 * gvfs-debugsource-1.48.2-150400.4.15.1 * gvfs-backend-samba-1.48.2-150400.4.15.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-afc-1.48.2-150400.4.15.1 * gvfs-fuse-1.48.2-150400.4.15.1 * gvfs-backends-1.48.2-150400.4.15.1 * gvfs-debuginfo-1.48.2-150400.4.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * gvfs-lang-1.48.2-150400.4.15.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * gvfs-devel-1.48.2-150400.4.15.1 * gvfs-backend-afc-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.15.1 * gvfs-1.48.2-150400.4.15.1 * gvfs-backends-debuginfo-1.48.2-150400.4.15.1 * gvfs-debugsource-1.48.2-150400.4.15.1 * gvfs-backend-samba-1.48.2-150400.4.15.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-afc-1.48.2-150400.4.15.1 * gvfs-fuse-1.48.2-150400.4.15.1 * gvfs-backends-1.48.2-150400.4.15.1 * gvfs-debuginfo-1.48.2-150400.4.15.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * gvfs-lang-1.48.2-150400.4.15.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * gvfs-devel-1.48.2-150400.4.15.1 * gvfs-backend-afc-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.15.1 * gvfs-1.48.2-150400.4.15.1 * gvfs-backends-debuginfo-1.48.2-150400.4.15.1 * gvfs-debugsource-1.48.2-150400.4.15.1 * gvfs-backend-samba-1.48.2-150400.4.15.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-afc-1.48.2-150400.4.15.1 * gvfs-fuse-1.48.2-150400.4.15.1 * gvfs-backends-1.48.2-150400.4.15.1 * gvfs-debuginfo-1.48.2-150400.4.15.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * gvfs-lang-1.48.2-150400.4.15.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * gvfs-devel-1.48.2-150400.4.15.1 * gvfs-backend-afc-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.15.1 * gvfs-1.48.2-150400.4.15.1 * gvfs-backends-debuginfo-1.48.2-150400.4.15.1 * gvfs-debugsource-1.48.2-150400.4.15.1 * gvfs-backend-samba-1.48.2-150400.4.15.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-afc-1.48.2-150400.4.15.1 * gvfs-fuse-1.48.2-150400.4.15.1 * gvfs-backends-1.48.2-150400.4.15.1 * gvfs-debuginfo-1.48.2-150400.4.15.1 * openSUSE Leap 15.4 (x86_64) * gvfs-32bit-1.48.2-150400.4.15.1 * gvfs-32bit-debuginfo-1.48.2-150400.4.15.1 * openSUSE Leap 15.4 (aarch64_ilp32) * gvfs-64bit-1.48.2-150400.4.15.1 * gvfs-64bit-debuginfo-1.48.2-150400.4.15.1 * openSUSE Leap 15.4 (noarch) * gvfs-lang-1.48.2-150400.4.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * gvfs-devel-1.48.2-150400.4.15.1 * gvfs-backend-afc-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.15.1 * gvfs-1.48.2-150400.4.15.1 * gvfs-backends-debuginfo-1.48.2-150400.4.15.1 * gvfs-debugsource-1.48.2-150400.4.15.1 * gvfs-backend-samba-1.48.2-150400.4.15.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-afc-1.48.2-150400.4.15.1 * gvfs-fuse-1.48.2-150400.4.15.1 * gvfs-backends-1.48.2-150400.4.15.1 * gvfs-debuginfo-1.48.2-150400.4.15.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * gvfs-lang-1.48.2-150400.4.15.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * gvfs-devel-1.48.2-150400.4.15.1 * gvfs-backend-afc-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.15.1 * gvfs-1.48.2-150400.4.15.1 * gvfs-backends-debuginfo-1.48.2-150400.4.15.1 * gvfs-debugsource-1.48.2-150400.4.15.1 * gvfs-backend-samba-1.48.2-150400.4.15.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-afc-1.48.2-150400.4.15.1 * gvfs-fuse-1.48.2-150400.4.15.1 * gvfs-backends-1.48.2-150400.4.15.1 * gvfs-debuginfo-1.48.2-150400.4.15.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * gvfs-lang-1.48.2-150400.4.15.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * gvfs-devel-1.48.2-150400.4.15.1 * gvfs-backend-afc-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.15.1 * gvfs-1.48.2-150400.4.15.1 * gvfs-backends-debuginfo-1.48.2-150400.4.15.1 * gvfs-debugsource-1.48.2-150400.4.15.1 * gvfs-backend-samba-1.48.2-150400.4.15.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-afc-1.48.2-150400.4.15.1 * gvfs-fuse-1.48.2-150400.4.15.1 * gvfs-backends-1.48.2-150400.4.15.1 * gvfs-debuginfo-1.48.2-150400.4.15.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * gvfs-lang-1.48.2-150400.4.15.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * gvfs-devel-1.48.2-150400.4.15.1 * gvfs-backend-afc-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.15.1 * gvfs-1.48.2-150400.4.15.1 * gvfs-backends-debuginfo-1.48.2-150400.4.15.1 * gvfs-debugsource-1.48.2-150400.4.15.1 * gvfs-backend-samba-1.48.2-150400.4.15.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-afc-1.48.2-150400.4.15.1 * gvfs-fuse-1.48.2-150400.4.15.1 * gvfs-backends-1.48.2-150400.4.15.1 * gvfs-debuginfo-1.48.2-150400.4.15.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * gvfs-lang-1.48.2-150400.4.15.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gvfs-devel-1.48.2-150400.4.15.1 * gvfs-backend-afc-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-samba-debuginfo-1.48.2-150400.4.15.1 * gvfs-1.48.2-150400.4.15.1 * gvfs-backends-debuginfo-1.48.2-150400.4.15.1 * gvfs-debugsource-1.48.2-150400.4.15.1 * gvfs-backend-samba-1.48.2-150400.4.15.1 * gvfs-fuse-debuginfo-1.48.2-150400.4.15.1 * gvfs-backend-afc-1.48.2-150400.4.15.1 * gvfs-fuse-1.48.2-150400.4.15.1 * gvfs-backends-1.48.2-150400.4.15.1 * gvfs-debuginfo-1.48.2-150400.4.15.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * gvfs-lang-1.48.2-150400.4.15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-84267.html * https://www.suse.com/security/cve/CVE-2026-84268.html * https://www.suse.com/security/cve/CVE-2026-84269.html * https://www.suse.com/security/cve/CVE-2026-84270.html * https://bugzilla.suse.com/show_bug.cgi?id=1278156 * https://bugzilla.suse.com/show_bug.cgi?id=1278157 * https://bugzilla.suse.com/show_bug.cgi?id=1278158 * https://bugzilla.suse.com/show_bug.cgi?id=1278159 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 16:36:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 16:36:18 -0000 Subject: SUSE-SU-2026:4237-1: important: Security update for cjose Message-ID: <178966297817.23775.18012911429376305809@200ee98c8b1d> # Security update for cjose Announcement ID: SUSE-SU-2026:4237-1 Release Date: 2026-09-17T11:47:18Z Rating: important References: * bsc#1279844 * bsc#1279846 Cross-References: * CVE-2026-53938 * CVE-2026-53939 CVSS scores: * CVE-2026-53938 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53938 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53938 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53939 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53939 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53939 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for cjose fixes the following issues: * CVE-2026-53938: missing encrypted_key length validation during AES Key Wrap decryption can cause heap-based buffer overflow (bsc#1279844). * CVE-2026-53939: zero-filled content-encryption key generation in AES-CBC- HMAC JWE encryption within cjose can allow unauthorized content modification (bsc#1279846). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4237 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4237 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libcjose0-0.6.1-7.8.1 * libcjose0-debuginfo-0.6.1-7.8.1 * cjose-debugsource-0.6.1-7.8.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libcjose0-0.6.1-7.8.1 * libcjose0-debuginfo-0.6.1-7.8.1 * cjose-debugsource-0.6.1-7.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53938.html * https://www.suse.com/security/cve/CVE-2026-53939.html * https://bugzilla.suse.com/show_bug.cgi?id=1279844 * https://bugzilla.suse.com/show_bug.cgi?id=1279846 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 20:45:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 20:45:10 -0000 Subject: SUSE-SU-2026:4254-1: important: Security update for the Linux Kernel Message-ID: <178967791023.5437.7122469029268168988@55cee2c216ba> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:4254-1 Release Date: 2026-09-17T16:03:41Z Rating: important References: * bsc#1230238 * bsc#1235944 * bsc#1236344 * bsc#1240957 * bsc#1241363 * bsc#1247180 * bsc#1247455 * bsc#1249104 * bsc#1250748 * bsc#1251130 * bsc#1251966 * bsc#1252682 * bsc#1253454 * bsc#1254306 * bsc#1255225 * bsc#1255250 * bsc#1256629 * bsc#1256708 * bsc#1257154 * bsc#1258430 * bsc#1258472 * bsc#1258517 * bsc#1260522 * bsc#1261562 * bsc#1261780 * bsc#1262073 * bsc#1263004 * bsc#1263052 * bsc#1263061 * bsc#1263133 * bsc#1263864 * bsc#1264010 * bsc#1264012 * bsc#1264335 * bsc#1264446 * bsc#1264541 * bsc#1264587 * bsc#1264619 * bsc#1264643 * bsc#1264740 * bsc#1264807 * bsc#1265068 * bsc#1265121 * bsc#1265220 * bsc#1265449 * bsc#1265928 * bsc#1266402 * bsc#1266860 * bsc#1266874 * bsc#1266897 * bsc#1267023 * bsc#1267236 * bsc#1267238 * bsc#1267501 * bsc#1267505 * bsc#1267612 * bsc#1268276 * bsc#1268972 * bsc#1268979 * bsc#1268987 * bsc#1269004 * bsc#1269013 * bsc#1269108 * bsc#1269113 * bsc#1269114 * bsc#1269126 * bsc#1269140 * bsc#1269167 * bsc#1269234 * bsc#1269238 * bsc#1269242 * bsc#1269256 * bsc#1269301 * bsc#1269306 * bsc#1269313 * bsc#1269381 * bsc#1269388 * bsc#1269402 * bsc#1269412 * bsc#1269530 * bsc#1269579 * bsc#1269590 * bsc#1269635 * bsc#1269647 * bsc#1269655 * bsc#1269665 * bsc#1269686 * bsc#1269695 * bsc#1269713 * bsc#1269731 * bsc#1269774 * bsc#1269783 * bsc#1269792 * bsc#1269815 * bsc#1269888 * bsc#1269965 * bsc#1269969 * bsc#1269981 * bsc#1269985 * bsc#1270090 * bsc#1270108 * bsc#1270111 * bsc#1270251 * bsc#1270263 * bsc#1270268 * bsc#1271256 * bsc#1271365 * bsc#1271366 * bsc#1271825 * bsc#1271830 * bsc#1272150 * bsc#1272175 * bsc#1272179 * bsc#1272182 * bsc#1272200 * bsc#1272210 * bsc#1272213 * bsc#1272230 * bsc#1272260 * bsc#1272261 * bsc#1272262 * bsc#1272297 * bsc#1272346 * bsc#1272351 * bsc#1272359 * bsc#1272381 * bsc#1272383 * bsc#1272385 * bsc#1272390 * bsc#1272423 * bsc#1272429 * bsc#1272484 * bsc#1272486 * bsc#1272497 * bsc#1272502 * bsc#1272516 * bsc#1272569 * bsc#1272571 * bsc#1272618 * bsc#1272641 * bsc#1272643 * bsc#1272662 * bsc#1272673 * bsc#1272680 * bsc#1272682 * bsc#1272756 * bsc#1272786 * bsc#1272788 * bsc#1272798 * bsc#1272799 * bsc#1272804 * bsc#1272868 * bsc#1272877 * bsc#1272891 * bsc#1272893 * bsc#1272963 * bsc#1272983 * bsc#1272993 * bsc#1273005 * bsc#1273008 * bsc#1273019 * bsc#1273027 * bsc#1273028 * bsc#1273030 * bsc#1273032 * bsc#1273033 * bsc#1273036 * bsc#1273037 * bsc#1273038 * bsc#1273053 * bsc#1273054 * bsc#1273060 * bsc#1273105 * bsc#1273134 * bsc#1273249 * bsc#1273250 * bsc#1273260 * bsc#1273273 * bsc#1273274 * bsc#1273276 * bsc#1273277 * bsc#1273280 * bsc#1273281 * bsc#1273284 * bsc#1273285 * bsc#1273289 * bsc#1273291 * bsc#1273294 * bsc#1273302 * bsc#1273303 * bsc#1273305 * bsc#1273310 * bsc#1273311 * bsc#1273316 * bsc#1273318 * bsc#1273319 * bsc#1273323 * bsc#1273325 * bsc#1273327 * bsc#1273334 * bsc#1273335 * bsc#1273336 * bsc#1273337 * bsc#1273338 * bsc#1273340 * bsc#1273341 * bsc#1273346 * bsc#1273422 * bsc#1273426 * bsc#1273443 * bsc#1273460 * bsc#1273463 * bsc#1273465 * bsc#1273468 * bsc#1273469 * bsc#1273471 * bsc#1273479 * bsc#1273480 * bsc#1273482 * bsc#1273484 * bsc#1273488 * bsc#1273490 * bsc#1273501 * bsc#1273503 * bsc#1273504 * bsc#1273506 * bsc#1273523 * bsc#1273525 * bsc#1273533 * bsc#1273536 * bsc#1273542 * bsc#1273555 * bsc#1273578 * bsc#1273579 * bsc#1273581 * bsc#1273582 * bsc#1273596 * bsc#1273597 * bsc#1273598 * bsc#1273600 * bsc#1273601 * bsc#1273602 * bsc#1273603 * bsc#1273679 * bsc#1273681 * bsc#1273682 * bsc#1273734 * bsc#1273738 * bsc#1273739 * bsc#1273741 * bsc#1273742 * bsc#1273743 * bsc#1273745 * bsc#1273748 * bsc#1273749 * bsc#1273755 * bsc#1273762 * bsc#1273765 * bsc#1273766 * bsc#1273769 * bsc#1273774 * bsc#1273778 * bsc#1273780 * bsc#1273790 * bsc#1273796 * bsc#1273797 * bsc#1273801 * bsc#1273804 * bsc#1273810 * bsc#1273811 * bsc#1273812 * bsc#1273813 * bsc#1273817 * bsc#1273822 * bsc#1273824 * bsc#1273831 * bsc#1273832 * bsc#1273834 * bsc#1273838 * bsc#1273844 * bsc#1273849 * bsc#1273859 * bsc#1273860 * bsc#1273862 * bsc#1273867 * bsc#1273868 * bsc#1273869 * bsc#1273872 * bsc#1273876 * bsc#1273877 * bsc#1273880 * bsc#1273882 * bsc#1273890 * bsc#1273891 * bsc#1273892 * bsc#1273895 * bsc#1273896 * bsc#1273903 * bsc#1273905 * bsc#1273930 * bsc#1273933 * bsc#1273934 * bsc#1273935 * bsc#1273936 * bsc#1273939 * bsc#1273940 * bsc#1273941 * bsc#1273942 * bsc#1273944 * bsc#1273945 * bsc#1273946 * bsc#1273956 * bsc#1273957 * bsc#1273958 * bsc#1273966 * bsc#1273967 * bsc#1273968 * bsc#1273972 * bsc#1273974 * bsc#1273975 * bsc#1273977 * bsc#1273982 * bsc#1273988 * bsc#1273990 * bsc#1273991 * bsc#1273995 * bsc#1274001 * bsc#1274003 * bsc#1274006 * bsc#1274008 * bsc#1274009 * bsc#1274010 * bsc#1274011 * bsc#1274012 * bsc#1274014 * bsc#1274017 * bsc#1274019 * bsc#1274020 * bsc#1274026 * bsc#1274028 * bsc#1274030 * bsc#1274031 * bsc#1274035 * bsc#1274040 * bsc#1274041 * bsc#1274055 * bsc#1274057 * bsc#1274058 * bsc#1274061 * bsc#1274063 * bsc#1274065 * bsc#1274067 * bsc#1274071 * bsc#1274075 * bsc#1274076 * bsc#1274077 * bsc#1274078 * bsc#1274208 * bsc#1274226 * bsc#1274239 * bsc#1274243 * bsc#1274258 * bsc#1274264 * bsc#1274265 * bsc#1274267 * bsc#1274274 * bsc#1274277 * bsc#1274278 * bsc#1274281 * bsc#1274283 * bsc#1274286 * bsc#1274290 * bsc#1274294 * bsc#1274295 * bsc#1274296 * bsc#1274297 * bsc#1274298 * bsc#1274314 * bsc#1274321 * bsc#1274491 * bsc#1274497 * bsc#1274539 * bsc#1274541 * bsc#1274543 * bsc#1274545 * bsc#1274547 * bsc#1274550 * bsc#1274573 * bsc#1274578 * bsc#1274580 * bsc#1274581 * bsc#1274620 * bsc#1274622 * bsc#1274624 * bsc#1274629 * bsc#1274632 * bsc#1274636 * bsc#1274639 * bsc#1274640 * bsc#1274642 * bsc#1274644 * bsc#1274645 * bsc#1274646 * bsc#1274649 * bsc#1274650 * bsc#1274651 * bsc#1274656 * bsc#1274659 * bsc#1274662 * bsc#1274663 * bsc#1274665 * bsc#1274667 * bsc#1274670 * bsc#1274675 * bsc#1274677 * bsc#1274678 * bsc#1274679 * bsc#1274681 * bsc#1274682 * bsc#1274690 * bsc#1274694 * bsc#1274696 * bsc#1274698 * bsc#1274699 * bsc#1274700 * bsc#1274702 * bsc#1274703 * bsc#1274705 * bsc#1274706 * bsc#1274709 * bsc#1274710 * bsc#1274713 * bsc#1274716 * bsc#1274721 * bsc#1274725 * bsc#1274737 * bsc#1274738 * bsc#1274749 * bsc#1274752 * bsc#1274753 * bsc#1274754 * bsc#1274755 * bsc#1274756 * bsc#1274764 * bsc#1274768 * bsc#1274770 * bsc#1274783 * bsc#1274787 * bsc#1274800 * bsc#1274801 * bsc#1274802 * bsc#1274804 * bsc#1274805 * bsc#1274807 * bsc#1274808 * bsc#1274811 * bsc#1274813 * bsc#1274814 * bsc#1274831 * bsc#1274834 * bsc#1274835 * bsc#1274847 * bsc#1274849 * bsc#1274853 * bsc#1274868 * bsc#1274869 * bsc#1274872 * bsc#1274873 * bsc#1274874 * bsc#1274876 * bsc#1274877 * bsc#1274879 * bsc#1274881 * bsc#1274883 * bsc#1274886 * bsc#1274888 * bsc#1274891 * bsc#1274892 * bsc#1274893 * bsc#1274894 * bsc#1274895 * bsc#1274896 * bsc#1274897 * bsc#1274898 * bsc#1274899 * bsc#1274901 * bsc#1274902 * bsc#1274905 * bsc#1274906 * bsc#1274907 * bsc#1274908 * bsc#1274913 * bsc#1274914 * bsc#1274920 * bsc#1274921 * bsc#1274924 * bsc#1274925 * bsc#1274929 * bsc#1274930 * bsc#1274933 * bsc#1274934 * bsc#1274935 * bsc#1274941 * bsc#1274945 * bsc#1274947 * bsc#1274951 * bsc#1274953 * bsc#1274958 * bsc#1274968 * bsc#1274981 * bsc#1275040 * bsc#1275069 * bsc#1275071 * bsc#1275073 * bsc#1275076 * bsc#1275080 * bsc#1275081 * bsc#1275083 * bsc#1275088 * bsc#1275091 * bsc#1275125 * bsc#1275126 * bsc#1275131 * bsc#1275132 * bsc#1275139 * bsc#1275141 * bsc#1275146 * bsc#1275148 * bsc#1275149 * bsc#1275150 * bsc#1275152 * bsc#1275154 * bsc#1275155 * bsc#1275156 * bsc#1275157 * bsc#1275158 * bsc#1275161 * bsc#1275163 * bsc#1275164 * bsc#1275169 * bsc#1275173 * bsc#1275176 * bsc#1275185 * bsc#1275190 * bsc#1275192 * bsc#1275236 * bsc#1275237 * bsc#1275239 * bsc#1275294 * bsc#1275300 * bsc#1275301 * bsc#1275303 * bsc#1275304 * bsc#1275305 * bsc#1275306 * bsc#1275307 * bsc#1275470 * bsc#1275472 * bsc#1275474 * bsc#1275479 * bsc#1275483 * bsc#1275486 * bsc#1275487 * bsc#1275506 * bsc#1275509 * bsc#1275511 * bsc#1275517 * bsc#1275519 * bsc#1275528 * bsc#1275535 * bsc#1275540 * bsc#1275553 * bsc#1275555 * bsc#1275557 * bsc#1275561 * bsc#1275566 * bsc#1275569 * bsc#1275572 * bsc#1275574 * bsc#1275578 * bsc#1275582 * bsc#1275583 * bsc#1275584 * bsc#1275591 * bsc#1275595 * bsc#1275633 * bsc#1275636 * bsc#1275650 * bsc#1275656 * bsc#1275659 * bsc#1275665 * bsc#1275669 * bsc#1275687 * bsc#1275688 * bsc#1275695 * bsc#1275696 * bsc#1275704 * bsc#1275737 * bsc#1275782 * bsc#1275784 * bsc#1275787 * bsc#1275788 * bsc#1275789 * bsc#1275790 * bsc#1275797 * bsc#1275798 * bsc#1275805 * bsc#1275817 * bsc#1275818 * bsc#1275819 * bsc#1275820 * bsc#1275821 * bsc#1275822 * bsc#1275823 * bsc#1275827 * bsc#1275864 * bsc#1275867 * bsc#1275869 * bsc#1275870 * bsc#1275871 * bsc#1275872 * bsc#1275886 * bsc#1275905 * bsc#1275923 * bsc#1275925 * bsc#1275928 * bsc#1275946 * bsc#1275950 * bsc#1275954 * bsc#1275970 * bsc#1275973 * bsc#1275975 * bsc#1275976 * bsc#1276029 * bsc#1276257 * bsc#1276263 * bsc#1276270 * bsc#1276273 * bsc#1276277 * bsc#1276335 * bsc#1276346 * bsc#1276350 * bsc#1276355 * bsc#1276446 * bsc#1276452 * bsc#1276500 * bsc#1276507 * bsc#1276542 * bsc#1276546 * bsc#1276551 * bsc#1276552 * bsc#1276561 * bsc#1276569 * bsc#1276577 * bsc#1276665 * bsc#1276864 * bsc#1276912 * bsc#1276913 * bsc#1276927 * bsc#1276931 * bsc#1276937 * bsc#1276941 * bsc#1276943 * bsc#1276944 * bsc#1276955 * bsc#1276961 * bsc#1277022 * bsc#1277034 * bsc#1277037 * bsc#1277047 * bsc#1277054 * bsc#1277057 * bsc#1277059 * bsc#1277064 * bsc#1277066 * bsc#1277069 * bsc#1277073 * bsc#1277077 * bsc#1277095 * bsc#1277155 * bsc#1277159 * bsc#1277160 * bsc#1277202 * bsc#1277204 * bsc#1277275 * bsc#1277285 * bsc#1277391 * bsc#1277408 * bsc#1277516 * bsc#1277523 * bsc#1277551 * bsc#1277625 * bsc#1277660 * bsc#1277678 * bsc#1277688 * bsc#1277775 * bsc#1277776 * jsc#PED-15880 * jsc#PED-16798 Cross-References: * CVE-2024-44981 * CVE-2024-57841 * CVE-2025-23137 * CVE-2025-38469 * CVE-2025-39939 * CVE-2025-39964 * CVE-2025-40022 * CVE-2025-40199 * CVE-2025-68179 * CVE-2025-68214 * CVE-2025-71075 * CVE-2025-71104 * CVE-2026-23210 * CVE-2026-23227 * CVE-2026-23230 * CVE-2026-23454 * CVE-2026-31418 * CVE-2026-31531 * CVE-2026-31557 * CVE-2026-31658 * CVE-2026-31663 * CVE-2026-43014 * CVE-2026-43015 * CVE-2026-43116 * CVE-2026-43125 * CVE-2026-43163 * CVE-2026-43213 * CVE-2026-43271 * CVE-2026-43273 * CVE-2026-43363 * CVE-2026-43386 * CVE-2026-43416 * CVE-2026-43448 * CVE-2026-45897 * CVE-2026-45968 * CVE-2026-46070 * CVE-2026-46078 * CVE-2026-46091 * CVE-2026-46107 * CVE-2026-46115 * CVE-2026-46127 * CVE-2026-46195 * CVE-2026-52920 * CVE-2026-52925 * CVE-2026-52929 * CVE-2026-52935 * CVE-2026-52939 * CVE-2026-52946 * CVE-2026-52975 * CVE-2026-52977 * CVE-2026-52990 * CVE-2026-52994 * CVE-2026-53001 * CVE-2026-53033 * CVE-2026-53034 * CVE-2026-53059 * CVE-2026-53076 * CVE-2026-53077 * CVE-2026-53089 * CVE-2026-53091 * CVE-2026-53094 * CVE-2026-53096 * CVE-2026-53110 * CVE-2026-53111 * CVE-2026-53126 * CVE-2026-53142 * CVE-2026-53154 * CVE-2026-53163 * CVE-2026-53180 * CVE-2026-53207 * CVE-2026-53219 * CVE-2026-53220 * CVE-2026-53223 * CVE-2026-53228 * CVE-2026-53238 * CVE-2026-53260 * CVE-2026-53263 * CVE-2026-53264 * CVE-2026-53269 * CVE-2026-53273 * CVE-2026-53309 * CVE-2026-53330 * CVE-2026-53336 * CVE-2026-53337 * CVE-2026-53353 * CVE-2026-53365 * CVE-2026-53366 * CVE-2026-53381 * CVE-2026-53388 * CVE-2026-63801 * CVE-2026-63808 * CVE-2026-63810 * CVE-2026-63823 * CVE-2026-63827 * CVE-2026-63828 * CVE-2026-63842 * CVE-2026-63850 * CVE-2026-63860 * CVE-2026-63865 * CVE-2026-63868 * CVE-2026-63879 * CVE-2026-63881 * CVE-2026-63886 * CVE-2026-63887 * CVE-2026-63888 * CVE-2026-63889 * CVE-2026-63891 * CVE-2026-63898 * CVE-2026-63920 * CVE-2026-63923 * CVE-2026-63925 * CVE-2026-63926 * CVE-2026-63928 * CVE-2026-63937 * CVE-2026-63944 * CVE-2026-63969 * CVE-2026-63970 * CVE-2026-63972 * CVE-2026-63973 * CVE-2026-63980 * CVE-2026-63985 * CVE-2026-63990 * CVE-2026-63992 * CVE-2026-63995 * CVE-2026-63996 * CVE-2026-63997 * CVE-2026-63998 * CVE-2026-63999 * CVE-2026-64000 * CVE-2026-64001 * CVE-2026-64002 * CVE-2026-64004 * CVE-2026-64005 * CVE-2026-64006 * CVE-2026-64007 * CVE-2026-64010 * CVE-2026-64011 * CVE-2026-64014 * CVE-2026-64015 * CVE-2026-64018 * CVE-2026-64021 * CVE-2026-64029 * CVE-2026-64033 * CVE-2026-64034 * CVE-2026-64039 * CVE-2026-64047 * CVE-2026-64048 * CVE-2026-64051 * CVE-2026-64052 * CVE-2026-64055 * CVE-2026-64056 * CVE-2026-64073 * CVE-2026-64083 * CVE-2026-64084 * CVE-2026-64085 * CVE-2026-64086 * CVE-2026-64087 * CVE-2026-64088 * CVE-2026-64097 * CVE-2026-64098 * CVE-2026-64099 * CVE-2026-64102 * CVE-2026-64109 * CVE-2026-64112 * CVE-2026-64113 * CVE-2026-64114 * CVE-2026-64115 * CVE-2026-64118 * CVE-2026-64121 * CVE-2026-64125 * CVE-2026-64126 * CVE-2026-64127 * CVE-2026-64128 * CVE-2026-64131 * CVE-2026-64133 * CVE-2026-64134 * CVE-2026-64135 * CVE-2026-64136 * CVE-2026-64137 * CVE-2026-64144 * CVE-2026-64146 * CVE-2026-64148 * CVE-2026-64155 * CVE-2026-64164 * CVE-2026-64166 * CVE-2026-64168 * CVE-2026-64178 * CVE-2026-64180 * CVE-2026-64185 * CVE-2026-64188 * CVE-2026-64190 * CVE-2026-64192 * CVE-2026-64214 * CVE-2026-64217 * CVE-2026-64218 * CVE-2026-64219 * CVE-2026-64222 * CVE-2026-64224 * CVE-2026-64225 * CVE-2026-64237 * CVE-2026-64243 * CVE-2026-64244 * CVE-2026-64245 * CVE-2026-64246 * CVE-2026-64247 * CVE-2026-64249 * CVE-2026-64257 * CVE-2026-64266 * CVE-2026-64268 * CVE-2026-64269 * CVE-2026-64271 * CVE-2026-64273 * CVE-2026-64274 * CVE-2026-64275 * CVE-2026-64276 * CVE-2026-64277 * CVE-2026-64286 * CVE-2026-64287 * CVE-2026-64294 * CVE-2026-64296 * CVE-2026-64303 * CVE-2026-64304 * CVE-2026-64305 * CVE-2026-64306 * CVE-2026-64312 * CVE-2026-64313 * CVE-2026-64315 * CVE-2026-64316 * CVE-2026-64317 * CVE-2026-64322 * CVE-2026-64323 * CVE-2026-64329 * CVE-2026-64331 * CVE-2026-64332 * CVE-2026-64333 * CVE-2026-64334 * CVE-2026-64335 * CVE-2026-64337 * CVE-2026-64338 * CVE-2026-64340 * CVE-2026-64341 * CVE-2026-64342 * CVE-2026-64343 * CVE-2026-64344 * CVE-2026-64346 * CVE-2026-64348 * CVE-2026-64350 * CVE-2026-64351 * CVE-2026-64355 * CVE-2026-64358 * CVE-2026-64362 * CVE-2026-64365 * CVE-2026-64375 * CVE-2026-64376 * CVE-2026-64378 * CVE-2026-64381 * CVE-2026-64382 * CVE-2026-64383 * CVE-2026-64384 * CVE-2026-64385 * CVE-2026-64386 * CVE-2026-64387 * CVE-2026-64388 * CVE-2026-64401 * CVE-2026-64403 * CVE-2026-64406 * CVE-2026-64407 * CVE-2026-64408 * CVE-2026-64409 * CVE-2026-64411 * CVE-2026-64412 * CVE-2026-64420 * CVE-2026-64421 * CVE-2026-64423 * CVE-2026-64427 * CVE-2026-64429 * CVE-2026-64433 * CVE-2026-64434 * CVE-2026-64436 * CVE-2026-64440 * CVE-2026-64442 * CVE-2026-64443 * CVE-2026-64444 * CVE-2026-64445 * CVE-2026-64448 * CVE-2026-64450 * CVE-2026-64452 * CVE-2026-64454 * CVE-2026-64455 * CVE-2026-64463 * CVE-2026-64470 * CVE-2026-64471 * CVE-2026-64472 * CVE-2026-64477 * CVE-2026-64478 * CVE-2026-64479 * CVE-2026-64480 * CVE-2026-64481 * CVE-2026-64482 * CVE-2026-64483 * CVE-2026-64484 * CVE-2026-64486 * CVE-2026-64487 * CVE-2026-64489 * CVE-2026-64494 * CVE-2026-64495 * CVE-2026-64496 * CVE-2026-64497 * CVE-2026-64500 * CVE-2026-64503 * CVE-2026-64504 * CVE-2026-64505 * CVE-2026-64511 * CVE-2026-64512 * CVE-2026-64513 * CVE-2026-64515 * CVE-2026-64517 * CVE-2026-64524 * CVE-2026-64527 * CVE-2026-64536 * CVE-2026-64537 * CVE-2026-64538 * CVE-2026-64539 * CVE-2026-64540 * CVE-2026-64541 * CVE-2026-64543 * CVE-2026-64544 * CVE-2026-64545 * CVE-2026-64546 * CVE-2026-64547 * CVE-2026-64548 * CVE-2026-64549 * CVE-2026-64551 * CVE-2026-64552 * CVE-2026-64553 * CVE-2026-64554 * CVE-2026-64558 * CVE-2026-64559 * CVE-2026-64562 * CVE-2026-64563 * CVE-2026-64565 * CVE-2026-64567 * CVE-2026-64568 * CVE-2026-64569 * CVE-2026-64570 * CVE-2026-64571 * CVE-2026-64572 * CVE-2026-64573 * CVE-2026-64574 * CVE-2026-64576 * CVE-2026-64577 * CVE-2026-64581 * CVE-2026-64582 * CVE-2026-64583 * CVE-2026-64584 * CVE-2026-64585 * CVE-2026-64593 * CVE-2026-64597 * CVE-2026-64598 * CVE-2026-64599 * CVE-2026-64602 * CVE-2026-64603 * CVE-2026-64604 * CVE-2026-68081 * CVE-2026-68082 * CVE-2026-68085 * CVE-2026-68086 * CVE-2026-68088 * CVE-2026-68091 * CVE-2026-68093 * CVE-2026-68102 * CVE-2026-68104 * CVE-2026-68105 * CVE-2026-68106 * CVE-2026-68107 * CVE-2026-68108 * CVE-2026-68110 * CVE-2026-68111 * CVE-2026-68112 * CVE-2026-68113 * CVE-2026-68115 * CVE-2026-68116 * CVE-2026-68117 * CVE-2026-68121 * CVE-2026-68123 * CVE-2026-68124 * CVE-2026-68125 * CVE-2026-68126 * CVE-2026-68127 * CVE-2026-68129 * CVE-2026-68132 * CVE-2026-68133 * CVE-2026-68135 * CVE-2026-68136 * CVE-2026-68137 * CVE-2026-68138 * CVE-2026-68139 * CVE-2026-68142 * CVE-2026-68143 * CVE-2026-68145 * CVE-2026-68149 * CVE-2026-68152 * CVE-2026-68153 * CVE-2026-68154 * CVE-2026-68155 * CVE-2026-68156 * CVE-2026-68157 * CVE-2026-68158 * CVE-2026-68159 * CVE-2026-68160 * CVE-2026-68161 * CVE-2026-68162 * CVE-2026-68166 * CVE-2026-68180 * CVE-2026-68181 * CVE-2026-68182 * CVE-2026-68184 * CVE-2026-68188 * CVE-2026-68189 * CVE-2026-68192 * CVE-2026-68193 * CVE-2026-68194 * CVE-2026-68195 * CVE-2026-68196 * CVE-2026-68197 * CVE-2026-68199 * CVE-2026-68202 * CVE-2026-68204 * CVE-2026-68205 * CVE-2026-68206 * CVE-2026-68207 * CVE-2026-68209 * CVE-2026-68210 * CVE-2026-68212 * CVE-2026-68213 * CVE-2026-68214 * CVE-2026-68215 * CVE-2026-68216 * CVE-2026-68217 * CVE-2026-68218 * CVE-2026-68219 * CVE-2026-68220 * CVE-2026-68222 * CVE-2026-68223 * CVE-2026-68226 * CVE-2026-68227 * CVE-2026-68229 * CVE-2026-68231 * CVE-2026-68234 * CVE-2026-68235 * CVE-2026-68236 * CVE-2026-68238 * CVE-2026-68243 * CVE-2026-68244 * CVE-2026-68245 * CVE-2026-68246 * CVE-2026-68247 * CVE-2026-68248 * CVE-2026-68249 * CVE-2026-68250 * CVE-2026-68251 * CVE-2026-68252 * CVE-2026-68253 * CVE-2026-68254 * CVE-2026-68255 * CVE-2026-68256 * CVE-2026-68257 * CVE-2026-68259 * CVE-2026-68260 * CVE-2026-68261 * CVE-2026-68262 * CVE-2026-68263 * CVE-2026-68267 * CVE-2026-68269 * CVE-2026-68271 * CVE-2026-68272 * CVE-2026-68277 * CVE-2026-68278 * CVE-2026-68279 * CVE-2026-68280 * CVE-2026-68281 * CVE-2026-68284 * CVE-2026-68286 * CVE-2026-68288 * CVE-2026-68289 * CVE-2026-68293 * CVE-2026-68297 * CVE-2026-68299 * CVE-2026-68300 * CVE-2026-68302 * CVE-2026-68303 * CVE-2026-68304 * CVE-2026-68306 * CVE-2026-68308 * CVE-2026-68309 * CVE-2026-68310 * CVE-2026-68312 * CVE-2026-68313 * CVE-2026-68315 * CVE-2026-68320 * CVE-2026-68322 * CVE-2026-68324 * CVE-2026-68325 * CVE-2026-68326 * CVE-2026-68327 * CVE-2026-68328 * CVE-2026-68329 * CVE-2026-68331 * CVE-2026-68333 * CVE-2026-68335 * CVE-2026-68336 * CVE-2026-68339 * CVE-2026-68340 * CVE-2026-68343 * CVE-2026-68346 * CVE-2026-68348 * CVE-2026-68349 * CVE-2026-68350 * CVE-2026-68351 * CVE-2026-68352 * CVE-2026-68353 * CVE-2026-68354 * CVE-2026-68355 * CVE-2026-68357 * CVE-2026-68359 * CVE-2026-68360 * CVE-2026-68361 * CVE-2026-68362 * CVE-2026-68363 * CVE-2026-68365 * CVE-2026-68366 * CVE-2026-68368 * CVE-2026-68369 * CVE-2026-68370 * CVE-2026-68372 * CVE-2026-68373 * CVE-2026-68375 * CVE-2026-68377 * CVE-2026-68386 * CVE-2026-68389 * CVE-2026-68391 * CVE-2026-68392 * CVE-2026-68394 * CVE-2026-68397 * CVE-2026-68398 * CVE-2026-68399 * CVE-2026-68402 * CVE-2026-68403 * CVE-2026-68405 * CVE-2026-68406 * CVE-2026-68407 * CVE-2026-68408 * CVE-2026-68410 * CVE-2026-68413 * CVE-2026-68414 * CVE-2026-68417 * CVE-2026-68418 * CVE-2026-68419 * CVE-2026-68422 * CVE-2026-68425 * CVE-2026-68426 * CVE-2026-68427 * CVE-2026-68428 * CVE-2026-68429 * CVE-2026-68430 * CVE-2026-68432 * CVE-2026-68433 * CVE-2026-68434 * CVE-2026-68437 * CVE-2026-68444 * CVE-2026-68445 * CVE-2026-68446 * CVE-2026-68450 * CVE-2026-68470 * CVE-2026-68480 * CVE-2026-72020 * CVE-2026-72032 * CVE-2026-72035 * CVE-2026-72036 * CVE-2026-72046 * CVE-2026-72069 * CVE-2026-72072 * CVE-2026-72083 * CVE-2026-72084 * CVE-2026-72123 * CVE-2026-72132 * CVE-2026-72221 * CVE-2026-72222 * CVE-2026-72251 * CVE-2026-72254 * CVE-2026-72262 * CVE-2026-72288 * CVE-2026-72289 * CVE-2026-72296 * CVE-2026-72307 * CVE-2026-72308 * CVE-2026-72317 * CVE-2026-72341 * CVE-2026-72342 * CVE-2026-72343 * CVE-2026-72389 * CVE-2026-72463 * CVE-2026-72464 * CVE-2026-72466 * CVE-2026-72467 * CVE-2026-72469 * CVE-2026-72473 * CVE-2026-72494 * CVE-2026-72495 * CVE-2026-72496 * CVE-2026-72497 * CVE-2026-72498 * CVE-2026-72499 * CVE-2026-72500 * CVE-2026-72501 * CVE-2026-72502 * CVE-2026-74269 * CVE-2026-74296 * CVE-2026-74297 * CVE-2026-74318 * CVE-2026-74321 * CVE-2026-74334 * CVE-2026-74345 * CVE-2026-74394 * CVE-2026-74395 * CVE-2026-74454 * CVE-2026-74474 * CVE-2026-74481 * CVE-2026-74482 * CVE-2026-74488 * CVE-2026-74495 * CVE-2026-74496 * CVE-2026-74509 * CVE-2026-74510 * CVE-2026-74512 * CVE-2026-74516 * CVE-2026-74518 * CVE-2026-74527 * CVE-2026-74537 * CVE-2026-74548 * CVE-2026-74550 * CVE-2026-74556 * CVE-2026-74563 * CVE-2026-74566 * CVE-2026-74567 * CVE-2026-74571 * CVE-2026-74577 * CVE-2026-74581 * CVE-2026-74582 * CVE-2026-74584 * CVE-2026-74610 * CVE-2026-74669 * CVE-2026-74692 * CVE-2026-74694 * CVE-2026-74695 * CVE-2026-74712 * CVE-2026-74717 * CVE-2026-74722 * CVE-2026-80529 * CVE-2026-80534 * CVE-2026-80590 * CVE-2026-80654 CVSS scores: * CVE-2024-44981 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L * CVE-2024-44981 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L * CVE-2024-44981 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-57841 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-23137 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-23137 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-23137 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-38469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-38469 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39939 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39939 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-39939 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-39964 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-39964 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-39964 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-39964 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-40022 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-40022 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-40199 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-40199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-40199 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68179 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68179 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68214 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-71075 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-71104 ( SUSE ): 8.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2025-71104 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2025-71104 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23210 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23210 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23227 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23227 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23227 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23230 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23230 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23230 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23230 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-23454 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-23454 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-23454 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31418 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31418 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31531 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31531 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31557 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31557 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31658 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31658 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31658 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31663 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31663 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31663 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43014 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43014 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43015 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43116 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43163 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43213 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43271 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43271 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43271 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43273 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43386 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43386 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-43416 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43448 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43448 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45897 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-45897 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-45897 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46070 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46070 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46078 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-46078 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-46091 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-46091 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-46091 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46107 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46107 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46107 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46115 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46115 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46127 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-46127 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46127 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46195 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46195 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52920 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-52920 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-52925 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52925 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52925 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52935 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52939 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52939 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52975 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52977 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52977 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52990 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52990 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52994 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53033 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53033 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53034 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53034 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53034 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53059 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53059 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53059 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53076 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53076 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53077 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53077 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53077 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53089 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53089 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53091 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53091 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53091 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53091 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-53094 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53094 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53096 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53096 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53110 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53110 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53111 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53111 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53111 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53126 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53142 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53142 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53142 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53154 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53180 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53180 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53180 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53207 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53207 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53228 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53228 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53238 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53238 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53263 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53263 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53269 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53269 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53269 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53309 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53309 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53309 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53330 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53330 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53336 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53336 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53337 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53353 ( SUSE ): 0.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53353 ( SUSE ): 0.0 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:N * CVE-2026-53353 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53365 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53365 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53365 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53366 ( SUSE ): 9.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-53366 ( SUSE ): 8.5 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53366 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53381 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63801 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63801 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63801 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63808 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63808 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-63808 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63810 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63810 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63823 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63823 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63823 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63827 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63828 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63828 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63828 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-63842 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63842 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63842 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63850 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63850 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63850 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63860 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63860 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63860 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63865 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63865 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63865 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-63868 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63868 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63879 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63879 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63879 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63881 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63881 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63886 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63886 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63886 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63887 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63887 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63887 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63888 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63888 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63888 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63889 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63889 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63889 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63891 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63891 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63898 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63898 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63920 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63920 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63920 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63923 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63923 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63923 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-63925 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-63925 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-63925 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-63926 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63926 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63926 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63928 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63928 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63937 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63937 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63937 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-63944 ( SUSE ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63944 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63969 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63969 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63970 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63970 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63970 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63972 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63972 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63972 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63973 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63973 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63980 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63980 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63985 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63985 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63985 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63990 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63990 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63992 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63992 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63992 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63995 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63995 ( SUSE ): 6.2 CVSS:3.1/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63995 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63996 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63996 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63996 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63997 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63997 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63998 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63998 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63999 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63999 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64000 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64000 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64000 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64001 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64001 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64002 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64002 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64002 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64004 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64004 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64004 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64005 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64005 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64005 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64006 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-64006 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-64007 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64007 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64007 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64010 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64011 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64014 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64014 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64015 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64015 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64018 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H * CVE-2026-64018 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-64018 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64021 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64021 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64029 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64029 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64029 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64033 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64033 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64033 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( SUSE ): 7.5 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64034 ( SUSE ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64034 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64039 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64039 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64039 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64047 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64047 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64048 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64048 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64048 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64051 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64051 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64051 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64052 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64052 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64052 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64055 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-64055 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-64055 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64056 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64056 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64056 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64073 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64073 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64073 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64083 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64083 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64083 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64084 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64084 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64084 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64085 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64085 ( SUSE ): 5.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64085 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64086 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64086 ( SUSE ): 5.2 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64086 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64087 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64087 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64087 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64088 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64088 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64088 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64097 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64097 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64097 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64098 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64099 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64099 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64099 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64102 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-64102 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-64102 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64112 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64113 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64113 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64114 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64115 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64118 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64118 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64118 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64121 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64121 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64121 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64125 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64126 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64126 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:L * CVE-2026-64126 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2026-64127 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64127 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64128 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64131 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64133 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64134 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64134 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64135 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64135 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64136 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64136 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64137 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64137 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64137 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64144 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64144 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64144 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64146 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64146 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64146 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64148 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64148 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64148 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64155 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64155 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64164 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64166 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64166 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64168 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64168 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64178 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64178 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64180 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64180 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64180 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64185 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64185 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64185 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64188 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64188 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64188 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64190 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64190 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64190 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64192 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64214 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64217 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64217 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64217 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64218 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64218 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64219 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64222 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64222 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64222 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64224 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64224 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64224 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64225 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64225 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64225 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64237 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64237 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64243 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64244 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64245 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64245 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64246 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64246 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64246 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64247 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64247 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-64249 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64249 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64257 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64257 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H * CVE-2026-64257 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64266 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64266 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64268 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64269 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:L * CVE-2026-64269 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64271 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64271 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64271 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64273 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64273 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64274 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64274 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64275 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64275 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64276 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64277 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64286 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64286 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64287 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64287 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64294 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64294 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64303 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64303 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64303 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64304 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64305 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64305 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64306 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64313 ( SUSE ): 7.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-64313 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64313 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64315 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64316 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64316 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64317 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64317 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64317 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64322 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64322 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64322 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64323 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64323 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64329 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64329 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64329 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64331 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64331 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64333 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64333 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64334 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64334 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64334 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64335 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64335 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64335 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64337 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64337 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64337 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64338 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64338 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64340 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64340 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64340 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64341 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64342 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64342 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64343 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64344 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64346 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64348 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64348 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64348 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64350 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64350 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64350 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64351 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64351 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64351 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64355 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64355 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64358 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64358 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64362 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64365 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64365 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64375 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64375 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64376 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64376 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64376 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64378 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64381 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64381 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64382 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64382 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64383 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64383 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64384 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64384 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64385 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64385 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64386 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64386 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64387 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64387 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64388 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64388 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-64388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64401 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64401 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64403 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64403 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-64403 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64406 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64406 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64407 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64407 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64408 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64408 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64409 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64409 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64411 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64411 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64411 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64412 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64412 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64412 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64420 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64420 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64421 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64421 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64427 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64427 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64429 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64433 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64434 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64436 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64436 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64440 ( SUSE ): 8.7 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64440 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64440 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-64442 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64442 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64443 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64443 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64444 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64444 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64444 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64445 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64445 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64448 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64448 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64450 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64452 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64452 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64454 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64455 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64463 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64471 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64472 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64477 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64478 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64478 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64479 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64480 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64481 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64481 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64482 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64482 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64483 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64484 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64484 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64486 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64487 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64489 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64496 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64497 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64500 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64503 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64504 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64505 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64511 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64511 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64512 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64513 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64515 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64515 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-64517 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64524 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64527 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64536 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64537 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64537 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64538 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64539 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64540 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64540 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64540 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64541 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64541 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64541 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64544 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64544 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64545 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64545 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64546 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64547 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64547 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64547 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64548 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64548 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64549 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64551 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64551 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64552 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64552 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64552 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64553 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64554 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64558 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64558 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64558 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64559 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64559 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64559 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64562 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64562 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64563 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64563 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64565 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64565 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64567 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64567 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64567 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64568 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64568 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64568 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64569 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64569 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64570 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64570 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64570 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64571 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64571 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64572 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64572 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64573 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64573 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64574 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64574 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64576 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64576 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64576 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64577 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64577 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64577 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64581 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64581 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64581 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64582 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64583 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64583 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64584 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64584 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64585 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64585 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64593 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64593 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64597 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64598 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64598 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-64599 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64599 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64602 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64603 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64604 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68081 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68081 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68082 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68082 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68082 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68085 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68085 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68085 ( NVD ): 8.0 CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68086 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-68086 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-68088 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68088 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68091 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68091 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68091 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68093 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-68093 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68102 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68102 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68104 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68104 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68105 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68105 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68106 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68106 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68106 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68107 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68107 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68107 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68108 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68108 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68108 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68110 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68110 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68111 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68111 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68112 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68112 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68113 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68113 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68115 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68115 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68116 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68116 ( SUSE ): 3.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L * CVE-2026-68116 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68117 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68117 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68121 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68121 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68123 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68123 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68123 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68124 ( SUSE ): 5.9 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68124 ( SUSE ): 6.0 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H * CVE-2026-68124 ( NVD ): 9.6 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68125 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68125 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68125 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68126 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68126 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68127 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68127 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68127 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68129 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68129 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68129 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68132 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68132 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68133 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68133 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68135 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68135 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68136 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68136 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68137 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68137 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68139 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68139 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68142 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-68142 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-68142 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68143 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68143 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68143 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68145 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68145 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68145 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68149 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68149 ( SUSE ): 3.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-68149 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-68152 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68152 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68152 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68153 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68153 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68153 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68154 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68154 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68154 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68155 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68155 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68155 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68156 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68156 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68156 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68157 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68157 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68157 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68158 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68158 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68158 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68159 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68159 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68159 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68160 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68160 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68160 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68161 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68161 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68161 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68162 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68162 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68166 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68166 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68180 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68181 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68182 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68184 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68184 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68188 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68189 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68192 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68192 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68193 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68194 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68195 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68196 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68197 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68199 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68202 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68204 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68204 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68205 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68206 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68207 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68209 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68210 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68210 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68212 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68213 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68215 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68216 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68217 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68218 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68218 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68219 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68219 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68220 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68220 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68222 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68222 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68223 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68223 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68226 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68226 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68227 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68227 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68229 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68229 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-68229 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68231 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68231 ( SUSE ): 2.1 CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68234 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68235 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68235 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68236 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68236 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68236 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68238 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68238 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68243 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68243 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68244 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68245 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-68245 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68246 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68246 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68247 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68247 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68248 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68248 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68249 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68249 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68250 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68250 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68251 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68251 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68252 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68252 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68253 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68253 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68255 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68256 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68257 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68257 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68259 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68259 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68260 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68261 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68262 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68262 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68263 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68263 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68267 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68269 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68271 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68272 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68278 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68278 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68279 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68279 ( SUSE ): 2.4 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68280 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68280 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68281 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68281 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68284 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68284 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68286 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-68286 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N * CVE-2026-68288 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68288 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68289 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68293 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68293 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68299 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68302 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68302 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68303 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68304 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68308 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68309 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68310 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68312 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68313 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-68322 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68324 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68325 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68326 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68327 ( SUSE ): 4.1 CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68327 ( SUSE ): 4.2 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68328 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68331 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68333 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68335 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68336 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68339 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68340 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68343 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68346 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68348 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68349 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68350 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68351 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68352 ( NVD ): 8.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68353 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68353 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68354 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68354 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68355 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68357 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68359 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68360 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68361 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68362 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68365 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68365 ( SUSE ): 6.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-68366 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68368 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68369 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68370 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68370 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68372 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68373 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-68375 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68377 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68377 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68386 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68389 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68389 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68391 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68391 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68392 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68392 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68394 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68394 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68399 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68402 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68402 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68403 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68405 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68406 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68407 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68408 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68410 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68413 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68414 ( SUSE ): 6.4 CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68414 ( NVD ): 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68418 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68419 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68422 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68425 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68425 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68426 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68426 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68427 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68427 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68427 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68428 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68429 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68430 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68430 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68433 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-68434 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68437 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68444 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68445 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68445 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68445 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68446 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68446 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68470 ( SUSE ): 6.0 CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68470 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68470 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68480 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-72020 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72020 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72020 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72032 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-72032 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-72035 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72035 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72035 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72036 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72046 ( SUSE ): 0.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:N * CVE-2026-72046 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72069 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72072 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72083 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72084 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72123 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72132 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72132 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72221 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72221 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72221 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72222 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72222 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72251 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72251 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72251 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72254 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72254 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72254 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72262 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72262 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72288 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72289 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72289 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72289 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72296 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72296 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72296 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-72307 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72307 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72308 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72308 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72317 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72317 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72317 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72341 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72342 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72342 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72343 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72343 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72389 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72463 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-72463 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72464 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72464 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72467 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72469 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72473 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-72473 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72494 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72494 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72495 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72495 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72496 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72496 ( NVD ): 9.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H * CVE-2026-72497 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72497 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72498 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72499 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72499 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72500 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72500 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72501 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74269 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74269 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74318 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74321 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74345 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74345 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74345 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74394 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74395 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74395 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74454 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74454 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-74454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74474 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74474 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74481 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74482 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74482 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74488 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74488 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74495 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74495 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74509 ( SUSE ): 5.9 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74509 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74512 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74516 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-74516 ( NVD ): 8.2 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74518 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74518 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74527 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:H * CVE-2026-74527 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74537 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74537 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74550 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74550 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74556 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-74556 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74563 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74566 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L * CVE-2026-74567 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74567 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74571 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74577 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-74581 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74581 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74582 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74584 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-74584 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-74584 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-74610 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-74610 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-74610 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74692 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74694 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74694 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74695 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74695 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74712 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-74712 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74717 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74717 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74722 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80529 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80534 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80534 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80590 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-80654 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80654 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * Legacy Module 15-SP7 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Availability Extension 15 SP7 * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 An update that solves 662 vulnerabilities, contains two features and has 35 security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP7 kernel was updated to fix various security issues: The following security issues were fixed: * CVE-2024-57841,CVE-2026-53260: net: fix memory leak in tcp_conn_request() (bsc#1235944 bsc#1269731). * CVE-2025-68214: timers: Fix NULL function pointer race in timer_shutdown_sync() (bsc#1255225). * CVE-2025-71075: scsi: aic94xx: fix use-after-free in device removal path (bsc#1256629). * CVE-2026-31418: netfilter: ipset: drop logically empty buckets in mtype_del (bsc#1262073). * CVE-2026-31531: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() (bsc#1263004). * CVE-2026-31557: nvmet: move async event work off nvmet-wq (bsc#1263061). * CVE-2026-31658: net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() (bsc#1263052). * CVE-2026-31663: xfrm: hold device only for the asynchronous decryption (bsc#1263133). * CVE-2026-43014,CVE-2026-43015: net: macb: fix clk handling on PCI glue driver removal (bsc#1264010 bsc#1264012). * CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack (bsc#1264619). * CVE-2026-43125: dlm: validate length in dlm_search_rsb_tree (bsc#1264541). * CVE-2026-43163: md/bitmap: fix GPF in write_page caused by resize race (bsc#1264335). * CVE-2026-43213: wifi: rtw89: pci: validate sequence number of TX release report (bsc#1264643). * CVE-2026-43271: md-cluster: fix NULL pointer dereference in process_metadata_update (bsc#1264587). * CVE-2026-43273: ceph: supply snapshot context in ceph_zero_partial_object() (bsc#1264446). * CVE-2026-43363: x86/apic: Disable x2apic on resume if the kernel expects so (bsc#1265068). * CVE-2026-43386: staging: rtl8723bs: fix potential out-of-bounds read in rtw_restruct_wmm_ie (bsc#1264740). * CVE-2026-43416: powerpc, perf: Check that current->mm is alive before getting user callchain (bsc#1265121). * CVE-2026-43448: nvme-pci: Fix race bug in nvme_poll_irqdisable() (bsc#1264807). * CVE-2026-45897: bpf: Fix UAF in sock clone early bailouts (bsc#1266897). * CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). * CVE-2026-46070: md/raid5: validate payload size before accessing journal metadata (bsc#1267501). * CVE-2026-46078: erofs: fix the out-of-bounds nameoff handling for trailing dirents (bsc#1267505). * CVE-2026-46091: media: rc: igorplugusb: heed coherency rules (bsc#1267238). * CVE-2026-46107: dm-thin: fix metadata refcount underflow (bsc#1267612). * CVE-2026-46115: block: add pgmap check to biovec_phys_mergeable (bsc#1266874). * CVE-2026-46127: RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() (bsc#1267236). * CVE-2026-46195: smb: client: validate dacloffset before building DACL pointers (bsc#1266860). * CVE-2026-52920: netfilter: xt_policy: fix strict mode inbound policy matching (bsc#1269013). * CVE-2026-52925: vrf: Fix a potential NPD when removing a port from a VRF (bsc#1268987). * CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). * CVE-2026-52935: xfrm: espintcp: do not reuse an in-progress partial send (bsc#1268979). * CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion (bsc#1268972). * CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (bsc#1269113). * CVE-2026-52975: bonding: 802.3ad replace MAC_ADDRESS_EQUAL with __agg_has_partner (bsc#1269234). * CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). * CVE-2026-52990: fsnotify: fix inode reference leak in fsnotify_recalc_mask() (bsc#1269108). * CVE-2026-52994: vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting (bsc#1269126). * CVE-2026-53001: netfilter: xtables: restrict several matches to inet family (bsc#1269114). * CVE-2026-53033: bpf, sockmap: Take state lock for af_unix iter (bsc#1269388). * CVE-2026-53034: bpf, sockmap: Fix af_unix null-ptr-deref in proto update (bsc#1269140). * CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). * CVE-2026-53076: bpf: Fix OOB in pcpu_init_value (bsc#1269695). * CVE-2026-53077: net/rds: Restrict use of RDS/IB to the initial network namespace (bsc#1269412). * CVE-2026-53089: bpf: Fix use-after-free in offloaded map/prog info fill (bsc#1269783). * CVE-2026-53091: net: account for encap headers in qdisc pkt len (bsc#1269530). * CVE-2026-53094: bpf: Fix stale offload->prog pointer after constant blinding (bsc#1269965). * CVE-2026-53096: bpf: Use RCU-safe iteration in dev_map_redirect_multi() SKB path (bsc#1269969). * CVE-2026-53110: selftests/bpf: Add ASSERT_OK_FD macro (bsc#1269985). * CVE-2026-53111: bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap (bsc#1269167). * CVE-2026-53126: blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current() (bsc#1269635). * CVE-2026-53142: drm/xe/display: fix oops in suspend/shutdown without display (bsc#1269402). * CVE-2026-53154: mm/hugetlb: restore reservation on error in hugetlb folio copy paths (bsc#1269665). * CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). * CVE-2026-53180: timers/migration: Fix livelock in tmigr_handle_remote_up() (bsc#1269888). * CVE-2026-53207: mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison (bsc#1269590). * CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers (bsc#1269686). * CVE-2026-53220: netfilter: revalidate bridge ports (bsc#1269381). * CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs (bsc#1269301). * CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads (bsc#1269256). * CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths (bsc#1269774). * CVE-2026-53263: 6lowpan: fix off-by-one in multicast context address compression (bsc#1269647). * CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). * CVE-2026-53269: netfilter: synproxy: add mutex to guard hook reference counting (bsc#1269579). * CVE-2026-53273: tee: optee: prevent use-after-free when the client exits before the supplicant (bsc#1269713). * CVE-2026-53309: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (bsc#1269815). * CVE-2026-53330: drm/amd/display: Fix out-of-bounds read in (bsc#1270090). * CVE-2026-53336: nvmem: layouts: onie-tlv: fix hang on unknown types (bsc#1270108). * CVE-2026-53337: net: bonding: fix NULL pointer dereference in bond_do_ioctl() (bsc#1270251). * CVE-2026-53353: hsr: Remove WARN_ONCE() in hsr_addr_is_self() (bsc#1270111). * CVE-2026-53365: vsock/virtio: fix zerocopy completion for multi-skb sends (bsc#1271365). * CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). * CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). * CVE-2026-63808: exfat: fix potential use-after-free in exfat_find_dir_entry() (bsc#1272260). * CVE-2026-63810: block: Avoid mounting the bdev pseudo-filesystem in userspace (bsc#1272297). * CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). * CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179). * CVE-2026-63828: apparmor: mediate the implicit connect of TCP fast open sendmsg (bsc#1272175). * CVE-2026-63860: RDMA/core: Prefer NLA_NUL_STRING (bsc#1272429). * CVE-2026-63865: bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks (bsc#1272486). * CVE-2026-63868: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (bsc#1272497). * CVE-2026-63879: drm/amdgpu: fix amdgpu_hmm_range_get_pages (bsc#1272569). * CVE-2026-63881: drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger (bsc#1272571). * CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). * CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). * CVE-2026-63889: scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 (bsc#1272423). * CVE-2026-63891: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (bsc#1272641). * CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). * CVE-2026-63923: octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify (bsc#1273005). * CVE-2026-63925: macsec: fix replay protection at XPN lower-PN wrap (bsc#1273008). * CVE-2026-63926: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data (bsc#1273019). * CVE-2026-63944: Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync (bsc#1272662). * CVE-2026-63969: ipv6: fix possible infinite loop in rt6_fill_node() (bsc#1272484). * CVE-2026-63970: vsock/virtio: bind uarg before filling zerocopy skb (bsc#1272673). * CVE-2026-63980: net/handshake: Use spin_lock_bh for hn_lock (bsc#1273028). * CVE-2026-63985: ethtool: eeprom: add more safeties to EEPROM Netlink fallback (bsc#1272963). * CVE-2026-63990: bonding: refuse to enslave CAN devices (bsc#1273027). * CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). * CVE-2026-63995: ethtool: cmis: validate start_cmd_payload_size from module (bsc#1273033). * CVE-2026-63996: ethtool: cmis: require exact CDB reply length (bsc#1273032). * CVE-2026-63997: ethtool: module: avoid leaking a netdev ref on module flash errors (bsc#1273036). * CVE-2026-63998: ethtool: module: call ethnl_ops_complete() on module flash errors (bsc#1273037). * CVE-2026-63999: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure (bsc#1273038). * CVE-2026-64000: net: hsr: fix potential OOB access in supervision frame handling (bsc#1273030). * CVE-2026-64001: ALSA: pcm: oss: Fix setup list UAF on proc write error (bsc#1273734). * CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). * CVE-2026-64004: net/iucv: fix locking in .getsockopt (bsc#1273804). * CVE-2026-64005: net/smc: Do not re-initialize smc hashtables (bsc#1273831). * CVE-2026-64006: netfilter: nf_tables: fix dst corruption in same register operation (bsc#1273834). * CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). * CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882). * CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891). * CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762). * CVE-2026-64029: ALSA: seq: Serialize UMP output teardown with event_input (bsc#1273766). * CVE-2026-64033: RDMA/rtrs: Fix use-after-free in path file creation cleanup (bsc#1273134). * CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). * CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). * CVE-2026-64052: block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() (bsc#1272983). * CVE-2026-64055,CVE-2026-64056: net: ethernet: cortina: Make RX SKB per-port (bsc#1272502 bsc#1272893). * CVE-2026-64055: net: ethernet: cortina: Drop half-assembled SKB (bsc#1272893). * CVE-2026-64073: irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT (bsc#1273490). * CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488). * CVE-2026-64099: drm/v3d: Fix use-after-free of CPU job query arrays on error path (bsc#1273465). * CVE-2026-64102: RDMA/siw: Reject MPA FPDU length underflow before signed receive math (bsc#1272516). * CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748). * CVE-2026-64112: rbd: eliminate a race in lock_dwork draining on unmap (bsc#1273741). * CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning (bsc#1272262). * CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). * CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). * CVE-2026-64118: qed: fix double free in qed_cxt_tables_alloc() (bsc#1273749). * CVE-2026-64121: net: ifb: report ethtool stats over num_tx_queues (bsc#1273743). * CVE-2026-64125: net: bcmgenet: keep RBUF EEE/PM disabled (bsc#1272346). * CVE-2026-64131: mm/memory: fix spurious warning when unmapping device- private/exclusive pages (bsc#1274063). * CVE-2026-64136: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() (bsc#1272351). * CVE-2026-64146: erofs: fix metabuf leak in inode xattr initialization (bsc#1273681). * CVE-2026-64148: pds_core: check health in devcmd wait (bsc#1273956). * CVE-2026-64164: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() (bsc#1273957). * CVE-2026-64180: mm/memory_hotplug: fix memory block reference leak on remove (bsc#1273679). * CVE-2026-64185: sysfs: don't remove existing directory on update failure (bsc#1272200). * CVE-2026-64188: net: qualcomm: rmnet: fix endpoint use-after-free in rmnet_dellink() (bsc#1272150). * CVE-2026-64190: net: team: fix NULL pointer dereference in team_xmit during mode change (bsc#1272210). * CVE-2026-64192: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized (bsc#1272213). * CVE-2026-64214: powerpc/time: Remove redundant preempt_disable|enable() calls from arch_irq_work_raise() (bsc#1272799). * CVE-2026-64217: netfs: Fix overrun check in netfs_extract_user_iter() (bsc#1272798). * CVE-2026-64222: octeontx2-pf: avoid double free of pool->stack on AQ init failure (bsc#1272788). * CVE-2026-64224: octeontx2-pf: fix double free in rvu_rep_rsrc_init() (bsc#1272804). * CVE-2026-64225: octeontx2-af: CGX: add bounds check to cgx_speed_mbps index (bsc#1272786). * CVE-2026-64244: drivers/base/memory: set mem->altmap after successful device registration (bsc#1273812). * CVE-2026-64245: fbdev: modedb: fix a possible UAF in fb_find_mode() (bsc#1273905). * CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). * CVE-2026-64269: RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg (bsc#1273280). * CVE-2026-64286: KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU (bsc#1274058). * CVE-2026-64287: KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU (bsc#1273325). * CVE-2026-64294: mm: do file ownership checks with the proper mount idmap (bsc#1273525). * CVE-2026-64296: exfat: bound uniname advance in exfat_find_dir_entry() (bsc#1273975). * CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944). * CVE-2026-64312: crypto: pcrypt - restore callback for non-parallel fallback (bsc#1273968). * CVE-2026-64315: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1274028). * CVE-2026-64316: crypto: caam - use print_hex_dump_devel to guard key hex dumps (bsc#1273598). * CVE-2026-64317: isofs: bound Rock Ridge symlink components to the SL record (bsc#1273936). * CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count (bsc#1273958). * CVE-2026-64323: udf: validate VAT header length against the VAT inode size (bsc#1273305). * CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). * CVE-2026-64375: proc: protect ptrace_may_access() with exec_update_lock (FD links) (bsc#1273868). * CVE-2026-64378: writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() (bsc#1273603). * CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard() (bsc#1273860). * CVE-2026-64382: smb: client: fix double-free in SMB2_open() replay (bsc#1273291). * CVE-2026-64383: smb: client: fix double-free in SMB2_flush() replay (bsc#1273426). * CVE-2026-64384: smb: client: fix change notify replay double-free (bsc#1274541). * CVE-2026-64385: smb: client: fix double-free in SMB2_ioctl() replay (bsc#1274539). * CVE-2026-64386: smb: client: fix query_info() replay double-free (bsc#1274543). * CVE-2026-64387: smb: client: fix query directory replay double-free (bsc#1274545). * CVE-2026-64388: smb/client: fix chown/chgrp with SMB3 POSIX Extensions (bsc#1274061). * CVE-2026-64411: netfilter: ebtables: terminate table name before find_table_lock() (bsc#1274077). * CVE-2026-64412: netfilter: ebtables: module names must be null-terminated (bsc#1273780). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). * CVE-2026-64434: Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref (bsc#1273880). * CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states (bsc#1274277). * CVE-2026-64448: smb: client: restrict implied bcc[0] exemption to responses without data area (bsc#1273982). * CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). * CVE-2026-64452: 6lowpan: fix NHC entry use-after-free on error path (bsc#1273460). * CVE-2026-64463: usb: typec: tcpci_rt1711h: unregister TCPCI port with devres (bsc#1273273). * CVE-2026-64472: vfio/mlx5: Fix racy bitfields and tighten struct layout (bsc#1274075). * CVE-2026-64477: x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC enabled (bsc#1274264). * CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547). * CVE-2026-64515: wifi: mac80211: fix MLE defragmentation (bsc#1273859). * CVE-2026-64537: bridge: cfm: reject invalid CCM interval at configuration time (bsc#1273289). * CVE-2026-64538: ipv6: Fix null-ptr-deref in fib6_nh_mtu_change() (bsc#1273335). * CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). * CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). * CVE-2026-64545: net, bpf: check master for NULL in xdp_master_redirect() (bsc#1273318). * CVE-2026-64548: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() (bsc#1273337). * CVE-2026-64551: sctp: validate STALE_COOKIE cause length before reading staleness (bsc#1273813). * CVE-2026-64552: virtio-net: fix len check in receive_big() (bsc#1273323). * CVE-2026-64553: net: psample: fix info leak in PSAMPLE_ATTR_DATA (bsc#1273336). * CVE-2026-64554: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() (bsc#1273340). * CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930). * CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). * CVE-2026-64567: btrfs: reject free space cache with more entries than pages (bsc#1274006). * CVE-2026-64569: mpls: fix NULL deref in mpls_valid_fib_dump_req() on CONFIG_INET=n (bsc#1274009). * CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). * CVE-2026-64576: nexthop: initialize extack in nh_res_bucket_migrate() (bsc#1274030). * CVE-2026-64577: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() (bsc#1274031). * CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). * CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (bsc#1274040). * CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497). * CVE-2026-64597: smb: client: fix double-free in SMB2_close() replay (bsc#1274297). * CVE-2026-64598: smb/client: Fix error code in smb2_aead_req_alloc() (bsc#1274298). * CVE-2026-68081: KVM: nVMX: Add helper to put (unmap) vmcs12 pages (bsc#1274580). * CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers() (bsc#1274581). * CVE-2026-68086: mm/khugepaged: write all dirty file folios when collapsing (bsc#1274713). * CVE-2026-68105: drm/amdgpu: Fix kernel panic during driver load failure (bsc#1274849). * CVE-2026-68116: vxlan: mdb: Fix source list corruption on a failed replace (bsc#1274876). * CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (bsc#1274881). * CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). * CVE-2026-68123: openvswitch: fix GSO userspace truncation underflow (bsc#1275169). * CVE-2026-68124: mctp: serial: handle zero-length frames to prevent rx buffer overflow (bsc#1275192). * CVE-2026-68127: ila: reload IPv6 header after pskb_may_pull in checksum adjust (bsc#1275237). * CVE-2026-68129: gve: fix Rx queue stall on alloc failure (bsc#1275517). * CVE-2026-68132: super: fix emergency thaw deadlock on frozen block devices (bsc#1275553). * CVE-2026-68135: net: hip04: fix RX buffer leak on build_skb failure (bsc#1275557). * CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). * CVE-2026-68139: net/mlx5e: Use sender devcom for MPV master-up (bsc#1275578). * CVE-2026-68142: geneve: require CAP_NET_ADMIN in the device netns for changelink (bsc#1275582). * CVE-2026-68143: net: slip: serialize receive against buffer reallocation (bsc#1275583). * CVE-2026-68145: iomap: fix out-of-bounds bitmap_set() with zero-length range (bsc#1275584). * CVE-2026-68149: fs: preserve ACL_DONT_CACHE state in forget_cached_acl() (bsc#1275294). * CVE-2026-68152: amt: fix use-after-free in AMT delayed works (bsc#1275300). * CVE-2026-68153: libceph: remove debugfs files before client teardown (bsc#1275301). * CVE-2026-68154: libceph: reject zero bucket types in crush_decode (bsc#1275303). * CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). * CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after authorizer update (bsc#1275305). * CVE-2026-68157: libceph: guard missing CRUSH type name lookup (bsc#1275306). * CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). * CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). * CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472). * CVE-2026-68161: sctp: close UDP tunnel sockets during netns teardown (bsc#1274892). * CVE-2026-68166: userfaultfd: prevent registration of special VMAs (bsc#1274930). * CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). * CVE-2026-68205: media: v4l2-fwnode: Fix subdev owner overwritten in v4l2_async_register_subdev_sensor() (bsc#1274934). * CVE-2026-68238: drm/amdgpu: Release VFCT ACPI table reference (bsc#1275704). * CVE-2026-68247: drm/i915/bios: range check LFP Data Block panel_type2 (bsc#1275817). * CVE-2026-68254: drm/i915/vrr: require valid min/max vfreq for VRR (bsc#1275150). * CVE-2026-68267: drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists (bsc#1275139). * CVE-2026-68284: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (bsc#1275970). * CVE-2026-68286: drop_monitor: perform u64_stats updates under IRQ-disabled section (bsc#1275973). * CVE-2026-68288: net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD (bsc#1275975). * CVE-2026-68289: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() (bsc#1275976). * CVE-2026-68293: net/mlx5: Fix MCIA register buffer overflow on 32 dword reads (bsc#1275091). * CVE-2026-68297: tipc: fix u16 MTU truncation in media and bearer MTU validation (bsc#1275040). * CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (bsc#1275088). * CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL (bsc#1275083). * CVE-2026-68302: amt: re-read skb header pointers after every pull (bsc#1275081). * CVE-2026-68312: cifs: fix cifsFileInfo leak on kmalloc failure in deferred close drain paths (bsc#1274663). * CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit (bsc#1274665). * CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq() (bsc#1274662). * CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (bsc#1274659). * CVE-2026-68322: rds: Fix inet6_addr_lst NULL dereference when IPv6 is disabled (bsc#1274656). * CVE-2026-68324: iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() (bsc#1274649). * CVE-2026-68325: iommu/amd: Bound the early ACPI HID map (bsc#1274651). * CVE-2026-68328: nfp: Check resource mutex allocation (bsc#1274646). * CVE-2026-68329: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (bsc#1274645). * CVE-2026-68331: dpaa2-eth: put MAC endpoint device on disconnect (bsc#1274642). * CVE-2026-68333: dpaa2-switch: put MAC endpoint device on disconnect (bsc#1274644). * CVE-2026-68335: rds: drop incoming messages that cross network namespace boundaries (bsc#1274640). * CVE-2026-68336: bonding: fix devconf_all NULL dereference when IPv6 is disabled (bsc#1274639). * CVE-2026-68343: smb: client: validate DFS referral PathConsumed (bsc#1274629). * CVE-2026-68375: bnxt_en: Handle partially initialized auxiliary devices (bsc#1274835). * CVE-2026-68377: net/sched: act_tunnel_key: Defer dst_release to RCU callback (bsc#1274831). * CVE-2026-68386: bpf, sockmap: Reject unhashed UDP sockets on sockmap update (bsc#1274814). * CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). * CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). * CVE-2026-68408: wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock (bsc#1274709). * CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). * CVE-2026-68418: RDMA/irdma: Prevent user-triggered null deref on QP create (bsc#1274690). * CVE-2026-68419: RDMA/irdma: Prevent rereg_mr for non-mem regions (bsc#1274698). * CVE-2026-68422: btrfs: fix root leak if its reloc root is unexpected in merge_reloc_roots() (bsc#1274706). * CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1274700). * CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). * CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink (bsc#1274800). * CVE-2026-68433: libceph: bound get_version reply decode to front len (bsc#1274801). * CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert (bsc#1274834). * CVE-2026-68470: wifi: cfg80211/mac80211: correctly parse S1G beacon optional elements (bsc#1276500). * CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). * CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). * CVE-2026-72032: net/mlx5: HWS, fix matcher leak on resize target setup failure (bsc#1276955). * CVE-2026-72035: net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1276961). * CVE-2026-72036: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1277034). * CVE-2026-72046: gve: fix header buffer corruption with header-split and HW- GRO (bsc#1275519). * CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). * CVE-2026-72072: net/mlx5e: macsec: fix use-after-free of metadata_dst on RX SC delete (bsc#1277155). * CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). * CVE-2026-72084: scsi: target: Bound PR-OUT TransportID parsing to the received buffer (bsc#1275540). * CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523). * CVE-2026-72132: NFS: Charge unstable writes by request size, not folio size (bsc#1277551). * CVE-2026-72221: sunrpc: wait for in-flight TLS handshake callback when cancel loses race (bsc#1275665). * CVE-2026-72222: sunrpc: pin svc_xprt across the asynchronous TLS handshake callback (bsc#1275669). * CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). * CVE-2026-72254: netfilter: nft_fib: reject fib expression on the netdev egress hook (bsc#1277204). * CVE-2026-72262: ASoC: SOF: ipc3-control: Fix heap overflow in bytes_ext put/get (bsc#1277678). * CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). * CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). * CVE-2026-72296: net: ife: require ETH_HLEN to be pullable in ife_decode() (bsc#1275923). * CVE-2026-72307: mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() (bsc#1277160). * CVE-2026-72308: mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() (bsc#1277159). * CVE-2026-72317: SUNRPC: pin upper rpc_clnt across the TLS connect_worker (bsc#1275925). * CVE-2026-72341: net/mlx5e: Fix publication race for priv->channel_stats[] (bsc#1277660). * CVE-2026-72342: net/mlx5e: Fix HV VHCA stats agent registration race (bsc#1277775). * CVE-2026-72343: net/mlx5e: Fix HV VHCA stats zero-sized buffer allocation (bsc#1277776). * CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). * CVE-2026-72463: xfrm: Fix dev use-after-free in xfrm async resumption (bsc#1268276 bsc#1277064). * CVE-2026-72464: xprtrdma: Remove temp allocation of rpcrdma_rep objects (bsc#1277069). * CVE-2026-72466: xprtrdma: Fix bcall rep leak and unbounded peek (bsc#1277057). * CVE-2026-72467: xprtrdma: Check frwr_wp_create() during connect (bsc#1277059). * CVE-2026-72469: xprtrdma: Fix ep kref imbalance on ADDR_CHANGE (bsc#1277047). * CVE-2026-72473: xprtrdma: Avoid 250 ms delay on backlog wakeup (bsc#1277037). * CVE-2026-72494: RDMA/irdma: Replace waitqueue and flag with completion (bsc#1276941). * CVE-2026-72495: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages (bsc#1276937). * CVE-2026-72496: RDMA/bnxt_re: Proper rollback if the ioremap fails (bsc#1276943). * CVE-2026-72497: RDMA/bnxt_re: Add a max slot check for SQ (bsc#1276913). * CVE-2026-72498: RDMA/bnxt_re: Avoid displaying the kernel pointer (bsc#1276912). * CVE-2026-72499: RDMA/bnxt_re: Free CQ toggle page after firmware teardown (bsc#1276551). * CVE-2026-72500: RDMA/bnxt_re: Free SRQ toggle page after firmware teardown (bsc#1276552). * CVE-2026-72501: RDMA/bnxt_re: Initialize dpi variable to zero (bsc#1276546). * CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (bsc#1276542). * CVE-2026-74269: bnxt: fix head underflow on XDP head-grow (bsc#1276507). * CVE-2026-74296: RDMA/mlx5: Release the HW-provided UAR index rather than the SW one (bsc#1276452). * CVE-2026-74297: RDMA/mlx5: Fix undefined shift of user RQ WQE size (bsc#1276446). * CVE-2026-74318: btrfs: fix deadlock cloning inline extent when using flushoncommit (bsc#1276864). * CVE-2026-74321: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() (bsc#1277202). * CVE-2026-74334: RDMA/nldev: Fix locking when accessing mr->pd (bsc#1277095). * CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). * CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). * CVE-2026-74395: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference (bsc#1277077). * CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073). * CVE-2026-74474: vxlan: use pskb_network_may_pull() for transmit path header pulls (bsc#1276335). * CVE-2026-74481: mm/page_reporting: use system_freezable_wq to fix UAF during suspend (bsc#1276355). * CVE-2026-74482: mm/huge_memory: unlock i_mmap_rwsem before releasing after- split folios (bsc#1276346). * CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350). * CVE-2026-74495: igbvf: Fix leak in TX DMA error cleanup (bsc#1275864). * CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). * CVE-2026-74509: Bluetooth: hci_sync: Fix advertising data UAFs (bsc#1275946). * CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation (bsc#1275950). * CVE-2026-74512: audit: fix potential use-after-free in audit_del_rule() (bsc#1275954). * CVE-2026-74516: KVM: SVM: Update x2APIC MSR intercepts if AVIC is inhibited while L2 is active (bsc#1275797). * CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). * CVE-2026-74527: octeontx2-af: Block VFs from clobbering special CGX PKIND state (bsc#1275805). * CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). * CVE-2026-74548: forcedeth: fix UAF of txrx_stats in nv_remove (bsc#1275695). * CVE-2026-74550: net: do not send ICMP/NDISC Redirects when peer allocation fails (bsc#1275688). * CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). * CVE-2026-74563: rds: tcp: hold the RCU lock across ipv6_chk_addr() in rds_tcp_laddr_check() (bsc#1275574). * CVE-2026-74566: keys: make keyring key-chunk byte order agree with keyring_diff_objects() (bsc#1275566). * CVE-2026-74567: keys: fix out-of-bounds read in keyring_get_key_chunk() (bsc#1275569). * CVE-2026-74571: btrfs: skip global block reserve accounting for rescue mounts (bsc#1275561). * CVE-2026-74577: net: mpls: initialize rtm_tos in mpls_getroute() (bsc#1275572). * CVE-2026-74581: net: ipv6: clear suppressed fib6 rule result (bsc#1275782). * CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). * CVE-2026-74584: RDMA/bnxt_re: zero shared page before exposing to userspace (bsc#1277066). * CVE-2026-74610: tls: don't leave a full plaintext sk_msg ring unpushed (bsc#1277054). * CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). * CVE-2026-74692: net/smc: fix TOCTOU race between smc_listen_out() and listener close (bsc#1276927). * CVE-2026-74694: net/ncsi: fix heap OOB read in NCSI_CMD_SEND_CMD payload length (bsc#1277625). * CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). * CVE-2026-74712: vdpa/mlx5: Fix buffer length in create_direct_keys() (bsc#1276577). * CVE-2026-74717: net/mlx5: fw_tracer, return NULL on create error (bsc#1276569). * CVE-2026-74722: btrfs: fix memory leak in btrfs_do_encoded_write() (bsc#1276561). * CVE-2026-80529: xfs: don't swallow dquot recovery verification errors (bsc#1277688). * CVE-2026-80534: xfs: fix ilock leak on error in xfs_dq_get_next_id (bsc#1277022). * CVE-2026-80590: inet: frags: strip GSO state from fragments before reassembly (bsc#1277275). * CVE-2026-80654: soc: xilinx: Shutdown and free rx mailbox channel (bsc#1277516). The following non security issues were fixed: * accessibility: speakup: Fix incorrect string length computation in report_char_chartab_status() (git-fixes). * accessibility: speakup: unregister tty ldisc on later init failures (git- fixes). * ACPI: APEI: Fix ERST timeout unit conversion (git-fixes). * ACPI: EC: Avoid _REG disconnect on GPIO IRQ defer (git-fixes). * ACPI: PCI: Clear driver_data on all paths that free the acpi_pci_root (git- fixes). * ACPI: pfr_update: fix stack buffer overflow in query_capability() (git- fixes). * ACPI: processor: idle: Expand _LPI package sanity checks (git-fixes). * ACPI: processor: validate MADT IOAPIC entry bounds (git-fixes). * ACPI: scan: fix bus ID cleanup on device_add() failures (git-fixes). * ACPI: video: Release PCI device reference after lookup (git-fixes). * add my missing Reviewed-by: tag. * ALSA: 6fire: bound the MIDI event length from the device (git-fixes). * ALSA: 6fire: Fix UAF at error handling during probe (stable-fixes). * ALSA: bcd2000: clear the URB pointers on disconnect (git-fixes). * ALSA: control: Don't add invalid kcontrols to LED layer (git-fixes). * ALSA: core: Fix use-after-free in snd_card_do_free() (git-fixes). * ALSA: dummy: Check card index validity at probe (stable-fixes). * ALSA: hda/ext: preserve PPLCCTL bits when clearing reset (git-fixes). * ALSA: hda: Fix connection list comparison in proc output (git-fixes). * ALSA: hpi: Check transport errors during HPI6000 adapter initialization (git-fixes). * ALSA: pcxhr: initialize mutexes before requesting threaded IRQ (git-fixes). * ALSA: scarlett2: Use a private URB for the notification endpoint (git- fixes). * ALSA: seq: Don't leak the extension cell pointer in the bounce payload (git- fixes). * ALSA: seq: midi: Optimize event_input locking with RCU (git-fixes). * ALSA: seq: midi: Serialize input teardown with event_input (git-fixes). * ALSA: ump: Fix corrupted data bytes at MIDI 1.0 SysEx to UMP conversion (git-fixes). * ALSA: usb-audio: Complete cleanup after system-resume errors (git-fixes). * ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() (git-fixes). * ALSA: usb-audio: fix OOB write on Type II inbound URBs (git-fixes). * ALSA: usb: Fix UAF at delayed release of MIDI2 EPs (git-fixes). * ALSA: usx2y: bound the hwdep mmap fault offset (git-fixes). * ALSA: via82xx: Remove unreachable branch in snd_via686_pcm_pointer() (git- fixes). * apparmor: advertise the tcp fast open fix is applied (git-fixes). * arm64: Exclude nohz_full CPUs from 32bits el0 support (bsc#1269313). * ASoC: adau1761: sort the register default table (git-fixes). * ASoC: amd: yc: Add DMI entry for MSI Thin A15 B7UC (git-fixes). * ASoC: apple: mca: increase SERDES reset delay (git-fixes). * ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses (git-fixes). * ASoC: cs35l33: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l34: drain threaded IRQ before runtime suspend (git-fixes). * ASoC: cs35l41: sort the register default table (git-fixes). * ASoC: cs35l45: sort the register default table (git-fixes). * ASoC: cs4265: sort the register default table (git-fixes). * ASoC: cx2072x: sort the register default table (git-fixes). * ASoC: dapm: Fix off-by-one check on the second enum channel (git-fixes). * ASoC: fix unmet dependencies on PPC_BESTCOMM and SND_SOC_AC97_BUS (git- fixes). * ASoC: fsl-asoc-card: defer probe when the CPU DAI device is not ready (git- fixes). * ASoC: fsl: mpc5200-i2s: Free DMA resources on probe failure (git-fixes). * ASoC: fsl_audmix: rework runtime PM handling in probe (git-fixes). * ASoC: fsl_easrc: sort the register default table (git-fixes). * ASoC: hdac_hda: Fix hlink refcount leak on component registration failure (git-fixes). * AsoC: intel: sst: fix PCI device reference leak on probe failure (git- fixes). * ASoC: max9860: sort the register default table (git-fixes). * ASoC: meson: Keep link pointers valid on realloc failure (git-fixes). * ASoC: ml26124: sort the register default table (git-fixes). * ASoC: pcm512x: sort the register default table (git-fixes). * ASoC: pxa: Use devm_clk_get_optional() for extclk clock (git-fixes). * ASoC: qcom: q6apm: keep the graph start count in sync with the DSP (git- fixes). * ASoC: rt274: sort the register default table (git-fixes). * ASoC: rt286: sort the register default table (git-fixes). * ASoC: rt298: sort the register default table (git-fixes). * ASoC: rt700-sdw: always drain jack work on remove (git-fixes). * ASoC: rt700: drop duplicate reg_default entry (git-fixes). * ASoC: rt700: sort the register default table (git-fixes). * ASoC: rt711-sdca: sort the register default tables (git-fixes). * ASoC: rt711: sort the register default table (git-fixes). * ASoC: rt712-sdca-dmic: sort the register default table (git-fixes). * ASoC: rt712-sdca-sdw: sort the register default table (git-fixes). * ASoC: rt715-sdca: drop duplicate reg_default entries (git-fixes). * ASoC: rt715-sdca: sort the register default tables (git-fixes). * ASoC: rt715: sort the register default table (git-fixes). * ASoC: rt1017-sdca-sdw: sort the register default table (git-fixes). * ASoC: rt1316-sdw: sort the register default table (git-fixes). * ASoC: rt1318-sdw: sort the register default table (git-fixes). * ASoC: samsung: aries_audio_probe: double of_node_put due to direct assignment without of_node_get (git-fixes). * ASoC: sgtl5000: sort the register default table (git-fixes). * ASoC: SOF: pcm: Move period/buffer configuration print after platform open (stable-fixes). * ASoC: sof: pcm: use snd_pcm_direction_name() (stable-fixes). * ASoC: SOF: Relocate and rework functionality for PCM stream freeing (stable- fixes). * ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() (git- fixes). * ASoC: SOF: validate topology volume range before allocation (git-fixes). * ASoC: sti-sas: sort the register default table (git-fixes). * ASoC: tas2552: sort the register default table (git-fixes). * ASoC: tas2764: sort the register default table (git-fixes). * ASoC: tas2780: sort the register default table (git-fixes). * ASoC: tegra210_i2s: sort the register default table (git-fixes). * ASoC: tegra210_mixer: sort the register default table (git-fixes). * ASoC: tegra: Fix the MIXER enable default value (git-fixes). * ASoC: tegra: Sort MBDRC register defaults (git-fixes). * ASoC: xilinx: formatter_pcm: fix stream_data leak on open error (git-fixes). * ASoC: xilinx: formatter_pcm: pass aud_drv_data to irq handlers (git-fixes). * batman-adv: bla: fix freeing of claims on meshif deletion (git-fixes). * batman-adv: bla: prevent CRC corruptions after claim flush (git-fixes). * batman-adv: dat: avoid unaligned fault in IP extraction (git-fixes). * batman-adv: fix stale receive device on merged fragments (git-fixes). * Bluetooth: btintel: Fix diagnostics event detection (git-fixes). * Bluetooth: btmtk: Do not discard the subsystem reset timeout (git-fixes). * Bluetooth: btmtk: Fix short read errors in btmtk_usb_uhw_reg_read() (stable- fixes). * Bluetooth: btmtksdio: Fix out-of-bounds DMA read in the TX path (git-fixes). * Bluetooth: btmtksdio: Take exclusive ownership of the SKB before TX (git- fixes). * Bluetooth: btqca: Fix qca_set_bdaddr() waiting for wrong HCI event (git- fixes). * Bluetooth: btusb: Fix BD_ADDR byte order in btusb_set_bdaddr_wcn6855() (git- fixes). * Bluetooth: do not leak an hci_conn when a second LE connect is rejected (git-fixes). * Bluetooth: eir: Fix OOB read in eir_get_service_data() (git-fixes). * Bluetooth: hci_bcm4377: Ignore reserved PHY in ext adv reports on BCM4378 (git-fixes). * Bluetooth: hci_bcm: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_conn: fix the SCO setup context lifetime (git-fixes). * Bluetooth: hci_conn: hold conn reference in abort_conn_sync() (git-fixes). * Bluetooth: hci_conn: re-enable advertising only for peripheral role (git- fixes). * Bluetooth: hci_core: use skb_get() instead of skb_clone() for req_skb (git- fixes). * Bluetooth: hci_event: clear HCI_LE_ADV only on a created connection (git- fixes). * Bluetooth: hci_event: fix LE list UAF on reset (git-fixes). * Bluetooth: hci_event: validate LE Set CIG Parameters response (git-fixes). * Bluetooth: hci_h5: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_intel: fix usage_count leak when autosuspend_delay is negative (git-fixes). * Bluetooth: hci_sync: Clear HCI_CMD_PENDING when dropping the last request (git-fixes). * Bluetooth: hci_sync: free the advertising instance on the failure and cancel paths (git-fixes). * Bluetooth: hci_sync: make hci_cmd_sync_run_once return -EEXIST if exists (stable-fixes). * Bluetooth: hci_uart: Fix false success return in hci_uart_setup() (git- fixes). * Bluetooth: ISO: fix use-after-free of listener socket in iso_conn_ready (git-fixes). * Bluetooth: MGMT: free the mesh send cancel command when it is cancelled (git-fixes). * Bluetooth: MSFT: validate evt_prefix_len against the response length (git- fixes). * Bluetooth: RFCOMM: serialize security confirmation handling (git-fixes). * Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (git- fixes). * Bluetooth: RFCOMM: Validate MTU in rfcomm_apply_pn() to prevent infinite loop (git-fixes). * Bluetooth: virtio_bt: avoid OOB read of build info string (git-fixes). * bnxt_en: Adjust TX rings if reservation is less than requested (jsc#PED-16798). * bnxt_en: Delay for 5 seconds after AER DPC for all chips (jsc#PED-16798). * bnxt_en: Don't assume XDP is never enabled in bnxt_init_dflt_ring_mode() (jsc#PED-16798). * bnxt_en: Drop pci_save_state() after pci_restore_state() (jsc#PED-16798). * bnxt_en: Implement XDP RSS hash metadata extraction (jsc#PED-16798). * bnxt_en: Implement XDP RSS hash metadata extraction for V3_CMP (jsc#PED-16798). * bnxt_en: Move bnxt_rss_ext_op into header (jsc#PED-16798). * bnxt_en: Refactor some basic ring setup and adjustment logic (jsc#PED-16798). * bnxt_en: Restore default stat ctxs for ULP when resource is available (jsc#PED-16798). * bnxt_en: Set bp->max_tpa according to what the FW supports (jsc#PED-16798). * bnxt_en: Use absolute target ns from ptp_clock_request (jsc#PED-16798). * bnxt_en: use bnxt_xdp_buff for xdp context (jsc#PED-16798). * bus: mhi: ep: Fix device refcount leak in the error path of MHI device creation (git-fixes). * bus: mhi: host: Flush the posted write after writing to MHI_SOC_RESET_REQ_OFFSET (git-fixes). * bus: ti-sysc: Fix /chosen node reference leak (git-fixes). * cacheinfo: don't propagate DT/ACPI error when arch supplies info (arm64) (git-fixes). * can: j1939: use netdevice_tracker for j1939_{priv,session,ecu} tracking (stable-fixes). * cpufreq: intel_pstate: Use correct scaling factor on Raptor Lake-E (bsc#1240957 bsc#1249104 bsc#1265220). * cpufreq: intel_pstate: Use CPPC to get scaling factors (bsc#1240957 bsc#1249104 bsc#1265220). * cpufreq: intel_pstate: Use HYBRID_SCALING_FACTOR_ADL for Bartlett Lake (bsc#1240957 bsc#1249104 bsc#1265220). * crypto: aspeed - Propagate platform_get_irq() errors (git-fixes). * crypto: atmel-sha204a - fix heap info leak on I2C transfer failure (git- fixes). * crypto: atmel-tdes - use scatterlist length before DMA mapping (git-fixes). * crypto: ccm - Set rfc4309 maxauthsize from child (git-fixes). * crypto: ccp - Fix memory leak in SEV INIT_EX path (git-fixes). * crypto: ccp - Fix possible deadlock in SEV init failure path (git-fixes). * crypto: doc - Remove extra parenthesis (git-fixes). * crypto: hisilicon/sec2 - fix CCM algorithm long packet failure (git-fixes). * crypto: keembay - Initialize completion before requesting IRQ (git-fixes). * crypto: keembay - publish OF module alias for OCS AES/SM4 (git-fixes). * crypto: mxs-dcp - fix source scatterlist length access (git-fixes). * crypto: qat - cancel work on re-enable SR-IOV timeout (git-fixes). * crypto: qat - clear AES key schedule from stack (git-fixes). * crypto: qce - fix CCM AAD buffer underallocation (git-fixes). * crypto: qce - fix error path in devm_qce_register_algs (git-fixes). * crypto: rk3288 - fail ahash requests on HASH idle timeout (git-fixes). * crypto: sa2ul - stop probe if context pool creation fails (git-fixes). * crypto: sl3516 - drop invalid sg_dma_len checks before DMA mapping (git- fixes). * device property: fix infinite loop in fwnode_for_each_child_node() (git- fixes). * dmaengine: dw-edma: Clear stale requests on termination (git-fixes). * dmaengine: dw-edma: Complete descriptors before pausing (git-fixes). * dmaengine: dw-edma: Initialize IRQ data before requesting IRQs (git-fixes). * dmaengine: dw-edma: Serialize abort state updates (git-fixes). * dmaengine: dw-edma: Serialize channel state checks (git-fixes). * dmaengine: hisilicon: Return -ENOMEM on dynamic memory allocation in probe (git-fixes). * dmaengine: mediatek: mtk-uart-apdma: Return -ENOMEM on memory allocation failure (git-fixes). * dmaengine: qcom-bam-dma: fix autosuspend cleanup during removal (git-fixes). * dmaengine: xilinx_dma: Fix channel idle state management in AXIDMA and MCDMA interrupt handlers (git-fixes). * dmaengine: xilinx_dma: Fix CPU stall in xilinx_dma_poll_timeout (git-fixes). * driver core: soc: Unregister bus on early device registration failure (git- fixes). * drm/amd/display: Add AV mute wait frames to dce110_set_avmute (stable- fixes). * drm/amd/display: avoid divide-by-zero in __is_lut_linear() (git-fixes). * drm/amd/display: Check for tg ops in dce110_set_avmute (git-fixes). * drm/amd/display: fix BT.2020 YCbCr limited output CSC matrix (git-fixes). * drm/amd/display: fix BT.2020 YCbCr output CSC matrices for DCE (git-fixes). * drm/amd/display: Fix NULL pointer dereference in amdgpu_dm_crtc_set_vblank() (git-fixes). * drm/amd/display: Increase HDMI AV mute wait from 2 to 3 frames (stable- fixes). * drm/amd/display: Remove unused-but-set variable hubp from (git-fixes). * drm/amd/display: validate plane degamma LUT size for private color prop (git-fixes). * drm/amd/pm: adjust the visibility of pp_table sysfs node (stable-fixes). * drm/amd/pm: Use same metric table for APU (stable-fixes). * drm/amd/powerplay: fix VoltageObjectInfo zero-stride loop and OOB read (git- fixes). * drm/amdgpu/gfx6: Fixup emit_cntxcntl() (git-fixes). * drm/amdgpu/gfx6: Fixup emitting SWITCH_BUFFER packets (git-fixes). * drm/amdgpu/gfx6: Use PFP on the compute queues too (git-fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in SMU7 lookup (git- fixes). * drm/amdgpu/pm/powerplay: bounds-check voltage index in Vega10 lookup (git- fixes). * drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check (git- fixes). * drm/amdgpu: cap GTT size to physical RAM on APUs (stable-fixes). * drm/amdgpu: check ASPM on the dGPU host link (git-fixes). * drm/amdgpu: disallow multiple FENCE chunks in one submit (git-fixes). * drm/amdgpu: fix aperture iounmap skipped on device removal (git-fixes). * drm/amdgpu: fix autosuspend cleanup during removal (git-fixes). * drm/amdgpu: fix nbif 6.3.1 l1 low power not functional (git-fixes). * drm/amdgpu: Fix UVD decode image min size calculation (stable-fixes). * drm/amdgpu: Fix UVD dpb min size calculation for H264 (stable-fixes). * drm/amdgpu: Fix UVD min buffer sizes (stable-fixes). * drm/amdgpu: Fix VCE 3 ring align_mask (git-fixes). * drm/amdgpu: Implement insert_end for VCE 3 (git-fixes). * drm/amdgpu: move debug_vm handling to amdgpu_cs_parser_fini (git-fixes). * drm/amdgpu: read TRUNCATE_COORD_MODE on gfx12 (git-fixes). * drm/amdgpu: reject oversized IBs with per-ring packet limits (stable-fixes). * drm/amdgpu: Reject UVD message with dimensions above 4096 (stable-fixes). * drm/amdgpu: Reject UVD message with invalid number of h265 refs (stable- fixes). * drm/amdgpu: remove unused function parameter (stable-fixes). * drm/amdgpu: restore UMD profile pstate after runtime resume (stable-fixes). * drm/amdgpu: validate GEM_CREATE domain combinations (stable-fixes). * drm/amdkfd: Fix missing authorization check in KFD_IOC_DBG_TRAP_DISABLE (stable-fixes). * drm/amdkfd: fix QID bit leak in pqm_create_queue() (stable-fixes). * drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore (git- fixes). * drm/amdkfd: Handle invalid event type in CRIU event restore (stable-fixes). * drm/bridge: cdns-mhdp8546: Return an error pointer on allocation failure (git-fixes). * drm/bridge: dw-hdmi: fix i2c adapter leak on probe failure (git-fixes). * drm/bridge: ps8640: propagate AUX transfer register errors (git-fixes). * drm/bridge: tc358767: clamp the reported AUX read size to the request (git- fixes). * drm/connector/hdmi: Fix out of bounds memory read (git-fixes). * drm/connector: Fix epoch_counter docs to reflect reality (git-fixes). * drm/hibmc: Fix list of formats on the primary plane (git-fixes). * drm/hibmc: Use drm_atomic_helper_check_plane_state() (git-fixes). * drm/i915/fbc: Extract intel_fbc_has_fences() (stable-fixes). * drm/i915/hdcp: check streams bounds before overflow (git-fixes). * drm/i915/hdcp: Move to using intel_display in intel_hdcp (stable-fixes). * drm/i915/hdcp: require monotonically increasing seq_num_v (git-fixes). * drm/i915/hdcp: Skip inactive MST connectors when building stream list (stable-fixes). * drm/i915/vrr: Check HAS_VRR() first in intel_vrr_is_capable() (stable- fixes). * drm/i915/vrr: require valid min/max vfreq for VRR (git-fixes). * drm/lima: call drm_mm_init() with a valid allocation range (git-fixes). * drm/msm/a6xx: Fix RBBM_CLOCK_CNTL3_TP0 value in a730_hwcg (git-fixes). * drm/msm/a6xx: Fix stale rpmh votes after suspend (git-fixes). * drm/msm/dpu: Drop sneaky dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: Drop dev_pm_opp_set_rate(0) (git-fixes). * drm/msm/dsi: round 6G byte clock rate to the PLL-achievable value (git- fixes). * drm/panel-edp: fix i2c adapter leak on probe failure (git-fixes). * drm/panel: samsung-s6d16d0: Power off on prepare failure (git-fixes). * drm/panthor: fix firmware control interface bounds checks (git-fixes). * drm/panthor: return PTR_ERR() from devm_drm_dev_alloc() (git-fixes). * drm/panthor: skip zero-sized firmware sections (git-fixes). * drm/radeon: fix autosuspend cleanup during teardown (git-fixes). * drm/radeon: restore hardware polling in fence_is_signaled to fix performance regression (git-fixes). * drm/rockchip: vop2: Recognise 10-bit YUV422 as YUV format (git-fixes). * drm/ssd130x: fix column and row end address in partial updates for ssd132x (git-fixes). * drm/ssd130x: fix column and row end address in partial updates in ssd133x (git-fixes). * drm/sun4i: crtc: Propagate layer initialization error (git-fixes). * drm/sun4i: Drop node references while building component list (git-fixes). * drm/sun4i: dw-hdmi: Drop TCON TOP port reference (git-fixes). * drm/sun4i: fix refcount leak in sun4i_backend_init_sat() (git-fixes). * drm/sun4i: hdmi-phy: Fix H6 8-bit MPLL config at 594 MHz (git-fixes). * drm/sun4i: hdmi: Don't leak sync polarity bits into packet control (git- fixes). * drm/sun4i: tcon: Drop remote endpoint reference (git-fixes). * drm/sun4i: tcon: Drop TCON TOP device reference (git-fixes). * drm/sun4i: tcon: Set output mux for DSI and LVDS (git-fixes). * drm/sun4i: vi scaler: Fix coefficient selection (git-fixes). * drm/tegra: dsi: Re-add clear enable register if DSI was powered by bootloader (git-fixes). * drm/tegra: fbdev: Do not assign to struct drm_fb_helper.info (git-fixes). * drm/tve200: add OF module alias for autoloading (git-fixes). * drm/xe/oa: Check managed mutex initialization errors (git-fixes). * drm/xe/oa: Fix sync entry leak on OA config emit failure (git-fixes). * drm/xe: Introduce xe_gt_dbg_printer() (stable-fixes). * drm/xe: Order ring writes before ring tail updates (git-fixes). * drm/xe: Stub out new pagefault layer (stable-fixes). * drm/xe: tests: fix error message in xe_migrate_sanity_test() (git-fixes). * drm: fix race between partial drm_dev_register() failure and ioctl (git- fixes). * drm: lcdif: Wait for vblank before disabling DMA (git-fixes). * drm: Remove unused header in drm_dumb_buffers.c (git-fixes). * ethtool: rss: fix hkey leak when indir_size is 0 (git-fixes). * fbdev: bitblit: bound-check glyph index in bit_cursor() (git-fixes). * fbdev: core: Fix pointer desynchronization in fb_io_read() (git-fixes). * fbdev: kyro: Validate overlay viewport coordinates (git-fixes). * fbdev: omapfb: panel-dsi-cm: initialize lock before registering display (git-fixes). * fbdev: ssd1307fb: defer I2C transfers from damage callbacks (git-fixes). * fbdev: tdfxfb: fix PCI enable cleanup with pcim_enable_device() (git-fixes). * fbdev: uvesafb: unregister connector callback on init failure (git-fixes). * firmware: arm_scmi: Avoid IDR updates while cleaning channels (git-fixes). * firmware: arm_scmi: Drop handle on protocol bind failures (git-fixes). * firmware: arm_scmi: Fix requested device removal race (git-fixes). * firmware: arm_scmi: Free transport channel on IDR failure (git-fixes). * firmware: arm_scmi: Protect device request lookup with RCU (git-fixes). * firmware: arm_scmi: Reject out of range DT protocol IDs (git-fixes). * firmware: arm_scmi: Unregister device notifier before IDR teardown (git- fixes). * firmware: arm_scmi: Use channel ID for transport teardown (git-fixes). * firmware_loader: do not queue completed sysfs fallback requests (git-fixes). * fpga: altera-cvp: Avoid out-of-bounds read in trailing byte write (git- fixes). * fpga: dfl: fme: add error handling (git-fixes). * fpga: stratix10-soc: Fix SVC mailbox handling during reconfiguration (git- fixes). * gpu: host1x: Avoid stack over-read in debug output helpers (git-fixes). * gpu: host1x: Fix offset calculation in trace_write_gather (git-fixes). * HID: core: fix number/pointer type confusion on long items (git-fixes). * HID: core: fix OOB read of field->usage in hid_set_field() (git-fixes). * HID: hyperv: validate initial device info bounds (git-fixes). * HID: i2c-hid: goodix: Disable VDD on VDDIO enable failure (git-fixes). * HID: lg4ff: validate report length before fixed offsets (git-fixes). * HID: logitech-dj: Fix maxfield check in DJ short report validation (git- fixes). * HID: logitech-dj: fix wrong detection of bad DJ_SHORT output report (git- fixes). * HID: logitech-dj: Prevent REPORT_ID_DJ_SHORT related user initiated OOB write (stable-fixes). * HID: logitech-dj: Standardise hid_report_enum variable nomenclature (stable- fixes). * HID: magicmouse: Prevent out-of-bounds (OOB) read during DOUBLE_REPORT_ID (stable-fixes). * HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() (git- fixes). * HID: mcp2221: validate report size in mcp2221_raw_event() (git-fixes). * HID: nintendo: Fix imu_timestamp_us double increment per report (git-fixes). * HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() (git- fixes). * HID: picolcd: clamp eeprom debugfs read to bytes actually received (git- fixes). * HID: roccat: bound device-supplied profile index (git-fixes). * HID: roccat: free buffered reports when destroying device (git-fixes). * HID: sensor-hub: Fix out-of-bounds write in sensor_hub_get_feature (git- fixes). * HID: sensor: custom: Fix field sysfs group cleanup on failure (git-fixes). * HID: sensor: custom: Fix use-after-free in enable_sensor (git-fixes). * HID: tmff: Use 64-bit arithmetic for force feedback scaling (git-fixes). * hwmon: (corsair-psu) fix possible out-of-bounds access on missing string termination (git-fixes). * hwmon: (lm25066) Use i2c_get_match_data() (stable-fixes). * hwmon: (max6621) fix negative temperature offset and crit readings (git- fixes). * hwmon: (max6621) fix temperature clamp range (git-fixes). * hwmon: (nzxt-smart2) Check return value of init_device() in probe (git- fixes). * hwmon: (pmbus/lm25066) Fix PMBus coefficient calculations (git-fixes). * hwrng: ks-sa - Fix runtime PM cleanup on registration failure (git-fixes). * hwrng: omap - Fix probe error path cleanup (git-fixes). * hwtracing: hisi_ptt: Propagate DMA reset timeout in trace_start() (git- fixes). * i2c: bcm-iproc: remove printout on handled timeouts (stable-fixes). * i2c: core: fix debugfs UAF on adapter removal (git-fixes). * i2c: iproc: reset bus after timeout if START_BUSY is stuck (git-fixes). * i2c: mux: demux-pinctrl: fix OF node leak on kstrdup failure (git-fixes). * i2c: mux: Fix channel node leak on adapter add failure (git-fixes). * i2c: ocores: Disable clock on failed resume (git-fixes). * i3c: dw: avoid shift-out-of-bounds when DAA assigns no devices (git-fixes). * i3c: master: Fix device_register() error path (git-fixes). * i3c: master: Fix info leak and UAF in device unregister path (git-fixes). * i3c: master: Fix potential UAF in i3c_device_uevent() (git-fixes). * i3c: master: svc: bound IBI payload to the requested max_payload_len (git- fixes). * ibmvnic: Only record tx completed bytes once per handler (bsc#1274620). * iio: accel: dmard09: Implement IIO_CHAN_INFO_SCALE (git-fixes). * iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable (git-fixes). * iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF (git-fixes). * iio: chemical: sgp30: Handle IAQ thread creation failure (git-fixes). * iio: dac: m62332: Fix regulator reference count imbalance (git-fixes). * iio: gyro: mpu3050: fix sign of raw angular velocity readings (git-fixes). * iio: light: cm32181: return zero after writing calibscale (git-fixes). * iio: light: gp2ap002: Disable regulators on resume failure (git-fixes). * iio: light: gp2ap002: re-enable irq if runtime suspend fails (git-fixes). * iio: light: isl29028: return zero in write_raw() on success (git-fixes). * iio: light: tsl2583: return zero in write_raw() on success (git-fixes). * iio: light: tsl2772: fix ALS calibscale readback (git-fixes). * iio: orientation: hid-sensor-rotation: Avoid race between callback setup and device exposure (git-fixes). * iio: pressure: dps310: fix NULL pointer dereference on ACPI probe (git- fixes). * iio: pressure: mpl115: Fix runtime PM cleanup (git-fixes). * iio: srf04: fix pm_runtime handling on probe error path (git-fixes). * iio: temperature: hid-sensor-temperature: switch to non-devm iio_device_register() (git-fixes). * Input: atkbd - skip deactivate for HONOR ZQC-P (git-fixes). * Input: atkbd - skip deactivate for Xiaomi Book Pro 14's internal keyboard (stable-fixes). * Input: evdev - fix information leak in evdev_pass_values() (stable-fixes). * Input: evdev - sanitize event type index when fetching event masks (stable- fixes). * Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (git-fixes). * Input: focaltech - use signed coordinates to prevent underflow (git-fixes). * Input: hynitron_cstxxx - validate touch count and finger IDs (git-fixes). * Input: iforce - validate input packet lengths (stable-fixes). * Input: iqs5xx - validate firmware record destination span (git-fixes). * Input: mms114 - fix Y-resolution configuration (git-fixes). * Input: psxpad-spi - set driver data before use (git-fixes). * Input: sur40 - fix input device registration ordering (stable-fixes). * Input: sur40 - fix V4L error path cleanup (stable-fixes). * Input: synaptics-rmi4 - block s_input when F54 queue is busy (git-fixes). * Input: synaptics-rmi4 - bound the F54 report size to the allocated buffer (git-fixes). * Input: synaptics-rmi4 - fix F55 transmitter electrode count typo (git- fixes). * Input: synaptics-rmi4 - propagate F54 worker errors to V4L2 queue (git- fixes). * Input: synaptics-rmi4 - zero report size on F54 work error (git-fixes). * Input: xpad - add support for ZENAIM LEVERLESS (stable-fixes). * interconnect: Fix use after free in icc_get() and of_icc_get_by_index() (git-fixes). * ipmi: ipmb: validate write message length (git-fixes). * ipmi: si: Fix NULL pointer dereference after failed registration (git- fixes). * kthread: Default affine kthread to its preferred NUMA node (bsc#1269313). * kthread: Make sure kthread hasn't started while binding it (bsc#1269313). * KVM: arm64: vgic: Fix IIDR revision field extracted from wrong value (git- fixes). * KVM: PPC: Book3S HV: Add support for compat CPU capabilities for KVM on PowerNV (bsc#1263864 ltc#217835). * KVM: PPC: Book3S HV: Implement compat CPU capability retrieval for KVM on PowerVM (bsc#1263864 ltc#217835). * KVM: PPC: Book3S HV: Validate arch_compat against host compatibility mode (bsc#1263864 ltc#217835). * KVM: PPC: Document KVM_PPC_GET_COMPAT_CAPS ioctl (bsc#1263864 ltc#217835). * KVM: PPC: Introduce KVM_CAP_PPC_COMPAT_CAPS and wire up ioctl (bsc#1263864 ltc#217835). * KVM: x86/mmu: WARN and clear role.invalid when creating a child shadow page (git-fixes). * leds: pca9532: Fix inverted GPIO output polarity (git-fixes). * leds: pca9532: Fix phantom device registration on missing hardware (git- fixes). * lib/string: fix memchr_inv() for large ranges (git-fixes). * lib/ucs2_string.c: fix out-of-bounds read in ucs2_strnlen() (git-fixes). * mailbox: qcom-ipcc: fix duplicate channel allocation across holes (git- fixes). * mailbox: rockchip: disable pclk on probe failure and unbind (git-fixes). * maple_tree: fix argument name in header (git-fixes). * md/raid1: create serial pool adding rdev to array with serialize_policy=1 (bsc#1272261). * media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref (git-fixes). * media: amphion: Remove obsolete frame_count check in venc_start_session (git-fixes). * media: cec-pin: Fix event FIFO ordering (git-fixes). * media: cec: disable delayed work before freeing an interrupted transmit (git-fixes). * media: cec: meson: ao-cec-g12a: name the CEC core regmap to avoid debugfs clash (git-fixes). * media: cec: Serialize exclusive follower delivery (git-fixes). * media: cec: stm32: prevent out-of-bounds write on RX overflow (git-fixes). * media: cedrus: fix memory leak in cedrus_init_ctrls() (git-fixes). * media: cobalt: Avoid freeing ALSA private data twice (git-fixes). * media: cx231xx: reject geometry changes while the VBI queue is busy (git- fixes). * media: cx23885: cancel NetUP CI work before teardown (git-fixes). * media: em28xx: defer audio-only extension registration (git-fixes). * media: em28xx: fix use-after-free of dev_next->devlist on disconnect (git- fixes). * media: go7007: defer the ALSA v4l2 put until card release (git-fixes). * media: i2c: imx219: Rename VTS to FRM_LENGTH (stable-fixes). * media: i2c: ov02a10: fix endpoint parsing use-after-free (git-fixes). * media: i2c: ov7740: fix use-after-destroy in remove (git-fixes). * media: i2c: rdacm21: Fix missing media_entity_cleanup() (git-fixes). * media: imx219: Fix maximum frame length in lines (git-fixes). * media: intel/ipu6: fix async notifier cleanup leak on parse error (git- fixes). * media: keymaps: Remove obsolete RC_MAP_HAUPPAUGE_NEW keymap define (git- fixes). * media: keymaps: Remove obsolete RC_MAP_RC5_TV keymap define (git-fixes). * media: mc-entity: Add missing kerneldoc (git-fixes). * media: meson: vdec: fix NULL pointer deref in vdec_try_fmt_common (git- fixes). * media: nxp: imx8-isi: Correct color map between V4L2 and ISI (git-fixes). * media: nxp: imx8-isi: Fix stream ID validation bypass in crossbar routing (git-fixes). * media: nxp: imx8-isi: Use BIT_ULL() for 64-bit stream masks (git-fixes). * media: rc: sunxi-cir: Unregister rc device on probe failure (git-fixes). * media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure (git-fixes). * media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak (git-fixes). * media: s2255: bound JPEG frame size before copying into the buffer (git- fixes). * media: s2255: check firmware size before reading trailing marker (git- fixes). * media: saa7164: fix cleanup on resource allocation failure (git-fixes). * media: tda18250: fix possible integer overflow (git-fixes). * media: usbtv: keep device alive while ALSA card exists (git-fixes). * media: v4l2-async: avoid deleting unlinked ASC entry on link error (git- fixes). * media: v4l2-async: Unregister sub-device if asc_list is empty (git-fixes). * media: v4l2-ctrls: Allow unknown HDR10 white point and luminance (git- fixes). * media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link (git-fixes). * media: venus: fix payload size calculation in parse_raw_formats() (git- fixes). * media: venus: fix payload size returned by parse_caps() and parse_alloc_mode() (git-fixes). * media: vicodec: fix out-of-bounds write in FWHT encoder (git-fixes). * media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure (git-fixes). * media: vimc: fix pixel format lookup in enum_framesizes (git-fixes). * media: zoran: Avoid freeing a registered video_device twice (git-fixes). * mei: pull kvfree out of spinlock (git-fixes). * mfd: iqs62x: Reject zero-length firmware records (git-fixes). * mfd: rave-sp: validate received frame payload lengths (git-fixes). * misc: bcm-vk: Use acquire/release for msgq_inited (git-fixes). * misc: fastrpc: fix channel ctx ref leak when session alloc fails (git- fixes). * misc: fastrpc: fix memory leak in fastrpc_channel_ctx_free (git-fixes). * misc: fastrpc: Remove buffer from list prior to unmap operation (git-fixes). * misc: fastrpc: take fl->lock when moving mmaps on interrupted invoke (git- fixes). * misc: rtsx: add missing write register handling (git-fixes). * misc: vmc_vmci: Fix potential memory leak in vmci_event_subscribe() (git- fixes). * mkspec-dtb: Move DTS prefix into package list. * mkspec-dtb: Move provides-obsoletes to package list. * mkspec-dtb: Put per-architecture package lists into a hash. * mkspec-dtb: re-indent. * mm: Create/affine kcompactd to its preferred node (bsc#1269313). * mm: Create/affine kswapd to its preferred node (bsc#1269313). * mmc: omap_hsmmc: fix busy_timeout overflow in ns conversion on 32-bit (git- fixes). * mmc: sdhci: unmap the bounce buffer before device release (git-fixes). * mmc: via-sdmmc: stop card-detect handling on probe failure (git-fixes). * mtd: afs: validate v2 image info bounds (git-fixes). * mtd: mtdoops: free page bitmap when the backing MTD is removed (git-fixes). * mtd: mtdswap: Avoid freeing registered blktrans device twice (git-fixes). * mtd: part: reject MTDPART_OFS_RETAIN in mtd_add_partition() (git-fixes). * mtd: rawnand: validate ONFI extended parameter page sections (git-fixes). * net: mana: Add debug knob to skip TX timeout recovery reset (git-fixes). * net: mana: Add handler for sriov configure (bsc#1272756). * net: mana: Cap MSI-X vectors to the device MSI-X table size (git-fixes). * net: mana: Extend RX CQE coalescing up to 8 packets (git-fixes). * net: mana: Fall back to scattered pages for GDMA queues (git-fixes). * net: mana: force full-page RX buffers via ethtool private flag (bsc#1269792). * net: mana: refactor mana_get_strings() and mana_get_sset_count() to use switch (bsc#1269792). * net: mana: Route ring-buffer access through offset-based helpers (git- fixes). * net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). * net: thunderbolt: Count delivered packets in rx_packets and rx_bytes (git- fixes). * net: thunderbolt: Mark the connection down when bringing it up fails (git- fixes). * net: thunderbolt: Release the Rx HopID that was handed out on mismatch (git- fixes). * net: thunderbolt: Tear down DMA paths before stopping the rings (git-fixes). * net: usb: ax88179_178a: fix skb leak in ax88179_tx_fixup() (git-fixes). * net: usb: ipheth: fix carrier_work UAF on disconnect (git-fixes). * nfc: digital: clamp SENSF_RES length to the destination buffer (git-fixes). * nfc: digital: Do not dump a NULL response in command completion (git-fixes). * nfc: fdp: bound the device-reported read length and fix an skb leak (git- fixes). * nfc: llcp: avoid userspace overflow on invalid optlen (git-fixes). * nfc: llcp: bound SNL TLV parsing to the skb and add length checks (git- fixes). * nfc: llcp: bound the connect_sn TLV walk to the skb (git-fixes). * nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers (git-fixes). * nfc: llcp: read llcp_sock->local under the socket lock in getsockopt (git- fixes). * nfc: llcp: reject PDUs shorter than the LLCP header (git-fixes). * nfc: microread: validate target discovery payload lengths (git-fixes). * nfc: nci: fix double completion race in nci_data_exchange_complete (git- fixes). * nfc: nci: fix out-of-bounds write in nci_target_auto_activated() (git- fixes). * nfc: nci: fix uninit-value in the RF discover/activated NTF handlers (git- fixes). * nfc: nci: fix use of uninitialized memory in CORE_INIT_RSP parsing (git- fixes). * nfc: nci: free destination parameters when closing a connection (git-fixes). * nfc: pn533: hold a reference to the request skb during send_frame (git- fixes). * nfc: pn533: purge fragmented skbs during cleanup (git-fixes). * nfc: st21nfca: validate ATR_REQ length against the received frame (git- fixes). * nouveau/gem: reserve the bo in the info ioctl around the vma lookup (git- fixes). * of: fix out-of-bounds read in of_alias_scan() stem parser (git-fixes). * PCI: Add ACS quirk for Pericom PI7C9X2G608 switches [12d8:2608] (git-fixes). * PCI: Fix 32-bit config write in Intel PCH Root Port MPC ACS quirk (git- fixes). * PCI: hv: Set irq_retrigger callback for the Hyper-V PCI MSI irqchip (git- fixes). * PCI: j721e: Fix incorrect max_lanes for J7200 (git-fixes). * PCI: meson: Fix GPIO state while requesting PERST# (git-fixes). * phy: qcom: qmp-combo: Correct pre-emphasis table for QMP v4 DP PHYs (git- fixes). * phy: qcom: snps-femto-v2: Fix possible NULL-deref on early runtime suspend (git-fixes). * phy: rockchip: phy-rockchip-inno-csidphy: fix rk1808 hsfreq table (git- fixes). * phy: sunplus: fix error handling in sp_uphy_init() (git-fixes). * pinctrl: bcm2835: Don't remove an unregistered GPIO chip (git-fixes). * pinctrl: mediatek: mt8167: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: mt8516: Fix Schmitt trigger register offset of pins 34-39 (git-fixes). * pinctrl: mediatek: use devm_gpiochip_add_data() for GPIO chip (git-fixes). * pinctrl: rockchip: Reset the pin count when recalculating SoC data (git- fixes). * platform/chrome: cros_ec_debugfs: Clean up console log on probe failure (git-fixes). * platform/chrome: cros_ec_debugfs: Unregister panic notifier (git-fixes). * platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count (git- fixes). * platform/chrome: sensorhub: Bound the EC-reported sensor number (git-fixes). * platform/chrome: sensorhub: Fix dropped timestamp events and log spam (git- fixes). * platform/chrome: sensorhub: Fix memory overread in ring handler (git-fixes). * platform/mellanox: mlxbf-pmc: Check ACPI_COMPANION() against NULL (git- fixes). * platform/surface: acpi-notify: Check ACPI companion before use (git-fixes). * platform/x86/amd/hsmp: Reject negative power cap writes in hwmon (git- fixes). * platform/x86: dell-privacy: Fix race condition (git-fixes). * platform/x86: dell-wmi-base: Fix resource leak on module load failure (git- fixes). * platform/x86: dell-wmi-sysman: Don't hex dump attribute security buffer (git-fixes). * platform/x86: dell-wmi-sysman: Fix instance ID bounds (git-fixes). * platform/x86: hp-bioscfg: accept reduced ACPI packages from older HP BIOS (git-fixes). * platform/x86: hp-bioscfg: advance elem past consumed array elements (git- fixes). * platform/x86: hp-bioscfg: fix heap OOB read in sk_store() and kek_store() (git-fixes). * platform/x86: hp-bioscfg: fix heap OOB read on empty password write (git- fixes). * platform/x86: hp-bioscfg: fix new_password_store() overwriting current_password (git-fixes). * platform/x86: hp-bioscfg: fix off-by-one write in hp_get_string_from_buffer() (git-fixes). * platform/x86: hp-bioscfg: fix ORD_LIST_ELEMENTS never being parsed (git- fixes). * platform/x86: hp-bioscfg: fix password encoding bounds check (git-fixes). * platform/x86: hp-bioscfg: warn on element type mismatch instead of failing (git-fixes). * platform/x86: ishtp_eclite: Fix ACPI device reference leak in probe error path (git-fixes). * platform/x86: ISST: Add a NULL check for sst_inst (git-fixes). * platform/x86: ISST: Just allow 2 bits for SST feature enable (git-fixes). * platform/x86: ISST: Return error during profile addition (git-fixes). * platform/x86: ISST: Use PP level enable mask (git-fixes). * platform/x86: ISST: Validate level in perf mask ioctls (git-fixes). * platform/x86: ISST: Validate logical CPU id and clos id (git-fixes). * platform/x86: ISST: Validate parameter for core power state (git-fixes). * platform/x86: ISST: Validate socket ID in clos_assoc ioctl (git-fixes). * PM: sleep: Fix off-by-one in wakelocks number limit check (git-fixes). * power: supply: bd99954: Drop bad register fields (git-fixes). * power: supply: bq27xxx: bq27z561: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq28z610: fix invalid AverageEnergy address (git- fixes). * power: supply: bq27xxx: bq27520g4: fix REG_TTES address (git-fixes). * power: supply: bq256xx: drain usb_work before freeing the charger (git- fixes). * power: supply: bq24257: fix use-after-free on remove (git-fixes). * power: supply: bq25890: Fix power_supply reference leak (git-fixes). * power: supply: cros_usbpd-charger: bound the EC-reported port count (git- fixes). * power: supply: cros_usbpd: Limit port counts to EC_USB_PD_MAX_PORTS (git- fixes). * power: supply: isp1704_charger: cancel work on remove (git-fixes). * power: supply: lp8727: fix use-after-free in lp8727_release_irq() (git- fixes). * power: supply: max17040: drop incorrect I2C functionality check (git-fixes). * power: supply: max17040: synchronize work cancellation on suspend (git- fixes). * power: supply: qcom_battmgr: terminate the strings from firmware (git- fixes). * power: supply: rt9455: quiesce delayed work before teardown (git-fixes). * power: supply: sbs-battery: Use a per-device serial number buffer (git- fixes). * power: supply: twl4030_charger: cancel workers via devm (git-fixes). * power: supply: ucs1002: fix use-after-free on remove (git-fixes). * powercap: intel_rapl_tpmi: Handle PMU registration failure during probe (git-fixes). * powerpc/dt_cpu_ftrs: Set CPU_FTR_P11_PVR for Power11 and later processors (bsc#1263864 ltc#217835). * powerpc/pseries: Ensure vpa,slb_shadow & dtl are unregistered during crash (bsc#1271256). * powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). * powerpc/pseries: pci - logic bug (bsc#1274749 ltc#221282 bsc#1274755 ltc#221284 bsc#1274756 ltc#221283). * powerpc: Replace **ASSEMBLY** with **ASSEMBLER** in non-uapi headers (bsc#1263864 ltc#217835). * powerpc: Replace **ASSEMBLY** with **ASSEMBLER** in uapi headers (bsc#1263864 ltc#217835). * ppdev: prevent overflow when setting port timeout (git-fixes). * qede: fix out-of-bounds check for cqe->len_list (git-fixes). * rapidio: clear mport->net when rio_add_net() fails (git-fixes). * rapidio: mport_cdev: fix use-after-free in dma_req_free() (git-fixes). * RDMA/irdma: Remove redundant legacy_mode checks (git-fixes). * RDMA/mana_ib: drain QP references after partial table insertion (git-fixes). * RDMA/mana_ib: unify QP lookup table (git-fixes). * RDMA/mlx5: Fix integer overflow of user QP buffer size (git-fixes). * regulator: as3722_get_regulator_dt_data: fix premature of_node_put leaving dangling of_node pointer (git-fixes). * regulator: core: use system_freezable_wq for init complete work (git-fixes). * regulator: devres: add API for reference voltage supplies (stable-fixes). * regulator: devres: fix devm_regulator_get_enable_read_voltage() return (git- fixes). * regulator: max8998_pmic_dt_parse_pdata: of_node_put on reg_np after ownership transferred to rdata (git-fixes). * regulator: qcom-rpmh: Fix PMIC5 BOB bypass mode handling (git-fixes). * remoteproc: qcom: Fix glink->node reference leak in qcom_add_glink_subdev (git-fixes). * remoteproc: qcom_q6v5_adsp: Fix reference leak for device node (git-fixes). * remoteproc: scp: Fix device reference leak on failed lookup (git-fixes). * Revert "drm/amdgpu: fix aperture mapping leak" (git-fixes). * Revert "media: v4l2-dev: fix error handling in __video_register_device()" (git-fixes). * Revert "thermal/drivers/hwmon: Cleanup coding style a bit" (stable-fixes). * rpmsg: core: Fix incorrect return value documentation (git-fixes). * rpmsg: glink: smem: order FIFO read after availability check (git-fixes). * rtc: gamecube: check return value of devm_rtc_register_device() (git-fixes). * rtc: pcf8563: fix clock provider leak on unbind (git-fixes). * rtc: pcf85363: Add error checking to regmap calls in probe() (git-fixes). * rtc: rzn1: Disable alarm interrupt before reprogramming alarm registers (git-fixes). * rtc: rzn1: Fix weekday underflow when alarm crosses month boundary (git- fixes). * rtc: zynqmp: Return optional clock lookup errors (git-fixes). * sched,arm64: Handle CPU isolation on last resort fallback rq (bsc#1269313). * scsi: fnic: Abort timed-out NVMe LS requests (bsc#1236344). * scsi: fnic: Add FDLS role handling for NVMe initiators (bsc#1236344). * scsi: fnic: Add the NVMe/FC transport path (bsc#1236344). * scsi: fnic: Advertise NVMe initiator service parameters (bsc#1236344). * scsi: fnic: Bump up version number (bsc#1236344). * scsi: fnic: Decode firmware role configuration (bsc#1236344). * scsi: fnic: Do not use GFP_ZERO for mempools (bsc#1236344). * scsi: fnic: Expose NVMe transport state in debugfs (bsc#1236344). * scsi: fnic: Handle NVMe LS frames in FDLS (bsc#1236344). * scsi: fnic: Make debug logging protocol independent (bsc#1236344). * scsi: fnic: Make fnic_queuecommand() easier to analyze (bsc#1236344). * scsi: fnic: Refactor in_remove flag and call to fnic_fcpio_reset() (bsc#1236344). * scsi: fnic: Remove a useless struct mempool forward declaration (bsc#1236344). * scsi: fnic: Rename fnic_scsi_fcpio_reset() (bsc#1236344). * scsi: fnic: Route completions and resets by initiator role (bsc#1236344). * scsi: fnic: Self-assignment of intr_time_type has no effect (bsc#1236344). * scsi: fnic: Send NVMe LS requests through FDLS (bsc#1236344). * scsi: fnic: Switch to use %ptSp (bsc#1236344). * scsi: fnic: Track NVMe transport statistics (bsc#1236344). * scsi: fnic: Use fnic_num for non-SCSI identifiers (bsc#1236344). * scsi: fnic: Use mempool for receive frames (bsc#1236344). * scsi: qla2xxx: Declare qla2xxx_mqueuecommand() static (bsc#1275737). * scsi: qla2xxx: Use nr_cpu_ids instead of NR_CPUS for qp_cpu_map allocation (bsc#1275737). * scsi: storvsc: Support manual scans for all Hyper-V targets (git-fixes). * sctp: avoid auth_enable sysctl UAF during netns teardown (git-fixes). * serial: 8250_dma: Clear stale RX state on shutdown (git-fixes). * serial: amba-pl011: unprepare console clock on unregister (git-fixes). * serial: core: clear freed pointers on uart_register_driver() failure (git- fixes). * serial: qcom-geni: fix TX DMA buffer flush (git-fixes). * serial: sc16is7xx: fix copy-paste errors in EFR_SWFLOWx_BIT constants (stable-fixes). * smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). * smb: client: reject overlapping data areas in SMB2 responses (git-fixes). * smb: client: require net admin for CIFS SWN netlink (bsc#1273966). * smb: client: resolve SWN tcon from live registrations (bsc#1273872). * soc: fsl: qe: check platform_driver_register() in qe_ic_of_init() (git- fixes). * soc: qcom: rpmh-rsc: manage PM notifiers with devres (git-fixes). * soc: samsung: exynos-pmu: fix of_node refcount leak in exynos_get_pmu_regmap() (git-fixes). * software node: Fix software_node_get_reference_args() with index -1 (git- fixes). * soundwire: qcom: Fix port exhaustion check in stream_alloc_ports (git- fixes). * speakup: keyhelp: guard letter_offsets possible out-of-range indexing (git- fixes). * spi: img-spfi: don't disable runtime PM on DMA deferred probe (git-fixes). * spi: spi-fsl-dspi: Avoid setup_accel logic for DMA transfers (stable-fixes). * spi: sprd-adi: Fix probe succeeding without registering the controller (git- fixes). * staging: fbtft: Use sysfs_emit_at() to print to sysfs file (git-fixes). * staging: media: tegra-video: fix of_node_put() on VIP parse errors (git- fixes). * staging: media: tegra-video: vi: fix probe failure on skipped last port (git-fixes). * staging: octeon: add missing tasklet_kill in cvm_oct_tx_shutdown (git- fixes). * staging: rtl8723bs: fix mismatched free of HalData in rtw_sdio_if1_init() (git-fixes). * staging: rtl8723bs: fix missing shared-key auth challenge length check (git- fixes). * staging: rtl8723bs: fix OOB read in rtw_get_wpa_ie() (git-fixes). * staging: rtl8723bs: fix OOB read in WMM_param_handler() (git-fixes). * staging: rtl8723bs: use kfree_sensitive() for key material (git-fixes). * staging: rtl8723bs: validate monitor transmit frame lengths (git-fixes). * staging: sm750fb: gate dualview dataflow using g_dualview (git-fixes). * thermal/drivers/imx: Disable clock on runtime resume failure (git-fixes). * thermal/drivers/qoriq: Disable clock on resume failure (git-fixes). * thermal: intel: int3400: clean up ODVP on probe failures (git-fixes). * thunderbolt: Bound the DROM dual link port number before indexing sw->ports (git-fixes). * thunderbolt: Fix bandwidth group reservation indexing (git-fixes). * thunderbolt: icm: Preserve USB4 proxy data-valid bit (git-fixes). * tlclk: if sscanf() fails, fall back to 0, not random value (git-fixes). * tpm: st33zp24: Return zero on status read failure (git-fixes). * tpm: st33zp24: Validate locality read result (git-fixes). * tpm: tpm_i2c_nuvoton: disable IRQ on wait timeout (git-fixes). * tty: clear cdev pointer after cdev_add() failure (git-fixes). * tty: hvc: restrict HVC_DCC to ARMv6+ and ARM64 (git-fixes). * tty: skip cdev_del() when no cdev is registered (git-fixes). * uaccess: add copy_struct_to_user helper (bsc#1263864 ltc#217835). * uaccess: fix ignored_trailing logic in copy_struct_to_user() (bsc#1263864 ltc#217835). * uio: Fix stale info pointer in failed registration path (git-fixes). * usb: atm: cxacru: properly kill rcv_urb on error in cxacru_cm() (git-fixes). * usb: atm: usbatm: fix invalid ci_range initialization (git-fixes). * USB: c67x00: fix use-after-free in c67x00_add_iso_urb() (git-fixes). * usb: cdnsp: fix incorrect endian conversions for APB timeout register (git- fixes). * usb: dwc2: add missing @remotewakeup kernel-doc parameter (git-fixes). * usb: dwc2: gadget: Exit partial power down state when changing USB pull-up (git-fixes). * usb: gadget: configfs: fix out-of-bounds read of qw_sign (git-fixes). * usb: gadget: f_fs: Prevent deadlock during ep0 read loop (git-fixes). * usb: gadget: f_ncm: Use unsigned int for ndp_index (git-fixes). * usb: gadget: f_tcm: fix deadlock in usbg_make_tpg() (git-fixes). * usb: gadget: f_uac1_legacy: remove broken string configfs attributes (git- fixes). * usb: gadget: pch_udc: remove excess kernel-doc member for registered (git- fixes). * usb: gadget: r8a66597: avoid double free of ep0_req in probe error path (git-fixes). * usb: gadget: snps_udc_plat: clean up PHY on probe deferral (git-fixes). * usb: gadget: u_audio: Fix use-after-free on sound card disconnect (git- fixes). * usb: gadget: uac: validate rate list length before storing (git-fixes). * usb: gadget: uvc: fix dangling pointers in uvc_function_bind() and uvc_function_unbind() (git-fixes). * usb: mtu3: allow system suspend during active gadget connection (git-fixes). * usb: musb: omap2430: clean up probe error handling (stable-fixes). * USB: phy: fsl-usb: fix missing static keywords (git-fixes). * usb: renesas_usbhs: Fix power-off ordering on unbind (git-fixes). * USB: serial: digi_acceleport: fix port registration order (git-fixes). * USB: serial: ftdi_sio: add support for E+H FXA291 (stable-fixes). * USB: serial: option: add TDTECH MT5710-CN (stable-fixes). * USB: serial: option: fix slab OOB read in interrupt URB callback (git- fixes). * USB: serial: spcp8x5: drop broken carrier detect support (git-fixes). * USB: storage: add NO_ATA_1X quirk for Longmai USB Key (stable-fixes). * usb: typec: tcpci: pass correct rx_type to tcpm_pd_receive() (git-fixes). * usb: typec: ucsi: unregister debugfs entries on teardown (git-fixes). * usb: usbfs: fix use-after-free of usb_device in usbdev_release() (git- fixes). * usb: xhci: Handle USB3 port events when there is one roothub (git-fixes). * vt: add permission check for KDSKBMETA ioctl (stable-fixes). * vt: stabilize tty reference in kbd_keycode with tty_port_tty_get (stable- fixes). * w1: ds28e17: reject an oversize length on an I2C block read (git-fixes). * w1: ds2482: Fix signedness bug in ds2482_w1_triplet() (git-fixes). * wifi: ath6kl: avoid buffer overreads in WMI event handlers (git-fixes). * wifi: ath6kl: clamp assoc request/response lengths before subtracting IE offsets (git-fixes). * wifi: ath10k: snoc: use memcpy_fromio() for MSA ramdump (git-fixes). * wifi: ath11k: Avoid buffer overread in ath11k_wmi_tlv_op_rx() (git-fixes). * wifi: ath11k: cap out-of-range rx MCS instead of leaving bogus rate (git- fixes). * wifi: ath11k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: ath12k: Avoid buffer overread in ath12k_wmi_op_rx() (git-fixes). * wifi: ath12k: Correctly copy the hint BSSID in WMI scan request (git-fixes). * wifi: brcmfmac: Fix memory leak in brcmf_sdio_read_control() (git-fixes). * wifi: brcmfmac: fix P2P action frame handling without device vif (git- fixes). * wifi: iwlwifi: fix counter type in iwl_fwrt_dump_error_logs (git-fixes). * wifi: iwlwifi: guard against division by zero in iwl_dbg_tlv_alloc_fragments (git-fixes). * wifi: iwlwifi: mei: check SAP message length before reading it (git-fixes). * wifi: iwlwifi: mei: pass correct argument to function (git-fixes). * wifi: iwlwifi: mvm: fix off-by-one in TXF key sanitiser (git-fixes). * wifi: mac80211: disconnect on CSA to channel 0 (git-fixes). * wifi: mac80211: fix multi-link element inheritance (git-fixes). * wifi: mac80211: fix per-STA profile length in cross-link CSA parsing (git- fixes). * wifi: mac80211: send TWT teardown to peer after setup TX failure (git- fixes). * wifi: mac80211: skip default WMM setup for AP_VLAN links (git-fixes). * wifi: mac80211: skip unused probe response countdown offsets (git-fixes). * wifi: mt76: fix 4th chain ACK RSSI bitmask in sta_poll (git-fixes). * wifi: mt76: fix ER-SU 106-tone RU check in RX rate decode (git-fixes). * wifi: mt76: fix HE DCM max-RU capability encoding (git-fixes). * wifi: mt76: mt76x02: do not WARN on invalid rx descriptor length (git- fixes). * wifi: mt76: mt792x: Fix memory leak in SDIO TX path (git-fixes). * wifi: mt76: mt7615: avoid waiting for mac work under the mt76 mutex (git- fixes). * wifi: mt76: mt7915: avoid nss underflow in mt7915_mcu_get_sta_nss (git- fixes). * wifi: mt76: mt7915: fix double hif2 init on the non-WED path (git-fixes). * wifi: mt76: mt7915: fix ext PHY use-after-free on register error path (git- fixes). * wifi: mt76: mt7915: fix net_fill_forward_path for non-DBDC mt7986 (git- fixes). * wifi: mt76: mt7915: poll the correct SLP CTRL register for the second adie (git-fixes). * wifi: mt76: mt7915: release hif2 reference on probe IRQ failure (git-fixes). * wifi: mt76: mt7915: unlink TWT flow if the MCU rejects the agreement (git- fixes). * wifi: mt76: mt7915: unwind state on add_interface failure (git-fixes). * wifi: mt76: mt7915: use little-endian for bss_info_ra wire fields (git- fixes). * wifi: mt76: mt7915: write RX header translation bit to the correct register (git-fixes). * wifi: mt76: mt7921: validate CLC firmware records (git-fixes). * wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb (git- fixes). * wifi: mt76: mt7925: fix msg len mismatch between driver and firmware (git- fixes). * wifi: mt76: mt7996: bound TLV walk in mt7996_mcu_get_chip_config (git- fixes). * wifi: mt76: mt7996: don't report a zero TX bitrate (git-fixes). * wifi: mt76: mt7996: fix capability of EHT-MCS 15 in MRU (git-fixes). * wifi: mt76: mt7996: fix reg addr remap when addr is 0 (git-fixes). * wifi: mt76: mt7996: reserve space for the CSA-abort countdown TLV (git- fixes). * wifi: mt76: mt7996: set MT76_MCU_RESET before waking MCU waiters on full reset (git-fixes). * wifi: mt76: mt7996: validate RX band_idx before dereferencing phys (git- fixes). * wifi: mt76: report data NSS for STBC frames in RX rate decode (git-fixes). * wifi: mwifiex: Detach sync cmd buffer on interrupted wait (git-fixes). * wifi: rtl818x: initialize eeprom_93cx6 struct to zero (git-fixes). * wifi: rtlwifi: pci: fix error path in rtl_pci_probe() (git-fixes). * wifi: rtw88: Fix potential memory leak in rtw_txq_push_skb() (git-fixes). * wifi: rtw89: fix HE extended capability length check (git-fixes). * wifi: zd1211rw: reject secondary interfaces to prevent conflicts (git- fixes). * x86/bugs: Clarify that syscall hardening isn't a BHI mitigation (git-fixes). * x86/cpu: Add CPU model number for Bartlett Lake CPUs with Raptor Cove cores (bsc#1240957 bsc#1249104 bsc#1265220). * xhci: dbgtty: Fix unregister on tty_alloc_driver() failure (git-fixes). * xhci: dbgtty: Fix unregister on tty_register_driver() failure (git-fixes). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-HA-15-SP7-2026-4254 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4254 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-4254 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-4254 * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-4254 Please note that this is the initial kernel livepatch without fixes itself, this package is later updated by separate standalone kernel livepatch updates. * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-4254 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-4254 ## Package List: * SUSE Linux Enterprise High Availability Extension 15 SP7 (aarch64 ppc64le s390x x86_64) * gfs2-kmp-default-6.4.0-150700.53.81.1 * cluster-md-kmp-default-6.4.0-150700.53.81.1 * kernel-default-debuginfo-6.4.0-150700.53.81.1 * ocfs2-kmp-default-debuginfo-6.4.0-150700.53.81.1 * dlm-kmp-default-debuginfo-6.4.0-150700.53.81.1 * ocfs2-kmp-default-6.4.0-150700.53.81.1 * gfs2-kmp-default-debuginfo-6.4.0-150700.53.81.1 * dlm-kmp-default-6.4.0-150700.53.81.1 * cluster-md-kmp-default-debuginfo-6.4.0-150700.53.81.1 * kernel-default-debugsource-6.4.0-150700.53.81.1 * SUSE Linux Enterprise High Availability Extension 15 SP7 (nosrc) * kernel-default-6.4.0-150700.53.81.1 * Basesystem Module 15-SP7 (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-6.4.0-150700.53.81.1 * Basesystem Module 15-SP7 (aarch64 ppc64le x86_64) * kernel-default-base-6.4.0-150700.53.81.1.150700.17.45.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-default-devel-debuginfo-6.4.0-150700.53.81.1 * kernel-default-debugsource-6.4.0-150700.53.81.1 * kernel-default-devel-6.4.0-150700.53.81.1 * kernel-default-debuginfo-6.4.0-150700.53.81.1 * Basesystem Module 15-SP7 (noarch) * kernel-macros-6.4.0-150700.53.81.1 * kernel-devel-6.4.0-150700.53.81.1 * Basesystem Module 15-SP7 (nosrc s390x) * kernel-zfcpdump-6.4.0-150700.53.81.1 * Basesystem Module 15-SP7 (s390x) * kernel-zfcpdump-debugsource-6.4.0-150700.53.81.1 * kernel-zfcpdump-debuginfo-6.4.0-150700.53.81.1 * Basesystem Module 15-SP7 (aarch64 nosrc) * kernel-64kb-6.4.0-150700.53.81.1 * Basesystem Module 15-SP7 (aarch64) * kernel-64kb-debuginfo-6.4.0-150700.53.81.1 * kernel-64kb-devel-6.4.0-150700.53.81.1 * kernel-64kb-devel-debuginfo-6.4.0-150700.53.81.1 * kernel-64kb-debugsource-6.4.0-150700.53.81.1 * Development Tools Module 15-SP7 (noarch nosrc) * kernel-docs-6.4.0-150700.53.81.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * kernel-syms-6.4.0-150700.53.81.1 * kernel-obs-build-6.4.0-150700.53.81.1 * kernel-obs-build-debugsource-6.4.0-150700.53.81.1 * Development Tools Module 15-SP7 (noarch) * kernel-source-6.4.0-150700.53.81.1 * Legacy Module 15-SP7 (nosrc) * kernel-default-6.4.0-150700.53.81.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * reiserfs-kmp-default-6.4.0-150700.53.81.1 * kernel-default-debugsource-6.4.0-150700.53.81.1 * reiserfs-kmp-default-debuginfo-6.4.0-150700.53.81.1 * kernel-default-debuginfo-6.4.0-150700.53.81.1 * SUSE Linux Enterprise Live Patching 15-SP7 (nosrc) * kernel-default-6.4.0-150700.53.81.1 * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-default-debuginfo-6.4.0-150700.53.81.1 * kernel-livepatch-6_4_0-150700_53_81-default-1-150700.15.3.1 * kernel-default-livepatch-6.4.0-150700.53.81.1 * kernel-livepatch-6_4_0-150700_53_81-default-debuginfo-1-150700.15.3.1 * kernel-livepatch-SLE15-SP7_Update_21-debugsource-1-150700.15.3.1 * kernel-default-livepatch-devel-6.4.0-150700.53.81.1 * kernel-default-debugsource-6.4.0-150700.53.81.1 * Public Cloud Module 15-SP7 (aarch64 nosrc x86_64) * kernel-azure-6.4.0-150700.53.81.1 * Public Cloud Module 15-SP7 (aarch64 x86_64) * kernel-azure-devel-6.4.0-150700.53.81.1 * kernel-azure-debugsource-6.4.0-150700.53.81.1 * kernel-azure-debuginfo-6.4.0-150700.53.81.1 * kernel-azure-devel-debuginfo-6.4.0-150700.53.81.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (nosrc) * kernel-default-6.4.0-150700.53.81.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * kernel-default-extra-debuginfo-6.4.0-150700.53.81.1 * kernel-default-extra-6.4.0-150700.53.81.1 * kernel-default-debugsource-6.4.0-150700.53.81.1 * kernel-default-debuginfo-6.4.0-150700.53.81.1 ## References: * https://www.suse.com/security/cve/CVE-2024-44981.html * https://www.suse.com/security/cve/CVE-2024-57841.html * https://www.suse.com/security/cve/CVE-2025-23137.html * https://www.suse.com/security/cve/CVE-2025-38469.html * https://www.suse.com/security/cve/CVE-2025-39939.html * https://www.suse.com/security/cve/CVE-2025-39964.html * https://www.suse.com/security/cve/CVE-2025-40022.html * https://www.suse.com/security/cve/CVE-2025-40199.html * https://www.suse.com/security/cve/CVE-2025-68179.html * https://www.suse.com/security/cve/CVE-2025-68214.html * https://www.suse.com/security/cve/CVE-2025-71075.html * https://www.suse.com/security/cve/CVE-2025-71104.html * https://www.suse.com/security/cve/CVE-2026-23210.html * https://www.suse.com/security/cve/CVE-2026-23227.html * https://www.suse.com/security/cve/CVE-2026-23230.html * https://www.suse.com/security/cve/CVE-2026-23454.html * https://www.suse.com/security/cve/CVE-2026-31418.html * https://www.suse.com/security/cve/CVE-2026-31531.html * https://www.suse.com/security/cve/CVE-2026-31557.html * https://www.suse.com/security/cve/CVE-2026-31658.html * https://www.suse.com/security/cve/CVE-2026-31663.html * https://www.suse.com/security/cve/CVE-2026-43014.html * https://www.suse.com/security/cve/CVE-2026-43015.html * https://www.suse.com/security/cve/CVE-2026-43116.html * https://www.suse.com/security/cve/CVE-2026-43125.html * https://www.suse.com/security/cve/CVE-2026-43163.html * https://www.suse.com/security/cve/CVE-2026-43213.html * https://www.suse.com/security/cve/CVE-2026-43271.html * https://www.suse.com/security/cve/CVE-2026-43273.html * https://www.suse.com/security/cve/CVE-2026-43363.html * https://www.suse.com/security/cve/CVE-2026-43386.html * https://www.suse.com/security/cve/CVE-2026-43416.html * https://www.suse.com/security/cve/CVE-2026-43448.html * https://www.suse.com/security/cve/CVE-2026-45897.html * https://www.suse.com/security/cve/CVE-2026-45968.html * https://www.suse.com/security/cve/CVE-2026-46070.html * https://www.suse.com/security/cve/CVE-2026-46078.html * https://www.suse.com/security/cve/CVE-2026-46091.html * https://www.suse.com/security/cve/CVE-2026-46107.html * https://www.suse.com/security/cve/CVE-2026-46115.html * https://www.suse.com/security/cve/CVE-2026-46127.html * https://www.suse.com/security/cve/CVE-2026-46195.html * https://www.suse.com/security/cve/CVE-2026-52920.html * https://www.suse.com/security/cve/CVE-2026-52925.html * https://www.suse.com/security/cve/CVE-2026-52929.html * https://www.suse.com/security/cve/CVE-2026-52935.html * https://www.suse.com/security/cve/CVE-2026-52939.html * https://www.suse.com/security/cve/CVE-2026-52946.html * https://www.suse.com/security/cve/CVE-2026-52975.html * https://www.suse.com/security/cve/CVE-2026-52977.html * https://www.suse.com/security/cve/CVE-2026-52990.html * https://www.suse.com/security/cve/CVE-2026-52994.html * https://www.suse.com/security/cve/CVE-2026-53001.html * https://www.suse.com/security/cve/CVE-2026-53033.html * https://www.suse.com/security/cve/CVE-2026-53034.html * https://www.suse.com/security/cve/CVE-2026-53059.html * https://www.suse.com/security/cve/CVE-2026-53076.html * https://www.suse.com/security/cve/CVE-2026-53077.html * https://www.suse.com/security/cve/CVE-2026-53089.html * https://www.suse.com/security/cve/CVE-2026-53091.html * https://www.suse.com/security/cve/CVE-2026-53094.html * https://www.suse.com/security/cve/CVE-2026-53096.html * https://www.suse.com/security/cve/CVE-2026-53110.html * https://www.suse.com/security/cve/CVE-2026-53111.html * https://www.suse.com/security/cve/CVE-2026-53126.html * https://www.suse.com/security/cve/CVE-2026-53142.html * https://www.suse.com/security/cve/CVE-2026-53154.html * https://www.suse.com/security/cve/CVE-2026-53163.html * https://www.suse.com/security/cve/CVE-2026-53180.html * https://www.suse.com/security/cve/CVE-2026-53207.html * https://www.suse.com/security/cve/CVE-2026-53219.html * https://www.suse.com/security/cve/CVE-2026-53220.html * https://www.suse.com/security/cve/CVE-2026-53223.html * https://www.suse.com/security/cve/CVE-2026-53228.html * https://www.suse.com/security/cve/CVE-2026-53238.html * https://www.suse.com/security/cve/CVE-2026-53260.html * https://www.suse.com/security/cve/CVE-2026-53263.html * https://www.suse.com/security/cve/CVE-2026-53264.html * https://www.suse.com/security/cve/CVE-2026-53269.html * https://www.suse.com/security/cve/CVE-2026-53273.html * https://www.suse.com/security/cve/CVE-2026-53309.html * https://www.suse.com/security/cve/CVE-2026-53330.html * https://www.suse.com/security/cve/CVE-2026-53336.html * https://www.suse.com/security/cve/CVE-2026-53337.html * https://www.suse.com/security/cve/CVE-2026-53353.html * https://www.suse.com/security/cve/CVE-2026-53365.html * https://www.suse.com/security/cve/CVE-2026-53366.html * https://www.suse.com/security/cve/CVE-2026-53381.html * https://www.suse.com/security/cve/CVE-2026-53388.html * https://www.suse.com/security/cve/CVE-2026-63801.html * https://www.suse.com/security/cve/CVE-2026-63808.html * https://www.suse.com/security/cve/CVE-2026-63810.html * https://www.suse.com/security/cve/CVE-2026-63823.html * https://www.suse.com/security/cve/CVE-2026-63827.html * https://www.suse.com/security/cve/CVE-2026-63828.html * https://www.suse.com/security/cve/CVE-2026-63842.html * https://www.suse.com/security/cve/CVE-2026-63850.html * https://www.suse.com/security/cve/CVE-2026-63860.html * https://www.suse.com/security/cve/CVE-2026-63865.html * https://www.suse.com/security/cve/CVE-2026-63868.html * https://www.suse.com/security/cve/CVE-2026-63879.html * https://www.suse.com/security/cve/CVE-2026-63881.html * https://www.suse.com/security/cve/CVE-2026-63886.html * https://www.suse.com/security/cve/CVE-2026-63887.html * https://www.suse.com/security/cve/CVE-2026-63888.html * https://www.suse.com/security/cve/CVE-2026-63889.html * https://www.suse.com/security/cve/CVE-2026-63891.html * https://www.suse.com/security/cve/CVE-2026-63898.html * https://www.suse.com/security/cve/CVE-2026-63920.html * https://www.suse.com/security/cve/CVE-2026-63923.html * https://www.suse.com/security/cve/CVE-2026-63925.html * https://www.suse.com/security/cve/CVE-2026-63926.html * https://www.suse.com/security/cve/CVE-2026-63928.html * https://www.suse.com/security/cve/CVE-2026-63937.html * https://www.suse.com/security/cve/CVE-2026-63944.html * https://www.suse.com/security/cve/CVE-2026-63969.html * https://www.suse.com/security/cve/CVE-2026-63970.html * https://www.suse.com/security/cve/CVE-2026-63972.html * https://www.suse.com/security/cve/CVE-2026-63973.html * https://www.suse.com/security/cve/CVE-2026-63980.html * https://www.suse.com/security/cve/CVE-2026-63985.html * https://www.suse.com/security/cve/CVE-2026-63990.html * https://www.suse.com/security/cve/CVE-2026-63992.html * https://www.suse.com/security/cve/CVE-2026-63995.html * https://www.suse.com/security/cve/CVE-2026-63996.html * https://www.suse.com/security/cve/CVE-2026-63997.html * https://www.suse.com/security/cve/CVE-2026-63998.html * https://www.suse.com/security/cve/CVE-2026-63999.html * https://www.suse.com/security/cve/CVE-2026-64000.html * https://www.suse.com/security/cve/CVE-2026-64001.html * https://www.suse.com/security/cve/CVE-2026-64002.html * https://www.suse.com/security/cve/CVE-2026-64004.html * https://www.suse.com/security/cve/CVE-2026-64005.html * https://www.suse.com/security/cve/CVE-2026-64006.html * https://www.suse.com/security/cve/CVE-2026-64007.html * https://www.suse.com/security/cve/CVE-2026-64010.html * https://www.suse.com/security/cve/CVE-2026-64011.html * https://www.suse.com/security/cve/CVE-2026-64014.html * https://www.suse.com/security/cve/CVE-2026-64015.html * https://www.suse.com/security/cve/CVE-2026-64018.html * https://www.suse.com/security/cve/CVE-2026-64021.html * https://www.suse.com/security/cve/CVE-2026-64029.html * https://www.suse.com/security/cve/CVE-2026-64033.html * https://www.suse.com/security/cve/CVE-2026-64034.html * https://www.suse.com/security/cve/CVE-2026-64039.html * https://www.suse.com/security/cve/CVE-2026-64047.html * https://www.suse.com/security/cve/CVE-2026-64048.html * https://www.suse.com/security/cve/CVE-2026-64051.html * https://www.suse.com/security/cve/CVE-2026-64052.html * https://www.suse.com/security/cve/CVE-2026-64055.html * https://www.suse.com/security/cve/CVE-2026-64056.html * https://www.suse.com/security/cve/CVE-2026-64073.html * https://www.suse.com/security/cve/CVE-2026-64083.html * https://www.suse.com/security/cve/CVE-2026-64084.html * https://www.suse.com/security/cve/CVE-2026-64085.html * https://www.suse.com/security/cve/CVE-2026-64086.html * https://www.suse.com/security/cve/CVE-2026-64087.html * https://www.suse.com/security/cve/CVE-2026-64088.html * https://www.suse.com/security/cve/CVE-2026-64097.html * https://www.suse.com/security/cve/CVE-2026-64098.html * https://www.suse.com/security/cve/CVE-2026-64099.html * https://www.suse.com/security/cve/CVE-2026-64102.html * https://www.suse.com/security/cve/CVE-2026-64109.html * https://www.suse.com/security/cve/CVE-2026-64112.html * https://www.suse.com/security/cve/CVE-2026-64113.html * https://www.suse.com/security/cve/CVE-2026-64114.html * https://www.suse.com/security/cve/CVE-2026-64115.html * https://www.suse.com/security/cve/CVE-2026-64118.html * https://www.suse.com/security/cve/CVE-2026-64121.html * https://www.suse.com/security/cve/CVE-2026-64125.html * https://www.suse.com/security/cve/CVE-2026-64126.html * https://www.suse.com/security/cve/CVE-2026-64127.html * https://www.suse.com/security/cve/CVE-2026-64128.html * https://www.suse.com/security/cve/CVE-2026-64131.html * https://www.suse.com/security/cve/CVE-2026-64133.html * https://www.suse.com/security/cve/CVE-2026-64134.html * https://www.suse.com/security/cve/CVE-2026-64135.html * https://www.suse.com/security/cve/CVE-2026-64136.html * https://www.suse.com/security/cve/CVE-2026-64137.html * https://www.suse.com/security/cve/CVE-2026-64144.html * https://www.suse.com/security/cve/CVE-2026-64146.html * https://www.suse.com/security/cve/CVE-2026-64148.html * https://www.suse.com/security/cve/CVE-2026-64155.html * https://www.suse.com/security/cve/CVE-2026-64164.html * https://www.suse.com/security/cve/CVE-2026-64166.html * https://www.suse.com/security/cve/CVE-2026-64168.html * https://www.suse.com/security/cve/CVE-2026-64178.html * https://www.suse.com/security/cve/CVE-2026-64180.html * https://www.suse.com/security/cve/CVE-2026-64185.html * https://www.suse.com/security/cve/CVE-2026-64188.html * https://www.suse.com/security/cve/CVE-2026-64190.html * https://www.suse.com/security/cve/CVE-2026-64192.html * https://www.suse.com/security/cve/CVE-2026-64214.html * https://www.suse.com/security/cve/CVE-2026-64217.html * https://www.suse.com/security/cve/CVE-2026-64218.html * https://www.suse.com/security/cve/CVE-2026-64219.html * https://www.suse.com/security/cve/CVE-2026-64222.html * https://www.suse.com/security/cve/CVE-2026-64224.html * https://www.suse.com/security/cve/CVE-2026-64225.html * https://www.suse.com/security/cve/CVE-2026-64237.html * https://www.suse.com/security/cve/CVE-2026-64243.html * https://www.suse.com/security/cve/CVE-2026-64244.html * https://www.suse.com/security/cve/CVE-2026-64245.html * https://www.suse.com/security/cve/CVE-2026-64246.html * https://www.suse.com/security/cve/CVE-2026-64247.html * https://www.suse.com/security/cve/CVE-2026-64249.html * https://www.suse.com/security/cve/CVE-2026-64257.html * https://www.suse.com/security/cve/CVE-2026-64266.html * https://www.suse.com/security/cve/CVE-2026-64268.html * https://www.suse.com/security/cve/CVE-2026-64269.html * https://www.suse.com/security/cve/CVE-2026-64271.html * https://www.suse.com/security/cve/CVE-2026-64273.html * https://www.suse.com/security/cve/CVE-2026-64274.html * https://www.suse.com/security/cve/CVE-2026-64275.html * https://www.suse.com/security/cve/CVE-2026-64276.html * https://www.suse.com/security/cve/CVE-2026-64277.html * https://www.suse.com/security/cve/CVE-2026-64286.html * https://www.suse.com/security/cve/CVE-2026-64287.html * https://www.suse.com/security/cve/CVE-2026-64294.html * https://www.suse.com/security/cve/CVE-2026-64296.html * https://www.suse.com/security/cve/CVE-2026-64303.html * https://www.suse.com/security/cve/CVE-2026-64304.html * https://www.suse.com/security/cve/CVE-2026-64305.html * https://www.suse.com/security/cve/CVE-2026-64306.html * https://www.suse.com/security/cve/CVE-2026-64312.html * https://www.suse.com/security/cve/CVE-2026-64313.html * https://www.suse.com/security/cve/CVE-2026-64315.html * https://www.suse.com/security/cve/CVE-2026-64316.html * https://www.suse.com/security/cve/CVE-2026-64317.html * https://www.suse.com/security/cve/CVE-2026-64322.html * https://www.suse.com/security/cve/CVE-2026-64323.html * https://www.suse.com/security/cve/CVE-2026-64329.html * https://www.suse.com/security/cve/CVE-2026-64331.html * https://www.suse.com/security/cve/CVE-2026-64332.html * https://www.suse.com/security/cve/CVE-2026-64333.html * https://www.suse.com/security/cve/CVE-2026-64334.html * https://www.suse.com/security/cve/CVE-2026-64335.html * https://www.suse.com/security/cve/CVE-2026-64337.html * https://www.suse.com/security/cve/CVE-2026-64338.html * https://www.suse.com/security/cve/CVE-2026-64340.html * https://www.suse.com/security/cve/CVE-2026-64341.html * https://www.suse.com/security/cve/CVE-2026-64342.html * https://www.suse.com/security/cve/CVE-2026-64343.html * https://www.suse.com/security/cve/CVE-2026-64344.html * https://www.suse.com/security/cve/CVE-2026-64346.html * https://www.suse.com/security/cve/CVE-2026-64348.html * https://www.suse.com/security/cve/CVE-2026-64350.html * https://www.suse.com/security/cve/CVE-2026-64351.html * https://www.suse.com/security/cve/CVE-2026-64355.html * https://www.suse.com/security/cve/CVE-2026-64358.html * https://www.suse.com/security/cve/CVE-2026-64362.html * https://www.suse.com/security/cve/CVE-2026-64365.html * https://www.suse.com/security/cve/CVE-2026-64375.html * https://www.suse.com/security/cve/CVE-2026-64376.html * https://www.suse.com/security/cve/CVE-2026-64378.html * https://www.suse.com/security/cve/CVE-2026-64381.html * https://www.suse.com/security/cve/CVE-2026-64382.html * https://www.suse.com/security/cve/CVE-2026-64383.html * https://www.suse.com/security/cve/CVE-2026-64384.html * https://www.suse.com/security/cve/CVE-2026-64385.html * https://www.suse.com/security/cve/CVE-2026-64386.html * https://www.suse.com/security/cve/CVE-2026-64387.html * https://www.suse.com/security/cve/CVE-2026-64388.html * https://www.suse.com/security/cve/CVE-2026-64401.html * https://www.suse.com/security/cve/CVE-2026-64403.html * https://www.suse.com/security/cve/CVE-2026-64406.html * https://www.suse.com/security/cve/CVE-2026-64407.html * https://www.suse.com/security/cve/CVE-2026-64408.html * https://www.suse.com/security/cve/CVE-2026-64409.html * https://www.suse.com/security/cve/CVE-2026-64411.html * https://www.suse.com/security/cve/CVE-2026-64412.html * https://www.suse.com/security/cve/CVE-2026-64420.html * https://www.suse.com/security/cve/CVE-2026-64421.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64427.html * https://www.suse.com/security/cve/CVE-2026-64429.html * https://www.suse.com/security/cve/CVE-2026-64433.html * https://www.suse.com/security/cve/CVE-2026-64434.html * https://www.suse.com/security/cve/CVE-2026-64436.html * https://www.suse.com/security/cve/CVE-2026-64440.html * https://www.suse.com/security/cve/CVE-2026-64442.html * https://www.suse.com/security/cve/CVE-2026-64443.html * https://www.suse.com/security/cve/CVE-2026-64444.html * https://www.suse.com/security/cve/CVE-2026-64445.html * https://www.suse.com/security/cve/CVE-2026-64448.html * https://www.suse.com/security/cve/CVE-2026-64450.html * https://www.suse.com/security/cve/CVE-2026-64452.html * https://www.suse.com/security/cve/CVE-2026-64454.html * https://www.suse.com/security/cve/CVE-2026-64455.html * https://www.suse.com/security/cve/CVE-2026-64463.html * https://www.suse.com/security/cve/CVE-2026-64470.html * https://www.suse.com/security/cve/CVE-2026-64471.html * https://www.suse.com/security/cve/CVE-2026-64472.html * https://www.suse.com/security/cve/CVE-2026-64477.html * https://www.suse.com/security/cve/CVE-2026-64478.html * https://www.suse.com/security/cve/CVE-2026-64479.html * https://www.suse.com/security/cve/CVE-2026-64480.html * https://www.suse.com/security/cve/CVE-2026-64481.html * https://www.suse.com/security/cve/CVE-2026-64482.html * https://www.suse.com/security/cve/CVE-2026-64483.html * https://www.suse.com/security/cve/CVE-2026-64484.html * https://www.suse.com/security/cve/CVE-2026-64486.html * https://www.suse.com/security/cve/CVE-2026-64487.html * https://www.suse.com/security/cve/CVE-2026-64489.html * https://www.suse.com/security/cve/CVE-2026-64494.html * https://www.suse.com/security/cve/CVE-2026-64495.html * https://www.suse.com/security/cve/CVE-2026-64496.html * https://www.suse.com/security/cve/CVE-2026-64497.html * https://www.suse.com/security/cve/CVE-2026-64500.html * https://www.suse.com/security/cve/CVE-2026-64503.html * https://www.suse.com/security/cve/CVE-2026-64504.html * https://www.suse.com/security/cve/CVE-2026-64505.html * https://www.suse.com/security/cve/CVE-2026-64511.html * https://www.suse.com/security/cve/CVE-2026-64512.html * https://www.suse.com/security/cve/CVE-2026-64513.html * https://www.suse.com/security/cve/CVE-2026-64515.html * https://www.suse.com/security/cve/CVE-2026-64517.html * https://www.suse.com/security/cve/CVE-2026-64524.html * https://www.suse.com/security/cve/CVE-2026-64527.html * https://www.suse.com/security/cve/CVE-2026-64536.html * https://www.suse.com/security/cve/CVE-2026-64537.html * https://www.suse.com/security/cve/CVE-2026-64538.html * https://www.suse.com/security/cve/CVE-2026-64539.html * https://www.suse.com/security/cve/CVE-2026-64540.html * https://www.suse.com/security/cve/CVE-2026-64541.html * https://www.suse.com/security/cve/CVE-2026-64543.html * https://www.suse.com/security/cve/CVE-2026-64544.html * https://www.suse.com/security/cve/CVE-2026-64545.html * https://www.suse.com/security/cve/CVE-2026-64546.html * https://www.suse.com/security/cve/CVE-2026-64547.html * https://www.suse.com/security/cve/CVE-2026-64548.html * https://www.suse.com/security/cve/CVE-2026-64549.html * https://www.suse.com/security/cve/CVE-2026-64551.html * https://www.suse.com/security/cve/CVE-2026-64552.html * https://www.suse.com/security/cve/CVE-2026-64553.html * https://www.suse.com/security/cve/CVE-2026-64554.html * https://www.suse.com/security/cve/CVE-2026-64558.html * https://www.suse.com/security/cve/CVE-2026-64559.html * https://www.suse.com/security/cve/CVE-2026-64562.html * https://www.suse.com/security/cve/CVE-2026-64563.html * https://www.suse.com/security/cve/CVE-2026-64565.html * https://www.suse.com/security/cve/CVE-2026-64567.html * https://www.suse.com/security/cve/CVE-2026-64568.html * https://www.suse.com/security/cve/CVE-2026-64569.html * https://www.suse.com/security/cve/CVE-2026-64570.html * https://www.suse.com/security/cve/CVE-2026-64571.html * https://www.suse.com/security/cve/CVE-2026-64572.html * https://www.suse.com/security/cve/CVE-2026-64573.html * https://www.suse.com/security/cve/CVE-2026-64574.html * https://www.suse.com/security/cve/CVE-2026-64576.html * https://www.suse.com/security/cve/CVE-2026-64577.html * https://www.suse.com/security/cve/CVE-2026-64581.html * https://www.suse.com/security/cve/CVE-2026-64582.html * https://www.suse.com/security/cve/CVE-2026-64583.html * https://www.suse.com/security/cve/CVE-2026-64584.html * https://www.suse.com/security/cve/CVE-2026-64585.html * https://www.suse.com/security/cve/CVE-2026-64593.html * https://www.suse.com/security/cve/CVE-2026-64597.html * https://www.suse.com/security/cve/CVE-2026-64598.html * https://www.suse.com/security/cve/CVE-2026-64599.html * https://www.suse.com/security/cve/CVE-2026-64602.html * https://www.suse.com/security/cve/CVE-2026-64603.html * https://www.suse.com/security/cve/CVE-2026-64604.html * https://www.suse.com/security/cve/CVE-2026-68081.html * https://www.suse.com/security/cve/CVE-2026-68082.html * https://www.suse.com/security/cve/CVE-2026-68085.html * https://www.suse.com/security/cve/CVE-2026-68086.html * https://www.suse.com/security/cve/CVE-2026-68088.html * https://www.suse.com/security/cve/CVE-2026-68091.html * https://www.suse.com/security/cve/CVE-2026-68093.html * https://www.suse.com/security/cve/CVE-2026-68102.html * https://www.suse.com/security/cve/CVE-2026-68104.html * https://www.suse.com/security/cve/CVE-2026-68105.html * https://www.suse.com/security/cve/CVE-2026-68106.html * https://www.suse.com/security/cve/CVE-2026-68107.html * https://www.suse.com/security/cve/CVE-2026-68108.html * https://www.suse.com/security/cve/CVE-2026-68110.html * https://www.suse.com/security/cve/CVE-2026-68111.html * https://www.suse.com/security/cve/CVE-2026-68112.html * https://www.suse.com/security/cve/CVE-2026-68113.html * https://www.suse.com/security/cve/CVE-2026-68115.html * https://www.suse.com/security/cve/CVE-2026-68116.html * https://www.suse.com/security/cve/CVE-2026-68117.html * https://www.suse.com/security/cve/CVE-2026-68121.html * https://www.suse.com/security/cve/CVE-2026-68123.html * https://www.suse.com/security/cve/CVE-2026-68124.html * https://www.suse.com/security/cve/CVE-2026-68125.html * https://www.suse.com/security/cve/CVE-2026-68126.html * https://www.suse.com/security/cve/CVE-2026-68127.html * https://www.suse.com/security/cve/CVE-2026-68129.html * https://www.suse.com/security/cve/CVE-2026-68132.html * https://www.suse.com/security/cve/CVE-2026-68133.html * https://www.suse.com/security/cve/CVE-2026-68135.html * https://www.suse.com/security/cve/CVE-2026-68136.html * https://www.suse.com/security/cve/CVE-2026-68137.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://www.suse.com/security/cve/CVE-2026-68139.html * https://www.suse.com/security/cve/CVE-2026-68142.html * https://www.suse.com/security/cve/CVE-2026-68143.html * https://www.suse.com/security/cve/CVE-2026-68145.html * https://www.suse.com/security/cve/CVE-2026-68149.html * https://www.suse.com/security/cve/CVE-2026-68152.html * https://www.suse.com/security/cve/CVE-2026-68153.html * https://www.suse.com/security/cve/CVE-2026-68154.html * https://www.suse.com/security/cve/CVE-2026-68155.html * https://www.suse.com/security/cve/CVE-2026-68156.html * https://www.suse.com/security/cve/CVE-2026-68157.html * https://www.suse.com/security/cve/CVE-2026-68158.html * https://www.suse.com/security/cve/CVE-2026-68159.html * https://www.suse.com/security/cve/CVE-2026-68160.html * https://www.suse.com/security/cve/CVE-2026-68161.html * https://www.suse.com/security/cve/CVE-2026-68162.html * https://www.suse.com/security/cve/CVE-2026-68166.html * https://www.suse.com/security/cve/CVE-2026-68180.html * https://www.suse.com/security/cve/CVE-2026-68181.html * https://www.suse.com/security/cve/CVE-2026-68182.html * https://www.suse.com/security/cve/CVE-2026-68184.html * https://www.suse.com/security/cve/CVE-2026-68188.html * https://www.suse.com/security/cve/CVE-2026-68189.html * https://www.suse.com/security/cve/CVE-2026-68192.html * https://www.suse.com/security/cve/CVE-2026-68193.html * https://www.suse.com/security/cve/CVE-2026-68194.html * https://www.suse.com/security/cve/CVE-2026-68195.html * https://www.suse.com/security/cve/CVE-2026-68196.html * https://www.suse.com/security/cve/CVE-2026-68197.html * https://www.suse.com/security/cve/CVE-2026-68199.html * https://www.suse.com/security/cve/CVE-2026-68202.html * https://www.suse.com/security/cve/CVE-2026-68204.html * https://www.suse.com/security/cve/CVE-2026-68205.html * https://www.suse.com/security/cve/CVE-2026-68206.html * https://www.suse.com/security/cve/CVE-2026-68207.html * https://www.suse.com/security/cve/CVE-2026-68209.html * https://www.suse.com/security/cve/CVE-2026-68210.html * https://www.suse.com/security/cve/CVE-2026-68212.html * https://www.suse.com/security/cve/CVE-2026-68213.html * https://www.suse.com/security/cve/CVE-2026-68214.html * https://www.suse.com/security/cve/CVE-2026-68215.html * https://www.suse.com/security/cve/CVE-2026-68216.html * https://www.suse.com/security/cve/CVE-2026-68217.html * https://www.suse.com/security/cve/CVE-2026-68218.html * https://www.suse.com/security/cve/CVE-2026-68219.html * https://www.suse.com/security/cve/CVE-2026-68220.html * https://www.suse.com/security/cve/CVE-2026-68222.html * https://www.suse.com/security/cve/CVE-2026-68223.html * https://www.suse.com/security/cve/CVE-2026-68226.html * https://www.suse.com/security/cve/CVE-2026-68227.html * https://www.suse.com/security/cve/CVE-2026-68229.html * https://www.suse.com/security/cve/CVE-2026-68231.html * https://www.suse.com/security/cve/CVE-2026-68234.html * https://www.suse.com/security/cve/CVE-2026-68235.html * https://www.suse.com/security/cve/CVE-2026-68236.html * https://www.suse.com/security/cve/CVE-2026-68238.html * https://www.suse.com/security/cve/CVE-2026-68243.html * https://www.suse.com/security/cve/CVE-2026-68244.html * https://www.suse.com/security/cve/CVE-2026-68245.html * https://www.suse.com/security/cve/CVE-2026-68246.html * https://www.suse.com/security/cve/CVE-2026-68247.html * https://www.suse.com/security/cve/CVE-2026-68248.html * https://www.suse.com/security/cve/CVE-2026-68249.html * https://www.suse.com/security/cve/CVE-2026-68250.html * https://www.suse.com/security/cve/CVE-2026-68251.html * https://www.suse.com/security/cve/CVE-2026-68252.html * https://www.suse.com/security/cve/CVE-2026-68253.html * https://www.suse.com/security/cve/CVE-2026-68254.html * https://www.suse.com/security/cve/CVE-2026-68255.html * https://www.suse.com/security/cve/CVE-2026-68256.html * https://www.suse.com/security/cve/CVE-2026-68257.html * https://www.suse.com/security/cve/CVE-2026-68259.html * https://www.suse.com/security/cve/CVE-2026-68260.html * https://www.suse.com/security/cve/CVE-2026-68261.html * https://www.suse.com/security/cve/CVE-2026-68262.html * https://www.suse.com/security/cve/CVE-2026-68263.html * https://www.suse.com/security/cve/CVE-2026-68267.html * https://www.suse.com/security/cve/CVE-2026-68269.html * https://www.suse.com/security/cve/CVE-2026-68271.html * https://www.suse.com/security/cve/CVE-2026-68272.html * https://www.suse.com/security/cve/CVE-2026-68277.html * https://www.suse.com/security/cve/CVE-2026-68278.html * https://www.suse.com/security/cve/CVE-2026-68279.html * https://www.suse.com/security/cve/CVE-2026-68280.html * https://www.suse.com/security/cve/CVE-2026-68281.html * https://www.suse.com/security/cve/CVE-2026-68284.html * https://www.suse.com/security/cve/CVE-2026-68286.html * https://www.suse.com/security/cve/CVE-2026-68288.html * https://www.suse.com/security/cve/CVE-2026-68289.html * https://www.suse.com/security/cve/CVE-2026-68293.html * https://www.suse.com/security/cve/CVE-2026-68297.html * https://www.suse.com/security/cve/CVE-2026-68299.html * https://www.suse.com/security/cve/CVE-2026-68300.html * https://www.suse.com/security/cve/CVE-2026-68302.html * https://www.suse.com/security/cve/CVE-2026-68303.html * https://www.suse.com/security/cve/CVE-2026-68304.html * https://www.suse.com/security/cve/CVE-2026-68306.html * https://www.suse.com/security/cve/CVE-2026-68308.html * https://www.suse.com/security/cve/CVE-2026-68309.html * https://www.suse.com/security/cve/CVE-2026-68310.html * https://www.suse.com/security/cve/CVE-2026-68312.html * https://www.suse.com/security/cve/CVE-2026-68313.html * https://www.suse.com/security/cve/CVE-2026-68315.html * https://www.suse.com/security/cve/CVE-2026-68320.html * https://www.suse.com/security/cve/CVE-2026-68322.html * https://www.suse.com/security/cve/CVE-2026-68324.html * https://www.suse.com/security/cve/CVE-2026-68325.html * https://www.suse.com/security/cve/CVE-2026-68326.html * https://www.suse.com/security/cve/CVE-2026-68327.html * https://www.suse.com/security/cve/CVE-2026-68328.html * https://www.suse.com/security/cve/CVE-2026-68329.html * https://www.suse.com/security/cve/CVE-2026-68331.html * https://www.suse.com/security/cve/CVE-2026-68333.html * https://www.suse.com/security/cve/CVE-2026-68335.html * https://www.suse.com/security/cve/CVE-2026-68336.html * https://www.suse.com/security/cve/CVE-2026-68339.html * https://www.suse.com/security/cve/CVE-2026-68340.html * https://www.suse.com/security/cve/CVE-2026-68343.html * https://www.suse.com/security/cve/CVE-2026-68346.html * https://www.suse.com/security/cve/CVE-2026-68348.html * https://www.suse.com/security/cve/CVE-2026-68349.html * https://www.suse.com/security/cve/CVE-2026-68350.html * https://www.suse.com/security/cve/CVE-2026-68351.html * https://www.suse.com/security/cve/CVE-2026-68352.html * https://www.suse.com/security/cve/CVE-2026-68353.html * https://www.suse.com/security/cve/CVE-2026-68354.html * https://www.suse.com/security/cve/CVE-2026-68355.html * https://www.suse.com/security/cve/CVE-2026-68357.html * https://www.suse.com/security/cve/CVE-2026-68359.html * https://www.suse.com/security/cve/CVE-2026-68360.html * https://www.suse.com/security/cve/CVE-2026-68361.html * https://www.suse.com/security/cve/CVE-2026-68362.html * https://www.suse.com/security/cve/CVE-2026-68363.html * https://www.suse.com/security/cve/CVE-2026-68365.html * https://www.suse.com/security/cve/CVE-2026-68366.html * https://www.suse.com/security/cve/CVE-2026-68368.html * https://www.suse.com/security/cve/CVE-2026-68369.html * https://www.suse.com/security/cve/CVE-2026-68370.html * https://www.suse.com/security/cve/CVE-2026-68372.html * https://www.suse.com/security/cve/CVE-2026-68373.html * https://www.suse.com/security/cve/CVE-2026-68375.html * https://www.suse.com/security/cve/CVE-2026-68377.html * https://www.suse.com/security/cve/CVE-2026-68386.html * https://www.suse.com/security/cve/CVE-2026-68389.html * https://www.suse.com/security/cve/CVE-2026-68391.html * https://www.suse.com/security/cve/CVE-2026-68392.html * https://www.suse.com/security/cve/CVE-2026-68394.html * https://www.suse.com/security/cve/CVE-2026-68397.html * https://www.suse.com/security/cve/CVE-2026-68398.html * https://www.suse.com/security/cve/CVE-2026-68399.html * https://www.suse.com/security/cve/CVE-2026-68402.html * https://www.suse.com/security/cve/CVE-2026-68403.html * https://www.suse.com/security/cve/CVE-2026-68405.html * https://www.suse.com/security/cve/CVE-2026-68406.html * https://www.suse.com/security/cve/CVE-2026-68407.html * https://www.suse.com/security/cve/CVE-2026-68408.html * https://www.suse.com/security/cve/CVE-2026-68410.html * https://www.suse.com/security/cve/CVE-2026-68413.html * https://www.suse.com/security/cve/CVE-2026-68414.html * https://www.suse.com/security/cve/CVE-2026-68417.html * https://www.suse.com/security/cve/CVE-2026-68418.html * https://www.suse.com/security/cve/CVE-2026-68419.html * https://www.suse.com/security/cve/CVE-2026-68422.html * https://www.suse.com/security/cve/CVE-2026-68425.html * https://www.suse.com/security/cve/CVE-2026-68426.html * https://www.suse.com/security/cve/CVE-2026-68427.html * https://www.suse.com/security/cve/CVE-2026-68428.html * https://www.suse.com/security/cve/CVE-2026-68429.html * https://www.suse.com/security/cve/CVE-2026-68430.html * https://www.suse.com/security/cve/CVE-2026-68432.html * https://www.suse.com/security/cve/CVE-2026-68433.html * https://www.suse.com/security/cve/CVE-2026-68434.html * https://www.suse.com/security/cve/CVE-2026-68437.html * https://www.suse.com/security/cve/CVE-2026-68444.html * https://www.suse.com/security/cve/CVE-2026-68445.html * https://www.suse.com/security/cve/CVE-2026-68446.html * https://www.suse.com/security/cve/CVE-2026-68450.html * https://www.suse.com/security/cve/CVE-2026-68470.html * https://www.suse.com/security/cve/CVE-2026-68480.html * https://www.suse.com/security/cve/CVE-2026-72020.html * https://www.suse.com/security/cve/CVE-2026-72032.html * https://www.suse.com/security/cve/CVE-2026-72035.html * https://www.suse.com/security/cve/CVE-2026-72036.html * https://www.suse.com/security/cve/CVE-2026-72046.html * https://www.suse.com/security/cve/CVE-2026-72069.html * https://www.suse.com/security/cve/CVE-2026-72072.html * https://www.suse.com/security/cve/CVE-2026-72083.html * https://www.suse.com/security/cve/CVE-2026-72084.html * https://www.suse.com/security/cve/CVE-2026-72123.html * https://www.suse.com/security/cve/CVE-2026-72132.html * https://www.suse.com/security/cve/CVE-2026-72221.html * https://www.suse.com/security/cve/CVE-2026-72222.html * https://www.suse.com/security/cve/CVE-2026-72251.html * https://www.suse.com/security/cve/CVE-2026-72254.html * https://www.suse.com/security/cve/CVE-2026-72262.html * https://www.suse.com/security/cve/CVE-2026-72288.html * https://www.suse.com/security/cve/CVE-2026-72289.html * https://www.suse.com/security/cve/CVE-2026-72296.html * https://www.suse.com/security/cve/CVE-2026-72307.html * https://www.suse.com/security/cve/CVE-2026-72308.html * https://www.suse.com/security/cve/CVE-2026-72317.html * https://www.suse.com/security/cve/CVE-2026-72341.html * https://www.suse.com/security/cve/CVE-2026-72342.html * https://www.suse.com/security/cve/CVE-2026-72343.html * https://www.suse.com/security/cve/CVE-2026-72389.html * https://www.suse.com/security/cve/CVE-2026-72463.html * https://www.suse.com/security/cve/CVE-2026-72464.html * https://www.suse.com/security/cve/CVE-2026-72466.html * https://www.suse.com/security/cve/CVE-2026-72467.html * https://www.suse.com/security/cve/CVE-2026-72469.html * https://www.suse.com/security/cve/CVE-2026-72473.html * https://www.suse.com/security/cve/CVE-2026-72494.html * https://www.suse.com/security/cve/CVE-2026-72495.html * https://www.suse.com/security/cve/CVE-2026-72496.html * https://www.suse.com/security/cve/CVE-2026-72497.html * https://www.suse.com/security/cve/CVE-2026-72498.html * https://www.suse.com/security/cve/CVE-2026-72499.html * https://www.suse.com/security/cve/CVE-2026-72500.html * https://www.suse.com/security/cve/CVE-2026-72501.html * https://www.suse.com/security/cve/CVE-2026-72502.html * https://www.suse.com/security/cve/CVE-2026-74269.html * https://www.suse.com/security/cve/CVE-2026-74296.html * https://www.suse.com/security/cve/CVE-2026-74297.html * https://www.suse.com/security/cve/CVE-2026-74318.html * https://www.suse.com/security/cve/CVE-2026-74321.html * https://www.suse.com/security/cve/CVE-2026-74334.html * https://www.suse.com/security/cve/CVE-2026-74345.html * https://www.suse.com/security/cve/CVE-2026-74394.html * https://www.suse.com/security/cve/CVE-2026-74395.html * https://www.suse.com/security/cve/CVE-2026-74454.html * https://www.suse.com/security/cve/CVE-2026-74474.html * https://www.suse.com/security/cve/CVE-2026-74481.html * https://www.suse.com/security/cve/CVE-2026-74482.html * https://www.suse.com/security/cve/CVE-2026-74488.html * https://www.suse.com/security/cve/CVE-2026-74495.html * https://www.suse.com/security/cve/CVE-2026-74496.html * https://www.suse.com/security/cve/CVE-2026-74509.html * https://www.suse.com/security/cve/CVE-2026-74510.html * https://www.suse.com/security/cve/CVE-2026-74512.html * https://www.suse.com/security/cve/CVE-2026-74516.html * https://www.suse.com/security/cve/CVE-2026-74518.html * https://www.suse.com/security/cve/CVE-2026-74527.html * https://www.suse.com/security/cve/CVE-2026-74537.html * https://www.suse.com/security/cve/CVE-2026-74548.html * https://www.suse.com/security/cve/CVE-2026-74550.html * https://www.suse.com/security/cve/CVE-2026-74556.html * https://www.suse.com/security/cve/CVE-2026-74563.html * https://www.suse.com/security/cve/CVE-2026-74566.html * https://www.suse.com/security/cve/CVE-2026-74567.html * https://www.suse.com/security/cve/CVE-2026-74571.html * https://www.suse.com/security/cve/CVE-2026-74577.html * https://www.suse.com/security/cve/CVE-2026-74581.html * https://www.suse.com/security/cve/CVE-2026-74582.html * https://www.suse.com/security/cve/CVE-2026-74584.html * https://www.suse.com/security/cve/CVE-2026-74610.html * https://www.suse.com/security/cve/CVE-2026-74669.html * https://www.suse.com/security/cve/CVE-2026-74692.html * https://www.suse.com/security/cve/CVE-2026-74694.html * https://www.suse.com/security/cve/CVE-2026-74695.html * https://www.suse.com/security/cve/CVE-2026-74712.html * https://www.suse.com/security/cve/CVE-2026-74717.html * https://www.suse.com/security/cve/CVE-2026-74722.html * https://www.suse.com/security/cve/CVE-2026-80529.html * https://www.suse.com/security/cve/CVE-2026-80534.html * https://www.suse.com/security/cve/CVE-2026-80590.html * https://www.suse.com/security/cve/CVE-2026-80654.html * https://bugzilla.suse.com/show_bug.cgi?id=1230238 * https://bugzilla.suse.com/show_bug.cgi?id=1235944 * https://bugzilla.suse.com/show_bug.cgi?id=1236344 * https://bugzilla.suse.com/show_bug.cgi?id=1240957 * https://bugzilla.suse.com/show_bug.cgi?id=1241363 * https://bugzilla.suse.com/show_bug.cgi?id=1247180 * https://bugzilla.suse.com/show_bug.cgi?id=1247455 * https://bugzilla.suse.com/show_bug.cgi?id=1249104 * https://bugzilla.suse.com/show_bug.cgi?id=1250748 * https://bugzilla.suse.com/show_bug.cgi?id=1251130 * https://bugzilla.suse.com/show_bug.cgi?id=1251966 * https://bugzilla.suse.com/show_bug.cgi?id=1252682 * https://bugzilla.suse.com/show_bug.cgi?id=1253454 * https://bugzilla.suse.com/show_bug.cgi?id=1254306 * https://bugzilla.suse.com/show_bug.cgi?id=1255225 * https://bugzilla.suse.com/show_bug.cgi?id=1255250 * https://bugzilla.suse.com/show_bug.cgi?id=1256629 * https://bugzilla.suse.com/show_bug.cgi?id=1256708 * https://bugzilla.suse.com/show_bug.cgi?id=1257154 * https://bugzilla.suse.com/show_bug.cgi?id=1258430 * https://bugzilla.suse.com/show_bug.cgi?id=1258472 * https://bugzilla.suse.com/show_bug.cgi?id=1258517 * https://bugzilla.suse.com/show_bug.cgi?id=1260522 * https://bugzilla.suse.com/show_bug.cgi?id=1261562 * https://bugzilla.suse.com/show_bug.cgi?id=1261780 * https://bugzilla.suse.com/show_bug.cgi?id=1262073 * https://bugzilla.suse.com/show_bug.cgi?id=1263004 * https://bugzilla.suse.com/show_bug.cgi?id=1263052 * https://bugzilla.suse.com/show_bug.cgi?id=1263061 * https://bugzilla.suse.com/show_bug.cgi?id=1263133 * https://bugzilla.suse.com/show_bug.cgi?id=1263864 * https://bugzilla.suse.com/show_bug.cgi?id=1264010 * https://bugzilla.suse.com/show_bug.cgi?id=1264012 * https://bugzilla.suse.com/show_bug.cgi?id=1264335 * https://bugzilla.suse.com/show_bug.cgi?id=1264446 * https://bugzilla.suse.com/show_bug.cgi?id=1264541 * https://bugzilla.suse.com/show_bug.cgi?id=1264587 * https://bugzilla.suse.com/show_bug.cgi?id=1264619 * https://bugzilla.suse.com/show_bug.cgi?id=1264643 * https://bugzilla.suse.com/show_bug.cgi?id=1264740 * https://bugzilla.suse.com/show_bug.cgi?id=1264807 * https://bugzilla.suse.com/show_bug.cgi?id=1265068 * https://bugzilla.suse.com/show_bug.cgi?id=1265121 * https://bugzilla.suse.com/show_bug.cgi?id=1265220 * https://bugzilla.suse.com/show_bug.cgi?id=1265449 * https://bugzilla.suse.com/show_bug.cgi?id=1265928 * https://bugzilla.suse.com/show_bug.cgi?id=1266402 * https://bugzilla.suse.com/show_bug.cgi?id=1266860 * https://bugzilla.suse.com/show_bug.cgi?id=1266874 * https://bugzilla.suse.com/show_bug.cgi?id=1266897 * https://bugzilla.suse.com/show_bug.cgi?id=1267023 * https://bugzilla.suse.com/show_bug.cgi?id=1267236 * https://bugzilla.suse.com/show_bug.cgi?id=1267238 * https://bugzilla.suse.com/show_bug.cgi?id=1267501 * https://bugzilla.suse.com/show_bug.cgi?id=1267505 * https://bugzilla.suse.com/show_bug.cgi?id=1267612 * https://bugzilla.suse.com/show_bug.cgi?id=1268276 * https://bugzilla.suse.com/show_bug.cgi?id=1268972 * https://bugzilla.suse.com/show_bug.cgi?id=1268979 * https://bugzilla.suse.com/show_bug.cgi?id=1268987 * https://bugzilla.suse.com/show_bug.cgi?id=1269004 * https://bugzilla.suse.com/show_bug.cgi?id=1269013 * https://bugzilla.suse.com/show_bug.cgi?id=1269108 * https://bugzilla.suse.com/show_bug.cgi?id=1269113 * https://bugzilla.suse.com/show_bug.cgi?id=1269114 * https://bugzilla.suse.com/show_bug.cgi?id=1269126 * https://bugzilla.suse.com/show_bug.cgi?id=1269140 * https://bugzilla.suse.com/show_bug.cgi?id=1269167 * https://bugzilla.suse.com/show_bug.cgi?id=1269234 * https://bugzilla.suse.com/show_bug.cgi?id=1269238 * https://bugzilla.suse.com/show_bug.cgi?id=1269242 * https://bugzilla.suse.com/show_bug.cgi?id=1269256 * https://bugzilla.suse.com/show_bug.cgi?id=1269301 * https://bugzilla.suse.com/show_bug.cgi?id=1269306 * https://bugzilla.suse.com/show_bug.cgi?id=1269313 * https://bugzilla.suse.com/show_bug.cgi?id=1269381 * https://bugzilla.suse.com/show_bug.cgi?id=1269388 * https://bugzilla.suse.com/show_bug.cgi?id=1269402 * https://bugzilla.suse.com/show_bug.cgi?id=1269412 * https://bugzilla.suse.com/show_bug.cgi?id=1269530 * https://bugzilla.suse.com/show_bug.cgi?id=1269579 * https://bugzilla.suse.com/show_bug.cgi?id=1269590 * https://bugzilla.suse.com/show_bug.cgi?id=1269635 * https://bugzilla.suse.com/show_bug.cgi?id=1269647 * https://bugzilla.suse.com/show_bug.cgi?id=1269655 * https://bugzilla.suse.com/show_bug.cgi?id=1269665 * https://bugzilla.suse.com/show_bug.cgi?id=1269686 * https://bugzilla.suse.com/show_bug.cgi?id=1269695 * https://bugzilla.suse.com/show_bug.cgi?id=1269713 * https://bugzilla.suse.com/show_bug.cgi?id=1269731 * https://bugzilla.suse.com/show_bug.cgi?id=1269774 * https://bugzilla.suse.com/show_bug.cgi?id=1269783 * https://bugzilla.suse.com/show_bug.cgi?id=1269792 * https://bugzilla.suse.com/show_bug.cgi?id=1269815 * https://bugzilla.suse.com/show_bug.cgi?id=1269888 * https://bugzilla.suse.com/show_bug.cgi?id=1269965 * https://bugzilla.suse.com/show_bug.cgi?id=1269969 * https://bugzilla.suse.com/show_bug.cgi?id=1269981 * https://bugzilla.suse.com/show_bug.cgi?id=1269985 * https://bugzilla.suse.com/show_bug.cgi?id=1270090 * https://bugzilla.suse.com/show_bug.cgi?id=1270108 * https://bugzilla.suse.com/show_bug.cgi?id=1270111 * https://bugzilla.suse.com/show_bug.cgi?id=1270251 * https://bugzilla.suse.com/show_bug.cgi?id=1270263 * https://bugzilla.suse.com/show_bug.cgi?id=1270268 * https://bugzilla.suse.com/show_bug.cgi?id=1271256 * https://bugzilla.suse.com/show_bug.cgi?id=1271365 * https://bugzilla.suse.com/show_bug.cgi?id=1271366 * https://bugzilla.suse.com/show_bug.cgi?id=1271825 * https://bugzilla.suse.com/show_bug.cgi?id=1271830 * https://bugzilla.suse.com/show_bug.cgi?id=1272150 * https://bugzilla.suse.com/show_bug.cgi?id=1272175 * https://bugzilla.suse.com/show_bug.cgi?id=1272179 * https://bugzilla.suse.com/show_bug.cgi?id=1272182 * https://bugzilla.suse.com/show_bug.cgi?id=1272200 * https://bugzilla.suse.com/show_bug.cgi?id=1272210 * https://bugzilla.suse.com/show_bug.cgi?id=1272213 * https://bugzilla.suse.com/show_bug.cgi?id=1272230 * https://bugzilla.suse.com/show_bug.cgi?id=1272260 * https://bugzilla.suse.com/show_bug.cgi?id=1272261 * https://bugzilla.suse.com/show_bug.cgi?id=1272262 * https://bugzilla.suse.com/show_bug.cgi?id=1272297 * https://bugzilla.suse.com/show_bug.cgi?id=1272346 * https://bugzilla.suse.com/show_bug.cgi?id=1272351 * https://bugzilla.suse.com/show_bug.cgi?id=1272359 * https://bugzilla.suse.com/show_bug.cgi?id=1272381 * https://bugzilla.suse.com/show_bug.cgi?id=1272383 * https://bugzilla.suse.com/show_bug.cgi?id=1272385 * https://bugzilla.suse.com/show_bug.cgi?id=1272390 * https://bugzilla.suse.com/show_bug.cgi?id=1272423 * https://bugzilla.suse.com/show_bug.cgi?id=1272429 * https://bugzilla.suse.com/show_bug.cgi?id=1272484 * https://bugzilla.suse.com/show_bug.cgi?id=1272486 * https://bugzilla.suse.com/show_bug.cgi?id=1272497 * https://bugzilla.suse.com/show_bug.cgi?id=1272502 * https://bugzilla.suse.com/show_bug.cgi?id=1272516 * https://bugzilla.suse.com/show_bug.cgi?id=1272569 * https://bugzilla.suse.com/show_bug.cgi?id=1272571 * https://bugzilla.suse.com/show_bug.cgi?id=1272618 * https://bugzilla.suse.com/show_bug.cgi?id=1272641 * https://bugzilla.suse.com/show_bug.cgi?id=1272643 * https://bugzilla.suse.com/show_bug.cgi?id=1272662 * https://bugzilla.suse.com/show_bug.cgi?id=1272673 * https://bugzilla.suse.com/show_bug.cgi?id=1272680 * https://bugzilla.suse.com/show_bug.cgi?id=1272682 * https://bugzilla.suse.com/show_bug.cgi?id=1272756 * https://bugzilla.suse.com/show_bug.cgi?id=1272786 * https://bugzilla.suse.com/show_bug.cgi?id=1272788 * https://bugzilla.suse.com/show_bug.cgi?id=1272798 * https://bugzilla.suse.com/show_bug.cgi?id=1272799 * https://bugzilla.suse.com/show_bug.cgi?id=1272804 * https://bugzilla.suse.com/show_bug.cgi?id=1272868 * https://bugzilla.suse.com/show_bug.cgi?id=1272877 * https://bugzilla.suse.com/show_bug.cgi?id=1272891 * https://bugzilla.suse.com/show_bug.cgi?id=1272893 * https://bugzilla.suse.com/show_bug.cgi?id=1272963 * https://bugzilla.suse.com/show_bug.cgi?id=1272983 * https://bugzilla.suse.com/show_bug.cgi?id=1272993 * https://bugzilla.suse.com/show_bug.cgi?id=1273005 * https://bugzilla.suse.com/show_bug.cgi?id=1273008 * https://bugzilla.suse.com/show_bug.cgi?id=1273019 * https://bugzilla.suse.com/show_bug.cgi?id=1273027 * https://bugzilla.suse.com/show_bug.cgi?id=1273028 * https://bugzilla.suse.com/show_bug.cgi?id=1273030 * https://bugzilla.suse.com/show_bug.cgi?id=1273032 * https://bugzilla.suse.com/show_bug.cgi?id=1273033 * https://bugzilla.suse.com/show_bug.cgi?id=1273036 * https://bugzilla.suse.com/show_bug.cgi?id=1273037 * https://bugzilla.suse.com/show_bug.cgi?id=1273038 * https://bugzilla.suse.com/show_bug.cgi?id=1273053 * https://bugzilla.suse.com/show_bug.cgi?id=1273054 * https://bugzilla.suse.com/show_bug.cgi?id=1273060 * https://bugzilla.suse.com/show_bug.cgi?id=1273105 * https://bugzilla.suse.com/show_bug.cgi?id=1273134 * https://bugzilla.suse.com/show_bug.cgi?id=1273249 * https://bugzilla.suse.com/show_bug.cgi?id=1273250 * https://bugzilla.suse.com/show_bug.cgi?id=1273260 * https://bugzilla.suse.com/show_bug.cgi?id=1273273 * https://bugzilla.suse.com/show_bug.cgi?id=1273274 * https://bugzilla.suse.com/show_bug.cgi?id=1273276 * https://bugzilla.suse.com/show_bug.cgi?id=1273277 * https://bugzilla.suse.com/show_bug.cgi?id=1273280 * https://bugzilla.suse.com/show_bug.cgi?id=1273281 * https://bugzilla.suse.com/show_bug.cgi?id=1273284 * https://bugzilla.suse.com/show_bug.cgi?id=1273285 * https://bugzilla.suse.com/show_bug.cgi?id=1273289 * https://bugzilla.suse.com/show_bug.cgi?id=1273291 * https://bugzilla.suse.com/show_bug.cgi?id=1273294 * https://bugzilla.suse.com/show_bug.cgi?id=1273302 * https://bugzilla.suse.com/show_bug.cgi?id=1273303 * https://bugzilla.suse.com/show_bug.cgi?id=1273305 * https://bugzilla.suse.com/show_bug.cgi?id=1273310 * https://bugzilla.suse.com/show_bug.cgi?id=1273311 * https://bugzilla.suse.com/show_bug.cgi?id=1273316 * https://bugzilla.suse.com/show_bug.cgi?id=1273318 * https://bugzilla.suse.com/show_bug.cgi?id=1273319 * https://bugzilla.suse.com/show_bug.cgi?id=1273323 * https://bugzilla.suse.com/show_bug.cgi?id=1273325 * https://bugzilla.suse.com/show_bug.cgi?id=1273327 * https://bugzilla.suse.com/show_bug.cgi?id=1273334 * https://bugzilla.suse.com/show_bug.cgi?id=1273335 * https://bugzilla.suse.com/show_bug.cgi?id=1273336 * https://bugzilla.suse.com/show_bug.cgi?id=1273337 * https://bugzilla.suse.com/show_bug.cgi?id=1273338 * https://bugzilla.suse.com/show_bug.cgi?id=1273340 * https://bugzilla.suse.com/show_bug.cgi?id=1273341 * https://bugzilla.suse.com/show_bug.cgi?id=1273346 * https://bugzilla.suse.com/show_bug.cgi?id=1273422 * https://bugzilla.suse.com/show_bug.cgi?id=1273426 * https://bugzilla.suse.com/show_bug.cgi?id=1273443 * https://bugzilla.suse.com/show_bug.cgi?id=1273460 * https://bugzilla.suse.com/show_bug.cgi?id=1273463 * https://bugzilla.suse.com/show_bug.cgi?id=1273465 * https://bugzilla.suse.com/show_bug.cgi?id=1273468 * https://bugzilla.suse.com/show_bug.cgi?id=1273469 * https://bugzilla.suse.com/show_bug.cgi?id=1273471 * https://bugzilla.suse.com/show_bug.cgi?id=1273479 * https://bugzilla.suse.com/show_bug.cgi?id=1273480 * https://bugzilla.suse.com/show_bug.cgi?id=1273482 * https://bugzilla.suse.com/show_bug.cgi?id=1273484 * https://bugzilla.suse.com/show_bug.cgi?id=1273488 * https://bugzilla.suse.com/show_bug.cgi?id=1273490 * https://bugzilla.suse.com/show_bug.cgi?id=1273501 * https://bugzilla.suse.com/show_bug.cgi?id=1273503 * https://bugzilla.suse.com/show_bug.cgi?id=1273504 * https://bugzilla.suse.com/show_bug.cgi?id=1273506 * https://bugzilla.suse.com/show_bug.cgi?id=1273523 * https://bugzilla.suse.com/show_bug.cgi?id=1273525 * https://bugzilla.suse.com/show_bug.cgi?id=1273533 * https://bugzilla.suse.com/show_bug.cgi?id=1273536 * https://bugzilla.suse.com/show_bug.cgi?id=1273542 * https://bugzilla.suse.com/show_bug.cgi?id=1273555 * https://bugzilla.suse.com/show_bug.cgi?id=1273578 * https://bugzilla.suse.com/show_bug.cgi?id=1273579 * https://bugzilla.suse.com/show_bug.cgi?id=1273581 * https://bugzilla.suse.com/show_bug.cgi?id=1273582 * https://bugzilla.suse.com/show_bug.cgi?id=1273596 * https://bugzilla.suse.com/show_bug.cgi?id=1273597 * https://bugzilla.suse.com/show_bug.cgi?id=1273598 * https://bugzilla.suse.com/show_bug.cgi?id=1273600 * https://bugzilla.suse.com/show_bug.cgi?id=1273601 * https://bugzilla.suse.com/show_bug.cgi?id=1273602 * https://bugzilla.suse.com/show_bug.cgi?id=1273603 * https://bugzilla.suse.com/show_bug.cgi?id=1273679 * https://bugzilla.suse.com/show_bug.cgi?id=1273681 * https://bugzilla.suse.com/show_bug.cgi?id=1273682 * https://bugzilla.suse.com/show_bug.cgi?id=1273734 * https://bugzilla.suse.com/show_bug.cgi?id=1273738 * https://bugzilla.suse.com/show_bug.cgi?id=1273739 * https://bugzilla.suse.com/show_bug.cgi?id=1273741 * https://bugzilla.suse.com/show_bug.cgi?id=1273742 * https://bugzilla.suse.com/show_bug.cgi?id=1273743 * https://bugzilla.suse.com/show_bug.cgi?id=1273745 * https://bugzilla.suse.com/show_bug.cgi?id=1273748 * https://bugzilla.suse.com/show_bug.cgi?id=1273749 * https://bugzilla.suse.com/show_bug.cgi?id=1273755 * https://bugzilla.suse.com/show_bug.cgi?id=1273762 * https://bugzilla.suse.com/show_bug.cgi?id=1273765 * https://bugzilla.suse.com/show_bug.cgi?id=1273766 * https://bugzilla.suse.com/show_bug.cgi?id=1273769 * https://bugzilla.suse.com/show_bug.cgi?id=1273774 * https://bugzilla.suse.com/show_bug.cgi?id=1273778 * https://bugzilla.suse.com/show_bug.cgi?id=1273780 * https://bugzilla.suse.com/show_bug.cgi?id=1273790 * https://bugzilla.suse.com/show_bug.cgi?id=1273796 * https://bugzilla.suse.com/show_bug.cgi?id=1273797 * https://bugzilla.suse.com/show_bug.cgi?id=1273801 * https://bugzilla.suse.com/show_bug.cgi?id=1273804 * https://bugzilla.suse.com/show_bug.cgi?id=1273810 * https://bugzilla.suse.com/show_bug.cgi?id=1273811 * https://bugzilla.suse.com/show_bug.cgi?id=1273812 * https://bugzilla.suse.com/show_bug.cgi?id=1273813 * https://bugzilla.suse.com/show_bug.cgi?id=1273817 * https://bugzilla.suse.com/show_bug.cgi?id=1273822 * https://bugzilla.suse.com/show_bug.cgi?id=1273824 * https://bugzilla.suse.com/show_bug.cgi?id=1273831 * https://bugzilla.suse.com/show_bug.cgi?id=1273832 * https://bugzilla.suse.com/show_bug.cgi?id=1273834 * https://bugzilla.suse.com/show_bug.cgi?id=1273838 * https://bugzilla.suse.com/show_bug.cgi?id=1273844 * https://bugzilla.suse.com/show_bug.cgi?id=1273849 * https://bugzilla.suse.com/show_bug.cgi?id=1273859 * https://bugzilla.suse.com/show_bug.cgi?id=1273860 * https://bugzilla.suse.com/show_bug.cgi?id=1273862 * https://bugzilla.suse.com/show_bug.cgi?id=1273867 * https://bugzilla.suse.com/show_bug.cgi?id=1273868 * https://bugzilla.suse.com/show_bug.cgi?id=1273869 * https://bugzilla.suse.com/show_bug.cgi?id=1273872 * https://bugzilla.suse.com/show_bug.cgi?id=1273876 * https://bugzilla.suse.com/show_bug.cgi?id=1273877 * https://bugzilla.suse.com/show_bug.cgi?id=1273880 * https://bugzilla.suse.com/show_bug.cgi?id=1273882 * https://bugzilla.suse.com/show_bug.cgi?id=1273890 * https://bugzilla.suse.com/show_bug.cgi?id=1273891 * https://bugzilla.suse.com/show_bug.cgi?id=1273892 * https://bugzilla.suse.com/show_bug.cgi?id=1273895 * https://bugzilla.suse.com/show_bug.cgi?id=1273896 * https://bugzilla.suse.com/show_bug.cgi?id=1273903 * https://bugzilla.suse.com/show_bug.cgi?id=1273905 * https://bugzilla.suse.com/show_bug.cgi?id=1273930 * https://bugzilla.suse.com/show_bug.cgi?id=1273933 * https://bugzilla.suse.com/show_bug.cgi?id=1273934 * https://bugzilla.suse.com/show_bug.cgi?id=1273935 * https://bugzilla.suse.com/show_bug.cgi?id=1273936 * https://bugzilla.suse.com/show_bug.cgi?id=1273939 * https://bugzilla.suse.com/show_bug.cgi?id=1273940 * https://bugzilla.suse.com/show_bug.cgi?id=1273941 * https://bugzilla.suse.com/show_bug.cgi?id=1273942 * https://bugzilla.suse.com/show_bug.cgi?id=1273944 * https://bugzilla.suse.com/show_bug.cgi?id=1273945 * https://bugzilla.suse.com/show_bug.cgi?id=1273946 * https://bugzilla.suse.com/show_bug.cgi?id=1273956 * https://bugzilla.suse.com/show_bug.cgi?id=1273957 * https://bugzilla.suse.com/show_bug.cgi?id=1273958 * https://bugzilla.suse.com/show_bug.cgi?id=1273966 * https://bugzilla.suse.com/show_bug.cgi?id=1273967 * https://bugzilla.suse.com/show_bug.cgi?id=1273968 * https://bugzilla.suse.com/show_bug.cgi?id=1273972 * https://bugzilla.suse.com/show_bug.cgi?id=1273974 * https://bugzilla.suse.com/show_bug.cgi?id=1273975 * https://bugzilla.suse.com/show_bug.cgi?id=1273977 * https://bugzilla.suse.com/show_bug.cgi?id=1273982 * https://bugzilla.suse.com/show_bug.cgi?id=1273988 * https://bugzilla.suse.com/show_bug.cgi?id=1273990 * https://bugzilla.suse.com/show_bug.cgi?id=1273991 * https://bugzilla.suse.com/show_bug.cgi?id=1273995 * https://bugzilla.suse.com/show_bug.cgi?id=1274001 * https://bugzilla.suse.com/show_bug.cgi?id=1274003 * https://bugzilla.suse.com/show_bug.cgi?id=1274006 * https://bugzilla.suse.com/show_bug.cgi?id=1274008 * https://bugzilla.suse.com/show_bug.cgi?id=1274009 * https://bugzilla.suse.com/show_bug.cgi?id=1274010 * https://bugzilla.suse.com/show_bug.cgi?id=1274011 * https://bugzilla.suse.com/show_bug.cgi?id=1274012 * https://bugzilla.suse.com/show_bug.cgi?id=1274014 * https://bugzilla.suse.com/show_bug.cgi?id=1274017 * https://bugzilla.suse.com/show_bug.cgi?id=1274019 * https://bugzilla.suse.com/show_bug.cgi?id=1274020 * https://bugzilla.suse.com/show_bug.cgi?id=1274026 * https://bugzilla.suse.com/show_bug.cgi?id=1274028 * https://bugzilla.suse.com/show_bug.cgi?id=1274030 * https://bugzilla.suse.com/show_bug.cgi?id=1274031 * https://bugzilla.suse.com/show_bug.cgi?id=1274035 * https://bugzilla.suse.com/show_bug.cgi?id=1274040 * https://bugzilla.suse.com/show_bug.cgi?id=1274041 * https://bugzilla.suse.com/show_bug.cgi?id=1274055 * https://bugzilla.suse.com/show_bug.cgi?id=1274057 * https://bugzilla.suse.com/show_bug.cgi?id=1274058 * https://bugzilla.suse.com/show_bug.cgi?id=1274061 * https://bugzilla.suse.com/show_bug.cgi?id=1274063 * https://bugzilla.suse.com/show_bug.cgi?id=1274065 * https://bugzilla.suse.com/show_bug.cgi?id=1274067 * https://bugzilla.suse.com/show_bug.cgi?id=1274071 * https://bugzilla.suse.com/show_bug.cgi?id=1274075 * https://bugzilla.suse.com/show_bug.cgi?id=1274076 * https://bugzilla.suse.com/show_bug.cgi?id=1274077 * https://bugzilla.suse.com/show_bug.cgi?id=1274078 * https://bugzilla.suse.com/show_bug.cgi?id=1274208 * https://bugzilla.suse.com/show_bug.cgi?id=1274226 * https://bugzilla.suse.com/show_bug.cgi?id=1274239 * https://bugzilla.suse.com/show_bug.cgi?id=1274243 * https://bugzilla.suse.com/show_bug.cgi?id=1274258 * https://bugzilla.suse.com/show_bug.cgi?id=1274264 * https://bugzilla.suse.com/show_bug.cgi?id=1274265 * https://bugzilla.suse.com/show_bug.cgi?id=1274267 * https://bugzilla.suse.com/show_bug.cgi?id=1274274 * https://bugzilla.suse.com/show_bug.cgi?id=1274277 * https://bugzilla.suse.com/show_bug.cgi?id=1274278 * https://bugzilla.suse.com/show_bug.cgi?id=1274281 * https://bugzilla.suse.com/show_bug.cgi?id=1274283 * https://bugzilla.suse.com/show_bug.cgi?id=1274286 * https://bugzilla.suse.com/show_bug.cgi?id=1274290 * https://bugzilla.suse.com/show_bug.cgi?id=1274294 * https://bugzilla.suse.com/show_bug.cgi?id=1274295 * https://bugzilla.suse.com/show_bug.cgi?id=1274296 * https://bugzilla.suse.com/show_bug.cgi?id=1274297 * https://bugzilla.suse.com/show_bug.cgi?id=1274298 * https://bugzilla.suse.com/show_bug.cgi?id=1274314 * https://bugzilla.suse.com/show_bug.cgi?id=1274321 * https://bugzilla.suse.com/show_bug.cgi?id=1274491 * https://bugzilla.suse.com/show_bug.cgi?id=1274497 * https://bugzilla.suse.com/show_bug.cgi?id=1274539 * https://bugzilla.suse.com/show_bug.cgi?id=1274541 * https://bugzilla.suse.com/show_bug.cgi?id=1274543 * https://bugzilla.suse.com/show_bug.cgi?id=1274545 * https://bugzilla.suse.com/show_bug.cgi?id=1274547 * https://bugzilla.suse.com/show_bug.cgi?id=1274550 * https://bugzilla.suse.com/show_bug.cgi?id=1274573 * https://bugzilla.suse.com/show_bug.cgi?id=1274578 * https://bugzilla.suse.com/show_bug.cgi?id=1274580 * https://bugzilla.suse.com/show_bug.cgi?id=1274581 * https://bugzilla.suse.com/show_bug.cgi?id=1274620 * https://bugzilla.suse.com/show_bug.cgi?id=1274622 * https://bugzilla.suse.com/show_bug.cgi?id=1274624 * https://bugzilla.suse.com/show_bug.cgi?id=1274629 * https://bugzilla.suse.com/show_bug.cgi?id=1274632 * https://bugzilla.suse.com/show_bug.cgi?id=1274636 * https://bugzilla.suse.com/show_bug.cgi?id=1274639 * https://bugzilla.suse.com/show_bug.cgi?id=1274640 * https://bugzilla.suse.com/show_bug.cgi?id=1274642 * https://bugzilla.suse.com/show_bug.cgi?id=1274644 * https://bugzilla.suse.com/show_bug.cgi?id=1274645 * https://bugzilla.suse.com/show_bug.cgi?id=1274646 * https://bugzilla.suse.com/show_bug.cgi?id=1274649 * https://bugzilla.suse.com/show_bug.cgi?id=1274650 * https://bugzilla.suse.com/show_bug.cgi?id=1274651 * https://bugzilla.suse.com/show_bug.cgi?id=1274656 * https://bugzilla.suse.com/show_bug.cgi?id=1274659 * https://bugzilla.suse.com/show_bug.cgi?id=1274662 * https://bugzilla.suse.com/show_bug.cgi?id=1274663 * https://bugzilla.suse.com/show_bug.cgi?id=1274665 * https://bugzilla.suse.com/show_bug.cgi?id=1274667 * https://bugzilla.suse.com/show_bug.cgi?id=1274670 * https://bugzilla.suse.com/show_bug.cgi?id=1274675 * https://bugzilla.suse.com/show_bug.cgi?id=1274677 * https://bugzilla.suse.com/show_bug.cgi?id=1274678 * https://bugzilla.suse.com/show_bug.cgi?id=1274679 * https://bugzilla.suse.com/show_bug.cgi?id=1274681 * https://bugzilla.suse.com/show_bug.cgi?id=1274682 * https://bugzilla.suse.com/show_bug.cgi?id=1274690 * https://bugzilla.suse.com/show_bug.cgi?id=1274694 * https://bugzilla.suse.com/show_bug.cgi?id=1274696 * https://bugzilla.suse.com/show_bug.cgi?id=1274698 * https://bugzilla.suse.com/show_bug.cgi?id=1274699 * https://bugzilla.suse.com/show_bug.cgi?id=1274700 * https://bugzilla.suse.com/show_bug.cgi?id=1274702 * https://bugzilla.suse.com/show_bug.cgi?id=1274703 * https://bugzilla.suse.com/show_bug.cgi?id=1274705 * https://bugzilla.suse.com/show_bug.cgi?id=1274706 * https://bugzilla.suse.com/show_bug.cgi?id=1274709 * https://bugzilla.suse.com/show_bug.cgi?id=1274710 * https://bugzilla.suse.com/show_bug.cgi?id=1274713 * https://bugzilla.suse.com/show_bug.cgi?id=1274716 * https://bugzilla.suse.com/show_bug.cgi?id=1274721 * https://bugzilla.suse.com/show_bug.cgi?id=1274725 * https://bugzilla.suse.com/show_bug.cgi?id=1274737 * https://bugzilla.suse.com/show_bug.cgi?id=1274738 * https://bugzilla.suse.com/show_bug.cgi?id=1274749 * https://bugzilla.suse.com/show_bug.cgi?id=1274752 * https://bugzilla.suse.com/show_bug.cgi?id=1274753 * https://bugzilla.suse.com/show_bug.cgi?id=1274754 * https://bugzilla.suse.com/show_bug.cgi?id=1274755 * https://bugzilla.suse.com/show_bug.cgi?id=1274756 * https://bugzilla.suse.com/show_bug.cgi?id=1274764 * https://bugzilla.suse.com/show_bug.cgi?id=1274768 * https://bugzilla.suse.com/show_bug.cgi?id=1274770 * https://bugzilla.suse.com/show_bug.cgi?id=1274783 * https://bugzilla.suse.com/show_bug.cgi?id=1274787 * https://bugzilla.suse.com/show_bug.cgi?id=1274800 * https://bugzilla.suse.com/show_bug.cgi?id=1274801 * https://bugzilla.suse.com/show_bug.cgi?id=1274802 * https://bugzilla.suse.com/show_bug.cgi?id=1274804 * https://bugzilla.suse.com/show_bug.cgi?id=1274805 * https://bugzilla.suse.com/show_bug.cgi?id=1274807 * https://bugzilla.suse.com/show_bug.cgi?id=1274808 * https://bugzilla.suse.com/show_bug.cgi?id=1274811 * https://bugzilla.suse.com/show_bug.cgi?id=1274813 * https://bugzilla.suse.com/show_bug.cgi?id=1274814 * https://bugzilla.suse.com/show_bug.cgi?id=1274831 * https://bugzilla.suse.com/show_bug.cgi?id=1274834 * https://bugzilla.suse.com/show_bug.cgi?id=1274835 * https://bugzilla.suse.com/show_bug.cgi?id=1274847 * https://bugzilla.suse.com/show_bug.cgi?id=1274849 * https://bugzilla.suse.com/show_bug.cgi?id=1274853 * https://bugzilla.suse.com/show_bug.cgi?id=1274868 * https://bugzilla.suse.com/show_bug.cgi?id=1274869 * https://bugzilla.suse.com/show_bug.cgi?id=1274872 * https://bugzilla.suse.com/show_bug.cgi?id=1274873 * https://bugzilla.suse.com/show_bug.cgi?id=1274874 * https://bugzilla.suse.com/show_bug.cgi?id=1274876 * https://bugzilla.suse.com/show_bug.cgi?id=1274877 * https://bugzilla.suse.com/show_bug.cgi?id=1274879 * https://bugzilla.suse.com/show_bug.cgi?id=1274881 * https://bugzilla.suse.com/show_bug.cgi?id=1274883 * https://bugzilla.suse.com/show_bug.cgi?id=1274886 * https://bugzilla.suse.com/show_bug.cgi?id=1274888 * https://bugzilla.suse.com/show_bug.cgi?id=1274891 * https://bugzilla.suse.com/show_bug.cgi?id=1274892 * https://bugzilla.suse.com/show_bug.cgi?id=1274893 * https://bugzilla.suse.com/show_bug.cgi?id=1274894 * https://bugzilla.suse.com/show_bug.cgi?id=1274895 * https://bugzilla.suse.com/show_bug.cgi?id=1274896 * https://bugzilla.suse.com/show_bug.cgi?id=1274897 * https://bugzilla.suse.com/show_bug.cgi?id=1274898 * https://bugzilla.suse.com/show_bug.cgi?id=1274899 * https://bugzilla.suse.com/show_bug.cgi?id=1274901 * https://bugzilla.suse.com/show_bug.cgi?id=1274902 * https://bugzilla.suse.com/show_bug.cgi?id=1274905 * https://bugzilla.suse.com/show_bug.cgi?id=1274906 * https://bugzilla.suse.com/show_bug.cgi?id=1274907 * https://bugzilla.suse.com/show_bug.cgi?id=1274908 * https://bugzilla.suse.com/show_bug.cgi?id=1274913 * https://bugzilla.suse.com/show_bug.cgi?id=1274914 * https://bugzilla.suse.com/show_bug.cgi?id=1274920 * https://bugzilla.suse.com/show_bug.cgi?id=1274921 * https://bugzilla.suse.com/show_bug.cgi?id=1274924 * https://bugzilla.suse.com/show_bug.cgi?id=1274925 * https://bugzilla.suse.com/show_bug.cgi?id=1274929 * https://bugzilla.suse.com/show_bug.cgi?id=1274930 * https://bugzilla.suse.com/show_bug.cgi?id=1274933 * https://bugzilla.suse.com/show_bug.cgi?id=1274934 * https://bugzilla.suse.com/show_bug.cgi?id=1274935 * https://bugzilla.suse.com/show_bug.cgi?id=1274941 * https://bugzilla.suse.com/show_bug.cgi?id=1274945 * https://bugzilla.suse.com/show_bug.cgi?id=1274947 * https://bugzilla.suse.com/show_bug.cgi?id=1274951 * https://bugzilla.suse.com/show_bug.cgi?id=1274953 * https://bugzilla.suse.com/show_bug.cgi?id=1274958 * https://bugzilla.suse.com/show_bug.cgi?id=1274968 * https://bugzilla.suse.com/show_bug.cgi?id=1274981 * https://bugzilla.suse.com/show_bug.cgi?id=1275040 * https://bugzilla.suse.com/show_bug.cgi?id=1275069 * https://bugzilla.suse.com/show_bug.cgi?id=1275071 * https://bugzilla.suse.com/show_bug.cgi?id=1275073 * https://bugzilla.suse.com/show_bug.cgi?id=1275076 * https://bugzilla.suse.com/show_bug.cgi?id=1275080 * https://bugzilla.suse.com/show_bug.cgi?id=1275081 * https://bugzilla.suse.com/show_bug.cgi?id=1275083 * https://bugzilla.suse.com/show_bug.cgi?id=1275088 * https://bugzilla.suse.com/show_bug.cgi?id=1275091 * https://bugzilla.suse.com/show_bug.cgi?id=1275125 * https://bugzilla.suse.com/show_bug.cgi?id=1275126 * https://bugzilla.suse.com/show_bug.cgi?id=1275131 * https://bugzilla.suse.com/show_bug.cgi?id=1275132 * https://bugzilla.suse.com/show_bug.cgi?id=1275139 * https://bugzilla.suse.com/show_bug.cgi?id=1275141 * https://bugzilla.suse.com/show_bug.cgi?id=1275146 * https://bugzilla.suse.com/show_bug.cgi?id=1275148 * https://bugzilla.suse.com/show_bug.cgi?id=1275149 * https://bugzilla.suse.com/show_bug.cgi?id=1275150 * https://bugzilla.suse.com/show_bug.cgi?id=1275152 * https://bugzilla.suse.com/show_bug.cgi?id=1275154 * https://bugzilla.suse.com/show_bug.cgi?id=1275155 * https://bugzilla.suse.com/show_bug.cgi?id=1275156 * https://bugzilla.suse.com/show_bug.cgi?id=1275157 * https://bugzilla.suse.com/show_bug.cgi?id=1275158 * https://bugzilla.suse.com/show_bug.cgi?id=1275161 * https://bugzilla.suse.com/show_bug.cgi?id=1275163 * https://bugzilla.suse.com/show_bug.cgi?id=1275164 * https://bugzilla.suse.com/show_bug.cgi?id=1275169 * https://bugzilla.suse.com/show_bug.cgi?id=1275173 * https://bugzilla.suse.com/show_bug.cgi?id=1275176 * https://bugzilla.suse.com/show_bug.cgi?id=1275185 * https://bugzilla.suse.com/show_bug.cgi?id=1275190 * https://bugzilla.suse.com/show_bug.cgi?id=1275192 * https://bugzilla.suse.com/show_bug.cgi?id=1275236 * https://bugzilla.suse.com/show_bug.cgi?id=1275237 * https://bugzilla.suse.com/show_bug.cgi?id=1275239 * https://bugzilla.suse.com/show_bug.cgi?id=1275294 * https://bugzilla.suse.com/show_bug.cgi?id=1275300 * https://bugzilla.suse.com/show_bug.cgi?id=1275301 * https://bugzilla.suse.com/show_bug.cgi?id=1275303 * https://bugzilla.suse.com/show_bug.cgi?id=1275304 * https://bugzilla.suse.com/show_bug.cgi?id=1275305 * https://bugzilla.suse.com/show_bug.cgi?id=1275306 * https://bugzilla.suse.com/show_bug.cgi?id=1275307 * https://bugzilla.suse.com/show_bug.cgi?id=1275470 * https://bugzilla.suse.com/show_bug.cgi?id=1275472 * https://bugzilla.suse.com/show_bug.cgi?id=1275474 * https://bugzilla.suse.com/show_bug.cgi?id=1275479 * https://bugzilla.suse.com/show_bug.cgi?id=1275483 * https://bugzilla.suse.com/show_bug.cgi?id=1275486 * https://bugzilla.suse.com/show_bug.cgi?id=1275487 * https://bugzilla.suse.com/show_bug.cgi?id=1275506 * https://bugzilla.suse.com/show_bug.cgi?id=1275509 * https://bugzilla.suse.com/show_bug.cgi?id=1275511 * https://bugzilla.suse.com/show_bug.cgi?id=1275517 * https://bugzilla.suse.com/show_bug.cgi?id=1275519 * https://bugzilla.suse.com/show_bug.cgi?id=1275528 * https://bugzilla.suse.com/show_bug.cgi?id=1275535 * https://bugzilla.suse.com/show_bug.cgi?id=1275540 * https://bugzilla.suse.com/show_bug.cgi?id=1275553 * https://bugzilla.suse.com/show_bug.cgi?id=1275555 * https://bugzilla.suse.com/show_bug.cgi?id=1275557 * https://bugzilla.suse.com/show_bug.cgi?id=1275561 * https://bugzilla.suse.com/show_bug.cgi?id=1275566 * https://bugzilla.suse.com/show_bug.cgi?id=1275569 * https://bugzilla.suse.com/show_bug.cgi?id=1275572 * https://bugzilla.suse.com/show_bug.cgi?id=1275574 * https://bugzilla.suse.com/show_bug.cgi?id=1275578 * https://bugzilla.suse.com/show_bug.cgi?id=1275582 * https://bugzilla.suse.com/show_bug.cgi?id=1275583 * https://bugzilla.suse.com/show_bug.cgi?id=1275584 * https://bugzilla.suse.com/show_bug.cgi?id=1275591 * https://bugzilla.suse.com/show_bug.cgi?id=1275595 * https://bugzilla.suse.com/show_bug.cgi?id=1275633 * https://bugzilla.suse.com/show_bug.cgi?id=1275636 * https://bugzilla.suse.com/show_bug.cgi?id=1275650 * https://bugzilla.suse.com/show_bug.cgi?id=1275656 * https://bugzilla.suse.com/show_bug.cgi?id=1275659 * https://bugzilla.suse.com/show_bug.cgi?id=1275665 * https://bugzilla.suse.com/show_bug.cgi?id=1275669 * https://bugzilla.suse.com/show_bug.cgi?id=1275687 * https://bugzilla.suse.com/show_bug.cgi?id=1275688 * https://bugzilla.suse.com/show_bug.cgi?id=1275695 * https://bugzilla.suse.com/show_bug.cgi?id=1275696 * https://bugzilla.suse.com/show_bug.cgi?id=1275704 * https://bugzilla.suse.com/show_bug.cgi?id=1275737 * https://bugzilla.suse.com/show_bug.cgi?id=1275782 * https://bugzilla.suse.com/show_bug.cgi?id=1275784 * https://bugzilla.suse.com/show_bug.cgi?id=1275787 * https://bugzilla.suse.com/show_bug.cgi?id=1275788 * https://bugzilla.suse.com/show_bug.cgi?id=1275789 * https://bugzilla.suse.com/show_bug.cgi?id=1275790 * https://bugzilla.suse.com/show_bug.cgi?id=1275797 * https://bugzilla.suse.com/show_bug.cgi?id=1275798 * https://bugzilla.suse.com/show_bug.cgi?id=1275805 * https://bugzilla.suse.com/show_bug.cgi?id=1275817 * https://bugzilla.suse.com/show_bug.cgi?id=1275818 * https://bugzilla.suse.com/show_bug.cgi?id=1275819 * https://bugzilla.suse.com/show_bug.cgi?id=1275820 * https://bugzilla.suse.com/show_bug.cgi?id=1275821 * https://bugzilla.suse.com/show_bug.cgi?id=1275822 * https://bugzilla.suse.com/show_bug.cgi?id=1275823 * https://bugzilla.suse.com/show_bug.cgi?id=1275827 * https://bugzilla.suse.com/show_bug.cgi?id=1275864 * https://bugzilla.suse.com/show_bug.cgi?id=1275867 * https://bugzilla.suse.com/show_bug.cgi?id=1275869 * https://bugzilla.suse.com/show_bug.cgi?id=1275870 * https://bugzilla.suse.com/show_bug.cgi?id=1275871 * https://bugzilla.suse.com/show_bug.cgi?id=1275872 * https://bugzilla.suse.com/show_bug.cgi?id=1275886 * https://bugzilla.suse.com/show_bug.cgi?id=1275905 * https://bugzilla.suse.com/show_bug.cgi?id=1275923 * https://bugzilla.suse.com/show_bug.cgi?id=1275925 * https://bugzilla.suse.com/show_bug.cgi?id=1275928 * https://bugzilla.suse.com/show_bug.cgi?id=1275946 * https://bugzilla.suse.com/show_bug.cgi?id=1275950 * https://bugzilla.suse.com/show_bug.cgi?id=1275954 * https://bugzilla.suse.com/show_bug.cgi?id=1275970 * https://bugzilla.suse.com/show_bug.cgi?id=1275973 * https://bugzilla.suse.com/show_bug.cgi?id=1275975 * https://bugzilla.suse.com/show_bug.cgi?id=1275976 * https://bugzilla.suse.com/show_bug.cgi?id=1276029 * https://bugzilla.suse.com/show_bug.cgi?id=1276257 * https://bugzilla.suse.com/show_bug.cgi?id=1276263 * https://bugzilla.suse.com/show_bug.cgi?id=1276270 * https://bugzilla.suse.com/show_bug.cgi?id=1276273 * https://bugzilla.suse.com/show_bug.cgi?id=1276277 * https://bugzilla.suse.com/show_bug.cgi?id=1276335 * https://bugzilla.suse.com/show_bug.cgi?id=1276346 * https://bugzilla.suse.com/show_bug.cgi?id=1276350 * https://bugzilla.suse.com/show_bug.cgi?id=1276355 * https://bugzilla.suse.com/show_bug.cgi?id=1276446 * https://bugzilla.suse.com/show_bug.cgi?id=1276452 * https://bugzilla.suse.com/show_bug.cgi?id=1276500 * https://bugzilla.suse.com/show_bug.cgi?id=1276507 * https://bugzilla.suse.com/show_bug.cgi?id=1276542 * https://bugzilla.suse.com/show_bug.cgi?id=1276546 * https://bugzilla.suse.com/show_bug.cgi?id=1276551 * https://bugzilla.suse.com/show_bug.cgi?id=1276552 * https://bugzilla.suse.com/show_bug.cgi?id=1276561 * https://bugzilla.suse.com/show_bug.cgi?id=1276569 * https://bugzilla.suse.com/show_bug.cgi?id=1276577 * https://bugzilla.suse.com/show_bug.cgi?id=1276665 * https://bugzilla.suse.com/show_bug.cgi?id=1276864 * https://bugzilla.suse.com/show_bug.cgi?id=1276912 * https://bugzilla.suse.com/show_bug.cgi?id=1276913 * https://bugzilla.suse.com/show_bug.cgi?id=1276927 * https://bugzilla.suse.com/show_bug.cgi?id=1276931 * https://bugzilla.suse.com/show_bug.cgi?id=1276937 * https://bugzilla.suse.com/show_bug.cgi?id=1276941 * https://bugzilla.suse.com/show_bug.cgi?id=1276943 * https://bugzilla.suse.com/show_bug.cgi?id=1276944 * https://bugzilla.suse.com/show_bug.cgi?id=1276955 * https://bugzilla.suse.com/show_bug.cgi?id=1276961 * https://bugzilla.suse.com/show_bug.cgi?id=1277022 * https://bugzilla.suse.com/show_bug.cgi?id=1277034 * https://bugzilla.suse.com/show_bug.cgi?id=1277037 * https://bugzilla.suse.com/show_bug.cgi?id=1277047 * https://bugzilla.suse.com/show_bug.cgi?id=1277054 * https://bugzilla.suse.com/show_bug.cgi?id=1277057 * https://bugzilla.suse.com/show_bug.cgi?id=1277059 * https://bugzilla.suse.com/show_bug.cgi?id=1277064 * https://bugzilla.suse.com/show_bug.cgi?id=1277066 * https://bugzilla.suse.com/show_bug.cgi?id=1277069 * https://bugzilla.suse.com/show_bug.cgi?id=1277073 * https://bugzilla.suse.com/show_bug.cgi?id=1277077 * https://bugzilla.suse.com/show_bug.cgi?id=1277095 * https://bugzilla.suse.com/show_bug.cgi?id=1277155 * https://bugzilla.suse.com/show_bug.cgi?id=1277159 * https://bugzilla.suse.com/show_bug.cgi?id=1277160 * https://bugzilla.suse.com/show_bug.cgi?id=1277202 * https://bugzilla.suse.com/show_bug.cgi?id=1277204 * https://bugzilla.suse.com/show_bug.cgi?id=1277275 * https://bugzilla.suse.com/show_bug.cgi?id=1277285 * https://bugzilla.suse.com/show_bug.cgi?id=1277391 * https://bugzilla.suse.com/show_bug.cgi?id=1277408 * https://bugzilla.suse.com/show_bug.cgi?id=1277516 * https://bugzilla.suse.com/show_bug.cgi?id=1277523 * https://bugzilla.suse.com/show_bug.cgi?id=1277551 * https://bugzilla.suse.com/show_bug.cgi?id=1277625 * https://bugzilla.suse.com/show_bug.cgi?id=1277660 * https://bugzilla.suse.com/show_bug.cgi?id=1277678 * https://bugzilla.suse.com/show_bug.cgi?id=1277688 * https://bugzilla.suse.com/show_bug.cgi?id=1277775 * https://bugzilla.suse.com/show_bug.cgi?id=1277776 * https://jira.suse.com/browse/PED-15880 * https://jira.suse.com/browse/PED-16798 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 20:45:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 20:45:54 -0000 Subject: SUSE-SU-2026:4244-1: important: Security update for the Linux Kernel (Live Patch 39 for SUSE Linux Enterprise 15 SP5) Message-ID: <178967795472.5437.15275050657081896517@55cee2c216ba> # Security update for the Linux Kernel (Live Patch 39 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:4244-1 Release Date: 2026-09-17T13:34:01Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.163 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-4244 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-4244 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_163-default-7-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_39-debugsource-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-7-150500.2.1 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_163-default-7-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_39-debugsource-7-150500.2.1 * kernel-livepatch-5_14_21-150500_55_163-default-debuginfo-7-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 20:46:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 20:46:52 -0000 Subject: SUSE-SU-2026:4243-1: important: Security update for the Linux Kernel (Live Patch 78 for SUSE Linux Enterprise 12 SP5) Message-ID: <178967801290.5437.5778615783461613575@55cee2c216ba> # Security update for the Linux Kernel (Live Patch 78 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:4243-1 Release Date: 2026-09-17T14:33:45Z Rating: important References: * bsc#1267388 * bsc#1274074 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64564 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.296 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-4243 SUSE-SLE-Live- Patching-12-SP5-2026-4245 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_296-default-9-2.1 * kgraft-patch-4_12_14-122_272-default-17-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 20:47:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 20:47:33 -0000 Subject: SUSE-SU-2026:4253-1: important: Security update for cjose Message-ID: <178967805308.5437.16610253423954633025@55cee2c216ba> # Security update for cjose Announcement ID: SUSE-SU-2026:4253-1 Release Date: 2026-09-17T16:02:17Z Rating: important References: * bsc#1279844 * bsc#1279846 Cross-References: * CVE-2026-53938 * CVE-2026-53939 CVSS scores: * CVE-2026-53938 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53938 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53938 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53939 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53939 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53939 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for cjose fixes the following issues: * CVE-2026-53938: missing encrypted_key length validation during AES Key Wrap decryption can cause heap-based buffer overflow (bsc#1279844). * CVE-2026-53939: zero-filled content-encryption key generation in AES-CBC- HMAC JWE encryption within cjose can allow unauthorized content modification (bsc#1279846). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4253 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4253 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4253 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4253 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4253 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4253 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4253 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4253 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libcjose-devel-0.6.1-150100.4.9.1 * libcjose0-debuginfo-0.6.1-150100.4.9.1 * libcjose0-0.6.1-150100.4.9.1 * cjose-debugsource-0.6.1-150100.4.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libcjose-devel-0.6.1-150100.4.9.1 * libcjose0-debuginfo-0.6.1-150100.4.9.1 * libcjose0-0.6.1-150100.4.9.1 * cjose-debugsource-0.6.1-150100.4.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libcjose-devel-0.6.1-150100.4.9.1 * libcjose0-debuginfo-0.6.1-150100.4.9.1 * libcjose0-0.6.1-150100.4.9.1 * cjose-debugsource-0.6.1-150100.4.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libcjose-devel-0.6.1-150100.4.9.1 * libcjose0-debuginfo-0.6.1-150100.4.9.1 * libcjose0-0.6.1-150100.4.9.1 * cjose-debugsource-0.6.1-150100.4.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libcjose-devel-0.6.1-150100.4.9.1 * libcjose0-debuginfo-0.6.1-150100.4.9.1 * libcjose0-0.6.1-150100.4.9.1 * cjose-debugsource-0.6.1-150100.4.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libcjose-devel-0.6.1-150100.4.9.1 * libcjose0-debuginfo-0.6.1-150100.4.9.1 * libcjose0-0.6.1-150100.4.9.1 * cjose-debugsource-0.6.1-150100.4.9.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libcjose-devel-0.6.1-150100.4.9.1 * libcjose0-debuginfo-0.6.1-150100.4.9.1 * libcjose0-0.6.1-150100.4.9.1 * cjose-debugsource-0.6.1-150100.4.9.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libcjose-devel-0.6.1-150100.4.9.1 * libcjose0-debuginfo-0.6.1-150100.4.9.1 * libcjose0-0.6.1-150100.4.9.1 * cjose-debugsource-0.6.1-150100.4.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53938.html * https://www.suse.com/security/cve/CVE-2026-53939.html * https://bugzilla.suse.com/show_bug.cgi?id=1279844 * https://bugzilla.suse.com/show_bug.cgi?id=1279846 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 20:48:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 20:48:11 -0000 Subject: SUSE-SU-2026:4252-1: moderate: Security update for tiff Message-ID: <178967809166.5437.4468719577451802991@55cee2c216ba> # Security update for tiff Announcement ID: SUSE-SU-2026:4252-1 Release Date: 2026-09-17T16:01:31Z Rating: moderate References: * bsc#1280164 Cross-References: * CVE-2026-18495 CVSS scores: * CVE-2026-18495 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-18495 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-18495 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for tiff fixes the following issue: * CVE-2026-18495: libtiff: heap-buffer overflow via numeric truncation in the JPEG raw passthrough (bsc#1280164). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4252 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libtiff5-debuginfo-4.0.9-44.118.1 * tiff-4.0.9-44.118.1 * tiff-debugsource-4.0.9-44.118.1 * libtiff5-debuginfo-32bit-4.0.9-44.118.1 * libtiff5-4.0.9-44.118.1 * tiff-debuginfo-4.0.9-44.118.1 * libtiff-devel-4.0.9-44.118.1 * libtiff5-32bit-4.0.9-44.118.1 ## References: * https://www.suse.com/security/cve/CVE-2026-18495.html * https://bugzilla.suse.com/show_bug.cgi?id=1280164 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 20:48:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 20:48:51 -0000 Subject: SUSE-SU-2026:4251-1: important: Security update for cjose Message-ID: <178967813152.5437.5589804188735846275@55cee2c216ba> # Security update for cjose Announcement ID: SUSE-SU-2026:4251-1 Release Date: 2026-09-17T16:01:20Z Rating: important References: * bsc#1279844 * bsc#1279846 Cross-References: * CVE-2026-53938 * CVE-2026-53939 CVSS scores: * CVE-2026-53938 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-53938 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53938 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-53939 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53939 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53939 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N Affected Products: * openSUSE Leap 15.6 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for cjose fixes the following issues: * CVE-2026-53938: missing encrypted_key length validation during AES Key Wrap decryption can cause heap-based buffer overflow (bsc#1279844). * CVE-2026-53939: zero-filled content-encryption key generation in AES-CBC- HMAC JWE encryption within cjose can allow unauthorized content modification (bsc#1279846). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4251 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4251 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-4251 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4251 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libcjose0-debuginfo-0.6.1-150600.18.3.1 * libcjose0-0.6.1-150600.18.3.1 * cjose-debugsource-0.6.1-150600.18.3.1 * libcjose-devel-0.6.1-150600.18.3.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libcjose0-debuginfo-0.6.1-150600.18.3.1 * libcjose0-0.6.1-150600.18.3.1 * cjose-debugsource-0.6.1-150600.18.3.1 * libcjose-devel-0.6.1-150600.18.3.1 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libcjose0-debuginfo-0.6.1-150600.18.3.1 * libcjose0-0.6.1-150600.18.3.1 * cjose-debugsource-0.6.1-150600.18.3.1 * libcjose-devel-0.6.1-150600.18.3.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libcjose0-debuginfo-0.6.1-150600.18.3.1 * libcjose0-0.6.1-150600.18.3.1 * cjose-debugsource-0.6.1-150600.18.3.1 * libcjose-devel-0.6.1-150600.18.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-53938.html * https://www.suse.com/security/cve/CVE-2026-53939.html * https://bugzilla.suse.com/show_bug.cgi?id=1279844 * https://bugzilla.suse.com/show_bug.cgi?id=1279846 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 20:49:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 20:49:57 -0000 Subject: SUSE-SU-2026:4250-1: moderate: Security update for glibc Message-ID: <178967819700.5437.3064292819367416464@55cee2c216ba> # Security update for glibc Announcement ID: SUSE-SU-2026:4250-1 Release Date: 2026-09-17T16:00:58Z Rating: moderate References: * bsc#1267610 * bsc#1274723 * bsc#1274726 * bsc#1276892 * bsc#1276946 * bsc#1277262 * bsc#1277921 * bsc#1277922 Cross-References: * CVE-2026-18374 * CVE-2026-19499 * CVE-2026-19542 * CVE-2026-6368 * CVE-2026-6791 * CVE-2026-77117 * CVE-2026-80489 CVSS scores: * CVE-2026-18374 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-18374 ( SUSE ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-18374 ( NVD ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-19499 ( SUSE ): 4.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-19499 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H * CVE-2026-19499 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-19542 ( SUSE ): 1.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-19542 ( SUSE ): 4.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2026-19542 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6368 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-6368 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green * CVE-2026-6791 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-6791 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-77117 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-77117 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-77117 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80489 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80489 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80489 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Development Tools Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves seven vulnerabilities and has one security fix can now be installed. ## Description: This update for glibc fixes the following issues: * CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). * CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). * CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). * CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). * CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). * CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). * CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4250 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4250 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4250 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-4250 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4250 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * glibc-extra-debuginfo-2.38-150600.14.58.1 * nscd-2.38-150600.14.58.1 * glibc-debugsource-2.38-150600.14.58.1 * glibc-extra-2.38-150600.14.58.1 * nscd-debuginfo-2.38-150600.14.58.1 * glibc-locale-base-debuginfo-2.38-150600.14.58.1 * glibc-locale-2.38-150600.14.58.1 * glibc-devel-static-2.38-150600.14.58.1 * glibc-debuginfo-2.38-150600.14.58.1 * glibc-2.38-150600.14.58.1 * glibc-utils-2.38-150600.14.58.1 * glibc-utils-src-debugsource-2.38-150600.14.58.1 * glibc-devel-debuginfo-2.38-150600.14.58.1 * glibc-profile-2.38-150600.14.58.1 * libnsl1-debuginfo-2.38-150600.14.58.1 * glibc-locale-base-2.38-150600.14.58.1 * glibc-utils-debuginfo-2.38-150600.14.58.1 * libnsl1-2.38-150600.14.58.1 * glibc-devel-2.38-150600.14.58.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * libnsl1-32bit-debuginfo-2.38-150600.14.58.1 * glibc-locale-base-32bit-2.38-150600.14.58.1 * glibc-locale-base-32bit-debuginfo-2.38-150600.14.58.1 * libnsl1-32bit-2.38-150600.14.58.1 * glibc-32bit-debuginfo-2.38-150600.14.58.1 * glibc-devel-32bit-2.38-150600.14.58.1 * glibc-32bit-2.38-150600.14.58.1 * glibc-devel-32bit-debuginfo-2.38-150600.14.58.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * glibc-i18ndata-2.38-150600.14.58.1 * glibc-lang-2.38-150600.14.58.1 * glibc-info-2.38-150600.14.58.1 * openSUSE Leap 15.6 (aarch64 i586 i686 ppc64le s390x x86_64) * glibc-2.38-150600.14.58.1 * glibc-devel-static-2.38-150600.14.58.1 * glibc-locale-base-2.38-150600.14.58.1 * glibc-debugsource-2.38-150600.14.58.1 * libnsl1-2.38-150600.14.58.1 * glibc-profile-2.38-150600.14.58.1 * glibc-devel-2.38-150600.14.58.1 * glibc-locale-base-debuginfo-2.38-150600.14.58.1 * glibc-devel-debuginfo-2.38-150600.14.58.1 * glibc-locale-2.38-150600.14.58.1 * glibc-debuginfo-2.38-150600.14.58.1 * libnsl1-debuginfo-2.38-150600.14.58.1 * openSUSE Leap 15.6 (x86_64) * libnsl1-32bit-debuginfo-2.38-150600.14.58.1 * glibc-profile-32bit-2.38-150600.14.58.1 * glibc-utils-32bit-2.38-150600.14.58.1 * glibc-locale-base-32bit-2.38-150600.14.58.1 * glibc-locale-base-32bit-debuginfo-2.38-150600.14.58.1 * libnsl1-32bit-2.38-150600.14.58.1 * glibc-devel-static-32bit-2.38-150600.14.58.1 * glibc-32bit-debuginfo-2.38-150600.14.58.1 * glibc-utils-32bit-debuginfo-2.38-150600.14.58.1 * glibc-devel-32bit-2.38-150600.14.58.1 * glibc-32bit-2.38-150600.14.58.1 * glibc-devel-32bit-debuginfo-2.38-150600.14.58.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libnsl1-64bit-2.38-150600.14.58.1 * libnsl1-64bit-debuginfo-2.38-150600.14.58.1 * glibc-locale-base-64bit-2.38-150600.14.58.1 * glibc-utils-64bit-2.38-150600.14.58.1 * glibc-devel-64bit-debuginfo-2.38-150600.14.58.1 * glibc-profile-64bit-2.38-150600.14.58.1 * glibc-devel-64bit-2.38-150600.14.58.1 * glibc-utils-64bit-debuginfo-2.38-150600.14.58.1 * glibc-locale-base-64bit-debuginfo-2.38-150600.14.58.1 * glibc-devel-static-64bit-2.38-150600.14.58.1 * glibc-64bit-2.38-150600.14.58.1 * glibc-64bit-debuginfo-2.38-150600.14.58.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * glibc-extra-debuginfo-2.38-150600.14.58.1 * nscd-2.38-150600.14.58.1 * glibc-utils-debuginfo-2.38-150600.14.58.1 * glibc-extra-2.38-150600.14.58.1 * glibc-utils-2.38-150600.14.58.1 * glibc-utils-src-debugsource-2.38-150600.14.58.1 * nscd-debuginfo-2.38-150600.14.58.1 * openSUSE Leap 15.6 (noarch) * glibc-i18ndata-2.38-150600.14.58.1 * glibc-lang-2.38-150600.14.58.1 * glibc-info-2.38-150600.14.58.1 * glibc-html-2.38-150600.14.58.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * glibc-extra-debuginfo-2.38-150600.14.58.1 * glibc-2.38-150600.14.58.1 * glibc-locale-base-2.38-150600.14.58.1 * nscd-2.38-150600.14.58.1 * nscd-debuginfo-2.38-150600.14.58.1 * glibc-debugsource-2.38-150600.14.58.1 * glibc-extra-2.38-150600.14.58.1 * libnsl1-2.38-150600.14.58.1 * glibc-profile-2.38-150600.14.58.1 * glibc-devel-2.38-150600.14.58.1 * glibc-locale-base-debuginfo-2.38-150600.14.58.1 * glibc-devel-debuginfo-2.38-150600.14.58.1 * glibc-locale-2.38-150600.14.58.1 * glibc-debuginfo-2.38-150600.14.58.1 * libnsl1-debuginfo-2.38-150600.14.58.1 * Basesystem Module 15-SP7 (x86_64) * libnsl1-32bit-debuginfo-2.38-150600.14.58.1 * glibc-locale-base-32bit-2.38-150600.14.58.1 * glibc-locale-base-32bit-debuginfo-2.38-150600.14.58.1 * libnsl1-32bit-2.38-150600.14.58.1 * glibc-32bit-debuginfo-2.38-150600.14.58.1 * glibc-32bit-2.38-150600.14.58.1 * Basesystem Module 15-SP7 (noarch) * glibc-i18ndata-2.38-150600.14.58.1 * glibc-lang-2.38-150600.14.58.1 * glibc-info-2.38-150600.14.58.1 * Development Tools Module 15-SP7 (x86_64) * glibc-devel-32bit-2.38-150600.14.58.1 * glibc-32bit-debuginfo-2.38-150600.14.58.1 * glibc-devel-32bit-debuginfo-2.38-150600.14.58.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * glibc-utils-debuginfo-2.38-150600.14.58.1 * glibc-debugsource-2.38-150600.14.58.1 * glibc-debuginfo-2.38-150600.14.58.1 * glibc-utils-2.38-150600.14.58.1 * glibc-utils-src-debugsource-2.38-150600.14.58.1 * glibc-devel-static-2.38-150600.14.58.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * glibc-extra-debuginfo-2.38-150600.14.58.1 * nscd-2.38-150600.14.58.1 * glibc-debugsource-2.38-150600.14.58.1 * glibc-extra-2.38-150600.14.58.1 * nscd-debuginfo-2.38-150600.14.58.1 * glibc-locale-base-debuginfo-2.38-150600.14.58.1 * glibc-locale-2.38-150600.14.58.1 * glibc-devel-static-2.38-150600.14.58.1 * glibc-debuginfo-2.38-150600.14.58.1 * glibc-2.38-150600.14.58.1 * glibc-utils-2.38-150600.14.58.1 * glibc-utils-src-debugsource-2.38-150600.14.58.1 * glibc-devel-debuginfo-2.38-150600.14.58.1 * glibc-profile-2.38-150600.14.58.1 * libnsl1-debuginfo-2.38-150600.14.58.1 * glibc-locale-base-2.38-150600.14.58.1 * glibc-utils-debuginfo-2.38-150600.14.58.1 * libnsl1-2.38-150600.14.58.1 * glibc-devel-2.38-150600.14.58.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * glibc-i18ndata-2.38-150600.14.58.1 * glibc-lang-2.38-150600.14.58.1 * glibc-info-2.38-150600.14.58.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (x86_64) * libnsl1-32bit-debuginfo-2.38-150600.14.58.1 * glibc-locale-base-32bit-2.38-150600.14.58.1 * glibc-locale-base-32bit-debuginfo-2.38-150600.14.58.1 * libnsl1-32bit-2.38-150600.14.58.1 * glibc-32bit-debuginfo-2.38-150600.14.58.1 * glibc-devel-32bit-2.38-150600.14.58.1 * glibc-32bit-2.38-150600.14.58.1 * glibc-devel-32bit-debuginfo-2.38-150600.14.58.1 ## References: * https://www.suse.com/security/cve/CVE-2026-18374.html * https://www.suse.com/security/cve/CVE-2026-19499.html * https://www.suse.com/security/cve/CVE-2026-19542.html * https://www.suse.com/security/cve/CVE-2026-6368.html * https://www.suse.com/security/cve/CVE-2026-6791.html * https://www.suse.com/security/cve/CVE-2026-77117.html * https://www.suse.com/security/cve/CVE-2026-80489.html * https://bugzilla.suse.com/show_bug.cgi?id=1267610 * https://bugzilla.suse.com/show_bug.cgi?id=1274723 * https://bugzilla.suse.com/show_bug.cgi?id=1274726 * https://bugzilla.suse.com/show_bug.cgi?id=1276892 * https://bugzilla.suse.com/show_bug.cgi?id=1276946 * https://bugzilla.suse.com/show_bug.cgi?id=1277262 * https://bugzilla.suse.com/show_bug.cgi?id=1277921 * https://bugzilla.suse.com/show_bug.cgi?id=1277922 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 20:50:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 20:50:52 -0000 Subject: SUSE-SU-2026:4249-1: important: Security update for netcdf Message-ID: <178967825257.5437.8242540819900408785@55cee2c216ba> # Security update for netcdf Announcement ID: SUSE-SU-2026:4249-1 Release Date: 2026-09-17T16:00:18Z Rating: important References: * bsc#1279882 Cross-References: * CVE-2026-86095 CVSS scores: * CVE-2026-86095 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-86095 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-86095 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-86095 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves one vulnerability can now be installed. ## Description: This update for netcdf fixes the following issue: * CVE-2026-86095: out-of-bounds write in `NC4_HDF5_inq_attname()` due to missing length validation when processing a crafted HDF5 file (bsc#1279882). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4249 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4249 ## Package List: * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * netcdf-openmpi2-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-hpc-devel-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi4-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mpich-hpc-devel-static-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mvapich2-hpc-devel-static-4.7.4-150600.15.5.1 * netcdf-openmpi4-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-openmpi2-hpc-4.7.4-150600.15.5.1 * netcdf-openmpi4-debugsource-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi3-hpc-4.7.4-150600.15.5.1 * netcdf-openmpi3-devel-debuginfo-4.7.4-150600.15.5.1 * libnetcdf18-4.7.4-150600.15.5.1 * libnetcdf18-openmpi2-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi3-hpc-debugsource-4.7.4-150600.15.5.1 * libnetcdf18-openmpi2-4.7.4-150600.15.5.1 * netcdf-openmpi2-devel-static-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-mvapich2-hpc-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-hpc-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mpich-hpc-devel-4.7.4-150600.15.5.1 * libnetcdf18-openmpi4-debuginfo-4.7.4-150600.15.5.1 * libnetcdf-gnu-mpich-hpc-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-openmpi3-hpc-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mpich-hpc-devel-debuginfo-4.7.4-150600.15.5.1 * netcdf-openmpi3-devel-4.7.4-150600.15.5.1 * netcdf-devel-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi4-hpc-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi4-hpc-debugsource-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-openmpi3-hpc-4.7.4-150600.15.5.1 * netcdf-openmpi4-devel-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi2-hpc-debuginfo-4.7.4-150600.15.5.1 * netcdf-devel-4.7.4-150600.15.5.1 * libnetcdf18-debuginfo-4.7.4-150600.15.5.1 * netcdf-devel-data-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi4-hpc-devel-4.7.4-150600.15.5.1 * netcdf-openmpi3-debuginfo-4.7.4-150600.15.5.1 * libnetcdf-gnu-openmpi2-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-hpc-debugsource-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi3-hpc-devel-static-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-hpc-4.7.4-150600.15.5.1 * libnetcdf18-openmpi4-4.7.4-150600.15.5.1 * netcdf-openmpi4-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi3-hpc-devel-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi3-hpc-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mvapich2-hpc-devel-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-hpc-devel-static-4.7.4-150600.15.5.1 * netcdf-debugsource-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mvapich2-hpc-4.7.4-150600.15.5.1 * netcdf-openmpi4-devel-static-4.7.4-150600.15.5.1 * netcdf-openmpi3-devel-static-4.7.4-150600.15.5.1 * netcdf-openmpi4-devel-4.7.4-150600.15.5.1 * netcdf-debuginfo-4.7.4-150600.15.5.1 * netcdf-openmpi2-devel-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi4-hpc-devel-debuginfo-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-mpich-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi2-hpc-devel-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-hpc-devel-4.7.4-150600.15.5.1 * netcdf-openmpi3-debugsource-4.7.4-150600.15.5.1 * libnetcdf-gnu-openmpi4-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi2-hpc-devel-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi4-hpc-devel-static-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-openmpi4-hpc-debuginfo-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-mvapich2-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi3-hpc-devel-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mvapich2-hpc-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mpich-hpc-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi2-hpc-devel-static-4.7.4-150600.15.5.1 * libnetcdf-gnu-mvapich2-hpc-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-hpc-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi2-hpc-4.7.4-150600.15.5.1 * libnetcdf18-openmpi3-debuginfo-4.7.4-150600.15.5.1 * netcdf-4.7.4-150600.15.5.1 * netcdf-openmpi2-debuginfo-4.7.4-150600.15.5.1 * libnetcdf-gnu-openmpi3-hpc-4.7.4-150600.15.5.1 * libnetcdf-gnu-hpc-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-openmpi2-hpc-debuginfo-4.7.4-150600.15.5.1 * libnetcdf18-openmpi3-4.7.4-150600.15.5.1 * netcdf-devel-static-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mvapich2-hpc-devel-debuginfo-4.7.4-150600.15.5.1 * netcdf-openmpi3-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi2-hpc-debugsource-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mpich-hpc-4.7.4-150600.15.5.1 * netcdf-openmpi2-devel-debuginfo-4.7.4-150600.15.5.1 * netcdf-openmpi2-debugsource-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mvapich2-hpc-debugsource-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-mpich-hpc-debuginfo-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-openmpi4-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mpich-hpc-debugsource-4.7.4-150600.15.5.1 * openSUSE Leap 15.6 (x86_64) * libnetcdf18-32bit-debuginfo-4.7.4-150600.15.5.1 * libnetcdf18-openmpi4-32bit-4.7.4-150600.15.5.1 * libnetcdf18-openmpi2-32bit-4.7.4-150600.15.5.1 * libnetcdf18-openmpi3-32bit-4.7.4-150600.15.5.1 * libnetcdf18-openmpi3-32bit-debuginfo-4.7.4-150600.15.5.1 * libnetcdf18-32bit-4.7.4-150600.15.5.1 * libnetcdf18-openmpi4-32bit-debuginfo-4.7.4-150600.15.5.1 * libnetcdf18-openmpi2-32bit-debuginfo-4.7.4-150600.15.5.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libnetcdf18-openmpi4-64bit-4.7.4-150600.15.5.1 * libnetcdf18-64bit-debuginfo-4.7.4-150600.15.5.1 * libnetcdf18-openmpi2-64bit-4.7.4-150600.15.5.1 * libnetcdf18-openmpi3-64bit-debuginfo-4.7.4-150600.15.5.1 * libnetcdf18-openmpi4-64bit-debuginfo-4.7.4-150600.15.5.1 * libnetcdf18-64bit-4.7.4-150600.15.5.1 * libnetcdf18-openmpi3-64bit-4.7.4-150600.15.5.1 * libnetcdf18-openmpi2-64bit-debuginfo-4.7.4-150600.15.5.1 * openSUSE Leap 15.6 (noarch) * netcdf-gnu-hpc-4.7.4-150600.15.5.1 * netcdf-gnu-openmpi3-hpc-devel-4.7.4-150600.15.5.1 * netcdf-gnu-openmpi2-hpc-4.7.4-150600.15.5.1 * netcdf-gnu-openmpi3-hpc-4.7.4-150600.15.5.1 * netcdf-gnu-mpich-hpc-4.7.4-150600.15.5.1 * netcdf-gnu-mvapich2-hpc-4.7.4-150600.15.5.1 * netcdf-gnu-hpc-devel-4.7.4-150600.15.5.1 * netcdf-gnu-openmpi2-hpc-devel-4.7.4-150600.15.5.1 * netcdf-gnu-openmpi4-hpc-devel-4.7.4-150600.15.5.1 * netcdf-gnu-mvapich2-hpc-devel-4.7.4-150600.15.5.1 * netcdf-gnu-openmpi4-hpc-4.7.4-150600.15.5.1 * netcdf-gnu-mpich-hpc-devel-4.7.4-150600.15.5.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * netcdf_4_7_4-gnu-openmpi2-hpc-4.7.4-150600.15.5.1 * libnetcdf18-openmpi3-debuginfo-4.7.4-150600.15.5.1 * netcdf-4.7.4-150600.15.5.1 * netcdf-openmpi2-4.7.4-150600.15.5.1 * netcdf-openmpi4-devel-static-4.7.4-150600.15.5.1 * netcdf-openmpi3-devel-static-4.7.4-150600.15.5.1 * netcdf-openmpi4-devel-4.7.4-150600.15.5.1 * netcdf-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi2-hpc-debuginfo-4.7.4-150600.15.5.1 * netcdf-devel-4.7.4-150600.15.5.1 * netcdf-openmpi2-debuginfo-4.7.4-150600.15.5.1 * netcdf-openmpi2-devel-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi2-hpc-devel-4.7.4-150600.15.5.1 * netcdf-openmpi4-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-openmpi2-hpc-4.7.4-150600.15.5.1 * libnetcdf18-debuginfo-4.7.4-150600.15.5.1 * netcdf-devel-data-4.7.4-150600.15.5.1 * netcdf-openmpi4-debugsource-4.7.4-150600.15.5.1 * netcdf-openmpi3-debugsource-4.7.4-150600.15.5.1 * netcdf-openmpi3-devel-debuginfo-4.7.4-150600.15.5.1 * libnetcdf18-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-openmpi2-hpc-debuginfo-4.7.4-150600.15.5.1 * libnetcdf18-openmpi3-4.7.4-150600.15.5.1 * libnetcdf18-openmpi2-debuginfo-4.7.4-150600.15.5.1 * netcdf-openmpi3-debuginfo-4.7.4-150600.15.5.1 * libnetcdf-gnu-openmpi2-hpc-4.7.4-150600.15.5.1 * netcdf-devel-static-4.7.4-150600.15.5.1 * netcdf-openmpi3-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi2-hpc-devel-debuginfo-4.7.4-150600.15.5.1 * libnetcdf18-openmpi2-4.7.4-150600.15.5.1 * netcdf-openmpi2-devel-static-4.7.4-150600.15.5.1 * libnetcdf18-openmpi4-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi2-hpc-debugsource-4.7.4-150600.15.5.1 * netcdf-openmpi4-debuginfo-4.7.4-150600.15.5.1 * libnetcdf18-openmpi4-debuginfo-4.7.4-150600.15.5.1 * netcdf-openmpi2-devel-debuginfo-4.7.4-150600.15.5.1 * netcdf-openmpi2-debugsource-4.7.4-150600.15.5.1 * netcdf-openmpi3-devel-4.7.4-150600.15.5.1 * netcdf-devel-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi2-hpc-devel-static-4.7.4-150600.15.5.1 * netcdf-debugsource-4.7.4-150600.15.5.1 * netcdf-openmpi4-devel-debuginfo-4.7.4-150600.15.5.1 * SUSE Package Hub 15 15-SP7 (ppc64le s390x) * netcdf_4_7_4-gnu-mvapich2-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-hpc-devel-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi4-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi4-hpc-devel-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mpich-hpc-devel-static-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-hpc-4.7.4-150600.15.5.1 * libnetcdf-gnu-openmpi3-hpc-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-mpich-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mvapich2-hpc-devel-static-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-hpc-devel-4.7.4-150600.15.5.1 * libnetcdf-gnu-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi3-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi4-hpc-devel-4.7.4-150600.15.5.1 * libnetcdf-gnu-openmpi4-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-hpc-debugsource-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi3-hpc-devel-static-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mvapich2-hpc-devel-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi3-hpc-debugsource-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi4-hpc-devel-static-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-mvapich2-hpc-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-hpc-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mpich-hpc-devel-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi4-hpc-debugsource-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-openmpi4-hpc-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi3-hpc-devel-debuginfo-4.7.4-150600.15.5.1 * libnetcdf-gnu-mpich-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mpich-hpc-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-openmpi3-hpc-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi3-hpc-debuginfo-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-mvapich2-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi3-hpc-devel-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mvapich2-hpc-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mpich-hpc-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mpich-hpc-devel-debuginfo-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mvapich2-hpc-debugsource-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-mpich-hpc-debuginfo-4.7.4-150600.15.5.1 * libnetcdf-gnu-mvapich2-hpc-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-openmpi4-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-hpc-devel-static-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mvapich2-hpc-devel-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-openmpi4-hpc-debuginfo-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-hpc-debuginfo-4.7.4-150600.15.5.1 * libnetcdf_4_7_4-gnu-openmpi3-hpc-4.7.4-150600.15.5.1 * netcdf_4_7_4-gnu-mpich-hpc-debugsource-4.7.4-150600.15.5.1 * SUSE Package Hub 15 15-SP7 (noarch) * netcdf-gnu-hpc-4.7.4-150600.15.5.1 * netcdf-gnu-openmpi3-hpc-devel-4.7.4-150600.15.5.1 * netcdf-gnu-openmpi3-hpc-4.7.4-150600.15.5.1 * netcdf-gnu-mpich-hpc-4.7.4-150600.15.5.1 * netcdf-gnu-mvapich2-hpc-4.7.4-150600.15.5.1 * netcdf-gnu-hpc-devel-4.7.4-150600.15.5.1 * netcdf-gnu-openmpi4-hpc-devel-4.7.4-150600.15.5.1 * netcdf-gnu-mvapich2-hpc-devel-4.7.4-150600.15.5.1 * netcdf-gnu-openmpi4-hpc-4.7.4-150600.15.5.1 * netcdf-gnu-mpich-hpc-devel-4.7.4-150600.15.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-86095.html * https://bugzilla.suse.com/show_bug.cgi?id=1279882 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 20:52:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 20:52:34 -0000 Subject: SUSE-SU-2026:4248-1: important: Security update for nodejs18 Message-ID: <178967835473.5437.11729091155748841317@55cee2c216ba> # Security update for nodejs18 Announcement ID: SUSE-SU-2026:4248-1 Release Date: 2026-09-17T15:59:56Z Rating: important References: * bsc#1236258 * bsc#1243218 * bsc#1243220 * bsc#1254738 * bsc#1256570 * bsc#1256573 * bsc#1256574 * bsc#1256576 * bsc#1256848 * bsc#1259853 * bsc#1260455 * bsc#1260463 * bsc#1260480 * bsc#1260494 * bsc#1268477 * bsc#1268479 * bsc#1268481 * bsc#1268482 * bsc#1268555 * bsc#1268592 * bsc#1268593 * bsc#1268605 * bsc#1268606 * bsc#1268608 * bsc#1268609 * bsc#1268611 * bsc#1268618 * bsc#1269825 * bsc#1272941 * bsc#1272942 * bsc#1272943 * bsc#1272944 * bsc#1272945 * bsc#1272947 * bsc#1272948 * bsc#1272951 * bsc#1272958 * bsc#1273591 * bsc#1273593 Cross-References: * CVE-2025-22150 * CVE-2025-23166 * CVE-2025-23167 * CVE-2025-55131 * CVE-2025-59465 * CVE-2025-59466 * CVE-2025-62408 * CVE-2026-11525 * CVE-2026-12151 * CVE-2026-15157 * CVE-2026-16728 * CVE-2026-16729 * CVE-2026-21637 * CVE-2026-21710 * CVE-2026-21713 * CVE-2026-21714 * CVE-2026-21717 * CVE-2026-22036 * CVE-2026-27135 * CVE-2026-48618 * CVE-2026-48619 * CVE-2026-48928 * CVE-2026-48930 * CVE-2026-48931 * CVE-2026-48933 * CVE-2026-48934 * CVE-2026-48935 * CVE-2026-48937 * CVE-2026-56846 * CVE-2026-56848 * CVE-2026-56850 * CVE-2026-58040 * CVE-2026-58042 * CVE-2026-58043 * CVE-2026-58044 * CVE-2026-58045 * CVE-2026-6733 * CVE-2026-9679 CVSS scores: * CVE-2025-22150 ( SUSE ): 7.4 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-22150 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-22150 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-23166 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-23166 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-23166 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-23167 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-23167 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-23167 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-55131 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-55131 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-55131 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2025-55131 ( NVD ): 7.1 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2025-59465 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-59465 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59465 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59465 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59466 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-59466 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59466 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59466 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-62408 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-62408 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11525 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-11525 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-12151 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15157 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-15157 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-15157 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-15157 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-16728 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-16728 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-16728 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16729 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-16729 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-16729 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-21637 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-21637 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-21637 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21637 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21710 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-21710 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21710 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21710 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21713 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-21713 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-21713 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-21714 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-21714 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21714 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-21717 ( SUSE ): 7.2 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-21717 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-21717 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21717 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-22036 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22036 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22036 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-22036 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27135 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48618 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48618 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-48618 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-48618 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48618 ( NVD ): 7.7 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-48619 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48619 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48619 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48928 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48928 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-48928 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48928 ( NVD ): 4.2 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48930 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48930 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-48930 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48930 ( NVD ): 5.6 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-48931 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48931 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48931 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48931 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48933 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48933 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48933 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48933 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48934 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48934 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48934 ( NVD ): 4.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-48935 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48935 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48935 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48937 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48937 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48937 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56846 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56846 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56848 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56848 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56848 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56850 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56850 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-56850 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-56850 ( NVD ): 4.1 CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-58040 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-58040 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-58040 ( NVD ): 6.3 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-58042 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58042 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58042 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58043 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2026-58043 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-58043 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-58043 ( NVD ): 7.5 CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-58044 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-58044 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-58044 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-58045 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58045 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58045 ( NVD ): 6.2 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6733 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-6733 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-9679 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-9679 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 38 vulnerabilities and has one security fix can now be installed. ## Description: This update for nodejs18 fixes the following issues: * CVE-2025-22150: undici: insufficiently random values used when defining the boundary for a multipart/form-data request (bsc#1236258). * CVE-2025-23166: improper error handling in async cryptographic operations crashes process (bsc#1243218). * CVE-2025-23167: llhttp: improper HTTP header block termination in llhttp (bsc#1243220). * CVE-2025-55131: timeout-based race conditions allow for allocations that contain leftover data from previous operations and lead to exposure of in- process secrets (bsc#1256570). * CVE-2025-59465: malformed HTTP/2 HEADERS frame with invalid HPACK data can cause a crash due to an unhandled error (bsc#1256573). * CVE-2025-59466: uncatchable "Maximum call stack size exceeded" error when `async_hooks.createHook()` is enabled can lead to crash (bsc#1256574). * CVE-2025-62408: c-ares 1.32.3-1.34.5 use after free() (bsc#1254738). * CVE-2026-6733: undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery (bsc#1268479). * CVE-2026-9679: undici: undici vulnerable to HTTP header injection via Set- Cookie percent-decoding (bsc#1268477). * CVE-2026-11525: undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (bsc#1268481). * CVE-2026-12151: undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (bsc#1268482). * CVE-2026-15157: No validation of the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher (bsc#1272958). * CVE-2026-16728: undici: downstream response desynchronization via retry interceptor (bsc#1273593). * CVE-2026-16729: undici: undici's setCookie function does not fully sanitize cookie attributes (bsc#1273591). * CVE-2026-21637: synchronous exceptions thrown during certain callbacks bypass the standard TLS error handling paths and can cause a denial of service (bsc#1256576). * CVE-2026-21710: uncaught TypeError exception can cause a denial of service (bsc#1260455). * CVE-2026-21713: timing side-channel in HMAC verification via memcmp can lead to potential MAC forgery (bsc#1260463). * CVE-2026-21714: WINDOW_UPDATE frames on stream 0 can lead to memory leak (bsc#1260480). * CVE-2026-21717: crafted request can lead to hash collisions trivially predictable (bsc#1260494). * CVE-2026-22036: undici: unbounded decompression chain in HTTP responses via Content-Encoding may lead to resource exhaustion (bsc#1256848). * CVE-2026-27135: nghttp2: assertion failure due to missing state validation can lead to DoS (bsc#1259853). * CVE-2026-48618: Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismatch (bsc#1268593). * CVE-2026-48619: Unbounded memory growth in node:http2 clients via attacker- controlled ORIGIN frames (bsc#1268618). * CVE-2026-48928: Uppercase sni context matching can lead to mtls authorization bypass due to case-sensitive hostname matching (bsc#1268605). * CVE-2026-48930: Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings (bsc#1268606). * CVE-2026-48931: HTTP Response Queue Poisoning via TOCTOU Race Condition in http.Agent (bsc#1268611). * CVE-2026-48933: Node.js WebCrypto AES Integer Overflow Leads to Remote Process Abort (bsc#1268592). * CVE-2026-48934: TLS host identity verification bypass via session reuse with different servername leads to unauthorized connections (bsc#1268608). * CVE-2026-48935: Permission Model bypass via FileHandle.utimes() in the promises API (bsc#1268609). * CVE-2026-48937: servers keep accepting data even after sending a `GOAWAY` frame (bsc#1268555). * CVE-2026-56846: HTTP/2 retained headers can bypass maxSessionMemory limits (bsc#1272941). * CVE-2026-56848: HTTP/2 re-entrant send can cause heap-use-after-free (bsc#1272942). * CVE-2026-56850: HTTPS Agent can reuse mTLS identities across PFX certificates (bsc#1272944). * CVE-2026-58040: HTTPS Agent session reuse can skip hostname verification (bsc#1272945). * CVE-2026-58042: dns.resolveAny() can abort on DNS responses with many A records (bsc#1272947). * CVE-2026-58043: Permission Model path matching can over-grant filesystem access (bsc#1272943). * CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951). * CVE-2026-58045: node:zlib sync APIs can crash on spoofed TypedArray length (bsc#1272948). Changes for nodejs18: * upgraded embedded undici to 6.28.0. * upgraded embedded nghttp2 to 1.69.0. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4248 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4248 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * nodejs18-devel-18.20.8-8.44.1 * npm18-18.20.8-8.44.1 * nodejs18-18.20.8-8.44.1 * nodejs18-debuginfo-18.20.8-8.44.1 * nodejs18-debugsource-18.20.8-8.44.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * nodejs18-docs-18.20.8-8.44.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * nodejs18-devel-18.20.8-8.44.1 * npm18-18.20.8-8.44.1 * nodejs18-18.20.8-8.44.1 * nodejs18-debuginfo-18.20.8-8.44.1 * nodejs18-debugsource-18.20.8-8.44.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * nodejs18-docs-18.20.8-8.44.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22150.html * https://www.suse.com/security/cve/CVE-2025-23166.html * https://www.suse.com/security/cve/CVE-2025-23167.html * https://www.suse.com/security/cve/CVE-2025-55131.html * https://www.suse.com/security/cve/CVE-2025-59465.html * https://www.suse.com/security/cve/CVE-2025-59466.html * https://www.suse.com/security/cve/CVE-2025-62408.html * https://www.suse.com/security/cve/CVE-2026-11525.html * https://www.suse.com/security/cve/CVE-2026-12151.html * https://www.suse.com/security/cve/CVE-2026-15157.html * https://www.suse.com/security/cve/CVE-2026-16728.html * https://www.suse.com/security/cve/CVE-2026-16729.html * https://www.suse.com/security/cve/CVE-2026-21637.html * https://www.suse.com/security/cve/CVE-2026-21710.html * https://www.suse.com/security/cve/CVE-2026-21713.html * https://www.suse.com/security/cve/CVE-2026-21714.html * https://www.suse.com/security/cve/CVE-2026-21717.html * https://www.suse.com/security/cve/CVE-2026-22036.html * https://www.suse.com/security/cve/CVE-2026-27135.html * https://www.suse.com/security/cve/CVE-2026-48618.html * https://www.suse.com/security/cve/CVE-2026-48619.html * https://www.suse.com/security/cve/CVE-2026-48928.html * https://www.suse.com/security/cve/CVE-2026-48930.html * https://www.suse.com/security/cve/CVE-2026-48931.html * https://www.suse.com/security/cve/CVE-2026-48933.html * https://www.suse.com/security/cve/CVE-2026-48934.html * https://www.suse.com/security/cve/CVE-2026-48935.html * https://www.suse.com/security/cve/CVE-2026-48937.html * https://www.suse.com/security/cve/CVE-2026-56846.html * https://www.suse.com/security/cve/CVE-2026-56848.html * https://www.suse.com/security/cve/CVE-2026-56850.html * https://www.suse.com/security/cve/CVE-2026-58040.html * https://www.suse.com/security/cve/CVE-2026-58042.html * https://www.suse.com/security/cve/CVE-2026-58043.html * https://www.suse.com/security/cve/CVE-2026-58044.html * https://www.suse.com/security/cve/CVE-2026-58045.html * https://www.suse.com/security/cve/CVE-2026-6733.html * https://www.suse.com/security/cve/CVE-2026-9679.html * https://bugzilla.suse.com/show_bug.cgi?id=1236258 * https://bugzilla.suse.com/show_bug.cgi?id=1243218 * https://bugzilla.suse.com/show_bug.cgi?id=1243220 * https://bugzilla.suse.com/show_bug.cgi?id=1254738 * https://bugzilla.suse.com/show_bug.cgi?id=1256570 * https://bugzilla.suse.com/show_bug.cgi?id=1256573 * https://bugzilla.suse.com/show_bug.cgi?id=1256574 * https://bugzilla.suse.com/show_bug.cgi?id=1256576 * https://bugzilla.suse.com/show_bug.cgi?id=1256848 * https://bugzilla.suse.com/show_bug.cgi?id=1259853 * https://bugzilla.suse.com/show_bug.cgi?id=1260455 * https://bugzilla.suse.com/show_bug.cgi?id=1260463 * https://bugzilla.suse.com/show_bug.cgi?id=1260480 * https://bugzilla.suse.com/show_bug.cgi?id=1260494 * https://bugzilla.suse.com/show_bug.cgi?id=1268477 * https://bugzilla.suse.com/show_bug.cgi?id=1268479 * https://bugzilla.suse.com/show_bug.cgi?id=1268481 * https://bugzilla.suse.com/show_bug.cgi?id=1268482 * https://bugzilla.suse.com/show_bug.cgi?id=1268555 * https://bugzilla.suse.com/show_bug.cgi?id=1268592 * https://bugzilla.suse.com/show_bug.cgi?id=1268593 * https://bugzilla.suse.com/show_bug.cgi?id=1268605 * https://bugzilla.suse.com/show_bug.cgi?id=1268606 * https://bugzilla.suse.com/show_bug.cgi?id=1268608 * https://bugzilla.suse.com/show_bug.cgi?id=1268609 * https://bugzilla.suse.com/show_bug.cgi?id=1268611 * https://bugzilla.suse.com/show_bug.cgi?id=1268618 * https://bugzilla.suse.com/show_bug.cgi?id=1269825 * https://bugzilla.suse.com/show_bug.cgi?id=1272941 * https://bugzilla.suse.com/show_bug.cgi?id=1272942 * https://bugzilla.suse.com/show_bug.cgi?id=1272943 * https://bugzilla.suse.com/show_bug.cgi?id=1272944 * https://bugzilla.suse.com/show_bug.cgi?id=1272945 * https://bugzilla.suse.com/show_bug.cgi?id=1272947 * https://bugzilla.suse.com/show_bug.cgi?id=1272948 * https://bugzilla.suse.com/show_bug.cgi?id=1272951 * https://bugzilla.suse.com/show_bug.cgi?id=1272958 * https://bugzilla.suse.com/show_bug.cgi?id=1273591 * https://bugzilla.suse.com/show_bug.cgi?id=1273593 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 17 20:53:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 17 Sep 2026 20:53:13 -0000 Subject: SUSE-SU-2026:4247-1: important: Security update for MozillaFirefox Message-ID: <178967839389.5437.14730514330257856935@55cee2c216ba> # Security update for MozillaFirefox Announcement ID: SUSE-SU-2026:4247-1 Release Date: 2026-09-17T15:59:43Z Rating: important References: * bsc#1280371 Cross-References: * CVE-2026-92005 * CVE-2026-92006 * CVE-2026-92007 * CVE-2026-92008 * CVE-2026-92009 * CVE-2026-92010 * CVE-2026-92011 * CVE-2026-92012 * CVE-2026-92013 * CVE-2026-92015 * CVE-2026-92016 * CVE-2026-92017 * CVE-2026-92018 * CVE-2026-92019 * CVE-2026-92020 * CVE-2026-92022 * CVE-2026-92023 * CVE-2026-92024 * CVE-2026-92025 * CVE-2026-92026 * CVE-2026-92027 * CVE-2026-92028 * CVE-2026-92029 * CVE-2026-92030 * CVE-2026-92031 * CVE-2026-92032 * CVE-2026-92035 * CVE-2026-92038 * CVE-2026-92039 * CVE-2026-92041 * CVE-2026-92042 * CVE-2026-92043 * CVE-2026-92044 * CVE-2026-92045 * CVE-2026-92046 * CVE-2026-92047 * CVE-2026-92048 * CVE-2026-92049 * CVE-2026-92052 * CVE-2026-92053 * CVE-2026-92054 * CVE-2026-92055 * CVE-2026-92056 * CVE-2026-92057 * CVE-2026-92058 * CVE-2026-92059 * CVE-2026-92060 * CVE-2026-92062 * CVE-2026-92064 * CVE-2026-92065 * CVE-2026-92067 * CVE-2026-92068 * CVE-2026-92069 * CVE-2026-92070 * CVE-2026-92071 * CVE-2026-92072 * CVE-2026-92073 * CVE-2026-92074 * CVE-2026-92075 * CVE-2026-92076 * CVE-2026-92077 * CVE-2026-92078 * CVE-2026-92079 CVSS scores: * CVE-2026-92006 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92006 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92007 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92008 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92009 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92010 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92011 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92012 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92013 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92015 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92017 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92020 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92043 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92047 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92052 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92053 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92054 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92055 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92062 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92073 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 63 vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 153.3.0 ESRi (MFSA 2026-93, bsc#1280371) * CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component. * CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-92015: Privilege escalation in the WebExtensions component. * CVE-2026-92016: Use-after-free in the Disability Access APIs component. * CVE-2026-92017: Privilege escalation in the DOM: Service Workers component. * CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component. * CVE-2026-92019: Mitigation bypass in the Remote Settings Client component. * CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. * CVE-2026-92022: Use-after-free in the DOM: HTML Parser component. * CVE-2026-92023: Use-after-free in the XML component. * CVE-2026-92024: Use-after-free in the SVG component. * CVE-2026-92025: Use-after-free in the DOM: Navigation component. * CVE-2026-92026: Use-after-free in the Networking component. * CVE-2026-92027: Use-after-free in the DOM: Streams component. * CVE-2026-92028: Use-after-free in the DOM: Core & HTML component. * CVE-2026-92029: Use-after-free in the SVG component. * CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. * CVE-2026-92031: Information disclosure in the Graphics: ImageLib component. * CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component. * CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component. * CVE-2026-92038: Mitigation bypass in the Remote Settings Client component. * CVE-2026-92039: Mitigation bypass in the DOM: Notifications component. * CVE-2026-92041: Mitigation bypass in the DOM: Networking component. * CVE-2026-92042: Race condition in the DOM: Content Processes component. * CVE-2026-92043: Privilege escalation due to incorrect boundary conditions in the Audio/Video component. * CVE-2026-92044: Information disclosure in the Networking: HTTP component. * CVE-2026-92045: Sandbox escape due to incorrect boundary conditions in the WebRTC component. * CVE-2026-92046: Use-after-free in the Graphics component. * CVE-2026-92047: Privilege escalation in the Crash Reporting component. * CVE-2026-92048: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. * CVE-2026-92049: Use-after-free in the Widget: Win32 component. * CVE-2026-92052: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. * CVE-2026-92053: Privilege escalation in the Graphics: CanvasWebGL component. * CVE-2026-92054: Privilege escalation in the Memory component. * CVE-2026-92055: Privilege escalation in the DevTools component. * CVE-2026-92056: Use-after-free in the Graphics: Text component. * CVE-2026-92057: Mitigation bypass in the Enterprise Policies component. * CVE-2026-92058: Use-after-free in the Graphics component. * CVE-2026-92059: Incorrect boundary conditions in the DOM: Editor component. * CVE-2026-92060: Use-after-free in the Internationalization component. * CVE-2026-92062: Privilege escalation in the Session Restore component. * CVE-2026-92064: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. * CVE-2026-92065: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. * CVE-2026-92067: Use-after-free in the Widget: Gtk component. * CVE-2026-92068: Site isolation issue in the Reader Mode component. * CVE-2026-92069: Spoofing issue in the DOM: Navigation component. * CVE-2026-92070: Information disclosure in the Networking component. * CVE-2026-92071: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. * CVE-2026-92072: Incorrect boundary conditions in the Safe Browsing component. * CVE-2026-92073: Privilege escalation in the Enterprise Policies component. * CVE-2026-92074: Mitigation bypass in the Popup Blocker component. * CVE-2026-92075: Mitigation bypass in the Networking component. * CVE-2026-92076: Incorrect boundary conditions in the Networking component. * CVE-2026-92077: Denial-of-service in the SVG component. * CVE-2026-92078: Denial-of-service in the Security component. * CVE-2026-92079: Mitigation bypass in the Widget: Win32 component. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4247 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4247 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-common-153.3.0-118.8.1 * MozillaFirefox-debuginfo-153.3.0-118.8.1 * MozillaFirefox-153.3.0-118.8.1 * MozillaFirefox-debugsource-153.3.0-118.8.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * MozillaFirefox-devel-153.3.0-118.8.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * MozillaFirefox-translations-common-153.3.0-118.8.1 * MozillaFirefox-debuginfo-153.3.0-118.8.1 * MozillaFirefox-153.3.0-118.8.1 * MozillaFirefox-debugsource-153.3.0-118.8.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * MozillaFirefox-devel-153.3.0-118.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-92005.html * https://www.suse.com/security/cve/CVE-2026-92006.html * https://www.suse.com/security/cve/CVE-2026-92007.html * https://www.suse.com/security/cve/CVE-2026-92008.html * https://www.suse.com/security/cve/CVE-2026-92009.html * https://www.suse.com/security/cve/CVE-2026-92010.html * https://www.suse.com/security/cve/CVE-2026-92011.html * https://www.suse.com/security/cve/CVE-2026-92012.html * https://www.suse.com/security/cve/CVE-2026-92013.html * https://www.suse.com/security/cve/CVE-2026-92015.html * https://www.suse.com/security/cve/CVE-2026-92016.html * https://www.suse.com/security/cve/CVE-2026-92017.html * https://www.suse.com/security/cve/CVE-2026-92018.html * https://www.suse.com/security/cve/CVE-2026-92019.html * https://www.suse.com/security/cve/CVE-2026-92020.html * https://www.suse.com/security/cve/CVE-2026-92022.html * https://www.suse.com/security/cve/CVE-2026-92023.html * https://www.suse.com/security/cve/CVE-2026-92024.html * https://www.suse.com/security/cve/CVE-2026-92025.html * https://www.suse.com/security/cve/CVE-2026-92026.html * https://www.suse.com/security/cve/CVE-2026-92027.html * https://www.suse.com/security/cve/CVE-2026-92028.html * https://www.suse.com/security/cve/CVE-2026-92029.html * https://www.suse.com/security/cve/CVE-2026-92030.html * https://www.suse.com/security/cve/CVE-2026-92031.html * https://www.suse.com/security/cve/CVE-2026-92032.html * https://www.suse.com/security/cve/CVE-2026-92035.html * https://www.suse.com/security/cve/CVE-2026-92038.html * https://www.suse.com/security/cve/CVE-2026-92039.html * https://www.suse.com/security/cve/CVE-2026-92041.html * https://www.suse.com/security/cve/CVE-2026-92042.html * https://www.suse.com/security/cve/CVE-2026-92043.html * https://www.suse.com/security/cve/CVE-2026-92044.html * https://www.suse.com/security/cve/CVE-2026-92045.html * https://www.suse.com/security/cve/CVE-2026-92046.html * https://www.suse.com/security/cve/CVE-2026-92047.html * https://www.suse.com/security/cve/CVE-2026-92048.html * https://www.suse.com/security/cve/CVE-2026-92049.html * https://www.suse.com/security/cve/CVE-2026-92052.html * https://www.suse.com/security/cve/CVE-2026-92053.html * https://www.suse.com/security/cve/CVE-2026-92054.html * https://www.suse.com/security/cve/CVE-2026-92055.html * https://www.suse.com/security/cve/CVE-2026-92056.html * https://www.suse.com/security/cve/CVE-2026-92057.html * https://www.suse.com/security/cve/CVE-2026-92058.html * https://www.suse.com/security/cve/CVE-2026-92059.html * https://www.suse.com/security/cve/CVE-2026-92060.html * https://www.suse.com/security/cve/CVE-2026-92062.html * https://www.suse.com/security/cve/CVE-2026-92064.html * https://www.suse.com/security/cve/CVE-2026-92065.html * https://www.suse.com/security/cve/CVE-2026-92067.html * https://www.suse.com/security/cve/CVE-2026-92068.html * https://www.suse.com/security/cve/CVE-2026-92069.html * https://www.suse.com/security/cve/CVE-2026-92070.html * https://www.suse.com/security/cve/CVE-2026-92071.html * https://www.suse.com/security/cve/CVE-2026-92072.html * https://www.suse.com/security/cve/CVE-2026-92073.html * https://www.suse.com/security/cve/CVE-2026-92074.html * https://www.suse.com/security/cve/CVE-2026-92075.html * https://www.suse.com/security/cve/CVE-2026-92076.html * https://www.suse.com/security/cve/CVE-2026-92077.html * https://www.suse.com/security/cve/CVE-2026-92078.html * https://www.suse.com/security/cve/CVE-2026-92079.html * https://bugzilla.suse.com/show_bug.cgi?id=1280371 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 18 08:30:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 18 Sep 2026 08:30:49 -0000 Subject: SUSE-SU-2026:4256-1: important: Security update for the Linux Kernel (Live Patch 30 for SUSE Linux Enterprise 15 SP5) Message-ID: <178972024960.28040.16878954118000220853@b9be41dc2e4b> # Security update for the Linux Kernel (Live Patch 30 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:4256-1 Release Date: 2026-09-17T19:33:54Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.121 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-4256 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4256 * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-4257 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-4257 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_55-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_222-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_222-default-5-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_55-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_222-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_222-default-5-150400.2.1 * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_121-default-18-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-18-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_30-debugsource-18-150500.2.1 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_121-default-18-150500.2.1 * kernel-livepatch-5_14_21-150500_55_121-default-debuginfo-18-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_30-debugsource-18-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 18 08:31:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 18 Sep 2026 08:31:49 -0000 Subject: SUSE-SU-2026:4255-1: important: Security update for the Linux Kernel (Live Patch 57 for SUSE Linux Enterprise 15 SP4) Message-ID: <178972030974.28040.16731241425311938480@b9be41dc2e4b> # Security update for the Linux Kernel (Live Patch 57 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:4255-1 Release Date: 2026-09-17T18:33:42Z Rating: important References: * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.228 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-4255 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4255 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_228-default-debuginfo-3-150400.2.1 * kernel-livepatch-5_14_21-150400_24_228-default-3-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_57-debugsource-3-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150400_24_228-default-debuginfo-3-150400.2.1 * kernel-livepatch-5_14_21-150400_24_228-default-3-150400.2.1 * kernel-livepatch-SLE15-SP4_Update_57-debugsource-3-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 18 12:30:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 18 Sep 2026 12:30:42 -0000 Subject: SUSE-SU-2026:4259-1: important: Security update for the Linux Kernel (Live Patch 56 for SUSE Linux Enterprise 15 SP4) Message-ID: <178973464220.6251.10582305745076966490@5ac198222802> # Security update for the Linux Kernel (Live Patch 56 for SUSE Linux Enterprise 15 SP4) Announcement ID: SUSE-SU-2026:4259-1 Release Date: 2026-09-17T20:34:25Z Rating: important References: * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150400.24.225 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-4259 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4259 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_56-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_225-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_225-default-5-150400.2.1 * openSUSE Leap 15.4 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP4_Update_56-debugsource-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_225-default-debuginfo-5-150400.2.1 * kernel-livepatch-5_14_21-150400_24_225-default-5-150400.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 18 12:31:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 18 Sep 2026 12:31:46 -0000 Subject: SUSE-SU-2026:4258-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise 15 SP7) Message-ID: <178973470669.6251.17368760821435476671@5ac198222802> # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:4258-1 Release Date: 2026-09-17T20:34:01Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.45 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-4258 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP7_Update_13-debugsource-7-150700.2.1 * kernel-livepatch-6_4_0-150700_53_45-default-7-150700.2.1 * kernel-livepatch-6_4_0-150700_53_45-default-debuginfo-7-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 18 12:33:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 18 Sep 2026 12:33:15 -0000 Subject: SUSE-SU-2026:4261-1: important: Security update for nodejs18 Message-ID: <178973479505.6251.16924760290216374680@5ac198222802> # Security update for nodejs18 Announcement ID: SUSE-SU-2026:4261-1 Release Date: 2026-09-18T07:44:29Z Rating: important References: * bsc#1236258 * bsc#1243218 * bsc#1243220 * bsc#1254738 * bsc#1256570 * bsc#1256573 * bsc#1256574 * bsc#1256576 * bsc#1256848 * bsc#1259853 * bsc#1260455 * bsc#1260463 * bsc#1260480 * bsc#1260494 * bsc#1268477 * bsc#1268479 * bsc#1268481 * bsc#1268482 * bsc#1268555 * bsc#1268592 * bsc#1268593 * bsc#1268605 * bsc#1268606 * bsc#1268608 * bsc#1268609 * bsc#1268611 * bsc#1268618 * bsc#1269825 * bsc#1272941 * bsc#1272942 * bsc#1272943 * bsc#1272944 * bsc#1272945 * bsc#1272947 * bsc#1272948 * bsc#1272951 * bsc#1272958 * bsc#1273591 * bsc#1273593 Cross-References: * CVE-2025-22150 * CVE-2025-23166 * CVE-2025-23167 * CVE-2025-55131 * CVE-2025-59465 * CVE-2025-59466 * CVE-2025-62408 * CVE-2026-11525 * CVE-2026-12151 * CVE-2026-15157 * CVE-2026-16728 * CVE-2026-16729 * CVE-2026-21637 * CVE-2026-21710 * CVE-2026-21713 * CVE-2026-21714 * CVE-2026-21717 * CVE-2026-22036 * CVE-2026-27135 * CVE-2026-48618 * CVE-2026-48619 * CVE-2026-48928 * CVE-2026-48930 * CVE-2026-48931 * CVE-2026-48933 * CVE-2026-48934 * CVE-2026-48935 * CVE-2026-48937 * CVE-2026-56846 * CVE-2026-56848 * CVE-2026-56850 * CVE-2026-58040 * CVE-2026-58042 * CVE-2026-58043 * CVE-2026-58044 * CVE-2026-58045 * CVE-2026-6733 * CVE-2026-9679 CVSS scores: * CVE-2025-22150 ( SUSE ): 7.4 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2025-22150 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-22150 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2025-23166 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-23166 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-23166 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-23167 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-23167 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-23167 ( NVD ): 6.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2025-55131 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2025-55131 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2025-55131 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2025-55131 ( NVD ): 7.1 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L * CVE-2025-59465 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-59465 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59465 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59465 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59466 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2025-59466 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59466 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-59466 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-62408 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2025-62408 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11525 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-11525 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-12151 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-12151 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15157 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-15157 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-15157 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-15157 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-16728 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-16728 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-16728 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-16729 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-16729 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-16729 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-21637 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-21637 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-21637 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21637 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21710 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-21710 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21710 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21710 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21713 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-21713 ( SUSE ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-21713 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-21714 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-21714 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21714 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-21717 ( SUSE ): 7.2 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-21717 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-21717 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-21717 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-22036 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-22036 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-22036 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-22036 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-27135 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-27135 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48618 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48618 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-48618 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-48618 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-48618 ( NVD ): 7.7 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-48619 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48619 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48619 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48928 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48928 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:N * CVE-2026-48928 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48928 ( NVD ): 4.2 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48930 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-48930 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-48930 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-48930 ( NVD ): 5.6 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-48931 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48931 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48931 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48931 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48933 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-48933 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48933 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48933 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48934 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48934 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-48934 ( NVD ): 4.3 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-48935 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-48935 ( SUSE ): 4.0 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48935 ( NVD ): 3.3 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2026-48937 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-48937 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-48937 ( NVD ): 5.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56846 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56846 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56846 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56848 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56848 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56848 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56850 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56850 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-56850 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-56850 ( NVD ): 4.1 CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-58040 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-58040 ( SUSE ): 6.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-58040 ( NVD ): 6.3 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-58042 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58042 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58042 ( NVD ): 5.9 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58043 ( SUSE ): 8.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2026-58043 ( SUSE ): 7.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-58043 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-58043 ( NVD ): 7.5 CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N * CVE-2026-58044 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-58044 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-58044 ( NVD ): 3.7 CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-58045 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-58045 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-58045 ( NVD ): 6.2 CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6733 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-6733 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-9679 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-9679 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves 38 vulnerabilities and has one security fix can now be installed. ## Description: This update for nodejs18 fixes the following issues: * CVE-2025-22150: undici: insufficiently random values used when defining the boundary for a multipart/form-data request (bsc#1236258). * CVE-2025-23166: improper error handling in async cryptographic operations crashes process (bsc#1243218). * CVE-2025-23167: llhttp: improper HTTP header block termination in llhttp (bsc#1243220). * CVE-2025-55131: timeout-based race conditions allow for allocations that contain leftover data from previous operations and lead to exposure of in- process secrets (bsc#1256570). * CVE-2025-59465: malformed HTTP/2 HEADERS frame with invalid HPACK data can cause a crash due to an unhandled error (bsc#1256573). * CVE-2025-59466: uncatchable "Maximum call stack size exceeded" error when `async_hooks.createHook()` is enabled can lead to crash (bsc#1256574). * CVE-2025-62408: c-ares 1.32.3-1.34.5 use after free() (bsc#1254738). * CVE-2026-6733: undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery (bsc#1268479). * CVE-2026-9679: undici: undici vulnerable to HTTP header injection via Set- Cookie percent-decoding (bsc#1268477). * CVE-2026-11525: undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (bsc#1268481). * CVE-2026-12151: undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (bsc#1268482). * CVE-2026-15157: No validation of the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher (bsc#1272958). * CVE-2026-16728: undici: downstream response desynchronization via retry interceptor (bsc#1273593). * CVE-2026-16729: undici: undici's setCookie function does not fully sanitize cookie attributes (bsc#1273591). * CVE-2026-21637: synchronous exceptions thrown during certain callbacks bypass the standard TLS error handling paths and can cause a denial of service (bsc#1256576). * CVE-2026-21710: uncaught TypeError exception can cause a denial of service (bsc#1260455). * CVE-2026-21713: timing side-channel in HMAC verification via memcmp can lead to potential MAC forgery (bsc#1260463). * CVE-2026-21714: WINDOW_UPDATE frames on stream 0 can lead to memory leak (bsc#1260480). * CVE-2026-21717: crafted request can lead to hash collisions trivially predictable (bsc#1260494). * CVE-2026-22036: undici: unbounded decompression chain in HTTP responses via Content-Encoding may lead to resource exhaustion (bsc#1256848). * CVE-2026-27135: nghttp2: assertion failure due to missing state validation can lead to DoS (bsc#1259853). * CVE-2026-48618: Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismatch (bsc#1268593). * CVE-2026-48619: Unbounded memory growth in node:http2 clients via attacker- controlled ORIGIN frames (bsc#1268618). * CVE-2026-48928: Uppercase sni context matching can lead to mtls authorization bypass due to case-sensitive hostname matching (bsc#1268605). * CVE-2026-48930: Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings (bsc#1268606). * CVE-2026-48931: HTTP Response Queue Poisoning via TOCTOU Race Condition in http.Agent (bsc#1268611). * CVE-2026-48933: Node.js WebCrypto AES Integer Overflow Leads to Remote Process Abort (bsc#1268592). * CVE-2026-48934: TLS host identity verification bypass via session reuse with different servername leads to unauthorized connections (bsc#1268608). * CVE-2026-48935: Permission Model bypass via FileHandle.utimes() in the promises API (bsc#1268609). * CVE-2026-48937: servers keep accepting data even after sending a `GOAWAY` frame (bsc#1268555). * CVE-2026-56846: HTTP/2 retained headers can bypass maxSessionMemory limits (bsc#1272941). * CVE-2026-56848: HTTP/2 re-entrant send can cause heap-use-after-free (bsc#1272942). * CVE-2026-56850: HTTPS Agent can reuse mTLS identities across PFX certificates (bsc#1272944). * CVE-2026-58040: HTTPS Agent session reuse can skip hostname verification (bsc#1272945). * CVE-2026-58042: dns.resolveAny() can abort on DNS responses with many A records (bsc#1272947). * CVE-2026-58043: Permission Model path matching can over-grant filesystem access (bsc#1272943). * CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951). * CVE-2026-58045: node:zlib sync APIs can crash on spoofed TypedArray length (bsc#1272948). Changes for nodejs18: * upgraded embedded undici to 6.28.0. * upgraded embedded nghttp2 to 1.69.0. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4261 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4261 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4261 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4261 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4261 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4261 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4261 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4261 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4261 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * nodejs18-debugsource-18.20.8-150400.9.39.1 * nodejs18-devel-18.20.8-150400.9.39.1 * nodejs18-18.20.8-150400.9.39.1 * nodejs18-debuginfo-18.20.8-150400.9.39.1 * npm18-18.20.8-150400.9.39.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * nodejs18-docs-18.20.8-150400.9.39.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * nodejs18-debugsource-18.20.8-150400.9.39.1 * nodejs18-devel-18.20.8-150400.9.39.1 * nodejs18-18.20.8-150400.9.39.1 * nodejs18-debuginfo-18.20.8-150400.9.39.1 * npm18-18.20.8-150400.9.39.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * nodejs18-docs-18.20.8-150400.9.39.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * nodejs18-debugsource-18.20.8-150400.9.39.1 * nodejs18-devel-18.20.8-150400.9.39.1 * nodejs18-18.20.8-150400.9.39.1 * nodejs18-debuginfo-18.20.8-150400.9.39.1 * npm18-18.20.8-150400.9.39.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * nodejs18-docs-18.20.8-150400.9.39.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * nodejs18-debugsource-18.20.8-150400.9.39.1 * nodejs18-devel-18.20.8-150400.9.39.1 * nodejs18-18.20.8-150400.9.39.1 * nodejs18-debuginfo-18.20.8-150400.9.39.1 * npm18-18.20.8-150400.9.39.1 * corepack18-18.20.8-150400.9.39.1 * openSUSE Leap 15.4 (noarch) * nodejs18-docs-18.20.8-150400.9.39.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * nodejs18-debugsource-18.20.8-150400.9.39.1 * nodejs18-devel-18.20.8-150400.9.39.1 * nodejs18-18.20.8-150400.9.39.1 * nodejs18-debuginfo-18.20.8-150400.9.39.1 * npm18-18.20.8-150400.9.39.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * nodejs18-docs-18.20.8-150400.9.39.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * nodejs18-debugsource-18.20.8-150400.9.39.1 * nodejs18-devel-18.20.8-150400.9.39.1 * nodejs18-18.20.8-150400.9.39.1 * nodejs18-debuginfo-18.20.8-150400.9.39.1 * npm18-18.20.8-150400.9.39.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * nodejs18-docs-18.20.8-150400.9.39.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * nodejs18-debugsource-18.20.8-150400.9.39.1 * nodejs18-devel-18.20.8-150400.9.39.1 * nodejs18-18.20.8-150400.9.39.1 * nodejs18-debuginfo-18.20.8-150400.9.39.1 * npm18-18.20.8-150400.9.39.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * nodejs18-docs-18.20.8-150400.9.39.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * nodejs18-debugsource-18.20.8-150400.9.39.1 * nodejs18-devel-18.20.8-150400.9.39.1 * nodejs18-18.20.8-150400.9.39.1 * nodejs18-debuginfo-18.20.8-150400.9.39.1 * npm18-18.20.8-150400.9.39.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * nodejs18-docs-18.20.8-150400.9.39.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * nodejs18-debugsource-18.20.8-150400.9.39.1 * nodejs18-devel-18.20.8-150400.9.39.1 * nodejs18-18.20.8-150400.9.39.1 * nodejs18-debuginfo-18.20.8-150400.9.39.1 * npm18-18.20.8-150400.9.39.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * nodejs18-docs-18.20.8-150400.9.39.1 ## References: * https://www.suse.com/security/cve/CVE-2025-22150.html * https://www.suse.com/security/cve/CVE-2025-23166.html * https://www.suse.com/security/cve/CVE-2025-23167.html * https://www.suse.com/security/cve/CVE-2025-55131.html * https://www.suse.com/security/cve/CVE-2025-59465.html * https://www.suse.com/security/cve/CVE-2025-59466.html * https://www.suse.com/security/cve/CVE-2025-62408.html * https://www.suse.com/security/cve/CVE-2026-11525.html * https://www.suse.com/security/cve/CVE-2026-12151.html * https://www.suse.com/security/cve/CVE-2026-15157.html * https://www.suse.com/security/cve/CVE-2026-16728.html * https://www.suse.com/security/cve/CVE-2026-16729.html * https://www.suse.com/security/cve/CVE-2026-21637.html * https://www.suse.com/security/cve/CVE-2026-21710.html * https://www.suse.com/security/cve/CVE-2026-21713.html * https://www.suse.com/security/cve/CVE-2026-21714.html * https://www.suse.com/security/cve/CVE-2026-21717.html * https://www.suse.com/security/cve/CVE-2026-22036.html * https://www.suse.com/security/cve/CVE-2026-27135.html * https://www.suse.com/security/cve/CVE-2026-48618.html * https://www.suse.com/security/cve/CVE-2026-48619.html * https://www.suse.com/security/cve/CVE-2026-48928.html * https://www.suse.com/security/cve/CVE-2026-48930.html * https://www.suse.com/security/cve/CVE-2026-48931.html * https://www.suse.com/security/cve/CVE-2026-48933.html * https://www.suse.com/security/cve/CVE-2026-48934.html * https://www.suse.com/security/cve/CVE-2026-48935.html * https://www.suse.com/security/cve/CVE-2026-48937.html * https://www.suse.com/security/cve/CVE-2026-56846.html * https://www.suse.com/security/cve/CVE-2026-56848.html * https://www.suse.com/security/cve/CVE-2026-56850.html * https://www.suse.com/security/cve/CVE-2026-58040.html * https://www.suse.com/security/cve/CVE-2026-58042.html * https://www.suse.com/security/cve/CVE-2026-58043.html * https://www.suse.com/security/cve/CVE-2026-58044.html * https://www.suse.com/security/cve/CVE-2026-58045.html * https://www.suse.com/security/cve/CVE-2026-6733.html * https://www.suse.com/security/cve/CVE-2026-9679.html * https://bugzilla.suse.com/show_bug.cgi?id=1236258 * https://bugzilla.suse.com/show_bug.cgi?id=1243218 * https://bugzilla.suse.com/show_bug.cgi?id=1243220 * https://bugzilla.suse.com/show_bug.cgi?id=1254738 * https://bugzilla.suse.com/show_bug.cgi?id=1256570 * https://bugzilla.suse.com/show_bug.cgi?id=1256573 * https://bugzilla.suse.com/show_bug.cgi?id=1256574 * https://bugzilla.suse.com/show_bug.cgi?id=1256576 * https://bugzilla.suse.com/show_bug.cgi?id=1256848 * https://bugzilla.suse.com/show_bug.cgi?id=1259853 * https://bugzilla.suse.com/show_bug.cgi?id=1260455 * https://bugzilla.suse.com/show_bug.cgi?id=1260463 * https://bugzilla.suse.com/show_bug.cgi?id=1260480 * https://bugzilla.suse.com/show_bug.cgi?id=1260494 * https://bugzilla.suse.com/show_bug.cgi?id=1268477 * https://bugzilla.suse.com/show_bug.cgi?id=1268479 * https://bugzilla.suse.com/show_bug.cgi?id=1268481 * https://bugzilla.suse.com/show_bug.cgi?id=1268482 * https://bugzilla.suse.com/show_bug.cgi?id=1268555 * https://bugzilla.suse.com/show_bug.cgi?id=1268592 * https://bugzilla.suse.com/show_bug.cgi?id=1268593 * https://bugzilla.suse.com/show_bug.cgi?id=1268605 * https://bugzilla.suse.com/show_bug.cgi?id=1268606 * https://bugzilla.suse.com/show_bug.cgi?id=1268608 * https://bugzilla.suse.com/show_bug.cgi?id=1268609 * https://bugzilla.suse.com/show_bug.cgi?id=1268611 * https://bugzilla.suse.com/show_bug.cgi?id=1268618 * https://bugzilla.suse.com/show_bug.cgi?id=1269825 * https://bugzilla.suse.com/show_bug.cgi?id=1272941 * https://bugzilla.suse.com/show_bug.cgi?id=1272942 * https://bugzilla.suse.com/show_bug.cgi?id=1272943 * https://bugzilla.suse.com/show_bug.cgi?id=1272944 * https://bugzilla.suse.com/show_bug.cgi?id=1272945 * https://bugzilla.suse.com/show_bug.cgi?id=1272947 * https://bugzilla.suse.com/show_bug.cgi?id=1272948 * https://bugzilla.suse.com/show_bug.cgi?id=1272951 * https://bugzilla.suse.com/show_bug.cgi?id=1272958 * https://bugzilla.suse.com/show_bug.cgi?id=1273591 * https://bugzilla.suse.com/show_bug.cgi?id=1273593 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 18 20:30:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 18 Sep 2026 20:30:43 -0000 Subject: SUSE-SU-2026:4268-1: important: Security update for MozillaThunderbird Message-ID: <178976344364.6724.15826579705043859044@b745e8aa27b6> # Security update for MozillaThunderbird Announcement ID: SUSE-SU-2026:4268-1 Release Date: 2026-09-18T14:51:02Z Rating: important References: * bsc#1271649 * bsc#1274867 * bsc#1278001 Cross-References: * CVE-2024-34703 * CVE-2026-14899 * CVE-2026-16349 * CVE-2026-16350 * CVE-2026-16351 * CVE-2026-16352 * CVE-2026-16353 * CVE-2026-16354 * CVE-2026-16355 * CVE-2026-16356 * CVE-2026-16357 * CVE-2026-16358 * CVE-2026-16359 * CVE-2026-16360 * CVE-2026-16362 * CVE-2026-16363 * CVE-2026-16364 * CVE-2026-16365 * CVE-2026-16366 * CVE-2026-16367 * CVE-2026-16368 * CVE-2026-16369 * CVE-2026-16370 * CVE-2026-16371 * CVE-2026-16372 * CVE-2026-16374 * CVE-2026-16375 * CVE-2026-16376 * CVE-2026-16377 * CVE-2026-16378 * CVE-2026-16379 * CVE-2026-16380 * CVE-2026-16381 * CVE-2026-16382 * CVE-2026-16383 * CVE-2026-16384 * CVE-2026-16385 * CVE-2026-16386 * CVE-2026-16387 * CVE-2026-16388 * CVE-2026-16389 * CVE-2026-16390 * CVE-2026-16391 * CVE-2026-16392 * CVE-2026-16393 * CVE-2026-16394 * CVE-2026-16395 * CVE-2026-16396 * CVE-2026-16398 * CVE-2026-16399 * CVE-2026-16400 * CVE-2026-16401 * CVE-2026-16402 * CVE-2026-16403 * CVE-2026-16405 * CVE-2026-16406 * CVE-2026-16407 * CVE-2026-16408 * CVE-2026-16409 * CVE-2026-16410 * CVE-2026-16411 * CVE-2026-16412 * CVE-2026-74934 * CVE-2026-74935 * CVE-2026-74936 * CVE-2026-74937 * CVE-2026-74938 * CVE-2026-74939 * CVE-2026-74940 * CVE-2026-74941 * CVE-2026-74942 * CVE-2026-74943 * CVE-2026-74944 * CVE-2026-74945 * CVE-2026-74946 * CVE-2026-74947 * CVE-2026-74948 * CVE-2026-74949 * CVE-2026-74950 * CVE-2026-74952 * CVE-2026-74953 * CVE-2026-74954 * CVE-2026-74955 * CVE-2026-74956 * CVE-2026-74957 * CVE-2026-74958 * CVE-2026-74959 * CVE-2026-74960 * CVE-2026-74961 * CVE-2026-74962 * CVE-2026-74963 * CVE-2026-74964 * CVE-2026-74965 * CVE-2026-74966 * CVE-2026-74967 * CVE-2026-74968 * CVE-2026-74969 * CVE-2026-74970 * CVE-2026-74971 * CVE-2026-74972 * CVE-2026-74973 * CVE-2026-74974 * CVE-2026-74976 * CVE-2026-74977 * CVE-2026-74978 * CVE-2026-74979 * CVE-2026-74981 * CVE-2026-74982 * CVE-2026-74983 * CVE-2026-74984 * CVE-2026-74985 * CVE-2026-74986 * CVE-2026-74987 * CVE-2026-74988 * CVE-2026-74990 * CVE-2026-75874 * CVE-2026-84118 * CVE-2026-84119 * CVE-2026-84120 * CVE-2026-84121 * CVE-2026-84122 * CVE-2026-84123 * CVE-2026-84124 * CVE-2026-84125 * CVE-2026-84129 * CVE-2026-84130 * CVE-2026-84131 * CVE-2026-84132 * CVE-2026-84133 * CVE-2026-84134 * CVE-2026-84136 * CVE-2026-84137 * CVE-2026-84139 * CVE-2026-84140 * CVE-2026-84141 * CVE-2026-84143 * CVE-2026-84144 * CVE-2026-84145 * CVE-2026-84637 * CVE-2026-84639 * CVE-2026-84640 * CVE-2026-84641 * CVE-2026-84642 CVSS scores: * CVE-2024-34703 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-34703 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-14899 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-14899 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16349 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N * CVE-2026-16349 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16350 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16350 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16351 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-16351 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16352 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16352 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16353 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16353 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16354 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16356 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16357 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16358 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16359 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16360 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16362 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16363 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16364 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16365 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16366 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16367 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-16368 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16369 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16370 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16371 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16372 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16374 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16375 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16376 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16377 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16378 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16379 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16380 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16381 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16382 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16384 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16385 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16386 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16387 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16388 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16389 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16390 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16391 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16392 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-16393 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-16394 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16395 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16396 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16398 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16399 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16400 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16401 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-16402 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16403 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-16405 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-16406 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-16407 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16408 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16409 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-16410 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16411 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-16412 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74934 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74934 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74935 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74935 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74936 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74936 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74936 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74937 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74938 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74938 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74939 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74940 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74940 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74941 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74942 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74943 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74943 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74944 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74944 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74945 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-74946 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74947 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74948 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-74949 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74950 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74952 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74953 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74954 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-74955 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74956 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74957 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74958 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-74959 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74960 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74961 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-74962 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74963 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-74963 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74964 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74965 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74966 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-74967 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74968 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74969 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74970 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74971 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-74972 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-74973 ( NVD ): 4.2 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74974 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-74976 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-74977 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74978 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74979 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74981 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74982 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74983 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74984 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N * CVE-2026-74985 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74986 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74987 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74988 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74990 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-74990 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-75874 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-84118 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84118 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84119 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-84119 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-84120 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84120 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84121 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-84121 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-84122 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84122 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84123 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84123 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84124 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84124 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84125 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84125 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84129 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84130 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84131 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84131 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84132 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84133 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84134 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-84136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84137 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-84137 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84139 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84139 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-84140 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84140 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84141 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84141 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84144 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84145 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84145 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84637 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84637 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84639 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-84640 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84641 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:H * CVE-2026-84641 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84642 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves 143 vulnerabilities can now be installed. ## Description: This update for MozillaThunderbird fixes the following issues: Mozilla Thunderbird 153.2: * fixed: Deleting an Exchange account retained the outgoing server settings * fixed: Thunderbird upgrade disabled Settings menu for versions before macOS 13 * fixed: Windows jump list menu no longer functioned correctly * fixed: Security fixes MFSA 2026-88 (bsc#1278001): * CVE-2026-84639 Uninitialized memory in MIME parsing * CVE-2026-84640 One byte overflow read in mail parser * CVE-2026-84641 Information disclosure due to malicious IMAP server response * CVE-2026-84637 Calendar invitation attachments could launch local executables * CVE-2026-84642 Allowed UNC hostnames for attachments interpreted as a regular expression * CVE-2026-75874 Sandbox escape in the Remote Settings Client component * CVE-2026-84118 Use-after-free in the JavaScript: GC component * CVE-2026-84119 Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120 Use-after-free in the Audio/Video component * CVE-2026-84121 Sandbox escape due to use-after-free in the DOM: Security component * CVE-2026-84122 Use-after-free in the Audio/Video component * CVE-2026-84123 Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124 Use-after-free in the DOM: Core & HTML component * CVE-2026-84125 Use-after-free in the DOM: Core & HTML component * CVE-2026-74952 Privilege escalation in the Application Update component * CVE-2026-84129 Site isolation issue in the DOM: Navigation component * CVE-2026-84130 Information disclosure in the Graphics: WebGPU component * CVE-2026-84131 Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-84132 Information disclosure in the Networking: HTTP component * CVE-2026-84133 Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134 Other issue in the Profile Backup component * CVE-2026-84136 Other issue in the DOM: Navigation component * CVE-2026-84137 Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139 Clickjacking issue in the DOM: Events component * CVE-2026-84140 Site isolation issue in the DOM: Navigation component * CVE-2026-84141 Integer overflow in the Graphics: ImageLib component * CVE-2026-84143 Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15 * CVE-2026-84144 Internally found bugs fixed in Thunderbird 155 and Thunderbird ESR 153.2 * CVE-2026-84145 Internally found bugs fixed in Thunderbird 155, Thunderbird ESR 153.2 and Thunderbird ESR 140.15 * Mozilla Thunderbird 153.1.1 * fixed: Thunderbird upgrade disabled composition toolbar * fixed: Draft was not preserved when encrypted message send failed * fixed: Account Hub prompted for calendar credentials after successful login * fixed: Thunderbird crash fixes * fixed: Folder compaction showed incorrect disk space recovery estimates * fixed: Thunderbird failed to launch GPU process * Mozilla Thunderbird 153.1 * fixed: Autoscroll icon was missing directional arrows in scrollable messages * fixed: Security fixes MFSA 2026-80 (bsc#1274867): * CVE-2026-74934 Site isolation issue in the Graphics: CanvasWebGL component * CVE-2026-74935 Privilege escalation in the DOM: Networking component * CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component * CVE-2026-74937 Use-after-free in the JavaScript: GC component * CVE-2026-74938 Mitigation bypass in the JavaScript: GC component * CVE-2026-74939 Privilege escalation in the DOM: Navigation component * CVE-2026-74940 Use-after-free in the Graphics: Text component * CVE-2026-74941 Privilege escalation in the Graphics: CanvasWebGL component * CVE-2026-74942 Privilege escalation in the Remote Settings Client component * CVE-2026-74943 Use-after-free in the Graphics: ImageLib component * CVE-2026-74944 Use-after-free in the DOM: Core & HTML component * CVE-2026-74945 Information disclosure in the Graphics: Text component * CVE-2026-74946 Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component * CVE-2026-74947 Privilege escalation due to invalid pointer in the Graphics component * CVE-2026-74948 Information disclosure in the Graphics component * CVE-2026-74949 Privilege escalation due to use-after-free in the Graphics: Canvas2D component * CVE-2026-74950 Privilege escalation in the Downloads API component * CVE-2026-74953 Privilege escalation in the Networking: Cookies component * CVE-2026-74954 Information disclosure due to side-channel in the Storage: Cache API component * CVE-2026-74955 Privilege escalation in the Request Handling component * CVE-2026-74956 Same-origin policy bypass in the DOM: Service Workers component * CVE-2026-74957 Mitigation bypass in the Safe Browsing component * CVE-2026-74958 Information disclosure in the WebRTC component * CVE-2026-74959 Mitigation bypass in the Storage: Cache API component * CVE-2026-74960 Site isolation issue in the WebExtensions component * CVE-2026-74961 Side-channel in the Web Audio component * CVE-2026-74962 Site isolation issue in the Networking: Cookies component * CVE-2026-74963 Same-origin policy bypass in the Networking: Cookies component * CVE-2026-74964 Integer overflow in the Graphics component * CVE-2026-74965 Privilege escalation in the Shell Integration component * CVE-2026-74966 Information disclosure in the Form Autofill component * CVE-2026-74967 Same-origin policy bypass in the Audio/Video: Playback component * CVE-2026-74968 Site isolation issue in the Graphics: WebRender component * CVE-2026-74969 Use-after-free in the Layout: Text and Fonts component * CVE-2026-74970 Site isolation issue in the Graphics component * CVE-2026-74971 Information disclosure in the DOM: UI Events & Focus Handling component * CVE-2026-74972 Information disclosure in the DOM: Push Subscriptions component * CVE-2026-74973 Race condition, use-after-free in the Graphics component * CVE-2026-74974 Same-origin policy bypass in the Graphics: ImageLib component * CVE-2026-74976 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-74977 Integer overflow in the Graphics component * CVE-2026-74978 Clickjacking issue in the Widget component * CVE-2026-74979 Mitigation bypass in the Add-ons Manager component * CVE-2026-74981 Site isolation issue in the Audio/Video: Web Codecs component * CVE-2026-74982 Denial-of-service in the Widget component * CVE-2026-74983 Mitigation bypass in the Data Loss Prevention component * CVE-2026-74984 Race condition in the JavaScript Engine component * CVE-2026-74985 Privilege escalation in the Enterprise Policies component * CVE-2026-74986 Site isolation issue in the CSS Parsing and Computation component * CVE-2026-74987 Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154 * CVE-2026-74988 Internally found bugs fixed in Thunderbird ESR 153.1 and Thunderbird 154 * CVE-2026-74990 Internally found bugs fixed in Thunderbird ESR 140.14, Thunderbird ESR 153.1 and Thunderbird 154 * Mozilla Thunderbird 153.0.3 * fixed: Dragging attachments from Local Folders to the desktop failed on Windows * fixed: IMAP tags did not sync automatically across clients * fixed: DisablePasswordReveal policy failed to prevent revealing saved passwords * fixed: Thunderbird could crash when saving a sent Exchange message * Mozilla Thunderbird 153.0.2 * changed: Restored previous Yahoo sign-in flow to improve login reliability * fixed: Edit Calendar dialog opened without a window title * fixed: Thunderbird could crash when going offline with active IMAP connection * Mozilla Thunderbird 153.0.1 * changed: There are no Thunderbird changes requiring release notes in this release * Mozilla Thunderbird 153 MFSA 2026-71 (bsc#1271649): * new: Visual signatures can be added to PDF attachments opened in Thunderbird * new: 'Copy Message Link' and 'Copy News Link' added to header pane 'More actions' * new: Accessiblity is improved in various tree views * new: Added 'Archive' action to mail notifications * new: Add "Show Full Path" folder pane option for compact view modes * new: Unified folders now display account color indicator with account name tooltip * new: Folder copy enabled within mail server accounts and local folders * new: 'Reset Folder Order' option added to folder pane to reset custom folder sorting * new: Add `mail.useLocalizedFolderNames' to toggle special folder name localization * new: 'Favorites' added as destination for 'Move To' and 'File' buttons * new: Composer now shows a warning if user's configured OpenPGP key expires soon * new: Enabled configuration of preferred OpenPGP keyserver via the UI * new: Add`mail.openpgp.load_untested_gpgme_version`to load untested GPGME version * new: Added support for generating Unobtrusive Signatures (OpenPGP) * new: Implemented option to show only messages without any tag * new: Message body search enabled for OpenPGP and S/MIME encrypted messages * new: SecurityDevices enabled in enterprise policies * new: Enable support for DNS over HTTPS * new: OAuth login for mail accounts now opens in default web browser * new: Thundermail services can now be used without installing an add-on * new: OAuth responses now verify issuer fields and reject missing required issuers * new: Enable the "Sign in with Thundermail" button in Account Hub * new: Account hub is opened on the first run of Thunderbird * new: Account Hub email manual config option added * new: Enable Thundermail OAuth sign-in with account auto- configuration * new: Address book cards can be copied to the clipboard as vCard * new: Enable exporting selected address book cards * new: Custom Accent Color can be chosen in Appearance Settings * new: Enable support for Microsoft Exchange via Exchange Web Services * new: Calendar month/multiweek views are now scrollable with touch screen * new: Tasks can be sorted by created or modified date * new: PDF pages can be reorganized directly in the PDF viewer * changed: 'Copy Message Location' removed from mail context menu * changed: Read folders are now removed from Unread Folders view * changed: Special folders are now localized based on a restricted set of names * changed: OpenPGP public key no longer attached by default in signed-only messages * changed: Address books are now created in Account Hub * changed: Yahoo, AT&T, AOL accounts migrated to OAuth 2.0 with PKCE for improved security * changed: GMail OAuth updated to use PKCE * changed: Skype has been retired and therefore dropped from Address book IM selection * changed: Removed pref`default_supports_diskspace.{HOST}`* changed: Removed pref`default_offline_support_level.{HOST}`* changed: Removed Odnoklassniki chat setup and directed users to XMPP configuration * changed: Use of the string "Junk" has been replaced with "Spam" * changed: Updated about:rights to replace local with hosted url * changed: Stop shipping 32-bit Linux x86 binaries * changed: 'Hide completed tasks' now also hides cancelled tasks * changed: Stop shipping 32-bit Linux x86 binaries * fixed: Thunderbird could crash when parsing message state * fixed: The English string for the Angry emoji was incorrectly named as the Yell emoji * fixed: Notification sounds did not respect operating system's do-not- disturb mode * fixed: Non-English localized Thunderbird created English special folders on first start * fixed: Copying text from some error alerts was not possible * fixed: Fastmail CalDAV app password access failed due to forced OAuth regression * fixed: Thunderbird could crash in server subscription logic * fixed: Could not distinguish folders with same name in 'Recent Destinations' and 'Favorites' * fixed: Donation banner stole focus when Thunderbird was running in the background * fixed: Unknown command- line arguments passed to Thunderbird did not print warning * fixed: Thunderbird could crash when processing new incoming messages * fixed: Spam messages triggered new mail notifications before being moved to Spam folder * fixed: Web pages with bad certificates displayed as blank * fixed: Memory leak after opening New Window from folder pane context menu * fixed: Importing a vCard only displayed VCF files in the file picker * fixed: Calendar view tabs were not properly keyboard accessible * fixed: Ctrl+S did not save PDF attachments opened in Thunderbird tabs * fixed: TLS errors incorrectly reported all unknown failures as untrusted certificates * fixed: Thunderbird could crash when copying an empty list of messages * fixed: Incorrect roaming data directory caused regression on Windows and macOS * fixed: Changing to new drafts folder and then back did not correctly restore the folder * fixed: Message headers were re- downloaded at every startup * fixed: Old IMAP profile migration deleted INBOX and other mailbox files * fixed: 'Search Messages...' dialog could not be opened outside the email tab * fixed: Option did not exist to create new address book under File -> New * fixed: Newly created folder was missing under "Recent" when moving a message * fixed: Could not compose new message if the folder pane was empty * fixed: 'Delete' was missing from context menu when multiple IMAP folders were selected * fixed: Compacting multiple folders failed and did not compact * fixed: Shift-click for 'Edit' button in drafts header view did not work * fixed: "Replace All" in Compose did not update plain text until dialog closed * fixed: Status bar messages displayed unlocalized folder names or IMAP mailbox names * fixed: Saved email filenames were not not always cross- platform safe * fixed: Space bar did not scroll in PDF attachments opened from emails * fixed: Folder location widget used non-localised name * fixed: Empty confirmation dialog when more messages opened in tabs than`mailnews.open_tab_warning`* fixed: Removing tags from IMAP messages could fail and tags reappeared after refresh * fixed: Toggling dark message mode did not restore focus and scroll position * fixed: 'Show remote content' did not display remote content for EML message * fixed: Emoji sequences were not properly handled in subject lines * fixed: 'Delete' button in unified toolbar could delete attachments instead of message * fixed: "Repair text encoding" could duplicate recipient and attachments * fixed: Some IMAP emails showed current time instead of correct received date * fixed: Deleting a single message in folder using 'Group by Sort' failed after CTRL+A * fixed: New newsgroups were not added in alphabetical order by default * fixed: Sorting by threads only brought threads with unread top messages to the top * fixed: News message marked read after NNTP error prevented retrieval from server * fixed: 'Recent destinations' submenu was not sorted by time of modification * fixed: Account column could display incorrect account name * fixed: 'Tag' submenu of mail context menu could be populated incorrectly * fixed: Unified archive subfolders could show wrong names and no messages * fixed: Moving saved search/virtual folder under IMAP could fail * fixed: New Folder dialog allowed invalid folder creation without a selected parent folder * fixed: New/unread messages in collapsed thread were not obvious enough * fixed: Pressing Delete on Trash folder could remove it without confirmation * fixed: Renaming of a 'unified folder' created a duplicate * fixed: Clicking on a folder in the folder pane did not always open folder * fixed: Messages nested deeper than 255 levels disappeared from threading view * fixed: Performing Delete followed by Undo on thread parent message could corrupt view * fixed: Single messages still appeared collapsible after thread members were deleted * fixed: Updated threads remained misordered until folder refresh or resort * fixed: Global search failed to display inaccessible messages found in local folders * fixed: Numeric subfolders were sorted alphabetically instead of naturally * fixed: Virtual folder folder-picker showed unlabeled IM account as selectable folder * fixed: Some folders showed new mail count prior to receiving mail * fixed: Menu Bar -> View contained duplicate accelerator keys * fixed: Unified toolbar Spam button did not switch to "Not Spam" when spam message selected * fixed: Warning was not logged if`mail.openpgp.alias_rules_file`file did not exist * fixed: Not all headers were signed when creating digitally signed OpenPGP email * fixed: When configuring external GnuPG, user was not promted to import public key * fixed: "Open and Show" for OpenPGP-signed message (.eml) did not work * fixed: Invalidly signed unencrypted emails were indicated as worse than unsigned ones * fixed: Reason for revoked certificate was not shown * fixed: Apple Mail OpenPGP emails failed to decrypt due to hidden recipient key ID * fixed: OpenPGP import of public key with experimental packets failed with unclear error * fixed: Opening messages with OpenPGP keys was slow and blocked the UI for large keyrings * fixed: OpenPGP key refresh failed when fingerprint lookup returned multiple results * fixed: Encrypted Gmail CSE emails with outer opaque S/MIME were not readable * fixed: Invalid S/MIME encryption certificate caused misleading send errors * fixed: "Search Messages" search did not finish due to unparsable local folders * fixed: Search results showed older irrelevant emails before newer exact matches * fixed: Filter search on Body missed draft messages containing German umlauts * fixed: Esc cleared quick filter pin after changing folder * fixed: Thunderbird could crash during local message search * fixed: Replying could fail with`mailnews.reply_quoting_selection.multi_word`set false * fixed: Drag-drop of unselected contact inserted wrong or no email address * fixed: Changing identity in compose window caused modified draft not to be saved * fixed: Shift-click 'Compose Message To' on 'mailto' link did not open in plain text * fixed: Reply with selected text lost formatting for HTML messages containing &lt;/pre&gt; * fixed: Multipart/related attachments were not preserved when editing or forwarding * fixed: Forwarded malformed MIME email had empty body and extra attachment * fixed: Message compose window was removed from Task Bar after saving as draft or template * fixed: Dragging email address between compose windows failed to add recipients * fixed: Thunderbird could crash when using Find and Replace All * fixed: Compose with PDF attachments opened PDFs instead of creating a new email * fixed: Multiple saves while using 'Options' -> 'Send a Copy' resulted in multiple copies * fixed: Search for "Attachment" in Settings menu did not find "Files and Attachments" * fixed: Add-on account creation did not work with Account Hub * fixed: Owl install did not show link to website in Account Hub * fixed: Username field did not appear in Account Hub when exchange authentication failed * fixed: Account Hub advanced config setup did not include default outgoing config * fixed: Disabled inputs could be toggled in Account Hub address book * fixed: Users could not disable spinning overlay in Account Hub for email * fixed: Account Hub local address book creation could continue with blank name * fixed: Account Hub email success messages were not always accurate about config source * fixed: Calendar/address book sections were shown in Account Hub when there were none * fixed: New password-based Exchange accounts failed to save passwords in login manager * fixed: Account hub showed connection security instead of actual authentication method * fixed: New identity dialog lacked reply-matching and end-to- end encryption settings * fixed: Thunderbird could fail to shut down cleanly during active OAuth requests * fixed: Account Hub kept OAuth selected after changing to hostname without OAuth support * fixed: Account Hub autodetect wrongly prompted for a password when auth was unavailable * fixed: Interrupted external OAuth2 setup required restarting Thunderbird * fixed: The default account could be reset after restart if uninitialized * fixed: Virtual folders did not update correctly for filtered POP3 messages * fixed: 'Copy Message to' action in a newsgroup filter did not work * fixed: Thunderbird could crash while importing mail thread * fixed: Thunderbird did not clearly fail when importing profile from a bad source * fixed: Thunderbird could not import profile located at the top level of zip file * fixed: 'Any Number' was unavailable in address book search with 'Match all of the following' * fixed: Contact not found in Advanced Address Book Search if phone number had a period * fixed: Thunderbird did not display contact photos in WebP format from CardDAV servers * fixed: Opening a vCard (.vcf) from file manager or CLI did not work in some cases * fixed: Redirected CardDAV URLs resolved relative URLs against the wrong host * fixed: Installations from Microsoft Store did not open when clicking 'mailto:' links * fixed: Windows new message notification click did not bring Thunderbird to foreground * fixed: Microsoft Store installs did not open when clicking 'news://' link or .eml file * fixed: Using thunderbird -compose with double quotes made last email address invalid * fixed: Clicking the backspace icon in the quick filter field cleared the input field * fixed: Subfolder kept stale accessibility unread count after unread messages were deleted * fixed: Moving virtual folder within maildir based IMAP or local folder could fail * fixed: Thunderbird could crash when completing folder copy/move * fixed: 'Edit as New Message' and inline 'Forward' not possible with PGP-signed messages * fixed: Various MIME improvements * fixed: Forwarding some Apple Mail messages incorrectly attached inline text as a file * fixed: Thunderbird could crash when marking all messages as read * fixed: Auto-compaction could corrupt database and cause crashes during syncs * fixed: 'news:' URIs without specific server had incorrect format displayed in status bar * fixed: 'Mark' -> 'All Read' affected newsgroup messages that had not been fetched yet * fixed: Thunderbird could not reconnect to newsgroups after connection loss until restarted * fixed: Sending a newsgroup post appeared successful when it had actually failed * fixed: Saving a new draft retained superceded version * fixed: Thunderbird hung when auto-checking multiple accounts for new messages * fixed: Spam not checked with`mail.server.default.check_all_folders_for_new` on * fixed: Startup could be slow with large number of folders not using subscriptions * fixed: Saved search in unified folder resulted in server error * fixed: Thunderbird did not report refused POP3 connection * fixed: Remove message body retention policy was not functional * fixed: POP3 could stop downloading mail until restart * fixed: With auto-mark-read disabled, large mail still marked as read during load delay * fixed: IMAP "Show only subscribed folders" could not be changed without restart * fixed: POP3 deadlocked when server went silent without closing socket * fixed: Thunderbird could crash when mail folder was renamed or moved * fixed: NNTP server with invalid TLS certificate could not be added to certificate exceptions * fixed: Cancelled message send could not be retried and hung with SMTP timeout errors * fixed: Corrupted NNTP account data caused excessive memory use and startup crash * fixed: Multiple selected IMAP folders could not be moved or deleted together * fixed: Non-Latin IMAP keywords were lowercased and encoded incorrectly as MUTF-7 * fixed: Message tags were lost when moving folder from local folder to IMAP folder * fixed: Removing a chat account threw an exception and failed to clear the UI * fixed: Enterprise policy use not indicated in about:preferences with link to about:policies * fixed: Language field in settings was empty after restart in Troubleshoot Mode * fixed: Primary Password policy was detected but not enforced for saved account passwords * fixed: Archived RSS feed messages were sent to the archive folder of default identity * fixed: Broken feed icon could prevent updating of feeds * fixed: Task reminders could fail for tasks without end dates or with shifted due dates * fixed: Calendar did not alert user for connection issues * fixed: Copying one recurring event occurrence failed to set the date when pasted * fixed: Could not copy an event in multiweek or month view by drag-and-drop * fixed: Duplicate attendees were added to invitations instead of being filtered out * fixed: Calendar discovery with certificate error displayed multiple exceptions * fixed: It was not possible to create date-only all-day tasks * fixed: Task percentage complete was not preserved separately from status in tooltips * fixed: Calendar invites were incorrectly marked processed after calendar sync completed * fixed: ICS event comments were not displayed in Thunderbird event details * fixed: Dismissed Gmail calendar reminder did nothing and item stayed visible * fixed: iCal imports misread unknown timezones as GMT, creating events at wrong times * fixed: Could not export local calendar as HTML * fixed: Cancelled filter edit dialog closed the message filter dialog * fixed: Visual and UX improvements * CVE-2026-14899 Off-by-one out of bounds read in MIME header parser for forwarding * CVE-2026-16349 Same-origin policy bypass in the DOM: Navigation component * CVE-2026-16350 Incorrect boundary conditions in the Audio/Video: cubeb component * CVE-2026-16362 Use-after-free in the WebRTC: Audio/Video component * CVE-2026-16351 Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-16352 Sandbox escape due to use-after- free in the Disability Access APIs component * CVE-2026-16363 JIT miscompilation in the JavaScript: WebAssembly component * CVE-2026-16364 Incorrect boundary conditions in the Audio/Video: Playback component * CVE-2026-16365 Privilege escalation in the DOM: Workers component * CVE-2026-16366 Privilege escalation in the DOM: Navigation component * CVE-2026-16353 Invalid pointer in the DOM: Bindings (WebIDL) component * CVE-2026-16354 Information disclosure in the Graphics: ImageLib component * CVE-2026-16367 Sandbox escape due to invalid pointer in the Disability Access APIs component * CVE-2026-16368 Incorrect boundary conditions in the JavaScript: WebAssembly component * CVE-2026-16369 Integer overflow in the JavaScript: WebAssembly component * CVE-2026-16355 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16356 Sandbox escape due to use-after-free in the Disability Access APIs component * CVE-2026-16357 Incorrect boundary conditions in the Graphics component * CVE-2026-16370 Mitigation bypass in the DOM: Networking component * CVE-2026-16371 Privilege escalation in the DOM: Navigation component * CVE-2026-16372 Privilege escalation in the DOM: Content Processes component * CVE-2026-16374 Information disclosure in the Framework component in DevTools * CVE-2026-16375 Site isolation issue in the Networking: HTTP component * CVE-2026-16376 Denial-of-service in the Graphics: WebGPU component * CVE-2026-16377 Mitigation bypass in the PDF Viewer component * CVE-2026-16378 Other issue in the DOM: Copy & Paste and Drag & Drop component * CVE-2026-16379 Privilege escalation in the DOM: Content Processes component * CVE-2026-16358 Site isolation issue in the Graphics: WebRender component * CVE-2026-16380 Mitigation bypass in the Networking component * CVE-2026-16381 Same-origin policy bypass in the Networking: DNS component * CVE-2026-16382 Mitigation bypass in the DOM: Service Workers component * CVE-2026-16383 Mitigation bypass in the DOM: Networking component * CVE-2026-16384 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16385 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16386 Information disclosure due to uninitialized memory in the Graphics: WebGPU component * CVE-2026-16387 Site isolation issue in the Networking component * CVE-2026-16388 Sandbox escape in the DOM: Networking component * CVE-2026-16389 Incorrect boundary conditions, integer overflow in the Libraries component in NSS * CVE-2026-16390 Mitigation bypass in the Enterprise Policies component * CVE-2026-16391 Information disclosure in the Storage: IndexedDB component * CVE-2026-16392 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16393 Incorrect boundary conditions in the Graphics: WebGPU component * CVE-2026-16359 Incorrect boundary conditions in the Audio/Video: GMP component * CVE-2026-16394 Mitigation bypass in the DOM: Security component * CVE-2026-16395 Integer overflow in the Audio/Video component * CVE-2026-16396 Privilege escalation in WebExtensions * CVE-2026-16398 Site isolation issue in the Graphics component * CVE-2026-16399 Site isolation issue in the DOM: Navigation component * CVE-2026-16400 Information disclosure in the DOM: Security component * CVE-2026-16401 Privilege escalation in the Data Loss Prevention component * CVE-2026-16402 Integer overflow in the Graphics: ImageLib component * CVE-2026-16403 Spoofing issue in the Address Bar component * CVE-2026-16405 Information disclosure in the Networking: WebSockets component * CVE-2026-16406 Mitigation bypass in the Networking component * CVE-2026-16407 Mitigation bypass in the DOM: Service Workers component * CVE-2026-16408 Integer overflow in the Audio/Video: Playback component * CVE-2026-16409 Invalid pointer in the Security: PSM component * CVE-2026-16410 JIT miscompilation in the JavaScript Engine: JIT component * CVE-2026-16411 Memory safety bugs fixed in Thunderbird 153 * CVE-2026-16412 Memory safety bugs fixed in Thunderbird ESR 140.13 and Thunderbird 153 * CVE-2026-16360 Memory safety bugs fixed in Thunderbird ESR 140.13 and Thunderbird 153 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4268 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-4268 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4268 ## Package List: * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * MozillaThunderbird-debuginfo-153.2.0-150400.13.3.1 * MozillaThunderbird-translations-other-153.2.0-150400.13.3.1 * MozillaThunderbird-153.2.0-150400.13.3.1 * MozillaThunderbird-debugsource-153.2.0-150400.13.3.1 * MozillaThunderbird-translations-common-153.2.0-150400.13.3.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * MozillaThunderbird-debuginfo-153.2.0-150400.13.3.1 * MozillaThunderbird-translations-other-153.2.0-150400.13.3.1 * MozillaThunderbird-153.2.0-150400.13.3.1 * MozillaThunderbird-debugsource-153.2.0-150400.13.3.1 * MozillaThunderbird-translations-common-153.2.0-150400.13.3.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x) * MozillaThunderbird-debuginfo-153.2.0-150400.13.3.1 * MozillaThunderbird-translations-other-153.2.0-150400.13.3.1 * MozillaThunderbird-153.2.0-150400.13.3.1 * MozillaThunderbird-debugsource-153.2.0-150400.13.3.1 * MozillaThunderbird-translations-common-153.2.0-150400.13.3.1 ## References: * https://www.suse.com/security/cve/CVE-2024-34703.html * https://www.suse.com/security/cve/CVE-2026-14899.html * https://www.suse.com/security/cve/CVE-2026-16349.html * https://www.suse.com/security/cve/CVE-2026-16350.html * https://www.suse.com/security/cve/CVE-2026-16351.html * https://www.suse.com/security/cve/CVE-2026-16352.html * https://www.suse.com/security/cve/CVE-2026-16353.html * https://www.suse.com/security/cve/CVE-2026-16354.html * https://www.suse.com/security/cve/CVE-2026-16355.html * https://www.suse.com/security/cve/CVE-2026-16356.html * https://www.suse.com/security/cve/CVE-2026-16357.html * https://www.suse.com/security/cve/CVE-2026-16358.html * https://www.suse.com/security/cve/CVE-2026-16359.html * https://www.suse.com/security/cve/CVE-2026-16360.html * https://www.suse.com/security/cve/CVE-2026-16362.html * https://www.suse.com/security/cve/CVE-2026-16363.html * https://www.suse.com/security/cve/CVE-2026-16364.html * https://www.suse.com/security/cve/CVE-2026-16365.html * https://www.suse.com/security/cve/CVE-2026-16366.html * https://www.suse.com/security/cve/CVE-2026-16367.html * https://www.suse.com/security/cve/CVE-2026-16368.html * https://www.suse.com/security/cve/CVE-2026-16369.html * https://www.suse.com/security/cve/CVE-2026-16370.html * https://www.suse.com/security/cve/CVE-2026-16371.html * https://www.suse.com/security/cve/CVE-2026-16372.html * https://www.suse.com/security/cve/CVE-2026-16374.html * https://www.suse.com/security/cve/CVE-2026-16375.html * https://www.suse.com/security/cve/CVE-2026-16376.html * https://www.suse.com/security/cve/CVE-2026-16377.html * https://www.suse.com/security/cve/CVE-2026-16378.html * https://www.suse.com/security/cve/CVE-2026-16379.html * https://www.suse.com/security/cve/CVE-2026-16380.html * https://www.suse.com/security/cve/CVE-2026-16381.html * https://www.suse.com/security/cve/CVE-2026-16382.html * https://www.suse.com/security/cve/CVE-2026-16383.html * https://www.suse.com/security/cve/CVE-2026-16384.html * https://www.suse.com/security/cve/CVE-2026-16385.html * https://www.suse.com/security/cve/CVE-2026-16386.html * https://www.suse.com/security/cve/CVE-2026-16387.html * https://www.suse.com/security/cve/CVE-2026-16388.html * https://www.suse.com/security/cve/CVE-2026-16389.html * https://www.suse.com/security/cve/CVE-2026-16390.html * https://www.suse.com/security/cve/CVE-2026-16391.html * https://www.suse.com/security/cve/CVE-2026-16392.html * https://www.suse.com/security/cve/CVE-2026-16393.html * https://www.suse.com/security/cve/CVE-2026-16394.html * https://www.suse.com/security/cve/CVE-2026-16395.html * https://www.suse.com/security/cve/CVE-2026-16396.html * https://www.suse.com/security/cve/CVE-2026-16398.html * https://www.suse.com/security/cve/CVE-2026-16399.html * https://www.suse.com/security/cve/CVE-2026-16400.html * https://www.suse.com/security/cve/CVE-2026-16401.html * https://www.suse.com/security/cve/CVE-2026-16402.html * https://www.suse.com/security/cve/CVE-2026-16403.html * https://www.suse.com/security/cve/CVE-2026-16405.html * https://www.suse.com/security/cve/CVE-2026-16406.html * https://www.suse.com/security/cve/CVE-2026-16407.html * https://www.suse.com/security/cve/CVE-2026-16408.html * https://www.suse.com/security/cve/CVE-2026-16409.html * https://www.suse.com/security/cve/CVE-2026-16410.html * https://www.suse.com/security/cve/CVE-2026-16411.html * https://www.suse.com/security/cve/CVE-2026-16412.html * https://www.suse.com/security/cve/CVE-2026-74934.html * https://www.suse.com/security/cve/CVE-2026-74935.html * https://www.suse.com/security/cve/CVE-2026-74936.html * https://www.suse.com/security/cve/CVE-2026-74937.html * https://www.suse.com/security/cve/CVE-2026-74938.html * https://www.suse.com/security/cve/CVE-2026-74939.html * https://www.suse.com/security/cve/CVE-2026-74940.html * https://www.suse.com/security/cve/CVE-2026-74941.html * https://www.suse.com/security/cve/CVE-2026-74942.html * https://www.suse.com/security/cve/CVE-2026-74943.html * https://www.suse.com/security/cve/CVE-2026-74944.html * https://www.suse.com/security/cve/CVE-2026-74945.html * https://www.suse.com/security/cve/CVE-2026-74946.html * https://www.suse.com/security/cve/CVE-2026-74947.html * https://www.suse.com/security/cve/CVE-2026-74948.html * https://www.suse.com/security/cve/CVE-2026-74949.html * https://www.suse.com/security/cve/CVE-2026-74950.html * https://www.suse.com/security/cve/CVE-2026-74952.html * https://www.suse.com/security/cve/CVE-2026-74953.html * https://www.suse.com/security/cve/CVE-2026-74954.html * https://www.suse.com/security/cve/CVE-2026-74955.html * https://www.suse.com/security/cve/CVE-2026-74956.html * https://www.suse.com/security/cve/CVE-2026-74957.html * https://www.suse.com/security/cve/CVE-2026-74958.html * https://www.suse.com/security/cve/CVE-2026-74959.html * https://www.suse.com/security/cve/CVE-2026-74960.html * https://www.suse.com/security/cve/CVE-2026-74961.html * https://www.suse.com/security/cve/CVE-2026-74962.html * https://www.suse.com/security/cve/CVE-2026-74963.html * https://www.suse.com/security/cve/CVE-2026-74964.html * https://www.suse.com/security/cve/CVE-2026-74965.html * https://www.suse.com/security/cve/CVE-2026-74966.html * https://www.suse.com/security/cve/CVE-2026-74967.html * https://www.suse.com/security/cve/CVE-2026-74968.html * https://www.suse.com/security/cve/CVE-2026-74969.html * https://www.suse.com/security/cve/CVE-2026-74970.html * https://www.suse.com/security/cve/CVE-2026-74971.html * https://www.suse.com/security/cve/CVE-2026-74972.html * https://www.suse.com/security/cve/CVE-2026-74973.html * https://www.suse.com/security/cve/CVE-2026-74974.html * https://www.suse.com/security/cve/CVE-2026-74976.html * https://www.suse.com/security/cve/CVE-2026-74977.html * https://www.suse.com/security/cve/CVE-2026-74978.html * https://www.suse.com/security/cve/CVE-2026-74979.html * https://www.suse.com/security/cve/CVE-2026-74981.html * https://www.suse.com/security/cve/CVE-2026-74982.html * https://www.suse.com/security/cve/CVE-2026-74983.html * https://www.suse.com/security/cve/CVE-2026-74984.html * https://www.suse.com/security/cve/CVE-2026-74985.html * https://www.suse.com/security/cve/CVE-2026-74986.html * https://www.suse.com/security/cve/CVE-2026-74987.html * https://www.suse.com/security/cve/CVE-2026-74988.html * https://www.suse.com/security/cve/CVE-2026-74990.html * https://www.suse.com/security/cve/CVE-2026-75874.html * https://www.suse.com/security/cve/CVE-2026-84118.html * https://www.suse.com/security/cve/CVE-2026-84119.html * https://www.suse.com/security/cve/CVE-2026-84120.html * https://www.suse.com/security/cve/CVE-2026-84121.html * https://www.suse.com/security/cve/CVE-2026-84122.html * https://www.suse.com/security/cve/CVE-2026-84123.html * https://www.suse.com/security/cve/CVE-2026-84124.html * https://www.suse.com/security/cve/CVE-2026-84125.html * https://www.suse.com/security/cve/CVE-2026-84129.html * https://www.suse.com/security/cve/CVE-2026-84130.html * https://www.suse.com/security/cve/CVE-2026-84131.html * https://www.suse.com/security/cve/CVE-2026-84132.html * https://www.suse.com/security/cve/CVE-2026-84133.html * https://www.suse.com/security/cve/CVE-2026-84134.html * https://www.suse.com/security/cve/CVE-2026-84136.html * https://www.suse.com/security/cve/CVE-2026-84137.html * https://www.suse.com/security/cve/CVE-2026-84139.html * https://www.suse.com/security/cve/CVE-2026-84140.html * https://www.suse.com/security/cve/CVE-2026-84141.html * https://www.suse.com/security/cve/CVE-2026-84143.html * https://www.suse.com/security/cve/CVE-2026-84144.html * https://www.suse.com/security/cve/CVE-2026-84145.html * https://www.suse.com/security/cve/CVE-2026-84637.html * https://www.suse.com/security/cve/CVE-2026-84639.html * https://www.suse.com/security/cve/CVE-2026-84640.html * https://www.suse.com/security/cve/CVE-2026-84641.html * https://www.suse.com/security/cve/CVE-2026-84642.html * https://bugzilla.suse.com/show_bug.cgi?id=1271649 * https://bugzilla.suse.com/show_bug.cgi?id=1274867 * https://bugzilla.suse.com/show_bug.cgi?id=1278001 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 18 20:31:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 18 Sep 2026 20:31:43 -0000 Subject: SUSE-SU-2026:4265-1: low: Security update for ImageMagick Message-ID: <178976350334.6724.9619453450517709988@b745e8aa27b6> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:4265-1 Release Date: 2026-09-18T13:55:28Z Rating: low References: * bsc#1279696 * bsc#1279711 * bsc#1279794 * bsc#1279797 Cross-References: * CVE-2026-86420 * CVE-2026-86421 * CVE-2026-86423 * CVE-2026-86425 CVSS scores: * CVE-2026-86420 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-86420 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-86420 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-86420 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-86420 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-86421 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-86421 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-86421 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-86421 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-86421 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-86423 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-86423 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-86423 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-86423 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-86423 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-86425 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-86425 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-86425 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-86425 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-86425 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves four vulnerabilities can now be installed. ## Description: This update for ImageMagick fixes the following issues: * CVE-2026-86420: denial of Service due to memory budget exhaustion (bsc#1279696). * CVE-2026-86421: denial of Service via memory leak in MSL decoder (bsc#1279711). * CVE-2026-86423: denial of service via heap-use-after-free in PerlMagick's GetList method (bsc#1279794). * CVE-2026-86425: denial of Service due to heap-use-after-free vulnerability (bsc#1279797). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4265 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * ImageMagick-debugsource-6.8.8.1-71.273.2 * ImageMagick-devel-6.8.8.1-71.273.2 * ImageMagick-config-6-SUSE-6.8.8.1-71.273.2 * libMagickCore-6_Q16-1-6.8.8.1-71.273.2 * ImageMagick-config-6-upstream-6.8.8.1-71.273.2 * libMagickWand-6_Q16-1-debuginfo-6.8.8.1-71.273.2 * libMagickWand-6_Q16-1-6.8.8.1-71.273.2 * libMagickCore-6_Q16-1-debuginfo-6.8.8.1-71.273.2 * ImageMagick-debuginfo-6.8.8.1-71.273.2 * libMagick++-devel-6.8.8.1-71.273.2 ## References: * https://www.suse.com/security/cve/CVE-2026-86420.html * https://www.suse.com/security/cve/CVE-2026-86421.html * https://www.suse.com/security/cve/CVE-2026-86423.html * https://www.suse.com/security/cve/CVE-2026-86425.html * https://bugzilla.suse.com/show_bug.cgi?id=1279696 * https://bugzilla.suse.com/show_bug.cgi?id=1279711 * https://bugzilla.suse.com/show_bug.cgi?id=1279794 * https://bugzilla.suse.com/show_bug.cgi?id=1279797 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Fri Sep 18 20:32:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Fri, 18 Sep 2026 20:32:22 -0000 Subject: SUSE-SU-2026:4264-1: important: Security update for MozillaFirefox Message-ID: <178976354248.6724.1906971030258365611@b745e8aa27b6> # Security update for MozillaFirefox Announcement ID: SUSE-SU-2026:4264-1 Release Date: 2026-09-18T13:54:58Z Rating: important References: * bsc#1280371 Cross-References: * CVE-2026-92005 * CVE-2026-92006 * CVE-2026-92007 * CVE-2026-92008 * CVE-2026-92009 * CVE-2026-92010 * CVE-2026-92011 * CVE-2026-92012 * CVE-2026-92013 * CVE-2026-92015 * CVE-2026-92016 * CVE-2026-92017 * CVE-2026-92018 * CVE-2026-92019 * CVE-2026-92020 * CVE-2026-92022 * CVE-2026-92023 * CVE-2026-92024 * CVE-2026-92025 * CVE-2026-92026 * CVE-2026-92027 * CVE-2026-92028 * CVE-2026-92029 * CVE-2026-92030 * CVE-2026-92031 * CVE-2026-92032 * CVE-2026-92035 * CVE-2026-92038 * CVE-2026-92039 * CVE-2026-92041 * CVE-2026-92042 * CVE-2026-92043 * CVE-2026-92044 * CVE-2026-92045 * CVE-2026-92046 * CVE-2026-92047 * CVE-2026-92048 * CVE-2026-92049 * CVE-2026-92052 * CVE-2026-92053 * CVE-2026-92054 * CVE-2026-92055 * CVE-2026-92056 * CVE-2026-92057 * CVE-2026-92058 * CVE-2026-92059 * CVE-2026-92060 * CVE-2026-92062 * CVE-2026-92064 * CVE-2026-92065 * CVE-2026-92067 * CVE-2026-92068 * CVE-2026-92069 * CVE-2026-92070 * CVE-2026-92071 * CVE-2026-92072 * CVE-2026-92073 * CVE-2026-92074 * CVE-2026-92075 * CVE-2026-92076 * CVE-2026-92077 * CVE-2026-92078 * CVE-2026-92079 CVSS scores: * CVE-2026-92005 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-92006 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92006 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92007 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92008 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92009 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92010 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92011 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92012 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92013 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92015 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92017 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92020 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92025 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92026 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92027 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92043 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92047 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92052 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92053 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92054 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92055 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92062 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-92073 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 63 vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issues: Update to Firefox Extended Support Release 153.3.0 ESRi (MFSA 2026-93, bsc#1280371) * CVE-2026-92005: Use-after-free in the Audio/Video: Web Codecs component. * CVE-2026-92006: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-92007: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-92008: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-92009: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-92010: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-92011: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-92012: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-92013: Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. * CVE-2026-92015: Privilege escalation in the WebExtensions component. * CVE-2026-92016: Use-after-free in the Disability Access APIs component. * CVE-2026-92017: Privilege escalation in the DOM: Service Workers component. * CVE-2026-92018: Sandbox escape in the DOM: Core & HTML component. * CVE-2026-92019: Mitigation bypass in the Remote Settings Client component. * CVE-2026-92020: Privilege escalation due to incorrect boundary conditions in the Graphics: WebRender component. * CVE-2026-92022: Use-after-free in the DOM: HTML Parser component. * CVE-2026-92023: Use-after-free in the XML component. * CVE-2026-92024: Use-after-free in the SVG component. * CVE-2026-92025: Use-after-free in the DOM: Navigation component. * CVE-2026-92026: Use-after-free in the Networking component. * CVE-2026-92027: Use-after-free in the DOM: Streams component. * CVE-2026-92028: Use-after-free in the DOM: Core & HTML component. * CVE-2026-92029: Use-after-free in the SVG component. * CVE-2026-92030: Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component. * CVE-2026-92031: Information disclosure in the Graphics: ImageLib component. * CVE-2026-92032: Sandbox escape due to invalid pointer in the Graphics component. * CVE-2026-92035: Sandbox escape due to incorrect boundary conditions in the Graphics component. * CVE-2026-92038: Mitigation bypass in the Remote Settings Client component. * CVE-2026-92039: Mitigation bypass in the DOM: Notifications component. * CVE-2026-92041: Mitigation bypass in the DOM: Networking component. * CVE-2026-92042: Race condition in the DOM: Content Processes component. * CVE-2026-92043: Privilege escalation due to incorrect boundary conditions in the Audio/Video component. * CVE-2026-92044: Information disclosure in the Networking: HTTP component. * CVE-2026-92045: Sandbox escape due to incorrect boundary conditions in the WebRTC component. * CVE-2026-92046: Use-after-free in the Graphics component. * CVE-2026-92047: Privilege escalation in the Crash Reporting component. * CVE-2026-92048: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. * CVE-2026-92049: Use-after-free in the Widget: Win32 component. * CVE-2026-92052: Privilege escalation due to uninitialized memory in the Graphics: CanvasWebGL component. * CVE-2026-92053: Privilege escalation in the Graphics: CanvasWebGL component. * CVE-2026-92054: Privilege escalation in the Memory component. * CVE-2026-92055: Privilege escalation in the DevTools component. * CVE-2026-92056: Use-after-free in the Graphics: Text component. * CVE-2026-92057: Mitigation bypass in the Enterprise Policies component. * CVE-2026-92058: Use-after-free in the Graphics component. * CVE-2026-92059: Incorrect boundary conditions in the DOM: Editor component. * CVE-2026-92060: Use-after-free in the Internationalization component. * CVE-2026-92062: Privilege escalation in the Session Restore component. * CVE-2026-92064: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. * CVE-2026-92065: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. * CVE-2026-92067: Use-after-free in the Widget: Gtk component. * CVE-2026-92068: Site isolation issue in the Reader Mode component. * CVE-2026-92069: Spoofing issue in the DOM: Navigation component. * CVE-2026-92070: Information disclosure in the Networking component. * CVE-2026-92071: Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. * CVE-2026-92072: Incorrect boundary conditions in the Safe Browsing component. * CVE-2026-92073: Privilege escalation in the Enterprise Policies component. * CVE-2026-92074: Mitigation bypass in the Popup Blocker component. * CVE-2026-92075: Mitigation bypass in the Networking component. * CVE-2026-92076: Incorrect boundary conditions in the Networking component. * CVE-2026-92077: Denial-of-service in the SVG component. * CVE-2026-92078: Denial-of-service in the Security component. * CVE-2026-92079: Mitigation bypass in the Widget: Win32 component. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4264 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4264 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4264 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4264 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4264 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4264 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4264 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4264 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4264 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4264 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4264 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4264 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * MozillaFirefox-translations-common-153.3.0-150400.157.8.1 * MozillaFirefox-debugsource-153.3.0-150400.157.8.1 * MozillaFirefox-153.3.0-150400.157.8.1 * MozillaFirefox-debuginfo-153.3.0-150400.157.8.1 * MozillaFirefox-translations-other-153.3.0-150400.157.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * MozillaFirefox-devel-153.3.0-150400.157.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * MozillaFirefox-translations-common-153.3.0-150400.157.8.1 * MozillaFirefox-debugsource-153.3.0-150400.157.8.1 * MozillaFirefox-153.3.0-150400.157.8.1 * MozillaFirefox-debuginfo-153.3.0-150400.157.8.1 * MozillaFirefox-translations-other-153.3.0-150400.157.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * MozillaFirefox-devel-153.3.0-150400.157.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * MozillaFirefox-translations-common-153.3.0-150400.157.8.1 * MozillaFirefox-debugsource-153.3.0-150400.157.8.1 * MozillaFirefox-153.3.0-150400.157.8.1 * MozillaFirefox-debuginfo-153.3.0-150400.157.8.1 * MozillaFirefox-translations-other-153.3.0-150400.157.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * MozillaFirefox-devel-153.3.0-150400.157.8.1 * openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-common-153.3.0-150400.157.8.1 * MozillaFirefox-debugsource-153.3.0-150400.157.8.1 * MozillaFirefox-153.3.0-150400.157.8.1 * MozillaFirefox-debuginfo-153.3.0-150400.157.8.1 * MozillaFirefox-translations-other-153.3.0-150400.157.8.1 * MozillaFirefox-branding-upstream-153.3.0-150400.157.8.1 * openSUSE Leap 15.4 (noarch) * MozillaFirefox-devel-153.3.0-150400.157.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * MozillaFirefox-translations-common-153.3.0-150400.157.8.1 * MozillaFirefox-debugsource-153.3.0-150400.157.8.1 * MozillaFirefox-153.3.0-150400.157.8.1 * MozillaFirefox-debuginfo-153.3.0-150400.157.8.1 * MozillaFirefox-translations-other-153.3.0-150400.157.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * MozillaFirefox-devel-153.3.0-150400.157.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * MozillaFirefox-translations-common-153.3.0-150400.157.8.1 * MozillaFirefox-debugsource-153.3.0-150400.157.8.1 * MozillaFirefox-153.3.0-150400.157.8.1 * MozillaFirefox-debuginfo-153.3.0-150400.157.8.1 * MozillaFirefox-translations-other-153.3.0-150400.157.8.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * MozillaFirefox-devel-153.3.0-150400.157.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * MozillaFirefox-translations-common-153.3.0-150400.157.8.1 * MozillaFirefox-debugsource-153.3.0-150400.157.8.1 * MozillaFirefox-153.3.0-150400.157.8.1 * MozillaFirefox-debuginfo-153.3.0-150400.157.8.1 * MozillaFirefox-translations-other-153.3.0-150400.157.8.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * MozillaFirefox-devel-153.3.0-150400.157.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * MozillaFirefox-translations-common-153.3.0-150400.157.8.1 * MozillaFirefox-debugsource-153.3.0-150400.157.8.1 * MozillaFirefox-153.3.0-150400.157.8.1 * MozillaFirefox-debuginfo-153.3.0-150400.157.8.1 * MozillaFirefox-translations-other-153.3.0-150400.157.8.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * MozillaFirefox-devel-153.3.0-150400.157.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-common-153.3.0-150400.157.8.1 * MozillaFirefox-debugsource-153.3.0-150400.157.8.1 * MozillaFirefox-153.3.0-150400.157.8.1 * MozillaFirefox-debuginfo-153.3.0-150400.157.8.1 * MozillaFirefox-translations-other-153.3.0-150400.157.8.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * MozillaFirefox-devel-153.3.0-150400.157.8.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-common-153.3.0-150400.157.8.1 * MozillaFirefox-debugsource-153.3.0-150400.157.8.1 * MozillaFirefox-153.3.0-150400.157.8.1 * MozillaFirefox-debuginfo-153.3.0-150400.157.8.1 * MozillaFirefox-translations-other-153.3.0-150400.157.8.1 * Desktop Applications Module 15-SP7 (noarch) * MozillaFirefox-devel-153.3.0-150400.157.8.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-common-153.3.0-150400.157.8.1 * MozillaFirefox-debugsource-153.3.0-150400.157.8.1 * MozillaFirefox-153.3.0-150400.157.8.1 * MozillaFirefox-debuginfo-153.3.0-150400.157.8.1 * MozillaFirefox-translations-other-153.3.0-150400.157.8.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * MozillaFirefox-devel-153.3.0-150400.157.8.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * MozillaFirefox-translations-common-153.3.0-150400.157.8.1 * MozillaFirefox-debugsource-153.3.0-150400.157.8.1 * MozillaFirefox-153.3.0-150400.157.8.1 * MozillaFirefox-debuginfo-153.3.0-150400.157.8.1 * MozillaFirefox-translations-other-153.3.0-150400.157.8.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * MozillaFirefox-devel-153.3.0-150400.157.8.1 ## References: * https://www.suse.com/security/cve/CVE-2026-92005.html * https://www.suse.com/security/cve/CVE-2026-92006.html * https://www.suse.com/security/cve/CVE-2026-92007.html * https://www.suse.com/security/cve/CVE-2026-92008.html * https://www.suse.com/security/cve/CVE-2026-92009.html * https://www.suse.com/security/cve/CVE-2026-92010.html * https://www.suse.com/security/cve/CVE-2026-92011.html * https://www.suse.com/security/cve/CVE-2026-92012.html * https://www.suse.com/security/cve/CVE-2026-92013.html * https://www.suse.com/security/cve/CVE-2026-92015.html * https://www.suse.com/security/cve/CVE-2026-92016.html * https://www.suse.com/security/cve/CVE-2026-92017.html * https://www.suse.com/security/cve/CVE-2026-92018.html * https://www.suse.com/security/cve/CVE-2026-92019.html * https://www.suse.com/security/cve/CVE-2026-92020.html * https://www.suse.com/security/cve/CVE-2026-92022.html * https://www.suse.com/security/cve/CVE-2026-92023.html * https://www.suse.com/security/cve/CVE-2026-92024.html * https://www.suse.com/security/cve/CVE-2026-92025.html * https://www.suse.com/security/cve/CVE-2026-92026.html * https://www.suse.com/security/cve/CVE-2026-92027.html * https://www.suse.com/security/cve/CVE-2026-92028.html * https://www.suse.com/security/cve/CVE-2026-92029.html * https://www.suse.com/security/cve/CVE-2026-92030.html * https://www.suse.com/security/cve/CVE-2026-92031.html * https://www.suse.com/security/cve/CVE-2026-92032.html * https://www.suse.com/security/cve/CVE-2026-92035.html * https://www.suse.com/security/cve/CVE-2026-92038.html * https://www.suse.com/security/cve/CVE-2026-92039.html * https://www.suse.com/security/cve/CVE-2026-92041.html * https://www.suse.com/security/cve/CVE-2026-92042.html * https://www.suse.com/security/cve/CVE-2026-92043.html * https://www.suse.com/security/cve/CVE-2026-92044.html * https://www.suse.com/security/cve/CVE-2026-92045.html * https://www.suse.com/security/cve/CVE-2026-92046.html * https://www.suse.com/security/cve/CVE-2026-92047.html * https://www.suse.com/security/cve/CVE-2026-92048.html * https://www.suse.com/security/cve/CVE-2026-92049.html * https://www.suse.com/security/cve/CVE-2026-92052.html * https://www.suse.com/security/cve/CVE-2026-92053.html * https://www.suse.com/security/cve/CVE-2026-92054.html * https://www.suse.com/security/cve/CVE-2026-92055.html * https://www.suse.com/security/cve/CVE-2026-92056.html * https://www.suse.com/security/cve/CVE-2026-92057.html * https://www.suse.com/security/cve/CVE-2026-92058.html * https://www.suse.com/security/cve/CVE-2026-92059.html * https://www.suse.com/security/cve/CVE-2026-92060.html * https://www.suse.com/security/cve/CVE-2026-92062.html * https://www.suse.com/security/cve/CVE-2026-92064.html * https://www.suse.com/security/cve/CVE-2026-92065.html * https://www.suse.com/security/cve/CVE-2026-92067.html * https://www.suse.com/security/cve/CVE-2026-92068.html * https://www.suse.com/security/cve/CVE-2026-92069.html * https://www.suse.com/security/cve/CVE-2026-92070.html * https://www.suse.com/security/cve/CVE-2026-92071.html * https://www.suse.com/security/cve/CVE-2026-92072.html * https://www.suse.com/security/cve/CVE-2026-92073.html * https://www.suse.com/security/cve/CVE-2026-92074.html * https://www.suse.com/security/cve/CVE-2026-92075.html * https://www.suse.com/security/cve/CVE-2026-92076.html * https://www.suse.com/security/cve/CVE-2026-92077.html * https://www.suse.com/security/cve/CVE-2026-92078.html * https://www.suse.com/security/cve/CVE-2026-92079.html * https://bugzilla.suse.com/show_bug.cgi?id=1280371 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:31:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:31:15 -0000 Subject: SUSE-SU-2026:23801-1: important: Security update for the Linux Kernel (Live Patch 6 for SUSE Linux Enterprise 16) Message-ID: <178997947515.10889.9934677668827292775@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 6 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23801-1 Release Date: 2026-09-17T09:20:55Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.27.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1694 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_27-default-debuginfo-10-160000.1.1 * kernel-livepatch-SLE16_Update_6-debugsource-10-160000.1.1 * kernel-livepatch-6_12_0-160000_27-default-10-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:31:57 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:31:57 -0000 Subject: SUSE-SU-2026:23800-1: moderate: Security update for libsoup Message-ID: <178997951779.10889.3510474015906806391@200ee98c8b1d> # Security update for libsoup Announcement ID: SUSE-SU-2026:23800-1 Release Date: 2026-09-17T07:54:41Z Rating: moderate References: * bsc#1271401 Cross-References: * CVE-2026-12478 CVSS scores: * CVE-2026-12478 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-12478 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-12478 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L Affected Products: * SUSE Linux Micro 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for libsoup fixes the following issues * CVE-2026-0716: out-of-bounds read when processing a crafted unmasked frame with a payload length near `UINT64_MAX` sent by a WebSocket server (bsc#1256418). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1693 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libsoup-debugsource-3.6.6-160000.3.1 * libsoup-3_0-0-debuginfo-3.6.6-160000.3.1 * libsoup-3_0-0-3.6.6-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-12478.html * https://bugzilla.suse.com/show_bug.cgi?id=1271401 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:32:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:32:46 -0000 Subject: SUSE-SU-2026:23799-1: important: Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 16) Message-ID: <178997956688.10889.16675262233563400051@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23799-1 Release Date: 2026-09-16T22:10:18Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.29.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1692 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_29-default-debuginfo-8-160000.1.1 * kernel-livepatch-6_12_0-160000_29-default-8-160000.1.1 * kernel-livepatch-SLE16_Update_8-debugsource-8-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:33:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:33:35 -0000 Subject: SUSE-SU-2026:23798-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 16) Message-ID: <178997961512.10889.12811326184085532066@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23798-1 Release Date: 2026-09-16T20:14:05Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.35.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1690 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_14-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_35-default-5-160000.1.1 * kernel-livepatch-6_12_0-160000_35-default-debuginfo-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:34:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:34:16 -0000 Subject: SUSE-SU-2026:23797-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 16) Message-ID: <178997965617.10889.8139085915190926799@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23797-1 Release Date: 2026-09-16T19:06:56Z Rating: important References: * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.37.1 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1689 ## Package List: * SUSE Linux Micro 6.2 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_37-default-debuginfo-2-160000.1.1 * kernel-livepatch-SLE16_Update_16-debugsource-2-160000.1.1 * kernel-livepatch-6_12_0-160000_37-default-2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:35:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:35:04 -0000 Subject: SUSE-SU-2026:23796-1: important: Security update for rpm Message-ID: <178997970446.10889.210514005995321949@200ee98c8b1d> # Security update for rpm Announcement ID: SUSE-SU-2026:23796-1 Release Date: 2026-09-16T14:28:53Z Rating: important References: * bsc#1218459 * bsc#1253139 * bsc#1259215 * bsc#1268747 * bsc#1269150 * bsc#1269571 * bsc#1269584 Cross-References: * CVE-2026-44604 * CVE-2026-44605 CVSS scores: * CVE-2026-44604 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44604 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44604 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44605 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44605 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44605 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities and has five fixes can now be installed. ## Description: This update for rpm fixes the following issues: Changes in rpm: * split imaevmsign plugin into a multibuild flavor Changes in rpm: * Add Requires: (rpm-plugin-selinux if selinux-policy) * harden ndb code [bsc#1269584] [CVE-2026-44605] * split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do * make the imaevmsign plugin build in a multibuild flavor * rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] * backport fix for add_sysuser macro [bsc#1269571] * backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] * switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures * turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new "rpm- imaevmsign" subpackage. [jsc#PED-7246] * Fix "unexpected EOF" when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) * Remove /var/lib/rpm migration scripting, retain an error if old location is found * Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) * flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added "rpm_flushes_runposttrans" provides for libzypp ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1688 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * rpm-plugin-imaevmsign-debuginfo-4.20.1-160000.3.1 * python313-rpm-4.20.1-160000.3.1 * python-rpm-debugsource-4.20.1-160000.3.1 * rpm-plugin-imaevmsign-4.20.1-160000.3.1 * rpm-plugin-imaevmsign-debugsource-4.20.1-160000.3.1 * rpm-debuginfo-4.20.1-160000.3.1 * python313-rpm-debuginfo-4.20.1-160000.3.1 * rpm-plugin-fapolicyd-4.20.1-160000.3.1 * rpm-plugin-syslog-4.20.1-160000.3.1 * librpmbuild10-debuginfo-4.20.1-160000.3.1 * rpm-plugin-ima-4.20.1-160000.3.1 * rpm-plugin-prioreset-4.20.1-160000.3.1 * rpm-plugin-selinux-4.20.1-160000.3.1 * rpm-4.20.1-160000.3.1 * rpm-plugin-unshare-4.20.1-160000.3.1 * rpm-debugsource-4.20.1-160000.3.1 * librpmbuild10-4.20.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44604.html * https://www.suse.com/security/cve/CVE-2026-44605.html * https://bugzilla.suse.com/show_bug.cgi?id=1218459 * https://bugzilla.suse.com/show_bug.cgi?id=1253139 * https://bugzilla.suse.com/show_bug.cgi?id=1259215 * https://bugzilla.suse.com/show_bug.cgi?id=1268747 * https://bugzilla.suse.com/show_bug.cgi?id=1269150 * https://bugzilla.suse.com/show_bug.cgi?id=1269571 * https://bugzilla.suse.com/show_bug.cgi?id=1269584 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:36:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:36:18 -0000 Subject: SUSE-SU-2026:23794-1: important: Security update for openssl-3-livepatches Message-ID: <178997977836.10889.16967378142423831041@200ee98c8b1d> # Security update for openssl-3-livepatches Announcement ID: SUSE-SU-2026:23794-1 Release Date: 2026-09-16T06:55:20Z Rating: important References: * bsc#1271712 * bsc#1271713 * bsc#1274788 * bsc#1274790 * bsc#1274792 * bsc#1275133 * bsc#1275143 * bsc#1275145 Cross-References: * CVE-2026-14457 * CVE-2026-63072 * CVE-2026-63076 CVSS scores: * CVE-2026-14457 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-14457 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves three vulnerabilities and has five fixes can now be installed. ## Description: This update for openssl-3-livepatches fixes the following issues: * "HollowByte" DoS via attacker-controlled memory allocation (bsc#1271712). * CVE-2026-14457: RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate (bsc#1274792). * CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788). * CVE-2026-63076: Invalid Pointer Dereference in CMP Server via Crafted protectionAlg (bsc#1274790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1685 ## Package List: * SUSE Linux Micro 6.2 (ppc64le x86_64) * openssl-3-livepatches-0.6-160000.1.1 * openssl-3-livepatches-debugsource-0.6-160000.1.1 * openssl-3-livepatches-debuginfo-0.6-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14457.html * https://www.suse.com/security/cve/CVE-2026-63072.html * https://www.suse.com/security/cve/CVE-2026-63076.html * https://bugzilla.suse.com/show_bug.cgi?id=1271712 * https://bugzilla.suse.com/show_bug.cgi?id=1271713 * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1274790 * https://bugzilla.suse.com/show_bug.cgi?id=1274792 * https://bugzilla.suse.com/show_bug.cgi?id=1275133 * https://bugzilla.suse.com/show_bug.cgi?id=1275143 * https://bugzilla.suse.com/show_bug.cgi?id=1275145 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:37:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:37:27 -0000 Subject: SUSE-SU-2026:23792-1: important: Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise 16) Message-ID: <178997984737.10889.8778219333812404277@200ee98c8b1d> # Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23792-1 Release Date: 2026-09-14T13:02:10Z Rating: important References: * bsc#1271923 * bsc#1271924 * bsc#1271925 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-15811 * CVE-2026-15812 * CVE-2026-15813 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-15811 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L * CVE-2026-15811 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L * CVE-2026-15812 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-15812 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-15813 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-15813 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 * SUSE Linux Micro 6.2 An update that solves seven vulnerabilities can now be installed. ## Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise 16) ### Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.36.1 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Security update for kronosnet ### Description: This update for kronosnet fixes the following issues: * CVE-2026-15811: improper sanitization of sensitive memory locations following cryptographic configuration adjustments can lead to potential exposure of encryption keys (bsc#1271923). * CVE-2026-15812: improper verification of packet origins allows for access control list (ACL) bypass via ID spoofing (bsc#1271924). * CVE-2026-15813: improper validation during fragment reassembly can trigger memory corruption or out-of-bounds memory access (bsc#1271925). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1681 * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1682 ## Package List: * SUSE Linux Micro 6.2 (x86_64) * kernel-livepatch-6_12_0-160000_36-rt-debuginfo-3-160000.1.1 * kernel-livepatch-SLE16-RT_Update_15-debugsource-3-160000.1.1 * kernel-livepatch-6_12_0-160000_36-rt-3-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libknet1-crypto-nss-plugin-1.30-160000.4.1 * libknet-devel-1.30-160000.4.1 * libknet1-compress-zlib-plugin-debuginfo-1.30-160000.4.1 * libknet1-1.30-160000.4.1 * libknet1-compress-lzma-plugin-debuginfo-1.30-160000.4.1 * libknet1-compress-plugins-all-1.30-160000.4.1 * libknet1-crypto-openssl-plugin-debuginfo-1.30-160000.4.1 * libnozzle1-debuginfo-1.30-160000.4.1 * libknet1-compress-lzma-plugin-1.30-160000.4.1 * kronosnet-debuginfo-1.30-160000.4.1 * libnozzle1-1.30-160000.4.1 * libknet1-compress-zstd-plugin-1.30-160000.4.1 * libknet1-crypto-openssl-plugin-1.30-160000.4.1 * libknet1-compress-lzo2-plugin-1.30-160000.4.1 * libknet1-compress-lz4-plugin-1.30-160000.4.1 * libknet1-compress-zlib-plugin-1.30-160000.4.1 * libknet1-compress-zstd-plugin-debuginfo-1.30-160000.4.1 * kronosnet-debugsource-1.30-160000.4.1 * libknet1-debuginfo-1.30-160000.4.1 * libknet1-compress-lzo2-plugin-debuginfo-1.30-160000.4.1 * libnozzle-devel-1.30-160000.4.1 * libknet1-compress-lz4-plugin-debuginfo-1.30-160000.4.1 * libknet1-plugins-all-1.30-160000.4.1 * libknet1-compress-bzip2-plugin-1.30-160000.4.1 * libknet1-crypto-plugins-all-1.30-160000.4.1 * libknet1-compress-bzip2-plugin-debuginfo-1.30-160000.4.1 * libknet1-crypto-nss-plugin-debuginfo-1.30-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15811.html * https://www.suse.com/security/cve/CVE-2026-15812.html * https://www.suse.com/security/cve/CVE-2026-15813.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1271923 * https://bugzilla.suse.com/show_bug.cgi?id=1271924 * https://bugzilla.suse.com/show_bug.cgi?id=1271925 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:38:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:38:13 -0000 Subject: SUSE-SU-2026:23791-1: important: Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 16) Message-ID: <178997989370.10889.9664457924169309203@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23791-1 Release Date: 2026-09-16T22:10:18Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.29.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1692 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1692 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_29-default-debuginfo-8-160000.1.1 * kernel-livepatch-6_12_0-160000_29-default-8-160000.1.1 * kernel-livepatch-SLE16_Update_8-debugsource-8-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_29-default-debuginfo-8-160000.1.1 * kernel-livepatch-6_12_0-160000_29-default-8-160000.1.1 * kernel-livepatch-SLE16_Update_8-debugsource-8-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:39:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:39:01 -0000 Subject: SUSE-SU-2026:23790-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 16) Message-ID: <178997994137.10889.6011627821486797143@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23790-1 Release Date: 2026-09-16T20:14:05Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.35.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1690 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1690 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-SLE16_Update_14-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_35-default-5-160000.1.1 * kernel-livepatch-6_12_0-160000_35-default-debuginfo-5-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-SLE16_Update_14-debugsource-5-160000.1.1 * kernel-livepatch-6_12_0-160000_35-default-5-160000.1.1 * kernel-livepatch-6_12_0-160000_35-default-debuginfo-5-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:39:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:39:42 -0000 Subject: SUSE-SU-2026:23789-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 16) Message-ID: <178997998284.10889.17002240879024106160@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise 16) Announcement ID: SUSE-SU-2026:23789-1 Release Date: 2026-09-16T19:06:56Z Rating: important References: * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.12.0-160000.37.1 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1689 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1689 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * kernel-livepatch-6_12_0-160000_37-default-debuginfo-2-160000.1.1 * kernel-livepatch-SLE16_Update_16-debugsource-2-160000.1.1 * kernel-livepatch-6_12_0-160000_37-default-2-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le s390x x86_64) * kernel-livepatch-6_12_0-160000_37-default-debuginfo-2-160000.1.1 * kernel-livepatch-SLE16_Update_16-debugsource-2-160000.1.1 * kernel-livepatch-6_12_0-160000_37-default-2-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:40:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:40:38 -0000 Subject: SUSE-SU-2026:23788-1: important: Security update for openssl-3-livepatches Message-ID: <178998003802.10889.2518260247759903420@200ee98c8b1d> # Security update for openssl-3-livepatches Announcement ID: SUSE-SU-2026:23788-1 Release Date: 2026-09-16T06:55:20Z Rating: important References: * bsc#1271712 * bsc#1271713 * bsc#1274788 * bsc#1274790 * bsc#1274792 * bsc#1275133 * bsc#1275143 * bsc#1275145 Cross-References: * CVE-2026-14457 * CVE-2026-63072 * CVE-2026-63076 CVSS scores: * CVE-2026-14457 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-14457 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63072 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-63072 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63076 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities and has five fixes can now be installed. ## Description: This update for openssl-3-livepatches fixes the following issues: * "HollowByte" DoS via attacker-controlled memory allocation (bsc#1271712). * CVE-2026-14457: RPK Server Signature Algorithm Selection Can Dereference a Missing Certificate (bsc#1274792). * CVE-2026-63072: Heap Buffer Overflow in CMS Key Unwrapping (bsc#1274788). * CVE-2026-63076: Invalid Pointer Dereference in CMP Server via Crafted protectionAlg (bsc#1274790). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1685 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1685 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * openssl-3-livepatches-0.6-160000.1.1 * openssl-3-livepatches-debugsource-0.6-160000.1.1 * openssl-3-livepatches-debuginfo-0.6-160000.1.1 * SUSE Linux Enterprise Server 16.0 (ppc64le x86_64) * openssl-3-livepatches-0.6-160000.1.1 * openssl-3-livepatches-debugsource-0.6-160000.1.1 * openssl-3-livepatches-debuginfo-0.6-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-14457.html * https://www.suse.com/security/cve/CVE-2026-63072.html * https://www.suse.com/security/cve/CVE-2026-63076.html * https://bugzilla.suse.com/show_bug.cgi?id=1271712 * https://bugzilla.suse.com/show_bug.cgi?id=1271713 * https://bugzilla.suse.com/show_bug.cgi?id=1274788 * https://bugzilla.suse.com/show_bug.cgi?id=1274790 * https://bugzilla.suse.com/show_bug.cgi?id=1274792 * https://bugzilla.suse.com/show_bug.cgi?id=1275133 * https://bugzilla.suse.com/show_bug.cgi?id=1275143 * https://bugzilla.suse.com/show_bug.cgi?id=1275145 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:41:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:41:27 -0000 Subject: SUSE-SU-2026:23787-1: important: Security update for rpm Message-ID: <178998008746.10889.15189798120159802089@200ee98c8b1d> # Security update for rpm Announcement ID: SUSE-SU-2026:23787-1 Release Date: 2026-09-16T14:28:22Z Rating: important References: * bsc#1218459 * bsc#1253139 * bsc#1259215 * bsc#1268747 * bsc#1269150 * bsc#1269571 * bsc#1269584 Cross-References: * CVE-2026-44604 * CVE-2026-44605 CVSS scores: * CVE-2026-44604 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44604 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44604 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44605 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44605 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44605 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves two vulnerabilities and has five fixes can now be installed. ## Description: This update for rpm fixes the following issues: Changes in rpm: * split imaevmsign plugin into a multibuild flavor Changes in rpm: * Add Requires: (rpm-plugin-selinux if selinux-policy) * harden ndb code [bsc#1269584] [CVE-2026-44605] * split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do * make the imaevmsign plugin build in a multibuild flavor * rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] * backport fix for add_sysuser macro [bsc#1269571] * backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] * switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures * turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new "rpm- imaevmsign" subpackage. [jsc#PED-7246] * Fix "unexpected EOF" when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) * Remove /var/lib/rpm migration scripting, retain an error if old location is found * Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) * flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added "rpm_flushes_runposttrans" provides for libzypp ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1688 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1688 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * python-rpm-debugsource-4.20.1-160000.3.1 * rpm-plugin-imaevmsign-4.20.1-160000.3.1 * rpm-build-4.20.1-160000.3.1 * rpm-plugin-imaevmsign-debugsource-4.20.1-160000.3.1 * rpm-plugin-syslog-4.20.1-160000.3.1 * librpmbuild10-debuginfo-4.20.1-160000.3.1 * rpm-plugin-ima-4.20.1-160000.3.1 * rpm-plugin-selinux-4.20.1-160000.3.1 * rpm-build-debuginfo-4.20.1-160000.3.1 * rpm-debuginfo-4.20.1-160000.3.1 * python313-rpm-4.20.1-160000.3.1 * rpm-plugin-fapolicyd-4.20.1-160000.3.1 * python313-rpm-debuginfo-4.20.1-160000.3.1 * rpm-devel-4.20.1-160000.3.1 * rpm-plugin-prioreset-4.20.1-160000.3.1 * rpm-4.20.1-160000.3.1 * rpm-debugsource-4.20.1-160000.3.1 * rpm-plugin-unshare-4.20.1-160000.3.1 * rpm-plugin-imaevmsign-debuginfo-4.20.1-160000.3.1 * librpmbuild10-4.20.1-160000.3.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x x86_64) * python-rpm-debugsource-4.20.1-160000.3.1 * rpm-plugin-imaevmsign-4.20.1-160000.3.1 * rpm-build-4.20.1-160000.3.1 * rpm-plugin-imaevmsign-debugsource-4.20.1-160000.3.1 * rpm-plugin-syslog-4.20.1-160000.3.1 * librpmbuild10-debuginfo-4.20.1-160000.3.1 * rpm-plugin-ima-4.20.1-160000.3.1 * rpm-plugin-selinux-4.20.1-160000.3.1 * rpm-build-debuginfo-4.20.1-160000.3.1 * rpm-debuginfo-4.20.1-160000.3.1 * python313-rpm-4.20.1-160000.3.1 * rpm-plugin-fapolicyd-4.20.1-160000.3.1 * python313-rpm-debuginfo-4.20.1-160000.3.1 * rpm-devel-4.20.1-160000.3.1 * rpm-plugin-prioreset-4.20.1-160000.3.1 * rpm-4.20.1-160000.3.1 * rpm-debugsource-4.20.1-160000.3.1 * rpm-plugin-unshare-4.20.1-160000.3.1 * rpm-plugin-imaevmsign-debuginfo-4.20.1-160000.3.1 * librpmbuild10-4.20.1-160000.3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44604.html * https://www.suse.com/security/cve/CVE-2026-44605.html * https://bugzilla.suse.com/show_bug.cgi?id=1218459 * https://bugzilla.suse.com/show_bug.cgi?id=1253139 * https://bugzilla.suse.com/show_bug.cgi?id=1259215 * https://bugzilla.suse.com/show_bug.cgi?id=1268747 * https://bugzilla.suse.com/show_bug.cgi?id=1269150 * https://bugzilla.suse.com/show_bug.cgi?id=1269571 * https://bugzilla.suse.com/show_bug.cgi?id=1269584 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:42:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:42:58 -0000 Subject: SUSE-SU-2026:23784-1: important: Security update for MozillaFirefox Message-ID: <178998017896.10889.2507193481473024764@200ee98c8b1d> # Security update for MozillaFirefox Announcement ID: SUSE-SU-2026:23784-1 Release Date: 2026-09-15T14:40:48Z Rating: important References: * bsc#1278001 Cross-References: * CVE-2026-74952 * CVE-2026-75874 * CVE-2026-84118 * CVE-2026-84119 * CVE-2026-84120 * CVE-2026-84121 * CVE-2026-84122 * CVE-2026-84123 * CVE-2026-84124 * CVE-2026-84125 * CVE-2026-84129 * CVE-2026-84130 * CVE-2026-84131 * CVE-2026-84132 * CVE-2026-84133 * CVE-2026-84134 * CVE-2026-84136 * CVE-2026-84137 * CVE-2026-84139 * CVE-2026-84140 * CVE-2026-84141 * CVE-2026-84143 * CVE-2026-84144 * CVE-2026-84145 CVSS scores: * CVE-2026-74952 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-75874 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-84118 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84118 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84119 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-84119 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-84120 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84120 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84121 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-84121 ( NVD ): 9.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H * CVE-2026-84122 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84122 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84123 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84123 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84124 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84124 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84125 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84125 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N * CVE-2026-84129 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84130 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84131 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84131 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84132 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84133 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84134 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84136 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-84136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84137 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-84137 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84139 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-84139 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84140 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84140 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84141 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84141 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84143 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84144 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84145 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84145 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for MozillaFirefox fixes the following issues: Firefox Extended Support Release 153.2.0 ESR MFSA 2026-85 (bsc#1278001): * CVE-2026-75874 (bmo#2039972) Sandbox escape in the Remote Settings Client component * CVE-2026-84118 (bmo#2057457) Use-after-free in the JavaScript: GC component * CVE-2026-84119 (bmo#2057817) Sandbox escape due to use-after-free in the DOM: Navigation component * CVE-2026-84120 (bmo#2058911) Use-after-free in the Audio/Video component * CVE-2026-84121 (bmo#2059018) Sandbox escape due to use-after-free in the DOM: Security * CVE-2026-84122 (bmo#2059965) * CVE-2026-84123 (bmo#2060047) Privilege escalation due to use-after-free in the Graphics: WebGPU component * CVE-2026-84124 (bmo#2061110) Use-after-free in the DOM: Core & HTML component * CVE-2026-84125 (bmo#2063871) * CVE-2026-74952 (bmo#2021757) Privilege escalation in the Application Update component * CVE-2026-84129 (bmo#2055028) Site isolation issue in the DOM: Navigation component * CVE-2026-84130 (bmo#2057834) Information disclosure in the Graphics: WebGPU component * CVE-2026-84131 (bmo#2060008) Privilege escalation due to invalid pointer in the Graphics * CVE-2026-84132 (bmo#2063020) Information disclosure in the Networking: HTTP component * CVE-2026-84133 (bmo#2032388) Site isolation issue in the DOM: Push Subscriptions component * CVE-2026-84134 (bmo#2044882) Other issue in the Profile Backup component * CVE-2026-84136 (bmo#2048699) Other issue in the DOM: Navigation component * CVE-2026-84137 (bmo#2051146) Spoofing issue in the DOM: Core & HTML component * CVE-2026-84139 (bmo#2060153) Clickjacking issue in the DOM: Events component * CVE-2026-84140 (bmo#2063780) * CVE-2026-84141 (bmo#2063994) Integer overflow in the Graphics: ImageLib component * CVE-2026-84143 (bmo#2048793, bmo#2054631, bmo#2054645, bmo#2054657, bmo#2055007, bmo#2055681, bmo#2057107, bmo#2057108, bmo#2057114, bmo#2058087, bmo#2058088, bmo#2058090, bmo#2058095, bmo#2058101, bmo#2059109, bmo#2059183, bmo#2059185, bmo#2061287, bmo#2061301, bmo#2061325) Internally found bugs fixed in Firefox 155, Firefox ESR 153.2 and Firefox ESR 140.15 * CVE-2026-84144 (bmo#2054619, bmo#2054620, bmo#2054624, bmo#2054625, bmo#2054691, bmo#2054702, bmo#2054726, bmo#2054775, bmo#2055703, bmo#2058006, bmo#2058013, bmo#2058085, bmo#2058098, bmo#2058627, bmo#2058661, bmo#2059002, bmo#2059127, bmo#2059128, bmo#2059144, bmo#2059180, bmo#2059191, bmo#2059192, bmo#2059199, bmo#2059205, bmo#2061320, bmo#2061430, bmo#2061495, bmo#2061505, bmo#2061521, bmo#2061532, bmo#2061775, bmo#2061799, bmo#2062395, bmo#2062404) Internally found bugs fixed in Firefox 155 and Firefox ESR 153.2 * CVE-2026-84145 (bmo#2054640, bmo#2054650, bmo#2054652, bmo#2055678, bmo#2055693, bmo#2055705, bmo#2058001, bmo#2058051, bmo#2058652, bmo#2058660, bmo#2059027, bmo#2059139, bmo#2061220, bmo#2061242, bmo#2061285, bmo#2061300, bmo#2061316, bmo#2061397, bmo#2062400, bmo#2062419) Internally found bugs fixed in Firefox 155, Firefox ESR 153.2, Firefox ESR 140.15 and Firefox ESR 115.40 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1684 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1684 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * MozillaFirefox-153.2.0-160000.1.1 * MozillaFirefox-translations-other-153.2.0-160000.1.1 * MozillaFirefox-debuginfo-153.2.0-160000.1.1 * MozillaFirefox-debugsource-153.2.0-160000.1.1 * MozillaFirefox-translations-common-153.2.0-160000.1.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * MozillaFirefox-devel-153.2.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le x86_64) * MozillaFirefox-153.2.0-160000.1.1 * MozillaFirefox-translations-other-153.2.0-160000.1.1 * MozillaFirefox-debuginfo-153.2.0-160000.1.1 * MozillaFirefox-debugsource-153.2.0-160000.1.1 * MozillaFirefox-translations-common-153.2.0-160000.1.1 * SUSE Linux Enterprise Server 16.0 (noarch) * MozillaFirefox-devel-153.2.0-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-74952.html * https://www.suse.com/security/cve/CVE-2026-75874.html * https://www.suse.com/security/cve/CVE-2026-84118.html * https://www.suse.com/security/cve/CVE-2026-84119.html * https://www.suse.com/security/cve/CVE-2026-84120.html * https://www.suse.com/security/cve/CVE-2026-84121.html * https://www.suse.com/security/cve/CVE-2026-84122.html * https://www.suse.com/security/cve/CVE-2026-84123.html * https://www.suse.com/security/cve/CVE-2026-84124.html * https://www.suse.com/security/cve/CVE-2026-84125.html * https://www.suse.com/security/cve/CVE-2026-84129.html * https://www.suse.com/security/cve/CVE-2026-84130.html * https://www.suse.com/security/cve/CVE-2026-84131.html * https://www.suse.com/security/cve/CVE-2026-84132.html * https://www.suse.com/security/cve/CVE-2026-84133.html * https://www.suse.com/security/cve/CVE-2026-84134.html * https://www.suse.com/security/cve/CVE-2026-84136.html * https://www.suse.com/security/cve/CVE-2026-84137.html * https://www.suse.com/security/cve/CVE-2026-84139.html * https://www.suse.com/security/cve/CVE-2026-84140.html * https://www.suse.com/security/cve/CVE-2026-84141.html * https://www.suse.com/security/cve/CVE-2026-84143.html * https://www.suse.com/security/cve/CVE-2026-84144.html * https://www.suse.com/security/cve/CVE-2026-84145.html * https://bugzilla.suse.com/show_bug.cgi?id=1278001 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:44:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:44:10 -0000 Subject: SUSE-SU-2026:23782-1: important: Security update for rpm Message-ID: <178998025078.10889.14252788443270583905@200ee98c8b1d> # Security update for rpm Announcement ID: SUSE-SU-2026:23782-1 Release Date: 2026-09-16T14:28:14Z Rating: important References: * bsc#1218459 * bsc#1253139 * bsc#1259215 * bsc#1268747 * bsc#1269150 * bsc#1269571 * bsc#1269584 * bsc#1271923 * bsc#1271924 * bsc#1271925 Cross-References: * CVE-2026-15811 * CVE-2026-15812 * CVE-2026-15813 * CVE-2026-44604 * CVE-2026-44605 CVSS scores: * CVE-2026-15811 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L * CVE-2026-15811 ( NVD ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:L * CVE-2026-15812 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-15812 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-15813 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-15813 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-44604 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44604 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44604 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44605 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-44605 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-44605 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server High Availability Extension 16.0 * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that solves five vulnerabilities and has five fixes can now be installed. ## Security update for rpm ### Description: This update for rpm fixes the following issues: Changes in rpm: * split imaevmsign plugin into a multibuild flavor Changes in rpm: * Add Requires: (rpm-plugin-selinux if selinux-policy) * harden ndb code [bsc#1269584] [CVE-2026-44605] * split all plugins into subpackages * this allows for an easy way to get rid of a plugin, it's also what other distributions do * make the imaevmsign plugin build in a multibuild flavor * rpm2archive: use size 0 for hardlinked files as bnew versions of gnu tar reject non-zero sizes [bsc#1269150] * backport fix for add_sysuser macro [bsc#1269571] * backport rpmuncompress security fix [bsc#1268747] [CVE-2026-44604] * switch from rpmpgp_legacy to libpgpr * multiple bug fixes, support for v5 and v6 signatures * turn on imaevm file signature support and move the imaevm code that needs the libimaevm library into a plugin. Put this plugin into a new "rpm- imaevmsign" subpackage. [jsc#PED-7246] * Fix "unexpected EOF" when using rpmbuild to install ELF binaries due to syntax error in /usr/lib/rpm/brp-strip. (boo#1259215) * Remove /var/lib/rpm migration scripting, retain an error if old location is found * Use systemd-tmpfiles to create & maintain /var/lib/rpm symlink (boo#1253139) * flush scriptlet notification messages in --runposttrans * needed to fix leaking tmp files [bsc#1218459] * added "rpm_flushes_runposttrans" provides for libzypp ## Security update for kronosnet ### Description: This update for kronosnet fixes the following issues: * CVE-2026-15811: improper sanitization of sensitive memory locations following cryptographic configuration adjustments can lead to potential exposure of encryption keys (bsc#1271923). * CVE-2026-15812: improper verification of packet origins allows for access control list (ACL) bypass via ID spoofing (bsc#1271924). * CVE-2026-15813: improper validation during fragment reassembly can trigger memory corruption or out-of-bounds memory access (bsc#1271925). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1688 * SUSE Linux Enterprise Server High Availability Extension 16.0 zypper in -t patch SUSE-SLES-HA-16.0-1682 ## Package List: * SUSE Linux Micro Extras 6.2 (aarch64 ppc64le s390x x86_64) * rpm-debugsource-4.20.1-160000.3.1 * rpm-build-4.20.1-160000.3.1 * rpm-debuginfo-4.20.1-160000.3.1 * rpm-build-debuginfo-4.20.1-160000.3.1 * SUSE Linux Enterprise Server High Availability Extension 16.0 (ppc64le s390x x86_64) * libknet1-crypto-nss-plugin-1.30-160000.4.1 * libknet-devel-1.30-160000.4.1 * libknet1-compress-zlib-plugin-debuginfo-1.30-160000.4.1 * libknet1-1.30-160000.4.1 * libknet1-compress-lzma-plugin-debuginfo-1.30-160000.4.1 * libknet1-compress-plugins-all-1.30-160000.4.1 * libknet1-crypto-openssl-plugin-debuginfo-1.30-160000.4.1 * libnozzle1-debuginfo-1.30-160000.4.1 * libknet1-compress-lzma-plugin-1.30-160000.4.1 * kronosnet-debuginfo-1.30-160000.4.1 * libnozzle1-1.30-160000.4.1 * libknet1-compress-zstd-plugin-1.30-160000.4.1 * libknet1-crypto-openssl-plugin-1.30-160000.4.1 * libknet1-compress-lzo2-plugin-1.30-160000.4.1 * libknet1-compress-lz4-plugin-1.30-160000.4.1 * libknet1-compress-zlib-plugin-1.30-160000.4.1 * libknet1-compress-zstd-plugin-debuginfo-1.30-160000.4.1 * kronosnet-debugsource-1.30-160000.4.1 * libknet1-debuginfo-1.30-160000.4.1 * libknet1-compress-lzo2-plugin-debuginfo-1.30-160000.4.1 * libnozzle-devel-1.30-160000.4.1 * libknet1-compress-lz4-plugin-debuginfo-1.30-160000.4.1 * libknet1-plugins-all-1.30-160000.4.1 * libknet1-compress-bzip2-plugin-1.30-160000.4.1 * libknet1-crypto-plugins-all-1.30-160000.4.1 * libknet1-compress-bzip2-plugin-debuginfo-1.30-160000.4.1 * libknet1-crypto-nss-plugin-debuginfo-1.30-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15811.html * https://www.suse.com/security/cve/CVE-2026-15812.html * https://www.suse.com/security/cve/CVE-2026-15813.html * https://www.suse.com/security/cve/CVE-2026-44604.html * https://www.suse.com/security/cve/CVE-2026-44605.html * https://bugzilla.suse.com/show_bug.cgi?id=1218459 * https://bugzilla.suse.com/show_bug.cgi?id=1253139 * https://bugzilla.suse.com/show_bug.cgi?id=1259215 * https://bugzilla.suse.com/show_bug.cgi?id=1268747 * https://bugzilla.suse.com/show_bug.cgi?id=1269150 * https://bugzilla.suse.com/show_bug.cgi?id=1269571 * https://bugzilla.suse.com/show_bug.cgi?id=1269584 * https://bugzilla.suse.com/show_bug.cgi?id=1271923 * https://bugzilla.suse.com/show_bug.cgi?id=1271924 * https://bugzilla.suse.com/show_bug.cgi?id=1271925 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:44:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:44:56 -0000 Subject: SUSE-SU-2026:23781-1: important: Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998029641.10889.8158533897650560133@200ee98c8b1d> # Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23781-1 Release Date: 2026-09-15T06:39:47Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-642 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-38-rt-12-1.1 * kernel-livepatch-6_4_0-38-rt-debuginfo-12-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_14-debugsource-12-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:45:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:45:42 -0000 Subject: SUSE-SU-2026:23780-1: important: Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998034261.10889.15609725527704066461@200ee98c8b1d> # Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23780-1 Release Date: 2026-09-15T06:39:47Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-37.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-641 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_13-debugsource-12-1.1 * kernel-livepatch-6_4_0-37-rt-debuginfo-12-1.1 * kernel-livepatch-6_4_0-37-rt-12-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:46:27 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:46:27 -0000 Subject: SUSE-SU-2026:23779-1: important: Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998038744.10889.14899032517360370967@200ee98c8b1d> # Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23779-1 Release Date: 2026-09-15T06:39:47Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-640 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_12-debugsource-16-1.1 * kernel-livepatch-6_4_0-36-rt-16-1.1 * kernel-livepatch-6_4_0-36-rt-debuginfo-16-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:47:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:47:13 -0000 Subject: SUSE-SU-2026:23778-1: important: Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998043326.10889.11845556144546660726@200ee98c8b1d> # Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23778-1 Release Date: 2026-09-15T06:39:47Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-639 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_11-debugsource-17-1.1 * kernel-livepatch-6_4_0-35-rt-17-1.1 * kernel-livepatch-6_4_0-35-rt-debuginfo-17-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:47:54 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:47:54 -0000 Subject: SUSE-SU-2026:23777-1: important: Security update for the Linux Kernel RT (Live Patch 28 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998047448.10889.7923659951291764637@200ee98c8b1d> # Security update for the Linux Kernel RT (Live Patch 28 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23777-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-51.1 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-626 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_28-debugsource-2-1.1 * kernel-livepatch-6_4_0-51-rt-debuginfo-2-1.1 * kernel-livepatch-6_4_0-51-rt-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:48:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:48:38 -0000 Subject: SUSE-SU-2026:23776-1: important: Security update for the Linux Kernel RT (Live Patch 27 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998051851.10889.11855963714486089166@200ee98c8b1d> # Security update for the Linux Kernel RT (Live Patch 27 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23776-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-50.2 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-625 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-50-rt-debuginfo-3-1.1 * kernel-livepatch-6_4_0-50-rt-3-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_27-debugsource-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:49:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:49:22 -0000 Subject: SUSE-SU-2026:23775-1: important: Security update for the Linux Kernel RT (Live Patch 26 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998056215.10889.16527209474574875911@200ee98c8b1d> # Security update for the Linux Kernel RT (Live Patch 26 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23775-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-49.1 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-624 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-49-rt-3-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_26-debugsource-3-1.1 * kernel-livepatch-6_4_0-49-rt-debuginfo-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:50:05 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:50:05 -0000 Subject: SUSE-SU-2026:23774-1: important: Security update for the Linux Kernel RT (Live Patch 25 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998060576.10889.14589393298108072610@200ee98c8b1d> # Security update for the Linux Kernel RT (Live Patch 25 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23774-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-48.1 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-623 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_25-debugsource-4-1.1 * kernel-livepatch-6_4_0-48-rt-4-1.1 * kernel-livepatch-6_4_0-48-rt-debuginfo-4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:50:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:50:53 -0000 Subject: SUSE-SU-2026:23773-1: important: Security update for the Linux Kernel RT (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998065327.10889.5445381504453027343@200ee98c8b1d> # Security update for the Linux Kernel RT (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23773-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-47.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-622 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-47-rt-5-1.1 * kernel-livepatch-6_4_0-47-rt-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_24-debugsource-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:51:39 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:51:39 -0000 Subject: SUSE-SU-2026:23772-1: important: Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998069989.10889.11512057418824841117@200ee98c8b1d> # Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23772-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-621 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-46-rt-6-1.1 * kernel-livepatch-6_4_0-46-rt-debuginfo-6-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_23-debugsource-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:52:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:52:25 -0000 Subject: SUSE-SU-2026:23771-1: important: Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998074576.10889.14436721586490559157@200ee98c8b1d> # Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23771-1 Release Date: 2026-09-14T08:55:41Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-620 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_22-debugsource-6-1.2 * kernel-livepatch-6_4_0-45-rt-debuginfo-6-1.2 * kernel-livepatch-6_4_0-45-rt-6-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:53:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:53:12 -0000 Subject: SUSE-SU-2026:23770-1: important: Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998079293.10889.9436974330110105061@200ee98c8b1d> # Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23770-1 Release Date: 2026-09-14T08:55:41Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-619 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-43-rt-debuginfo-6-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_21-debugsource-6-1.1 * kernel-livepatch-6_4_0-43-rt-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:54:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:54:00 -0000 Subject: SUSE-SU-2026:23769-1: important: Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998084009.10889.14002546291093071830@200ee98c8b1d> # Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23769-1 Release Date: 2026-09-14T08:55:41Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-618 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-42-rt-debuginfo-7-1.1 * kernel-livepatch-6_4_0-42-rt-7-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_20-debugsource-7-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:54:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:54:49 -0000 Subject: SUSE-SU-2026:23768-1: important: Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998088991.10889.6926799262212356635@200ee98c8b1d> # Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23768-1 Release Date: 2026-09-14T08:55:41Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-617 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-41-rt-debuginfo-9-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_19-debugsource-9-1.1 * kernel-livepatch-6_4_0-41-rt-9-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:55:41 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:55:41 -0000 Subject: SUSE-SU-2026:23767-1: important: Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998094148.10889.414846809883736202@200ee98c8b1d> # Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23767-1 Release Date: 2026-09-14T08:55:41Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-616 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-40-rt-debuginfo-10-1.1 * kernel-livepatch-6_4_0-40-rt-10-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_18-debugsource-10-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:56:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:56:36 -0000 Subject: SUSE-SU-2026:23766-1: important: Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998099630.10889.3116593640725383608@200ee98c8b1d> # Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23766-1 Release Date: 2026-09-14T08:55:41Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-615 ## Package List: * SUSE Linux Micro 6.1 (x86_64) * kernel-livepatch-6_4_0-39-rt-debuginfo-11-1.1 * kernel-livepatch-6_4_0-39-rt-11-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_15-debugsource-11-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:58:05 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:58:05 -0000 Subject: SUSE-SU-2026:23764-1: important: Security update for the Linux Kernel (Live Patch 28 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998108558.10889.14208904413206571732@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 28 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23764-1 Release Date: 2026-09-15T06:44:57Z Rating: important References: * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-51.1 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-646 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_28-debugsource-2-1.1 * kernel-livepatch-6_4_0-51-default-2-1.1 * kernel-livepatch-6_4_0-51-default-debuginfo-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:59:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:59:01 -0000 Subject: SUSE-SU-2026:23763-1: important: Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998114129.10889.14679679932146093966@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23763-1 Release Date: 2026-09-15T06:44:39Z Rating: important References: * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-50.2 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-645 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-50-default-debuginfo-3-1.1 * kernel-livepatch-MICRO-6-0_Update_27-debugsource-3-1.1 * kernel-livepatch-6_4_0-50-default-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 08:59:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 08:59:56 -0000 Subject: SUSE-SU-2026:23762-1: important: Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998119629.10889.12763315738203426980@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23762-1 Release Date: 2026-09-15T06:39:24Z Rating: important References: * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-49.1 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-644 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-49-default-debuginfo-3-1.1 * kernel-livepatch-MICRO-6-0_Update_26-debugsource-3-1.1 * kernel-livepatch-6_4_0-49-default-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:00:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:00:52 -0000 Subject: SUSE-SU-2026:23761-1: important: Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998125292.10889.18080241229549590077@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23761-1 Release Date: 2026-09-15T06:39:24Z Rating: important References: * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-48.1 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-643 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-48-default-debuginfo-4-1.1 * kernel-livepatch-MICRO-6-0_Update_25-debugsource-4-1.1 * kernel-livepatch-6_4_0-48-default-4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:01:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:01:49 -0000 Subject: SUSE-SU-2026:23760-1: important: Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998130965.10889.1550506986232250109@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23760-1 Release Date: 2026-09-14T08:30:43Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-638 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_22-debugsource-6-1.1 * kernel-livepatch-6_4_0-45-default-debuginfo-6-1.1 * kernel-livepatch-6_4_0-45-default-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:02:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:02:43 -0000 Subject: SUSE-SU-2026:23759-1: important: Security update for the Linux Kernel (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998136388.10889.17288873155273147746@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23759-1 Release Date: 2026-09-14T08:27:51Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-47.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-614 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-47-default-5-1.1 * kernel-livepatch-6_4_0-47-default-debuginfo-5-1.1 * kernel-livepatch-MICRO-6-0_Update_24-debugsource-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:03:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:03:38 -0000 Subject: SUSE-SU-2026:23758-1: important: Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998141838.10889.5300868838602507012@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23758-1 Release Date: 2026-09-14T08:27:51Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-613 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-46-default-6-1.1 * kernel-livepatch-MICRO-6-0_Update_23-debugsource-6-1.1 * kernel-livepatch-6_4_0-46-default-debuginfo-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:04:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:04:31 -0000 Subject: SUSE-SU-2026:23757-1: important: Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998147186.10889.14117573438419944248@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23757-1 Release Date: 2026-09-14T08:27:51Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-44.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-637 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-44-default-debuginfo-6-1.1 * kernel-livepatch-6_4_0-44-default-6-1.1 * kernel-livepatch-MICRO-6-0_Update_21-debugsource-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:05:24 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:05:24 -0000 Subject: SUSE-SU-2026:23756-1: important: Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998152488.10889.7738508816256974873@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23756-1 Release Date: 2026-09-14T08:27:51Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-636 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-43-default-debuginfo-6-1.1 * kernel-livepatch-6_4_0-43-default-6-1.1 * kernel-livepatch-MICRO-6-0_Update_20-debugsource-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:06:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:06:18 -0000 Subject: SUSE-SU-2026:23755-1: important: Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998157839.10889.7315987744236828682@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23755-1 Release Date: 2026-09-14T08:27:51Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-635 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_19-debugsource-7-1.1 * kernel-livepatch-6_4_0-42-default-7-1.1 * kernel-livepatch-6_4_0-42-default-debuginfo-7-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:07:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:07:11 -0000 Subject: SUSE-SU-2026:23754-1: important: Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998163150.10889.12305513800211986017@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23754-1 Release Date: 2026-09-14T08:27:51Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-634 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-41-default-debuginfo-9-1.1 * kernel-livepatch-MICRO-6-0_Update_18-debugsource-9-1.1 * kernel-livepatch-6_4_0-41-default-9-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:08:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:08:04 -0000 Subject: SUSE-SU-2026:23753-1: important: Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998168457.10889.4409533050217105419@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23753-1 Release Date: 2026-09-14T08:27:51Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-633 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-40-default-debuginfo-10-1.1 * kernel-livepatch-6_4_0-40-default-10-1.1 * kernel-livepatch-MICRO-6-0_Update_17-debugsource-10-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:08:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:08:58 -0000 Subject: SUSE-SU-2026:23752-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998173810.10889.12611205947232537644@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23752-1 Release Date: 2026-09-14T08:27:51Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-632 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-39-default-debuginfo-11-1.1 * kernel-livepatch-6_4_0-39-default-11-1.1 * kernel-livepatch-MICRO-6-0_Update_16-debugsource-11-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:09:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:09:52 -0000 Subject: SUSE-SU-2026:23751-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998179207.10889.12918283492885351562@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23751-1 Release Date: 2026-09-14T08:27:51Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-631 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-38-default-12-1.2 * kernel-livepatch-MICRO-6-0_Update_14-debugsource-12-1.2 * kernel-livepatch-6_4_0-38-default-debuginfo-12-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:10:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:10:50 -0000 Subject: SUSE-SU-2026:23750-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998185024.10889.13631875346839357799@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23750-1 Release Date: 2026-09-14T08:27:51Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-630 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_13-debugsource-14-1.1 * kernel-livepatch-6_4_0-36-default-debuginfo-14-1.1 * kernel-livepatch-6_4_0-36-default-14-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:11:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:11:44 -0000 Subject: SUSE-SU-2026:23749-1: important: Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998190461.10889.12756607467016967847@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23749-1 Release Date: 2026-09-14T08:27:51Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-35.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-629 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-35-default-debuginfo-16-1.1 * kernel-livepatch-6_4_0-35-default-16-1.1 * kernel-livepatch-MICRO-6-0_Update_12-debugsource-16-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:12:39 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:12:39 -0000 Subject: SUSE-SU-2026:23748-1: important: Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998195990.10889.12414144761107716740@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23748-1 Release Date: 2026-09-14T08:27:51Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-628 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-6_4_0-34-default-debuginfo-16-1.1 * kernel-livepatch-MICRO-6-0_Update_11-debugsource-16-1.1 * kernel-livepatch-6_4_0-34-default-16-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:13:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:13:36 -0000 Subject: SUSE-SU-2026:23747-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <178998201616.10889.4796879974770600692@200ee98c8b1d> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23747-1 Release Date: 2026-09-14T08:27:51Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-kernel-627 ## Package List: * SUSE Linux Micro 6.1 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_10-debugsource-17-1.1 * kernel-livepatch-6_4_0-32-default-debuginfo-17-1.1 * kernel-livepatch-6_4_0-32-default-17-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:14:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:14:36 -0000 Subject: SUSE-SU-2026:23746-1: important: Security update for freeipmi Message-ID: <178998207650.10889.8681987107948049371@200ee98c8b1d> # Security update for freeipmi Announcement ID: SUSE-SU-2026:23746-1 Release Date: 2026-09-17T07:27:57Z Rating: important References: * bsc#1278719 * bsc#1278721 * bsc#1278722 * bsc#1278724 * bsc#1278726 * bsc#1278727 Cross-References: * CVE-2026-85504 * CVE-2026-85505 * CVE-2026-85506 * CVE-2026-85507 * CVE-2026-85508 * CVE-2026-85509 CVSS scores: * CVE-2026-85504 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-85504 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-85504 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-85505 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-85505 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-85505 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-85506 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-85506 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-85506 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-85507 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-85507 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-85507 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-85508 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-85508 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-85508 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-85509 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-85509 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-85509 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities can now be installed. ## Description: This update for freeipmi fixes the following issues: * CVE-2026-85504: stack-based buffer overflow via malformed Fujitsu SEL long- text responses (bsc#1278719). * CVE-2026-85505: Denial of Service via stack-based buffer over-read in ipmi- oem (bsc#1278722). * CVE-2026-85506: Arbitrary code execution via stack-based buffer overflow in ipmi-oem (bsc#1278721). * CVE-2026-85507: stack-based buffer overflow in _output_dell_system_info_cmc_info (bsc#1278724). * CVE-2026-85508: stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info (bsc#1278726). * CVE-2026-85509: stack-based buffer overflow when a BMC returns more bytes than requested (bsc#1278727). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-735 ## Package List: * SUSE Linux Micro 6.1 (aarch64 x86_64) * freeipmi-debugsource-1.6.14-slfo.1.1_4.1 * libfreeipmi17-1.6.14-slfo.1.1_4.1 * libfreeipmi17-debuginfo-1.6.14-slfo.1.1_4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-85504.html * https://www.suse.com/security/cve/CVE-2026-85505.html * https://www.suse.com/security/cve/CVE-2026-85506.html * https://www.suse.com/security/cve/CVE-2026-85507.html * https://www.suse.com/security/cve/CVE-2026-85508.html * https://www.suse.com/security/cve/CVE-2026-85509.html * https://bugzilla.suse.com/show_bug.cgi?id=1278719 * https://bugzilla.suse.com/show_bug.cgi?id=1278721 * https://bugzilla.suse.com/show_bug.cgi?id=1278722 * https://bugzilla.suse.com/show_bug.cgi?id=1278724 * https://bugzilla.suse.com/show_bug.cgi?id=1278726 * https://bugzilla.suse.com/show_bug.cgi?id=1278727 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:15:32 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:15:32 -0000 Subject: SUSE-SU-2026:23745-1: important: Security update for google-guest-agent Message-ID: <178998213273.10889.15070654040599259066@200ee98c8b1d> # Security update for google-guest-agent Announcement ID: SUSE-SU-2026:23745-1 Release Date: 2026-09-17T07:25:20Z Rating: important References: * bsc#1260264 * bsc#1278597 Cross-References: * CVE-2026-33186 * CVE-2026-56854 * CVE-2026-56855 * CVE-2026-78662 CVSS scores: * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56854 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56854 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56854 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56855 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78662 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78662 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78662 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.1 An update that solves four vulnerabilities can now be installed. ## Description: This update for google-guest-agent fixes the following issues: * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260264). * CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-736 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260903.01-slfo.1.1_2.1 * google-guest-agent-debuginfo-20260903.01-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-56854.html * https://www.suse.com/security/cve/CVE-2026-56855.html * https://www.suse.com/security/cve/CVE-2026-78662.html * https://bugzilla.suse.com/show_bug.cgi?id=1260264 * https://bugzilla.suse.com/show_bug.cgi?id=1278597 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:17:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:17:34 -0000 Subject: SUSE-SU-2026:23743-1: important: Security update for python311 Message-ID: <178998225402.10889.15118828654875050429@200ee98c8b1d> # Security update for python311 Announcement ID: SUSE-SU-2026:23743-1 Release Date: 2026-09-16T09:53:12Z Rating: important References: * bsc#1259240 * bsc#1259611 * bsc#1259734 * bsc#1259735 * bsc#1260026 * bsc#1261969 * bsc#1262098 * bsc#1262319 * bsc#1264962 * bsc#1265268 * bsc#1267581 * bsc#1267821 * bsc#1267974 * bsc#1268977 * bsc#1269066 * bsc#1269788 * bsc#1269959 * bsc#1271192 * bsc#1276223 * bsc#1276226 Cross-References: * CVE-2021-4189 * CVE-2025-13462 * CVE-2025-4330 * CVE-2026-0864 * CVE-2026-11940 * CVE-2026-11972 * CVE-2026-1502 * CVE-2026-15308 * CVE-2026-15806 * CVE-2026-17084 * CVE-2026-2297 * CVE-2026-3276 * CVE-2026-3644 * CVE-2026-4224 * CVE-2026-4360 * CVE-2026-45186 * CVE-2026-4519 * CVE-2026-4786 * CVE-2026-6100 * CVE-2026-7210 * CVE-2026-72522 * CVE-2026-7774 * CVE-2026-8328 * CVE-2026-9669 CVSS scores: * CVE-2021-4189 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2021-4189 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2021-4189 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2025-13462 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-13462 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2025-13462 ( NVD ): 2.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-13462 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2025-4330 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N * CVE-2025-4330 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0864 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-0864 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-0864 ( NVD ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-0864 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-11940 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-11940 ( NVD ): 7.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-11972 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-11972 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-11972 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-1502 ( SUSE ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-1502 ( SUSE ): 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N * CVE-2026-1502 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-15308 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15308 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15308 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-15806 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15806 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-15806 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-17084 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-17084 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-17084 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-2297 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-2297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-2297 ( NVD ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3276 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-3276 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-3276 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3644 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-3644 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-3644 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-3644 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-4224 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-4224 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4224 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4224 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4360 ( SUSE ): 2.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-4360 ( SUSE ): 2.5 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4360 ( NVD ): 2.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4360 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-45186 ( SUSE ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45186 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-45186 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45186 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-4519 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:L/SI:H/SA:N * CVE-2026-4519 ( SUSE ): 6.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:H/A:N * CVE-2026-4519 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4519 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4519 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2026-4786 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-4786 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-4786 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L * CVE-2026-6100 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-6100 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-6100 ( NVD ): 9.1 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-6100 ( NVD ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-7210 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-7210 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7210 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-7210 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72522 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72522 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72522 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-7774 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-7774 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-7774 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-8328 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-8328 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-8328 ( NVD ): 5.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-9669 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9669 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9669 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.1 An update that solves 24 vulnerabilities can now be installed. ## Description: This update for python311 fixes the following issues: * CVE-2025-13462: incorrect parsing of TarInfo header when GNU long name and type AREGTYPE are combined (bsc#1259611). * CVE-2026-0864: improper handling of line-ending characters can lead to configuration file injection when the `configparser` module is used (bsc#1269066). * CVE-2026-1502: HTTP client proxy tunnel headers not validated for CR/LF (bsc#1261969). * CVE-2026-2297: cpython: incorrectly handled hook in FileLoader can lead to validation bypass (bsc#1259240). * CVE-2026-3276: quadratic complexity in `unicodedata.normalize()` can lead to DoS when processing specially crafted Unicode input (bsc#1267581). * CVE-2026-3644: incomplete control character validation in http.cookies (bsc#1259734). * CVE-2026-4224: C stack overflow when parsing XML with deeply nested DTD content models (bsc#1259735). * CVE-2026-4360: in the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks (bsc#1269959). * CVE-2026-4519: leading dashes in URLs are accepted by the `webbrowser.open()` API and allow for web browser command line option injection (bsc#1260026). * CVE-2026-4786: Incomplete mitigation of %action expansion for command injection to webbrowser.open() (bsc#1262319). * CVE-2026-6100: Arbitrary code execution or information disclosure via use- after-free in decompression modules (bsc#1262098). * CVE-2026-7210: `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection (bsc#1264962). * CVE-2026-7774: `tarfile.data_filter` path traversal bypass allows writing outside the extraction directory (bsc#1267821). * CVE-2026-8328: `ftpcp()` does not use actual peer address and trusts server- supplied PASV host address (bsc#1265268). * CVE-2026-9669: crafted input can cause a stack buffer overflow (bsc#1267974). * CVE-2026-11940: tarfile extraction filter bypass via a crafted archive allows escaping the destination directory and enables arbitrary file reads and writes (bsc#1268977). * CVE-2026-11972: infinite loop due to improper EOF handling in the tarfile module streaming mode can lead to DoS (bsc#1269788). * CVE-2026-15308: Incremental HTMLParser allows CPU-exhaustion DoS via repeated unterminated markup declarations (bsc#1271192). * CVE-2026-15806: urllib.request.HTTPPasswordMgr credentials for one URL scheme sent over another scheme (bsc#1276223). * CVE-2026-17084: StringPrep algorithm considered Unicode codepoint attributes outside Unicode 3.2.0 (bsc#1276226). Changes for python311: * Update to 3.11.16: * Build * gh-153438: Update Windows build and installer tooling and documentation to use the current download URL for nuget.exe. * Library * gh-109638: Fix exponential time in csv.Sniffer.sniff() for a sample which contains many quote characters. A doubled quote character is now also detected in a field which contains the delimiter or a line break. * gh-98820: Fix quadratic time in csv.Sniffer.sniff() for a sample which contains quoted fields, in particular for a single column of quoted fields. * gh-149231: In tomllib, the number of parts in TOML keys is now limited. * gh-146083: Update bundled libexpat to version 2.7.5. * gh-141707: Don't change tarfile.TarInfo type from AREGTYPE to DIRTYPE when parsing GNU long name or link headers (bsc#1259611, CVE-2025-13462). * gh-90949: Add SetBillionLaughsAttackProtectionActivationThreshold() and SetBillionLaughsAttackProtectionMaximumAmplification() to xmlparser objects to tune protections against billion laughs attacks. Patch by B?n?dikt Tran. * gh-100372: ssl.SSLContext.load_verify_locations() no longer incorrectly accepts some cases of trailing data when parsing DER. * Security * gh-155558: Update bundled libexpat to version 2.8.3 for the fix to CVE-2026-72522. * gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in html.parser.HTMLParser, which could be exploited for a denial of service (bsc#1271192, CVE-2026-15308). * gh-152674: The xml.etree.ElementTree.Element methods findall(), iterfind() and find() avoid quadratic behavior when using XPath index predicates ([1], [last()], [last()-N]) on XML documents with many same-tag siblings. * gh-152216: Update bundled libexpat to version 2.8.2. * gh-151987: The tarfile.TarFile.extract() method now applies the given filter when it extracts a link target from the archive as a fallback (bsc#1269959, CVE-2026-4360). * gh-151981: In tarfile, seeking a stream now stops when end of the stream is reached (bsc#1269788, CVE-2026-11972). * gh-151544: Modules/Setup.local is no longer used as a landmark to discover whether Python is running in a source tree, as it could potentially affect actual installs. The pybuilddir.txt file is now the sole indicator of running in a source tree. * gh-151558: Fixed an vulnerability in the tarfile data and tar extraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE-2025-4330 (bsc#1268977, CVE-2026-11940). * gh-150599: Fix a possible stack buffer overflow in bz2 when a bz2.BZ2Decompressor is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error (bsc#1267974, CVE-2026-9669). * gh-150743: http.client now limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or 100 Continue responses forever, hanging the client even when a socket timeout was in use. Reported by @YLChen-007 via GHSA-w4q2-g22w-6fr4. * gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE-2026-45186. * gh-87451: The ftplib module's undocumented ftpcp function no longer trusts the IPv4 address value returned from the source server in response to the PASV command by default, completing the fix for CVE-2021-4189. As with ftplib.FTP, the former behavior can be re-enabled by setting the trust_server_pasv_ipv4_address attribute on the source ftplib.FTP instance to True. Thanks to Qi Deng at Aurascape AI for the report (bsc#1265268, CVE-2026-8328). * gh-149486: tarfile.data_filter() now validates link targets using the same normalised value that is written to disk, strips trailing separators from the member name when resolving a symlink's directory, and rejects link members that would replace the destination directory itself. This closes several path-traversal bypasses of the data extraction filter (bsc#1267821, CVE-2026-7774). * gh-149079: Fix a potential denial of service in unicodedata.normalize(). The canonical ordering step of Unicode normalization used a quadratic-time insertion sort for reordering combining characters, which could be exploited with crafted input containing many combining characters in non-canonical order. Replaced with a linear-time counting sort for long runs (bsc#1267581, CVE-2026-3276). * gh-149018: Improved protection against XML hash-flooding attacks in xml.parsers.expat and xml.etree.ElementTree when Python is compiled with libExpat 2.8.0 or later (bsc#1264962, CVE-2026-7210). * gh-149017: Update bundled libexpat to version 2.8.0. * gh-148808: Added buffer boundary check when using nbytes parameter with asyncio.AbstractEventLoop.sock_recvfrom_into(). Only relevant for Windows and the asyncio.ProactorEventLoop. * gh-148395: Fix a dangling input pointer in lzma.LZMADecompressor, and bz2.BZ2Decompressor when memory allocation fails with MemoryError, which could let a subsequent decompress() call read or write through a stale pointer to the already-released caller buffer (bsc#1262098, CVE-2026-6100). * gh-148169: A bypass in webbrowser allowed URLs prefixed with %action to pass the dash-prefix safety check (bsc#1262319, CVE-2026-4786). * gh-146581: Fix vulnerability in shutil.unpack_archive() for ZIP files on Windows which allowed to write files outside of the destination tree if the patch in the archive contains a Windows drive prefix. Now such invalid paths will be skipped. Files containing ".." in the name (like "foo..bar") are no longer skipped. * gh-146333: Fix quadratic backtracking in configparser.RawConfigParser option parsing regexes (OPTCRE and OPTCRE_NV). A crafted configuration line with many whitespace characters could cause excessive CPU usage. * gh-146211: Reject CR/LF characters in tunnel request headers for the HTTPConnection.set_tunnel() method (bsc#1261969, CVE-2026-1502). * gh-145986: xml.parsers.expat: Fixed a crash caused by unbounded C recursion when converting deeply nested XML content models with ElementDeclHandler(). This addresses CVE-2026-4224 (bsc#1259735, CVE-2026-4224). * gh-145599: Reject control characters in http.cookies.Morsel update() and js_output(). This addresses CVE-2026-3644 (bsc#1259734, CVE-2026-3644). * gh-145506: Fixes CVE-2026-2297 by ensuring that SourcelessFileLoader uses io.open_code() when opening .pyc files (bsc#1259240, CVE-2026-2297). * gh-144370: Disallow usage of control characters in status in wsgiref.handlers to prevent HTTP header injections. Patch by Benedikt Johannes. * gh-143930: Reject leading dashes in URLs passed to webbrowser.open() (bsc#1260026, CVE-2026-4519). * gh-143927: Normalize all line endings (CR, CRLF, and LF) to LF+TAB when writing multi-line configparser values (bsc#1269066, CVE-2026-0864). * Tests * gh-149776: Fix test_socket on Linux kernel 7.1 and newer: skip UDP Lite tests if it's not supported. Patch by Victor Stinner. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-733 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * python311-debuginfo-3.11.16-slfo.1.1_1.1 * libpython3_11-1_0-debuginfo-3.11.16-slfo.1.1_1.1 * python311-core-debugsource-3.11.16-slfo.1.1_1.1 * python311-curses-3.11.16-slfo.1.1_1.1 * python311-base-3.11.16-slfo.1.1_1.1 * python311-base-debuginfo-3.11.16-slfo.1.1_1.1 * libpython3_11-1_0-3.11.16-slfo.1.1_1.1 * python311-curses-debuginfo-3.11.16-slfo.1.1_1.1 * python311-debugsource-3.11.16-slfo.1.1_1.1 * python311-3.11.16-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2021-4189.html * https://www.suse.com/security/cve/CVE-2025-13462.html * https://www.suse.com/security/cve/CVE-2025-4330.html * https://www.suse.com/security/cve/CVE-2026-0864.html * https://www.suse.com/security/cve/CVE-2026-11940.html * https://www.suse.com/security/cve/CVE-2026-11972.html * https://www.suse.com/security/cve/CVE-2026-1502.html * https://www.suse.com/security/cve/CVE-2026-15308.html * https://www.suse.com/security/cve/CVE-2026-15806.html * https://www.suse.com/security/cve/CVE-2026-17084.html * https://www.suse.com/security/cve/CVE-2026-2297.html * https://www.suse.com/security/cve/CVE-2026-3276.html * https://www.suse.com/security/cve/CVE-2026-3644.html * https://www.suse.com/security/cve/CVE-2026-4224.html * https://www.suse.com/security/cve/CVE-2026-4360.html * https://www.suse.com/security/cve/CVE-2026-45186.html * https://www.suse.com/security/cve/CVE-2026-4519.html * https://www.suse.com/security/cve/CVE-2026-4786.html * https://www.suse.com/security/cve/CVE-2026-6100.html * https://www.suse.com/security/cve/CVE-2026-7210.html * https://www.suse.com/security/cve/CVE-2026-72522.html * https://www.suse.com/security/cve/CVE-2026-7774.html * https://www.suse.com/security/cve/CVE-2026-8328.html * https://www.suse.com/security/cve/CVE-2026-9669.html * https://bugzilla.suse.com/show_bug.cgi?id=1259240 * https://bugzilla.suse.com/show_bug.cgi?id=1259611 * https://bugzilla.suse.com/show_bug.cgi?id=1259734 * https://bugzilla.suse.com/show_bug.cgi?id=1259735 * https://bugzilla.suse.com/show_bug.cgi?id=1260026 * https://bugzilla.suse.com/show_bug.cgi?id=1261969 * https://bugzilla.suse.com/show_bug.cgi?id=1262098 * https://bugzilla.suse.com/show_bug.cgi?id=1262319 * https://bugzilla.suse.com/show_bug.cgi?id=1264962 * https://bugzilla.suse.com/show_bug.cgi?id=1265268 * https://bugzilla.suse.com/show_bug.cgi?id=1267581 * https://bugzilla.suse.com/show_bug.cgi?id=1267821 * https://bugzilla.suse.com/show_bug.cgi?id=1267974 * https://bugzilla.suse.com/show_bug.cgi?id=1268977 * https://bugzilla.suse.com/show_bug.cgi?id=1269066 * https://bugzilla.suse.com/show_bug.cgi?id=1269788 * https://bugzilla.suse.com/show_bug.cgi?id=1269959 * https://bugzilla.suse.com/show_bug.cgi?id=1271192 * https://bugzilla.suse.com/show_bug.cgi?id=1276223 * https://bugzilla.suse.com/show_bug.cgi?id=1276226 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:18:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:18:29 -0000 Subject: SUSE-SU-2026:23742-1: important: Security update for kbd Message-ID: <178998230986.10889.9494849523739918528@200ee98c8b1d> # Security update for kbd Announcement ID: SUSE-SU-2026:23742-1 Release Date: 2026-09-16T09:16:27Z Rating: important References: * bsc#1275441 Cross-References: * CVE-2026-72693 CVSS scores: * CVE-2026-72693 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72693 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves one vulnerability can now be installed. ## Description: This update for kbd fixes the following issue: * CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-732 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * kbd-2.6.4-slfo.1.1_2.1 * kbd-debugsource-2.6.4-slfo.1.1_2.1 * kbd-debuginfo-2.6.4-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-72693.html * https://bugzilla.suse.com/show_bug.cgi?id=1275441 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:20:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:20:11 -0000 Subject: SUSE-SU-2026:23740-1: important: Security update for pcre2 Message-ID: <178998241174.10889.6771017163058970359@200ee98c8b1d> # Security update for pcre2 Announcement ID: SUSE-SU-2026:23740-1 Release Date: 2026-09-15T07:31:40Z Rating: important References: * bsc#1277707 * bsc#1277708 * bsc#1277709 * bsc#1277710 * bsc#1277711 * bsc#1277713 * bsc#1279893 * bsc#1280050 * bsc#1280051 * bsc#1280052 * bsc#1280053 * bsc#1280054 Cross-References: * CVE-2026-86145 * CVE-2026-89156 * CVE-2026-89157 * CVE-2026-89158 * CVE-2026-89160 * CVE-2026-89161 CVSS scores: * CVE-2026-86145 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-86145 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-86145 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-89156 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-89156 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-89156 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-89156 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-89157 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-89157 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-89157 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-89157 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-89158 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-89158 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-89158 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-89158 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-89160 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-89160 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-89160 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-89160 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-89161 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-89161 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-89161 ( NVD ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-89161 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves six vulnerabilities and has six fixes can now be installed. ## Description: This update for pcre2 fixes the following issues: * CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). * CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). * CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). * CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). * CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). * CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-730 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libpcre2-8-0-debuginfo-10.42-slfo.1.1_2.1 * pcre2-debugsource-10.42-slfo.1.1_2.1 * libpcre2-8-0-10.42-slfo.1.1_2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-86145.html * https://www.suse.com/security/cve/CVE-2026-89156.html * https://www.suse.com/security/cve/CVE-2026-89157.html * https://www.suse.com/security/cve/CVE-2026-89158.html * https://www.suse.com/security/cve/CVE-2026-89160.html * https://www.suse.com/security/cve/CVE-2026-89161.html * https://bugzilla.suse.com/show_bug.cgi?id=1277707 * https://bugzilla.suse.com/show_bug.cgi?id=1277708 * https://bugzilla.suse.com/show_bug.cgi?id=1277709 * https://bugzilla.suse.com/show_bug.cgi?id=1277710 * https://bugzilla.suse.com/show_bug.cgi?id=1277711 * https://bugzilla.suse.com/show_bug.cgi?id=1277713 * https://bugzilla.suse.com/show_bug.cgi?id=1279893 * https://bugzilla.suse.com/show_bug.cgi?id=1280050 * https://bugzilla.suse.com/show_bug.cgi?id=1280051 * https://bugzilla.suse.com/show_bug.cgi?id=1280052 * https://bugzilla.suse.com/show_bug.cgi?id=1280053 * https://bugzilla.suse.com/show_bug.cgi?id=1280054 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:21:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:21:04 -0000 Subject: SUSE-SU-2026:23739-1: important: Security update for google-osconfig-agent Message-ID: <178998246436.10889.620246580868916482@200ee98c8b1d> # Security update for google-osconfig-agent Announcement ID: SUSE-SU-2026:23739-1 Release Date: 2026-09-15T06:53:48Z Rating: important References: * bsc#1272118 * bsc#1278597 * bsc#1278967 * bsc#1279297 * bsc#1279414 Cross-References: * CVE-2026-56852 * CVE-2026-56854 * CVE-2026-56855 * CVE-2026-78662 * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56854 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56854 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56854 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56855 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78662 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78662 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78662 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84445 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.1 An update that solves seven vulnerabilities can now be installed. ## Description: This update for google-osconfig-agent fixes the following issues: * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272118). * CVE-2026-56854: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). * CVE-2026-56855: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). * CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). * CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279297). * CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279414). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278967). Changes for google-osconfig-agent: * Update to version 20260908.00 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-729 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * google-osconfig-agent-20260908.00-slfo.1.1_1.1 * google-osconfig-agent-debuginfo-20260908.00-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56852.html * https://www.suse.com/security/cve/CVE-2026-56854.html * https://www.suse.com/security/cve/CVE-2026-56855.html * https://www.suse.com/security/cve/CVE-2026-78662.html * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1272118 * https://bugzilla.suse.com/show_bug.cgi?id=1278597 * https://bugzilla.suse.com/show_bug.cgi?id=1278967 * https://bugzilla.suse.com/show_bug.cgi?id=1279297 * https://bugzilla.suse.com/show_bug.cgi?id=1279414 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:21:56 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:21:56 -0000 Subject: SUSE-SU-2026:23738-1: moderate: Security update for glibc Message-ID: <178998251681.10889.10806916654608324206@200ee98c8b1d> # Security update for glibc Announcement ID: SUSE-SU-2026:23738-1 Release Date: 2026-09-14T15:52:13Z Rating: moderate References: * bsc#1274723 * bsc#1274726 * bsc#1276892 * bsc#1276946 * bsc#1277262 * bsc#1277921 * bsc#1277922 Cross-References: * CVE-2026-18374 * CVE-2026-19499 * CVE-2026-19542 * CVE-2026-6368 * CVE-2026-6791 * CVE-2026-77117 * CVE-2026-80489 CVSS scores: * CVE-2026-18374 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-18374 ( SUSE ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-18374 ( NVD ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-19499 ( SUSE ): 4.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-19499 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H * CVE-2026-19499 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-19542 ( SUSE ): 1.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-19542 ( SUSE ): 4.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2026-19542 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6368 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-6368 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green * CVE-2026-6791 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-6791 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-77117 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-77117 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-77117 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80489 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80489 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80489 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves seven vulnerabilities can now be installed. ## Description: This update for glibc fixes the following issues: * CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). * CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). * CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). * CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). * CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). * CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). * CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-728 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * glibc-2.38-slfo.1.1_10.1 * glibc-locale-base-2.38-slfo.1.1_10.1 * glibc-debuginfo-2.38-slfo.1.1_10.1 * glibc-locale-base-debuginfo-2.38-slfo.1.1_10.1 * glibc-debugsource-2.38-slfo.1.1_10.1 * glibc-devel-debuginfo-2.38-slfo.1.1_10.1 * glibc-locale-2.38-slfo.1.1_10.1 * glibc-devel-2.38-slfo.1.1_10.1 ## References: * https://www.suse.com/security/cve/CVE-2026-18374.html * https://www.suse.com/security/cve/CVE-2026-19499.html * https://www.suse.com/security/cve/CVE-2026-19542.html * https://www.suse.com/security/cve/CVE-2026-6368.html * https://www.suse.com/security/cve/CVE-2026-6791.html * https://www.suse.com/security/cve/CVE-2026-77117.html * https://www.suse.com/security/cve/CVE-2026-80489.html * https://bugzilla.suse.com/show_bug.cgi?id=1274723 * https://bugzilla.suse.com/show_bug.cgi?id=1274726 * https://bugzilla.suse.com/show_bug.cgi?id=1276892 * https://bugzilla.suse.com/show_bug.cgi?id=1276946 * https://bugzilla.suse.com/show_bug.cgi?id=1277262 * https://bugzilla.suse.com/show_bug.cgi?id=1277921 * https://bugzilla.suse.com/show_bug.cgi?id=1277922 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:22:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:22:52 -0000 Subject: SUSE-SU-2026:23737-1: important: Security update for libpcap Message-ID: <178998257271.10889.5951749283269833442@200ee98c8b1d> # Security update for libpcap Announcement ID: SUSE-SU-2026:23737-1 Release Date: 2026-09-14T15:17:59Z Rating: important References: * bsc#1279584 * bsc#1279588 * bsc#1279593 * bsc#1279595 * bsc#1279782 * bsc#1279783 * bsc#1279784 Cross-References: * CVE-2026-0799 * CVE-2026-18238 * CVE-2026-18313 * CVE-2026-31911 * CVE-2026-31912 * CVE-2026-6244 * CVE-2026-6554 CVSS scores: * CVE-2026-0799 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-0799 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-0799 ( NVD ): 8.7 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H * CVE-2026-18238 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-18238 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-18238 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N * CVE-2026-18313 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-18313 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-18313 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-31911 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31911 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31911 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31912 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6244 ( SUSE ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6244 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6554 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-6554 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6554 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves seven vulnerabilities can now be installed. ## Description: This update for libpcap fixes the following issues: * CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a scratch memory register and allows for OOB access (bsc#1279782). * CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero (bsc#1279595). * CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584). * CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly validates its headers and allows for an OOB access (bsc#1279783). * CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ` message received from the client and never frees the memory (bsc#1279784). * CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588). * CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff (bsc#1279593). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-727 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libpcap1-1.10.4-slfo.1.1_3.1 * libpcap1-debuginfo-1.10.4-slfo.1.1_3.1 * libpcap-debugsource-1.10.4-slfo.1.1_3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-0799.html * https://www.suse.com/security/cve/CVE-2026-18238.html * https://www.suse.com/security/cve/CVE-2026-18313.html * https://www.suse.com/security/cve/CVE-2026-31911.html * https://www.suse.com/security/cve/CVE-2026-31912.html * https://www.suse.com/security/cve/CVE-2026-6244.html * https://www.suse.com/security/cve/CVE-2026-6554.html * https://bugzilla.suse.com/show_bug.cgi?id=1279584 * https://bugzilla.suse.com/show_bug.cgi?id=1279588 * https://bugzilla.suse.com/show_bug.cgi?id=1279593 * https://bugzilla.suse.com/show_bug.cgi?id=1279595 * https://bugzilla.suse.com/show_bug.cgi?id=1279782 * https://bugzilla.suse.com/show_bug.cgi?id=1279783 * https://bugzilla.suse.com/show_bug.cgi?id=1279784 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:23:42 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:23:42 -0000 Subject: SUSE-SU-2026:23736-1: important: Security update for google-guest-agent Message-ID: <178998262221.10889.8247651411670347116@200ee98c8b1d> # Security update for google-guest-agent Announcement ID: SUSE-SU-2026:23736-1 Release Date: 2026-09-14T09:42:12Z Rating: important References: * bsc#1253357 * bsc#1272118 * bsc#1278597 * bsc#1278967 * bsc#1279297 * bsc#1279414 Cross-References: * CVE-2026-56852 * CVE-2026-56854 * CVE-2026-56855 * CVE-2026-78662 * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56854 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56854 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56854 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56855 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78662 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78662 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78662 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84445 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.1 An update that solves seven vulnerabilities can now be installed. ## Description: This update for google-guest-agent fixes the following issues: * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272118). * CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). * CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279297). * CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279414). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278967). Changes for google-guest-agent: * Update to version 20260903.01 * Update dependencies to latest (#636) * fix octal digit comparison in morePermissive (#631) * Remove KillMode from google-guest-agent-manager (#629) * Fix SUSE Linux Micro 6+ (#628) * Fix oslogin for Micro 6+ * Exclude irrelevant tests on FreeBSD (#625) * Replace abandoned serial dependency (#624) * Add build rules for MWLID extension * Support basic account management on FreeBSD (#619) * fix dependency between sshd and google-guest-agent-manager.service (#621) * Update go.mod dependencies (#622) * Fallback to shebang execution when running scripts (#618) * Update go dependencies (#620) * Make guest-agent buildable on FreeBSD (#617) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-726 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260903.01-slfo.1.1_1.1 * google-guest-agent-debuginfo-20260903.01-slfo.1.1_1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56852.html * https://www.suse.com/security/cve/CVE-2026-56854.html * https://www.suse.com/security/cve/CVE-2026-56855.html * https://www.suse.com/security/cve/CVE-2026-78662.html * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1253357 * https://bugzilla.suse.com/show_bug.cgi?id=1272118 * https://bugzilla.suse.com/show_bug.cgi?id=1278597 * https://bugzilla.suse.com/show_bug.cgi?id=1278967 * https://bugzilla.suse.com/show_bug.cgi?id=1279297 * https://bugzilla.suse.com/show_bug.cgi?id=1279414 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:24:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:24:36 -0000 Subject: SUSE-SU-2026:23735-1: moderate: Security update for jq Message-ID: <178998267650.10889.7289449100326722666@200ee98c8b1d> # Security update for jq Announcement ID: SUSE-SU-2026:23735-1 Release Date: 2026-09-14T09:42:12Z Rating: moderate References: * bsc#1265071 * bsc#1269221 Cross-References: * CVE-2026-43895 * CVE-2026-47770 CVSS scores: * CVE-2026-43895 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43895 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-43895 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-47770 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-47770 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47770 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.1 An update that solves two vulnerabilities can now be installed. ## Description: This update for jq fixes the following issues: * CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure (bsc#1265071). * CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-725 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libjq1-debuginfo-1.7.1-slfo.1.1_5.1 * libjq1-1.7.1-slfo.1.1_5.1 * jq-1.7.1-slfo.1.1_5.1 * jq-debugsource-1.7.1-slfo.1.1_5.1 * jq-debuginfo-1.7.1-slfo.1.1_5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-43895.html * https://www.suse.com/security/cve/CVE-2026-47770.html * https://bugzilla.suse.com/show_bug.cgi?id=1265071 * https://bugzilla.suse.com/show_bug.cgi?id=1269221 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:27:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:27:15 -0000 Subject: SUSE-SU-2026:23731-1: critical: Security update for libzypp, zypper Message-ID: <178998283558.10889.5104811102427264216@200ee98c8b1d> # Security update for libzypp, zypper Announcement ID: SUSE-SU-2026:23731-1 Release Date: 2026-09-09T13:10:41Z Rating: critical References: * bsc#1257249 * bsc#1271730 * bsc#1272534 * bsc#1273242 * bsc#1274091 * bsc#1274625 * bsc#1277790 Affected Products: * SUSE Linux Micro 6.1 An update that has seven fixes can now be installed. ## Description: This update for libzypp, zypper fixes the following issues: Security issue fixed: * invalidating legacy libzypp unsigned-repository cache state [LIBZYPP-LEGACY- CACHE-01] (bsc#1274625). Non security issues fixed: * Econf parser adds tags in drop-in files outside any section to [main] (bsc#1272534). * Need zypper option to disable services to fix Dockerfile builds in OBS (bsc#1257249). * zypper loads repository data and installed packages prior to checking for required arguments (bsc#1274091). * Zypper patch doesn't give enough details about conflicts (bsc#1277790). Changes for libzypp: Update to version 17.38.1: * Prevent libgpgme from launching gpg-agents; we don't need them. * defaultLoadSystem: Hand out the ZYpp::Ptr as return value. * Log all solver problem rules (bsc#1277790) The log contains the most relevant problem rule, but sometimes it helps to know all rules associated with this problem. zypper shows them on demand as 'detail'. The log now remembers them as well. * Replace popen cat/zcat with solv_xfopen for testcase loaders (fixes #749) * repoGpgCheck: Strictly follow the repo_gpgcheck setting (bsc#1274625) There's been a legacy exception for unsigned repositories which were explicitly accepted in the past. After switching the repo_gpgcheck from off to on, they were allowed to stay unsigned until a first signed version was retrieved. From there on the handling was strict. Now the handling is strict as soon as the repo_gpgcheck turned on. The next set of metadata retrieved must be signed. * Iniparser: each new file starts in the unnamed section (bsc#1272534) * Fix hasCredentials() to require both username AND password to be non-empty (bsc#1273242) This avoids an unnecessary 2nd 401 response sending just the username in case the username but no password is known. Now it immediately fetches the credentials from disk if no password is known. * GPG Key hints in repoindex.xml require at least a long id to allow auto- import (bsc#1271730) The short Id (32bit/8byte) is not considered to be a safe identifier for a gpg key. A long id (64bit/16byte) or even better the full fingerprint is needed to identify the key. * zypp: Improve Testcase Loading for MCP Tools. Changes for zypper: Update to version 1.14.99: * Show solver problem details per default in not-interactive mode (bsc#1277790) This way they see all details when capturing zypper's output because the (d)etail button can't be pressed in not-interactive mode. * Add --servicesd-dir global option to relocate /etc/zypp/services.d (bsc#1257249) * info: check for missing positional args before systemSetup (bsc#1274091) * Remove deprecated installRecommends option from zypper.conf. The system wide default for all libzypp based applications is defined in zypp.conf(5). It is not recommended to define this in zypper exclusively. ## Special Instructions and Notes: ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-718 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * libzypp-17.38.15-slfo.1.1_1.1 * libzypp-debugsource-17.38.15-slfo.1.1_1.1 * zypper-1.14.101-slfo.1.1_1.1 * zypper-debugsource-1.14.101-slfo.1.1_1.1 * libzypp-debuginfo-17.38.15-slfo.1.1_1.1 * zypper-debuginfo-1.14.101-slfo.1.1_1.1 * SUSE Linux Micro 6.1 (noarch) * zypper-needs-restarting-1.14.101-slfo.1.1_1.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1257249 * https://bugzilla.suse.com/show_bug.cgi?id=1271730 * https://bugzilla.suse.com/show_bug.cgi?id=1272534 * https://bugzilla.suse.com/show_bug.cgi?id=1273242 * https://bugzilla.suse.com/show_bug.cgi?id=1274091 * https://bugzilla.suse.com/show_bug.cgi?id=1274625 * https://bugzilla.suse.com/show_bug.cgi?id=1277790 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:28:06 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:28:06 -0000 Subject: SUSE-SU-2026:23730-1: important: Security update for helm Message-ID: <178998288606.10889.1465292955587544922@200ee98c8b1d> # Security update for helm Announcement ID: SUSE-SU-2026:23730-1 Release Date: 2026-09-09T11:52:10Z Rating: important References: * bsc#1278270 * bsc#1278273 * bsc#1278688 Cross-References: * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84445 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.1 An update that solves three vulnerabilities can now be installed. ## Description: This update for helm fixes the following issues: * CVE-2026-84303: github.com/grpc/grpc-go: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1278270). * CVE-2026-84304: github.com/grpc/grpc-go: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1278273). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing `:authority` and `Host` headers in gRPC-Go xDS servers (bsc#1278688). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.1 zypper in -t patch SUSE-SLE-Micro-6.1-717 ## Package List: * SUSE Linux Micro 6.1 (aarch64 ppc64le s390x x86_64) * helm-3.21.3-slfo.1.1_3.1 * helm-debuginfo-3.21.3-slfo.1.1_3.1 * SUSE Linux Micro 6.1 (noarch) * helm-bash-completion-3.21.3-slfo.1.1_3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1278270 * https://bugzilla.suse.com/show_bug.cgi?id=1278273 * https://bugzilla.suse.com/show_bug.cgi?id=1278688 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 09:28:48 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 09:28:48 -0000 Subject: SUSE-SU-2026:2685-2: moderate: Security update for openCryptoki Message-ID: <178998292890.10889.14501477298776682620@200ee98c8b1d> # Security update for openCryptoki Announcement ID: SUSE-SU-2026:2685-2 Release Date: 2026-09-18T19:03:49Z Rating: moderate References: * bsc#1262283 Cross-References: * CVE-2026-40253 CVSS scores: * CVE-2026-40253 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40253 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-40253 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for openCryptoki fixes the following issue: * CVE-2026-40253: malformed BER-encoded cryptographic objects can lead to information disclosure and denial of service (bsc#1262283). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-2685 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * openCryptoki-devel-3.17.0-5.24.1 * openCryptoki-3.17.0-5.24.1 * openCryptoki-debuginfo-3.17.0-5.24.1 * openCryptoki-debugsource-3.17.0-5.24.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (ppc64le s390x x86_64) * openCryptoki-64bit-3.17.0-5.24.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390) * openCryptoki-32bit-3.17.0-5.24.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40253.html * https://bugzilla.suse.com/show_bug.cgi?id=1262283 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 12:31:10 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 12:31:10 -0000 Subject: SUSE-SU-2026:4275-1: important: Security update for jq Message-ID: <178999387080.9274.1856727061704000789@b745e8aa27b6> # Security update for jq Announcement ID: SUSE-SU-2026:4275-1 Release Date: 2026-09-21T07:33:04Z Rating: important References: * bsc#1215737 * bsc#1218034 * bsc#1218038 * bsc#1238078 * bsc#1248600 * bsc#1262043 * bsc#1262072 * bsc#1265060 * bsc#1265061 * bsc#1265062 * bsc#1265070 * bsc#1265071 * bsc#1265075 * bsc#1265076 * bsc#1269220 * bsc#1269221 * bsc#1269390 * bsc#976992 * jsc#PED-16516 Cross-References: * CVE-2015-8863 * CVE-2023-50246 * CVE-2023-50268 * CVE-2024-53427 * CVE-2025-9403 * CVE-2026-33948 * CVE-2026-40164 * CVE-2026-40612 * CVE-2026-41256 * CVE-2026-41257 * CVE-2026-43894 * CVE-2026-43895 * CVE-2026-43896 * CVE-2026-44777 * CVE-2026-47770 * CVE-2026-49839 * CVE-2026-54679 CVSS scores: * CVE-2015-8863 ( NVD ): 9.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2023-50246 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-50246 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-50246 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-50268 ( SUSE ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2023-50268 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-53427 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L * CVE-2024-53427 ( NVD ): 8.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2025-9403 ( SUSE ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-9403 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-9403 ( NVD ): 1.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-9403 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2025-9403 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-33948 ( SUSE ): 2.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-33948 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-33948 ( NVD ): 2.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-33948 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-40164 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40164 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40164 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40612 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-40612 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-40612 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-40612 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-41256 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-41256 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41256 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N * CVE-2026-41257 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-41257 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-41257 ( NVD ): 6.4 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-41257 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43894 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43894 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-43894 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43894 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43895 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-43895 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-43895 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N * CVE-2026-43896 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-43896 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-43896 ( NVD ): 6.2 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43896 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-44777 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-44777 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-44777 ( NVD ): 5.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44777 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-47770 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-47770 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-47770 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-49839 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-49839 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-54679 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-54679 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-54679 ( NVD ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-54679 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 17 vulnerabilities, contains one feature and has one security fix can now be installed. ## Description: This update for jq fixes the following issues: Security issues fixed: * CVE-2015-8863: heap buffer overflow in tokenadd() function (bsc#976992). * CVE-2023-50246: improper memory handling can lead to a heap buffer overflow in `decNumberToString` (bsc#1218034). * CVE-2023-50268: stack-based buffer overflow in builds using decNumber (bsc#1218038). * CVE-2024-53427: stack-buffer-overflow in the decNumberCopy function in decNumber.c (bsc#1238078). * CVE-2025-9403: reachable assertion in run_jq_tests() (bsc#1248600). * CVE-2026-33948: CLI input parsing allows validation bypass via embedded NUL bytes (bsc#1262043). * CVE-2026-40164: predictable hash collisions can lead to a denial of service (bsc#1262072). * CVE-2026-40612: jv_contains recurses into nested arrays/objects with no depth limit and can cause a stack overflow (bsc#1265060). * CVE-2026-41256: embedded NUL truncates top-level jq programs loaded with -f and can lead to execution of unintended programs (bsc#1265061). * CVE-2026-41257: integer overflow in `stack_reallocate` can lead to memory corruption and DoS (bsc#1265062). * CVE-2026-43894: signed integer overflow in `decNumber` can lead to out-of- bounds memory write (bsc#1265070). * CVE-2026-43895: embedded NUL bytes in import paths can lead to policy bypass and sensitive information disclosure (bsc#1265071). * CVE-2026-43896: unbounded recursion in `jv_object_merge_recursive()` can lead to C stack exhaustion and a process crash (bsc#1265075). * CVE-2026-44777: uncontrolled recursion in ordinary module loader when two valid modules `include` each other can lead to stack exhaustion and process crash (bsc#1265076). * CVE-2026-47770: stack overflow in deep structural equality (bsc#1269221). * CVE-2026-49839: `--rawfile` invalid-state reuse after `String too long` can lead to a heap buffer overflow (bsc#1269220). * CVE-2026-54679: integer overflow in `jvp_string_append` can lead to a buffer overrun on 32-bit systems (bsc#1269390). Changes for jq: Update to version 1.7.1: * Make the default background color more suitable for bright backgrounds. * Allow passing the inline jq script after --. * Fix possible uninitialised value dereference if jq_init() fails * Simplify paths/0 and paths/1. * Reject U+001F in string literals. * Remove unused nref accumulator in block_bind_library. * Remove a bunch of unused variables, and useless assignments. * main.c: Remove unused EXIT_STATUS_EXACT option. * Actually use the number correctly casted from double to int as index. * src/builtin.c: remove unnecessary jv_copy-s in type_error/type_error2. * Remove undefined behavior caught by LLVM 10 UBSAN. * Convert decnum to binary64 (double) instead of decimal64. This makes jq behave like the JSON specification suggests and more similar to other languages. * Fix memory leaks on invalid input for ltrimstr/1 and rtrimstr/1. * Fix memory leak on failed get for setpath/2. * Fix nan from json parsing also for nans with payload that start with 'n'. * Allow carriage return characters in comments. * Generate links in the man page. * Add extern C for C++. * Make object key color configurable using JQ_COLORS environment variable. * Change the default color of null to Bright Black. * Respect NO_COLOR environment variable to disable color output. * Improved --help output. Now mentions all options and nicer order. * Fix multiple issues of exit code using --exit-code/-e option. * Add --raw-output0 for NUL (zero byte) separated output. * Fix assert crash and validate JSON for --jsonarg. * Remove deprecated --argfile option. * Use decimal number literals to preserve precision. Comparison operations respects precision but arithmetic operations might truncate. * Adds new builtin pick(stream) to emit a projection of the input object or array. * Adds new builtin debug(msgs) that works like debug but applies a filter on the input before writing to stderr. * Adds new builtin scan($re; $flags). Was documented but not implemented. * Adds new builtin abs to get absolute value. This potentially allows the literal value of numbers to be preserved as length and fabs convert to float. * Allow if without else-branch. When skipped the else-branch will be . (identity). * Allow use of $binding as key in object literals. * Allow dot between chained indexes when using .["index"] * Allow dot for chained value iterator .[], .[]? * Fix try/catch catches more than it should. * Speed up and refactor some builtins, also remove scalars_or_empty/0. * Now halt and halt_error exit immediately instead of continuing to the next input. * Fix issue converting string to number after previous convert error. * Fix issue representing large numbers on some platforms causing invalid JSON output. * Fix deletion using assigning empty against arrays. * Allow keywords to be used as binding name in more places. * Allow using nan as NaN in JSON. * Expose a module's function names in modulemeta. * Fix contains/1 to handle strings with NUL. * Fix stderr/0 to output raw text without any decoration. * Fix nth/2 to emit empty on index out of range. * Fix implode to not assert and instead replace invalid unicode codepoints. * Fix indices/1 and rindex/1 in case of overlapping matches in strings. * Fix sub/3 to resolve issues involving global search-and-replace (gsub) operations. * Fix empty regular expression matches. * Fix overflow exception of the modulo operator. * Fix string multiplication by 0 (and less than 1) to emit empty string. * Fix segfault when using libjq and threads. * Fix constant folding of division and reminder with zero divisor. * Fix error/0, error/1 to throw null error. * Simpler and faster transpose. * Simple and efficient implementation of walk/1. * Remove deprecated filters leaf_paths, recurse_down. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4275 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4275 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4275 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4275 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4275 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4275 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4275 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4275 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4275 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4275 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4275 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4275 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4275 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4275 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4275 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4275 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libjq-devel-1.7.1-150000.3.25.1 * jq-1.7.1-150000.3.25.1 * libjq1-1.7.1-150000.3.25.1 * jq-debuginfo-1.7.1-150000.3.25.1 * libjq1-debuginfo-1.7.1-150000.3.25.1 * jq-debugsource-1.7.1-150000.3.25.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libjq-devel-1.7.1-150000.3.25.1 * jq-1.7.1-150000.3.25.1 * libjq1-1.7.1-150000.3.25.1 * jq-debuginfo-1.7.1-150000.3.25.1 * libjq1-debuginfo-1.7.1-150000.3.25.1 * jq-debugsource-1.7.1-150000.3.25.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libjq-devel-1.7.1-150000.3.25.1 * jq-1.7.1-150000.3.25.1 * libjq1-1.7.1-150000.3.25.1 * jq-debuginfo-1.7.1-150000.3.25.1 * libjq1-debuginfo-1.7.1-150000.3.25.1 * jq-debugsource-1.7.1-150000.3.25.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * jq-1.7.1-150000.3.25.1 * libjq1-1.7.1-150000.3.25.1 * jq-debuginfo-1.7.1-150000.3.25.1 * libjq1-debuginfo-1.7.1-150000.3.25.1 * jq-debugsource-1.7.1-150000.3.25.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * jq-1.7.1-150000.3.25.1 * libjq1-1.7.1-150000.3.25.1 * jq-debuginfo-1.7.1-150000.3.25.1 * libjq1-debuginfo-1.7.1-150000.3.25.1 * jq-debugsource-1.7.1-150000.3.25.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libjq-devel-1.7.1-150000.3.25.1 * jq-1.7.1-150000.3.25.1 * libjq1-1.7.1-150000.3.25.1 * jq-debuginfo-1.7.1-150000.3.25.1 * libjq1-debuginfo-1.7.1-150000.3.25.1 * jq-debugsource-1.7.1-150000.3.25.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libjq-devel-1.7.1-150000.3.25.1 * jq-1.7.1-150000.3.25.1 * libjq1-1.7.1-150000.3.25.1 * jq-debuginfo-1.7.1-150000.3.25.1 * libjq1-debuginfo-1.7.1-150000.3.25.1 * jq-debugsource-1.7.1-150000.3.25.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libjq-devel-1.7.1-150000.3.25.1 * jq-1.7.1-150000.3.25.1 * libjq1-1.7.1-150000.3.25.1 * jq-debuginfo-1.7.1-150000.3.25.1 * libjq1-debuginfo-1.7.1-150000.3.25.1 * jq-debugsource-1.7.1-150000.3.25.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * jq-1.7.1-150000.3.25.1 * libjq1-1.7.1-150000.3.25.1 * jq-debuginfo-1.7.1-150000.3.25.1 * libjq1-debuginfo-1.7.1-150000.3.25.1 * jq-debugsource-1.7.1-150000.3.25.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * jq-1.7.1-150000.3.25.1 * libjq1-1.7.1-150000.3.25.1 * jq-debuginfo-1.7.1-150000.3.25.1 * libjq1-debuginfo-1.7.1-150000.3.25.1 * jq-debugsource-1.7.1-150000.3.25.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libjq-devel-1.7.1-150000.3.25.1 * jq-1.7.1-150000.3.25.1 * libjq1-1.7.1-150000.3.25.1 * jq-debuginfo-1.7.1-150000.3.25.1 * libjq1-debuginfo-1.7.1-150000.3.25.1 * jq-debugsource-1.7.1-150000.3.25.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * jq-1.7.1-150000.3.25.1 * libjq1-1.7.1-150000.3.25.1 * jq-debuginfo-1.7.1-150000.3.25.1 * libjq1-debuginfo-1.7.1-150000.3.25.1 * jq-debugsource-1.7.1-150000.3.25.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libjq-devel-1.7.1-150000.3.25.1 * jq-1.7.1-150000.3.25.1 * libjq1-1.7.1-150000.3.25.1 * jq-debuginfo-1.7.1-150000.3.25.1 * libjq1-debuginfo-1.7.1-150000.3.25.1 * jq-debugsource-1.7.1-150000.3.25.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libjq-devel-1.7.1-150000.3.25.1 * jq-1.7.1-150000.3.25.1 * libjq1-1.7.1-150000.3.25.1 * jq-debuginfo-1.7.1-150000.3.25.1 * libjq1-debuginfo-1.7.1-150000.3.25.1 * jq-debugsource-1.7.1-150000.3.25.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libjq-devel-1.7.1-150000.3.25.1 * jq-1.7.1-150000.3.25.1 * libjq1-1.7.1-150000.3.25.1 * jq-debuginfo-1.7.1-150000.3.25.1 * libjq1-debuginfo-1.7.1-150000.3.25.1 * jq-debugsource-1.7.1-150000.3.25.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libjq-devel-1.7.1-150000.3.25.1 * jq-1.7.1-150000.3.25.1 * libjq1-1.7.1-150000.3.25.1 * jq-debuginfo-1.7.1-150000.3.25.1 * libjq1-debuginfo-1.7.1-150000.3.25.1 * jq-debugsource-1.7.1-150000.3.25.1 ## References: * https://www.suse.com/security/cve/CVE-2015-8863.html * https://www.suse.com/security/cve/CVE-2023-50246.html * https://www.suse.com/security/cve/CVE-2023-50268.html * https://www.suse.com/security/cve/CVE-2024-53427.html * https://www.suse.com/security/cve/CVE-2025-9403.html * https://www.suse.com/security/cve/CVE-2026-33948.html * https://www.suse.com/security/cve/CVE-2026-40164.html * https://www.suse.com/security/cve/CVE-2026-40612.html * https://www.suse.com/security/cve/CVE-2026-41256.html * https://www.suse.com/security/cve/CVE-2026-41257.html * https://www.suse.com/security/cve/CVE-2026-43894.html * https://www.suse.com/security/cve/CVE-2026-43895.html * https://www.suse.com/security/cve/CVE-2026-43896.html * https://www.suse.com/security/cve/CVE-2026-44777.html * https://www.suse.com/security/cve/CVE-2026-47770.html * https://www.suse.com/security/cve/CVE-2026-49839.html * https://www.suse.com/security/cve/CVE-2026-54679.html * https://bugzilla.suse.com/show_bug.cgi?id=1215737 * https://bugzilla.suse.com/show_bug.cgi?id=1218034 * https://bugzilla.suse.com/show_bug.cgi?id=1218038 * https://bugzilla.suse.com/show_bug.cgi?id=1238078 * https://bugzilla.suse.com/show_bug.cgi?id=1248600 * https://bugzilla.suse.com/show_bug.cgi?id=1262043 * https://bugzilla.suse.com/show_bug.cgi?id=1262072 * https://bugzilla.suse.com/show_bug.cgi?id=1265060 * https://bugzilla.suse.com/show_bug.cgi?id=1265061 * https://bugzilla.suse.com/show_bug.cgi?id=1265062 * https://bugzilla.suse.com/show_bug.cgi?id=1265070 * https://bugzilla.suse.com/show_bug.cgi?id=1265071 * https://bugzilla.suse.com/show_bug.cgi?id=1265075 * https://bugzilla.suse.com/show_bug.cgi?id=1265076 * https://bugzilla.suse.com/show_bug.cgi?id=1269220 * https://bugzilla.suse.com/show_bug.cgi?id=1269221 * https://bugzilla.suse.com/show_bug.cgi?id=1269390 * https://bugzilla.suse.com/show_bug.cgi?id=976992 * https://jira.suse.com/browse/PED-16516 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 12:31:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 12:31:51 -0000 Subject: SUSE-SU-2026:4274-1: important: Security update for libsoup Message-ID: <178999391142.9274.2362942978405895473@b745e8aa27b6> # Security update for libsoup Announcement ID: SUSE-SU-2026:4274-1 Release Date: 2026-09-21T07:31:26Z Rating: important References: * bsc#1279238 * bsc#1279239 Cross-References: * CVE-2026-85197 * CVE-2026-85534 CVSS scores: * CVE-2026-85197 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-85197 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-85197 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-85534 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-85534 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-85534 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves two vulnerabilities can now be installed. ## Description: This update for libsoup fixes the following issues: * CVE-2026-85197: heap use-after-free in HTTP/2 `client on_data_read()` via `GOAWAY` during body upload (bsc#1279238). * CVE-2026-85534: heap buffer overflow in `SoupSession` through `on_data_source_read_callback()` via `SETTINGS` frame with crafted `INITIAL_WINDOW_SIZE` (bsc#1279239). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4274 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4274 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4274 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4274 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4274 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4274 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4274 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4274 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4274 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * libsoup-3_0-0-debuginfo-3.0.4-150400.3.49.1 * typelib-1_0-Soup-3_0-3.0.4-150400.3.49.1 * libsoup-debugsource-3.0.4-150400.3.49.1 * libsoup-devel-3.0.4-150400.3.49.1 * libsoup-3_0-0-3.0.4-150400.3.49.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * libsoup-lang-3.0.4-150400.3.49.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * libsoup-3_0-0-debuginfo-3.0.4-150400.3.49.1 * typelib-1_0-Soup-3_0-3.0.4-150400.3.49.1 * libsoup-debugsource-3.0.4-150400.3.49.1 * libsoup-devel-3.0.4-150400.3.49.1 * libsoup-3_0-0-3.0.4-150400.3.49.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * libsoup-lang-3.0.4-150400.3.49.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * libsoup-3_0-0-debuginfo-3.0.4-150400.3.49.1 * typelib-1_0-Soup-3_0-3.0.4-150400.3.49.1 * libsoup-debugsource-3.0.4-150400.3.49.1 * libsoup-devel-3.0.4-150400.3.49.1 * libsoup-3_0-0-3.0.4-150400.3.49.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * libsoup-lang-3.0.4-150400.3.49.1 * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libsoup-3_0-0-debuginfo-3.0.4-150400.3.49.1 * typelib-1_0-Soup-3_0-3.0.4-150400.3.49.1 * libsoup-debugsource-3.0.4-150400.3.49.1 * libsoup-devel-3.0.4-150400.3.49.1 * libsoup-3_0-0-3.0.4-150400.3.49.1 * openSUSE Leap 15.4 (x86_64) * libsoup-3_0-0-32bit-debuginfo-3.0.4-150400.3.49.1 * libsoup-devel-32bit-3.0.4-150400.3.49.1 * libsoup-3_0-0-32bit-3.0.4-150400.3.49.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libsoup-3_0-0-64bit-3.0.4-150400.3.49.1 * libsoup-devel-64bit-3.0.4-150400.3.49.1 * libsoup-3_0-0-64bit-debuginfo-3.0.4-150400.3.49.1 * openSUSE Leap 15.4 (noarch) * libsoup-lang-3.0.4-150400.3.49.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * libsoup-3_0-0-debuginfo-3.0.4-150400.3.49.1 * typelib-1_0-Soup-3_0-3.0.4-150400.3.49.1 * libsoup-debugsource-3.0.4-150400.3.49.1 * libsoup-devel-3.0.4-150400.3.49.1 * libsoup-3_0-0-3.0.4-150400.3.49.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * libsoup-lang-3.0.4-150400.3.49.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * libsoup-3_0-0-debuginfo-3.0.4-150400.3.49.1 * typelib-1_0-Soup-3_0-3.0.4-150400.3.49.1 * libsoup-debugsource-3.0.4-150400.3.49.1 * libsoup-devel-3.0.4-150400.3.49.1 * libsoup-3_0-0-3.0.4-150400.3.49.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * libsoup-lang-3.0.4-150400.3.49.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * libsoup-3_0-0-debuginfo-3.0.4-150400.3.49.1 * typelib-1_0-Soup-3_0-3.0.4-150400.3.49.1 * libsoup-debugsource-3.0.4-150400.3.49.1 * libsoup-devel-3.0.4-150400.3.49.1 * libsoup-3_0-0-3.0.4-150400.3.49.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * libsoup-lang-3.0.4-150400.3.49.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * libsoup-3_0-0-debuginfo-3.0.4-150400.3.49.1 * typelib-1_0-Soup-3_0-3.0.4-150400.3.49.1 * libsoup-debugsource-3.0.4-150400.3.49.1 * libsoup-devel-3.0.4-150400.3.49.1 * libsoup-3_0-0-3.0.4-150400.3.49.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * libsoup-lang-3.0.4-150400.3.49.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libsoup-3_0-0-debuginfo-3.0.4-150400.3.49.1 * typelib-1_0-Soup-3_0-3.0.4-150400.3.49.1 * libsoup-debugsource-3.0.4-150400.3.49.1 * libsoup-devel-3.0.4-150400.3.49.1 * libsoup-3_0-0-3.0.4-150400.3.49.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * libsoup-lang-3.0.4-150400.3.49.1 ## References: * https://www.suse.com/security/cve/CVE-2026-85197.html * https://www.suse.com/security/cve/CVE-2026-85534.html * https://bugzilla.suse.com/show_bug.cgi?id=1279238 * https://bugzilla.suse.com/show_bug.cgi?id=1279239 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 12:32:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 12:32:49 -0000 Subject: SUSE-SU-2026:4273-1: important: Security update for libsoup Message-ID: <178999396948.9274.10451391054757953937@b745e8aa27b6> # Security update for libsoup Announcement ID: SUSE-SU-2026:4273-1 Release Date: 2026-09-21T07:30:38Z Rating: important References: * bsc#1279238 * bsc#1279239 Cross-References: * CVE-2026-85197 * CVE-2026-85534 CVSS scores: * CVE-2026-85197 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-85197 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-85197 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-85534 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-85534 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-85534 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves two vulnerabilities can now be installed. ## Description: This update for libsoup fixes the following issues: * CVE-2026-85197: heap use-after-free in HTTP/2 `client on_data_read()` via `GOAWAY` during body upload (bsc#1279238). * CVE-2026-85534: heap buffer overflow in `SoupSession` through `on_data_source_read_callback()` via `SETTINGS` frame with crafted `INITIAL_WINDOW_SIZE` (bsc#1279239). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4273 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4273 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4273 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4273 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * libsoup-3_0-0-debuginfo-3.4.4-150600.3.53.1 * libsoup-3_0-0-3.4.4-150600.3.53.1 * typelib-1_0-Soup-3_0-3.4.4-150600.3.53.1 * libsoup-debugsource-3.4.4-150600.3.53.1 * libsoup-devel-3.4.4-150600.3.53.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * libsoup-lang-3.4.4-150600.3.53.1 * openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64) * libsoup-3_0-0-debuginfo-3.4.4-150600.3.53.1 * libsoup-3_0-0-3.4.4-150600.3.53.1 * typelib-1_0-Soup-3_0-3.4.4-150600.3.53.1 * libsoup-debugsource-3.4.4-150600.3.53.1 * libsoup-devel-3.4.4-150600.3.53.1 * openSUSE Leap 15.6 (x86_64) * libsoup-devel-32bit-3.4.4-150600.3.53.1 * libsoup-3_0-0-32bit-3.4.4-150600.3.53.1 * libsoup-3_0-0-32bit-debuginfo-3.4.4-150600.3.53.1 * openSUSE Leap 15.6 (aarch64_ilp32) * libsoup-3_0-0-64bit-debuginfo-3.4.4-150600.3.53.1 * libsoup-3_0-0-64bit-3.4.4-150600.3.53.1 * libsoup-devel-64bit-3.4.4-150600.3.53.1 * openSUSE Leap 15.6 (noarch) * libsoup-lang-3.4.4-150600.3.53.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libsoup-3_0-0-debuginfo-3.4.4-150600.3.53.1 * libsoup-3_0-0-3.4.4-150600.3.53.1 * typelib-1_0-Soup-3_0-3.4.4-150600.3.53.1 * libsoup-debugsource-3.4.4-150600.3.53.1 * libsoup-devel-3.4.4-150600.3.53.1 * Basesystem Module 15-SP7 (noarch) * libsoup-lang-3.4.4-150600.3.53.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * libsoup-3_0-0-debuginfo-3.4.4-150600.3.53.1 * libsoup-3_0-0-3.4.4-150600.3.53.1 * typelib-1_0-Soup-3_0-3.4.4-150600.3.53.1 * libsoup-debugsource-3.4.4-150600.3.53.1 * libsoup-devel-3.4.4-150600.3.53.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * libsoup-lang-3.4.4-150600.3.53.1 ## References: * https://www.suse.com/security/cve/CVE-2026-85197.html * https://www.suse.com/security/cve/CVE-2026-85534.html * https://bugzilla.suse.com/show_bug.cgi?id=1279238 * https://bugzilla.suse.com/show_bug.cgi?id=1279239 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 12:33:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 12:33:52 -0000 Subject: SUSE-SU-2026:4272-1: important: Security update for google-guest-agent Message-ID: <178999403241.9274.11712797255731494264@b745e8aa27b6> # Security update for google-guest-agent Announcement ID: SUSE-SU-2026:4272-1 Release Date: 2026-09-21T07:30:16Z Rating: important References: * bsc#1253357 * bsc#1272118 * bsc#1278597 * bsc#1278967 * bsc#1279297 * bsc#1279414 Cross-References: * CVE-2026-33186 * CVE-2026-56852 * CVE-2026-56854 * CVE-2026-56855 * CVE-2026-78662 * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56854 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56854 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56854 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56855 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78662 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78662 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78662 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84445 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for google-guest-agent fixes the following issues: * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header. * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272118). * CVE-2026-56854: golang.org/x/crypto/ssh: source-address critical option not enforced for non-public-key auth callbacks (bsc#1278597) * CVE-2026-56855: golang.org/x/crypto/ssh: prevent DoS on deadlocked established channel (bsc#1278597) * CVE-2026-78662: golang.org/x/crypto/ssh: prevent DoS on deadlocked undecided channel (bsc#1278597). * CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279297). * CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279414). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278967). Changes for google-guest-agent: * Updated to version 20260903.01 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2026-4272 ## Package List: * Public Cloud Module 12 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260903.01-1.75.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://www.suse.com/security/cve/CVE-2026-56854.html * https://www.suse.com/security/cve/CVE-2026-56855.html * https://www.suse.com/security/cve/CVE-2026-78662.html * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1253357 * https://bugzilla.suse.com/show_bug.cgi?id=1272118 * https://bugzilla.suse.com/show_bug.cgi?id=1278597 * https://bugzilla.suse.com/show_bug.cgi?id=1278967 * https://bugzilla.suse.com/show_bug.cgi?id=1279297 * https://bugzilla.suse.com/show_bug.cgi?id=1279414 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 12:34:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 12:34:31 -0000 Subject: SUSE-SU-2026:4271-1: moderate: Security update for dovecot22 Message-ID: <178999407172.9274.9169542780026230160@b745e8aa27b6> # Security update for dovecot22 Announcement ID: SUSE-SU-2026:4271-1 Release Date: 2026-09-21T07:30:05Z Rating: moderate References: * bsc#1265148 Cross-References: * CVE-2026-40016 CVSS scores: * CVE-2026-40016 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-40016 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40016 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-40016 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for dovecot22 fixes the following issue: * CVE-2026-40016: Sieve :contains/:matches O(NxM) substring match bypasses sieve_max_cpu_time limit (bsc#1265148). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4271 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * dovecot22-backend-pgsql-2.2.31-19.43.1 * dovecot22-backend-mysql-2.2.31-19.43.1 * dovecot22-backend-mysql-debuginfo-2.2.31-19.43.1 * dovecot22-backend-sqlite-debuginfo-2.2.31-19.43.1 * dovecot22-2.2.31-19.43.1 * dovecot22-backend-sqlite-2.2.31-19.43.1 * dovecot22-devel-2.2.31-19.43.1 * dovecot22-debugsource-2.2.31-19.43.1 * dovecot22-backend-pgsql-debuginfo-2.2.31-19.43.1 * dovecot22-debuginfo-2.2.31-19.43.1 ## References: * https://www.suse.com/security/cve/CVE-2026-40016.html * https://bugzilla.suse.com/show_bug.cgi?id=1265148 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 12:35:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 12:35:19 -0000 Subject: SUSE-SU-2026:4270-1: important: Security update for google-guest-agent Message-ID: <178999411973.9274.8290828035256103204@b745e8aa27b6> # Security update for google-guest-agent Announcement ID: SUSE-SU-2026:4270-1 Release Date: 2026-09-21T07:29:56Z Rating: important References: * bsc#1253357 * bsc#1260264 * bsc#1272118 * bsc#1278597 * bsc#1278967 * bsc#1279297 * bsc#1279414 Cross-References: * CVE-2026-33186 * CVE-2026-56852 * CVE-2026-56854 * CVE-2026-56855 * CVE-2026-78662 * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-33186 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-33186 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-33186 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56854 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56854 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56854 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56855 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78662 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78662 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78662 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84445 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves eight vulnerabilities can now be installed. ## Description: This update for google-guest-agent fixes the following issues: * CVE-2026-33186: google.golang.org/grpc: authorization bypass due to improper validation of the HTTP/2 :path pseudo- header (bsc#1260264). * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272118). * CVE-2026-56854: golang.org/x/crypto/ssh: source-address critical option not enforced for non-public-key auth callbacks (bsc#1278597) * CVE-2026-56855: golang.org/x/crypto/ssh: prevent DoS on deadlocked established channel (bsc#1278597) * CVE-2026-78662: golang.org/x/crypto/ssh: prevent DoS on deadlocked undecided channel (bsc#1278597). * CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279297). * CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279414). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278967). Changes for google-guest-agent: * Updated to version 20260903.01 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-4270 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-4270 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-4270 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4270 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-4270 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260903.01-150000.1.85.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260903.01-150000.1.85.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260903.01-150000.1.85.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260903.01-150000.1.85.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * google-guest-agent-20260903.01-150000.1.85.1 ## References: * https://www.suse.com/security/cve/CVE-2026-33186.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://www.suse.com/security/cve/CVE-2026-56854.html * https://www.suse.com/security/cve/CVE-2026-56855.html * https://www.suse.com/security/cve/CVE-2026-78662.html * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1253357 * https://bugzilla.suse.com/show_bug.cgi?id=1260264 * https://bugzilla.suse.com/show_bug.cgi?id=1272118 * https://bugzilla.suse.com/show_bug.cgi?id=1278597 * https://bugzilla.suse.com/show_bug.cgi?id=1278967 * https://bugzilla.suse.com/show_bug.cgi?id=1279297 * https://bugzilla.suse.com/show_bug.cgi?id=1279414 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Mon Sep 21 16:30:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Mon, 21 Sep 2026 16:30:49 -0000 Subject: SUSE-SU-2026:4276-1: important: Security update for libheif Message-ID: <179000824934.9555.2258889870036530858@5ac198222802> # Security update for libheif Announcement ID: SUSE-SU-2026:4276-1 Release Date: 2026-09-21T09:21:15Z Rating: important References: * bsc#1279443 * bsc#1279444 * bsc#1279445 * bsc#1279446 * bsc#1279447 * bsc#1279448 * bsc#1279449 * bsc#1280001 * bsc#1280002 * jsc#PED-16355 Cross-References: * CVE-2026-84383 * CVE-2026-84384 * CVE-2026-84444 * CVE-2026-84446 * CVE-2026-84447 * CVE-2026-84448 * CVE-2026-84450 * CVE-2026-84451 CVSS scores: * CVE-2026-84383 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-84383 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84383 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84384 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84384 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84384 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84444 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-84444 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-84444 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-84446 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84446 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84446 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84447 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84447 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84447 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84448 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84448 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-84448 ( NVD ): 4.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-84450 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84450 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84450 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-84451 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84451 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84451 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Desktop Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves eight vulnerabilities, contains one feature and has one security fix can now be installed. ## Description: This update for libheif fixes the following issues: * CVE-2026-84383: Heap buffer overflow in scale_nearest_neighbor() via duplicate alpha planes from nested iden/auxl items (bsc#1279443). * CVE-2026-84384: brotli/zlib decompression paths lack output-size limits, allowing decompression-bomb OOM/DoS (bsc#1279445). * CVE-2026-84444: Out-of-bounds write in the unci encoder (bsc#1279448). * CVE-2026-84446: Sequence decode timing-table initialization allows non- terminating loops and unbounded memory, bypassing max_sequence_frames (bsc#1279447). * CVE-2026-84447: Derived-image indirect reference chains and tiled offsets bypass decode caching and MemoryHandle limits, causing CPU/memory amplification DoS (bsc#1279446). * CVE-2026-84448: Heap out-of-bounds read in the inline-mask region API (bsc#1279449). * CVE-2026-84450: image item with `clap` property and an ispe declaring a dimension greater than `INT32_MAX + 1` can lead to a crash via an abort (bsc#1280002). * CVE-2026-84451: crafted HEIF file advertising a 4096 x 4096 uncompressed tile grid can cause an out-of-bounds read due to an integer overflow (bsc#1280001). * Out-of-bounds read and write in derived-item and pixel-plane handling (bsc#1279444). Changes for libheif: * Update to version 1.23.4 (jsc#PED-16355) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4276 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4276 ## Package List: * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libheif-dav1d-1.23.4-150700.3.21.1 * libheif-aom-1.23.4-150700.3.21.1 * libheif-debugsource-1.23.4-150700.3.21.1 * libheif-jpeg-1.23.4-150700.3.21.1 * libheif1-debuginfo-1.23.4-150700.3.21.1 * libheif-dav1d-debuginfo-1.23.4-150700.3.21.1 * libheif-jpeg-debuginfo-1.23.4-150700.3.21.1 * libheif-rav1e-debuginfo-1.23.4-150700.3.21.1 * libheif-rav1e-1.23.4-150700.3.21.1 * libheif-aom-debuginfo-1.23.4-150700.3.21.1 * libheif1-1.23.4-150700.3.21.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * libheif-debugsource-1.23.4-150700.3.21.1 * libheif-devel-1.23.4-150700.3.21.1 * gdk-pixbuf-loader-libheif-debuginfo-1.23.4-150700.3.21.1 * gdk-pixbuf-loader-libheif-1.23.4-150700.3.21.1 * libheif-ffmpeg-debuginfo-1.23.4-150700.3.21.1 * libheif-ffmpeg-1.23.4-150700.3.21.1 ## References: * https://www.suse.com/security/cve/CVE-2026-84383.html * https://www.suse.com/security/cve/CVE-2026-84384.html * https://www.suse.com/security/cve/CVE-2026-84444.html * https://www.suse.com/security/cve/CVE-2026-84446.html * https://www.suse.com/security/cve/CVE-2026-84447.html * https://www.suse.com/security/cve/CVE-2026-84448.html * https://www.suse.com/security/cve/CVE-2026-84450.html * https://www.suse.com/security/cve/CVE-2026-84451.html * https://bugzilla.suse.com/show_bug.cgi?id=1279443 * https://bugzilla.suse.com/show_bug.cgi?id=1279444 * https://bugzilla.suse.com/show_bug.cgi?id=1279445 * https://bugzilla.suse.com/show_bug.cgi?id=1279446 * https://bugzilla.suse.com/show_bug.cgi?id=1279447 * https://bugzilla.suse.com/show_bug.cgi?id=1279448 * https://bugzilla.suse.com/show_bug.cgi?id=1279449 * https://bugzilla.suse.com/show_bug.cgi?id=1280001 * https://bugzilla.suse.com/show_bug.cgi?id=1280002 * https://jira.suse.com/browse/PED-16355 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:31:04 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:31:04 -0000 Subject: SUSE-SU-2026:23845-1: moderate: Security update for python311 Message-ID: <179008026435.204.2882939526537395734@e7f4ad8d9866> # Security update for python311 Announcement ID: SUSE-SU-2026:23845-1 Release Date: 2026-09-16T09:39:43Z Rating: moderate References: * bsc#1267974 * bsc#1276223 * bsc#1276226 Cross-References: * CVE-2026-15806 * CVE-2026-17084 * CVE-2026-9669 CVSS scores: * CVE-2026-15806 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-15806 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-15806 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-17084 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-17084 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2026-17084 ( NVD ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-9669 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-9669 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-9669 ( NVD ): 8.2 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for python311 fixes the following issues: * CVE-2026-9669: crafted input can cause a stack buffer overflow (bsc#1267974). * CVE-2026-15806: urllib.request.HTTPPasswordMgr credentials for one URL scheme sent over another scheme (bsc#1276223). * CVE-2026-17084: StringPrep algorithm considered Unicode codepoint attributes outside Unicode 3.2.0 (bsc#1276226). Changes for python311: * Updated to version 3.11.16 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-902 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * python311-curses-debuginfo-3.11.16-1.1 * python311-debugsource-3.11.16-1.1 * python311-3.11.16-1.1 * python311-base-debuginfo-3.11.16-1.1 * python311-core-debugsource-3.11.16-1.1 * python311-debuginfo-3.11.16-1.1 * python311-base-3.11.16-1.1 * libpython3_11-1_0-debuginfo-3.11.16-1.1 * python311-curses-3.11.16-1.1 * libpython3_11-1_0-3.11.16-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-15806.html * https://www.suse.com/security/cve/CVE-2026-17084.html * https://www.suse.com/security/cve/CVE-2026-9669.html * https://bugzilla.suse.com/show_bug.cgi?id=1267974 * https://bugzilla.suse.com/show_bug.cgi?id=1276223 * https://bugzilla.suse.com/show_bug.cgi?id=1276226 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:31:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:31:44 -0000 Subject: SUSE-SU-2026:23844-1: important: Security update for kbd Message-ID: <179008030428.204.16214657486854957075@e7f4ad8d9866> # Security update for kbd Announcement ID: SUSE-SU-2026:23844-1 Release Date: 2026-09-16T09:28:13Z Rating: important References: * bsc#1275441 Cross-References: * CVE-2026-72693 CVSS scores: * CVE-2026-72693 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72693 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72693 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves one vulnerability can now be installed. ## Description: This update for kbd fixes the following issue: * CVE-2026-72693: local privilege escalation in `openvt` due to incorrect process owner verification that allows `passwordless` root login (bsc#1275441). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-903 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * kbd-2.6.4-2.1 * kbd-debugsource-2.6.4-2.1 * kbd-debuginfo-2.6.4-2.1 * SUSE Linux Micro 6.0 (noarch) * kbd-legacy-2.6.4-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-72693.html * https://bugzilla.suse.com/show_bug.cgi?id=1275441 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:33:15 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:33:15 -0000 Subject: SUSE-SU-2026:23841-1: important: Security update for google-osconfig-agent Message-ID: <179008039535.204.10430667325668701952@e7f4ad8d9866> # Security update for google-osconfig-agent Announcement ID: SUSE-SU-2026:23841-1 Release Date: 2026-09-15T07:06:11Z Rating: important References: * bsc#1278597 Cross-References: * CVE-2026-56854 * CVE-2026-56855 * CVE-2026-78662 CVSS scores: * CVE-2026-56854 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56854 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56854 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56855 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78662 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78662 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78662 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * SUSE Linux Micro 6.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for google-osconfig-agent fixes the following issue: * CVE-2026-56854: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). * CVE-2026-56855: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). * CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-900 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * google-osconfig-agent-debuginfo-20260908.00-2.1 * google-osconfig-agent-20260908.00-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56854.html * https://www.suse.com/security/cve/CVE-2026-56855.html * https://www.suse.com/security/cve/CVE-2026-78662.html * https://bugzilla.suse.com/show_bug.cgi?id=1278597 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:34:05 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:34:05 -0000 Subject: SUSE-SU-2026:23840-1: important: Security update for pcre2 Message-ID: <179008044519.204.14308763070020946459@e7f4ad8d9866> # Security update for pcre2 Announcement ID: SUSE-SU-2026:23840-1 Release Date: 2026-09-15T07:04:05Z Rating: important References: * bsc#1277707 * bsc#1277708 * bsc#1277709 * bsc#1277710 * bsc#1277711 * bsc#1277713 * bsc#1279893 * bsc#1280050 * bsc#1280051 * bsc#1280052 * bsc#1280053 * bsc#1280054 Cross-References: * CVE-2026-86145 * CVE-2026-89156 * CVE-2026-89157 * CVE-2026-89158 * CVE-2026-89160 * CVE-2026-89161 CVSS scores: * CVE-2026-86145 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-86145 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-86145 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-89156 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-89156 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-89156 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-89156 ( NVD ): 2.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-89157 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-89157 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-89157 ( NVD ): 5.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-89157 ( NVD ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-89158 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-89158 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-89158 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-89158 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-89160 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-89160 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-89160 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L * CVE-2026-89160 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-89161 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-89161 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-89161 ( NVD ): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-89161 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves six vulnerabilities and has six fixes can now be installed. ## Description: This update for pcre2 fixes the following issues: * CVE-2026-86145: missing size checks in `pcre2_dfa_match` code can lead to an out-of-bounds write (bsc#1279893). * CVE-2026-89156: out-of-bounds read via invalid UTF data during JIT fallback (bsc#1280054). * CVE-2026-89157: out-of-bounds write via large pattern input (bsc#1280053). * CVE-2026-89158: out-of-bounds write due to integer overflow in `pcre2_compile_32` for 32-bit platforms (bsc#1280052). * CVE-2026-89160: out-of-bounds read during the `PCRE2_MATCH_INVALID_UTF` matching of an invalid UTF subject (bsc#1280051). * CVE-2026-89161: incorrect free operation due to mishandling of a previously copied subject in `pcre2_jit_match` (bsc#1280050). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-901 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libpcre2-8-0-10.42-3.1 * pcre2-debugsource-10.42-3.1 * libpcre2-8-0-debuginfo-10.42-3.1 ## References: * https://www.suse.com/security/cve/CVE-2026-86145.html * https://www.suse.com/security/cve/CVE-2026-89156.html * https://www.suse.com/security/cve/CVE-2026-89157.html * https://www.suse.com/security/cve/CVE-2026-89158.html * https://www.suse.com/security/cve/CVE-2026-89160.html * https://www.suse.com/security/cve/CVE-2026-89161.html * https://bugzilla.suse.com/show_bug.cgi?id=1277707 * https://bugzilla.suse.com/show_bug.cgi?id=1277708 * https://bugzilla.suse.com/show_bug.cgi?id=1277709 * https://bugzilla.suse.com/show_bug.cgi?id=1277710 * https://bugzilla.suse.com/show_bug.cgi?id=1277711 * https://bugzilla.suse.com/show_bug.cgi?id=1277713 * https://bugzilla.suse.com/show_bug.cgi?id=1279893 * https://bugzilla.suse.com/show_bug.cgi?id=1280050 * https://bugzilla.suse.com/show_bug.cgi?id=1280051 * https://bugzilla.suse.com/show_bug.cgi?id=1280052 * https://bugzilla.suse.com/show_bug.cgi?id=1280053 * https://bugzilla.suse.com/show_bug.cgi?id=1280054 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:34:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:34:46 -0000 Subject: SUSE-SU-2026:23839-1: important: Security update for the Linux Kernel (Live Patch 28 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008048641.204.18172047281732918220@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 28 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23839-1 Release Date: 2026-09-15T06:39:47Z Rating: important References: * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-51.1 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-646 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-51-default-2-1.1 * kernel-livepatch-6_4_0-51-default-debuginfo-2-1.1 * kernel-livepatch-MICRO-6-0_Update_28-debugsource-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:35:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:35:31 -0000 Subject: SUSE-SU-2026:23838-1: important: Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008053131.204.8761538667786248448@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23838-1 Release Date: 2026-09-15T06:39:47Z Rating: important References: * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-50.2 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-645 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-50-default-debuginfo-3-1.1 * kernel-livepatch-6_4_0-50-default-3-1.1 * kernel-livepatch-MICRO-6-0_Update_27-debugsource-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:36:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:36:14 -0000 Subject: SUSE-SU-2026:23837-1: important: Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008057496.204.5513586424831976390@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 26 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23837-1 Release Date: 2026-09-15T06:39:47Z Rating: important References: * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-49.1 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-644 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-49-default-debuginfo-3-1.1 * kernel-livepatch-MICRO-6-0_Update_26-debugsource-3-1.1 * kernel-livepatch-6_4_0-49-default-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:36:58 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:36:58 -0000 Subject: SUSE-SU-2026:23836-1: important: Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008061839.204.2748281028637505748@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 25 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23836-1 Release Date: 2026-09-15T06:39:47Z Rating: important References: * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-48.1 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-643 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-48-default-4-1.1 * kernel-livepatch-6_4_0-48-default-debuginfo-4-1.1 * kernel-livepatch-MICRO-6-0_Update_25-debugsource-4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:37:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:37:44 -0000 Subject: SUSE-SU-2026:23835-1: important: Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008066425.204.9747141629456568450@e7f4ad8d9866> # Security update for the Linux Kernel RT (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23835-1 Release Date: 2026-09-15T06:39:47Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-642 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_14-debugsource-12-1.1 * kernel-livepatch-6_4_0-38-rt-debuginfo-12-1.1 * kernel-livepatch-6_4_0-38-rt-12-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:38:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:38:29 -0000 Subject: SUSE-SU-2026:23834-1: important: Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008070910.204.3215156542028005891@e7f4ad8d9866> # Security update for the Linux Kernel RT (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23834-1 Release Date: 2026-09-15T06:39:47Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-37.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-641 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_13-debugsource-12-1.1 * kernel-livepatch-6_4_0-37-rt-debuginfo-12-1.1 * kernel-livepatch-6_4_0-37-rt-12-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:39:14 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:39:14 -0000 Subject: SUSE-SU-2026:23833-1: important: Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008075434.204.14574110806297907544@e7f4ad8d9866> # Security update for the Linux Kernel RT (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23833-1 Release Date: 2026-09-15T06:39:47Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-640 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-36-rt-debuginfo-16-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_12-debugsource-16-1.1 * kernel-livepatch-6_4_0-36-rt-16-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:39:59 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:39:59 -0000 Subject: SUSE-SU-2026:23832-1: important: Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008079987.204.6228999363192314159@e7f4ad8d9866> # Security update for the Linux Kernel RT (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23832-1 Release Date: 2026-09-15T06:39:47Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-639 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-35-rt-17-1.1 * kernel-livepatch-6_4_0-35-rt-debuginfo-17-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_11-debugsource-17-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:40:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:40:46 -0000 Subject: SUSE-SU-2026:23831-1: important: Security update for google-guest-agent Message-ID: <179008084618.204.4935916451496856044@e7f4ad8d9866> # Security update for google-guest-agent Announcement ID: SUSE-SU-2026:23831-1 Release Date: 2026-09-14T11:13:59Z Rating: important References: * bsc#1253357 * bsc#1272118 * bsc#1278597 * bsc#1278967 * bsc#1279297 * bsc#1279414 Cross-References: * CVE-2026-56852 * CVE-2026-56854 * CVE-2026-56855 * CVE-2026-78662 * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56854 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56854 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56854 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56855 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78662 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78662 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78662 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84445 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * SUSE Linux Micro 6.0 An update that solves seven vulnerabilities can now be installed. ## Description: This update for google-guest-agent fixes the following issues: * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272118). * CVE-2026-56854,CVE-2026-56855,CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). * CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279297). * CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279414). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278967). Changes for google-guest-agent: * Update to version 20260903.01 * Update dependencies to latest (#636) * fix octal digit comparison in morePermissive (#631) * Remove KillMode from google-guest-agent-manager (#629) * Fix SUSE Linux Micro 6+ (#628) * Fix oslogin for Micro 6+ * Exclude irrelevant tests on FreeBSD (#625) * Replace abandoned serial dependency (#624) * Add build rules for MWLID extension * Support basic account management on FreeBSD (#619) * fix dependency between sshd and google-guest-agent-manager.service (#621) * Update go.mod dependencies (#622) * Fallback to shebang execution when running scripts (#618) * Update go dependencies (#620) * Make guest-agent buildable on FreeBSD (#617) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-898 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * google-guest-agent-20260903.01-1.1 * google-guest-agent-debuginfo-20260903.01-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56852.html * https://www.suse.com/security/cve/CVE-2026-56854.html * https://www.suse.com/security/cve/CVE-2026-56855.html * https://www.suse.com/security/cve/CVE-2026-78662.html * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1253357 * https://bugzilla.suse.com/show_bug.cgi?id=1272118 * https://bugzilla.suse.com/show_bug.cgi?id=1278597 * https://bugzilla.suse.com/show_bug.cgi?id=1278967 * https://bugzilla.suse.com/show_bug.cgi?id=1279297 * https://bugzilla.suse.com/show_bug.cgi?id=1279414 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:41:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:41:34 -0000 Subject: SUSE-SU-2026:23830-1: moderate: Security update for glibc Message-ID: <179008089468.204.6916309441880809252@e7f4ad8d9866> # Security update for glibc Announcement ID: SUSE-SU-2026:23830-1 Release Date: 2026-09-14T11:13:58Z Rating: moderate References: * bsc#1274723 * bsc#1274726 * bsc#1276892 * bsc#1276946 * bsc#1277262 * bsc#1277921 * bsc#1277922 Cross-References: * CVE-2026-18374 * CVE-2026-19499 * CVE-2026-19542 * CVE-2026-6368 * CVE-2026-6791 * CVE-2026-77117 * CVE-2026-80489 CVSS scores: * CVE-2026-18374 ( SUSE ): 2.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-18374 ( SUSE ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-18374 ( NVD ): 4.9 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-19499 ( SUSE ): 4.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-19499 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H * CVE-2026-19499 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:H * CVE-2026-19542 ( SUSE ): 1.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-19542 ( SUSE ): 4.2 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L * CVE-2026-19542 ( NVD ): 5.6 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L * CVE-2026-6368 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-6368 ( NVD ): 2.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:X/V:X/RE:X/U:Green * CVE-2026-6791 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-6791 ( NVD ): 6.6 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:L/SA:H/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-77117 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-77117 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-77117 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80489 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80489 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80489 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves seven vulnerabilities can now be installed. ## Description: This update for glibc fixes the following issues: * CVE-2026-6368: invalid free via wordexp WRDE_APPEND rollback (bsc#1274726). * CVE-2026-6791: stack overflow in wordexp tilde expansion (bsc#1274723). * CVE-2026-18374: heap buffer overflow in the fopen ccs extension (bsc#1277262). * CVE-2026-19499: buffer overflow in strfmon right-justification padding (bsc#1276892). * CVE-2026-19542: out-of-bounds array write in tdelete (bsc#1276946). * CVE-2026-77117: SHIFT_JISX0213 decoding lacks pending character reset (bsc#1277921). * CVE-2026-80489: EUC_JISX0213 decoding lacks pending character reset (bsc#1277922). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-897 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * glibc-devel-2.38-15.1 * glibc-debuginfo-2.38-15.1 * glibc-locale-base-2.38-15.1 * glibc-2.38-15.1 * glibc-locale-base-debuginfo-2.38-15.1 * glibc-locale-2.38-15.1 * glibc-devel-debuginfo-2.38-15.1 * glibc-debugsource-2.38-15.1 ## References: * https://www.suse.com/security/cve/CVE-2026-18374.html * https://www.suse.com/security/cve/CVE-2026-19499.html * https://www.suse.com/security/cve/CVE-2026-19542.html * https://www.suse.com/security/cve/CVE-2026-6368.html * https://www.suse.com/security/cve/CVE-2026-6791.html * https://www.suse.com/security/cve/CVE-2026-77117.html * https://www.suse.com/security/cve/CVE-2026-80489.html * https://bugzilla.suse.com/show_bug.cgi?id=1274723 * https://bugzilla.suse.com/show_bug.cgi?id=1274726 * https://bugzilla.suse.com/show_bug.cgi?id=1276892 * https://bugzilla.suse.com/show_bug.cgi?id=1276946 * https://bugzilla.suse.com/show_bug.cgi?id=1277262 * https://bugzilla.suse.com/show_bug.cgi?id=1277921 * https://bugzilla.suse.com/show_bug.cgi?id=1277922 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:42:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:42:22 -0000 Subject: SUSE-SU-2026:23829-1: important: Security update for libpcap Message-ID: <179008094253.204.12580502428649471982@e7f4ad8d9866> # Security update for libpcap Announcement ID: SUSE-SU-2026:23829-1 Release Date: 2026-09-14T11:13:58Z Rating: important References: * bsc#1279584 * bsc#1279588 * bsc#1279593 * bsc#1279595 * bsc#1279782 * bsc#1279783 * bsc#1279784 Cross-References: * CVE-2026-0799 * CVE-2026-18238 * CVE-2026-18313 * CVE-2026-31911 * CVE-2026-31912 * CVE-2026-6244 * CVE-2026-6554 CVSS scores: * CVE-2026-0799 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-0799 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-0799 ( NVD ): 8.7 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H * CVE-2026-18238 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-18238 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-18238 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N * CVE-2026-18313 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-18313 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-18313 ( NVD ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-31911 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31911 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31911 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31912 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31912 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31912 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6244 ( SUSE ): 4.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-6244 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6244 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-6554 ( SUSE ): 2.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-6554 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-6554 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves seven vulnerabilities can now be installed. ## Description: This update for libpcap fixes the following issues: * CVE-2026-0799: the BPF interpreter does not validate values in BPF instructions that load/store a value from/to a scratch memory register and allows for OOB access (bsc#1279782). * CVE-2026-6244: libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero (bsc#1279595). * CVE-2026-6554: libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction implements looping via backward jumps, but it does not limit the number of loop iterations. Can cause infinite loop (bsc#1279584). * CVE-2026-18238: `rpcap` client code that processes a `RPCAP_MSG_PACKET` message received from the server incorrectly validates its headers and allows for an OOB access (bsc#1279783). * CVE-2026-18313: `rpcapd` allocates up to 65536 bytes per each `RPCAP_MSG_UPDATEFILTER_REQ` or `RPCAP_MSG_STARTCAP_REQ` message received from the client and never frees the memory (bsc#1279784). * CVE-2026-31911: libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process (bsc#1279588). * CVE-2026-31912: libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buff (bsc#1279593). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-896 ## Package List: * SUSE Linux Micro 6.0 (aarch64 s390x x86_64) * libpcap1-debuginfo-1.10.4-5.1 * libpcap1-1.10.4-5.1 * libpcap-debugsource-1.10.4-5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-0799.html * https://www.suse.com/security/cve/CVE-2026-18238.html * https://www.suse.com/security/cve/CVE-2026-18313.html * https://www.suse.com/security/cve/CVE-2026-31911.html * https://www.suse.com/security/cve/CVE-2026-31912.html * https://www.suse.com/security/cve/CVE-2026-6244.html * https://www.suse.com/security/cve/CVE-2026-6554.html * https://bugzilla.suse.com/show_bug.cgi?id=1279584 * https://bugzilla.suse.com/show_bug.cgi?id=1279588 * https://bugzilla.suse.com/show_bug.cgi?id=1279593 * https://bugzilla.suse.com/show_bug.cgi?id=1279595 * https://bugzilla.suse.com/show_bug.cgi?id=1279782 * https://bugzilla.suse.com/show_bug.cgi?id=1279783 * https://bugzilla.suse.com/show_bug.cgi?id=1279784 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:43:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:43:07 -0000 Subject: SUSE-SU-2026:23828-1: important: Security update for the Linux Kernel (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008098726.204.13096736440217396056@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23828-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-47.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-614 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_24-debugsource-5-1.1 * kernel-livepatch-6_4_0-47-default-5-1.1 * kernel-livepatch-6_4_0-47-default-debuginfo-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:43:52 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:43:52 -0000 Subject: SUSE-SU-2026:23827-1: important: Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008103207.204.12015227670902082868@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23827-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-613 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-46-default-debuginfo-6-1.1 * kernel-livepatch-MICRO-6-0_Update_23-debugsource-6-1.1 * kernel-livepatch-6_4_0-46-default-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:44:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:44:36 -0000 Subject: SUSE-SU-2026:23826-1: important: Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008107667.204.5635934466224524090@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23826-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-638 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_22-debugsource-6-1.1 * kernel-livepatch-6_4_0-45-default-6-1.1 * kernel-livepatch-6_4_0-45-default-debuginfo-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:45:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:45:25 -0000 Subject: SUSE-SU-2026:23825-1: important: Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008112510.204.13941336649497748401@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23825-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-44.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-637 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_21-debugsource-6-1.1 * kernel-livepatch-6_4_0-44-default-debuginfo-6-1.1 * kernel-livepatch-6_4_0-44-default-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:46:11 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:46:11 -0000 Subject: SUSE-SU-2026:23824-1: important: Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008117154.204.6522450853425669932@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23824-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-636 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-43-default-6-1.1 * kernel-livepatch-6_4_0-43-default-debuginfo-6-1.1 * kernel-livepatch-MICRO-6-0_Update_20-debugsource-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:47:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:47:01 -0000 Subject: SUSE-SU-2026:23823-1: important: Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008122138.204.15711553692776576280@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23823-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-635 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-42-default-debuginfo-7-1.1 * kernel-livepatch-MICRO-6-0_Update_19-debugsource-7-1.1 * kernel-livepatch-6_4_0-42-default-7-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:47:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:47:46 -0000 Subject: SUSE-SU-2026:23822-1: important: Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008126654.204.14976363906890698730@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23822-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-634 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-41-default-9-1.1 * kernel-livepatch-MICRO-6-0_Update_18-debugsource-9-1.1 * kernel-livepatch-6_4_0-41-default-debuginfo-9-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:49:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:49:16 -0000 Subject: SUSE-SU-2026:23820-1: important: Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008135631.204.1498492522669867427@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 16 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23820-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-632 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_16-debugsource-11-1.1 * kernel-livepatch-6_4_0-39-default-11-1.1 * kernel-livepatch-6_4_0-39-default-debuginfo-11-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:48:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:48:31 -0000 Subject: SUSE-SU-2026:23821-1: important: Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008131171.204.13348491842322270165@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 17 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23821-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-633 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-40-default-debuginfo-10-1.1 * kernel-livepatch-MICRO-6-0_Update_17-debugsource-10-1.1 * kernel-livepatch-6_4_0-40-default-10-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:50:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:50:01 -0000 Subject: SUSE-SU-2026:23819-1: important: Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008140146.204.10315160360315532910@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 14 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23819-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-38.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-631 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-38-default-debuginfo-12-1.2 * kernel-livepatch-6_4_0-38-default-12-1.2 * kernel-livepatch-MICRO-6-0_Update_14-debugsource-12-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:50:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:50:50 -0000 Subject: SUSE-SU-2026:23818-1: important: Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008145094.204.14463228635105793517@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 13 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23818-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-36.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-630 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-36-default-14-1.1 * kernel-livepatch-MICRO-6-0_Update_13-debugsource-14-1.1 * kernel-livepatch-6_4_0-36-default-debuginfo-14-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:51:35 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:51:35 -0000 Subject: SUSE-SU-2026:23817-1: important: Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008149585.204.4620686160373191317@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23817-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-35.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-629 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-35-default-debuginfo-16-1.1 * kernel-livepatch-MICRO-6-0_Update_12-debugsource-16-1.1 * kernel-livepatch-6_4_0-35-default-16-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:52:20 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:52:20 -0000 Subject: SUSE-SU-2026:23816-1: important: Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008154079.204.18390956280700181360@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 11 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23816-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-34.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-628 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-6_4_0-34-default-16-1.1 * kernel-livepatch-6_4_0-34-default-debuginfo-16-1.1 * kernel-livepatch-MICRO-6-0_Update_11-debugsource-16-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:53:07 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:53:07 -0000 Subject: SUSE-SU-2026:23815-1: important: Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008158739.204.8452173581882392559@e7f4ad8d9866> # Security update for the Linux Kernel (Live Patch 10 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23815-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-32.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-627 ## Package List: * SUSE Linux Micro 6.0 (s390x x86_64) * kernel-livepatch-MICRO-6-0_Update_10-debugsource-17-1.1 * kernel-livepatch-6_4_0-32-default-17-1.1 * kernel-livepatch-6_4_0-32-default-debuginfo-17-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:53:48 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:53:48 -0000 Subject: SUSE-SU-2026:23814-1: important: Security update for the Linux Kernel RT (Live Patch 28 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008162831.204.11420163345235254757@e7f4ad8d9866> # Security update for the Linux Kernel RT (Live Patch 28 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23814-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves two vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-51.1 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-626 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-51-rt-debuginfo-2-1.1 * kernel-livepatch-6_4_0-51-rt-2-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_28-debugsource-2-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:54:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:54:31 -0000 Subject: SUSE-SU-2026:23813-1: important: Security update for the Linux Kernel RT (Live Patch 27 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008167104.204.16645797184725746541@e7f4ad8d9866> # Security update for the Linux Kernel RT (Live Patch 27 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23813-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-50.2 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-625 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-50-rt-3-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_27-debugsource-3-1.1 * kernel-livepatch-6_4_0-50-rt-debuginfo-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:55:19 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:55:19 -0000 Subject: SUSE-SU-2026:23812-1: important: Security update for the Linux Kernel RT (Live Patch 26 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008171964.204.5906609541410828728@e7f4ad8d9866> # Security update for the Linux Kernel RT (Live Patch 26 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23812-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-49.1 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-624 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_26-debugsource-3-1.1 * kernel-livepatch-6_4_0-49-rt-3-1.1 * kernel-livepatch-6_4_0-49-rt-debuginfo-3-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:56:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:56:03 -0000 Subject: SUSE-SU-2026:23811-1: important: Security update for the Linux Kernel RT (Live Patch 25 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008176347.204.11229259396518820113@e7f4ad8d9866> # Security update for the Linux Kernel RT (Live Patch 25 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23811-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-48.1 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-623 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-48-rt-4-1.1 * kernel-livepatch-6_4_0-48-rt-debuginfo-4-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_25-debugsource-4-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:56:48 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:56:48 -0000 Subject: SUSE-SU-2026:23810-1: important: Security update for the Linux Kernel RT (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008180849.204.13363794688573214834@e7f4ad8d9866> # Security update for the Linux Kernel RT (Live Patch 24 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23810-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-47.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-622 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_24-debugsource-5-1.1 * kernel-livepatch-6_4_0-47-rt-5-1.1 * kernel-livepatch-6_4_0-47-rt-debuginfo-5-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:57:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:57:33 -0000 Subject: SUSE-SU-2026:23809-1: important: Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008185347.204.18234324588781626175@e7f4ad8d9866> # Security update for the Linux Kernel RT (Live Patch 23 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23809-1 Release Date: 2026-09-14T08:55:42Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-46.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-621 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-46-rt-6-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_23-debugsource-6-1.1 * kernel-livepatch-6_4_0-46-rt-debuginfo-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:58:18 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:58:18 -0000 Subject: SUSE-SU-2026:23808-1: important: Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008189837.204.7042517119451209405@e7f4ad8d9866> # Security update for the Linux Kernel RT (Live Patch 22 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23808-1 Release Date: 2026-09-14T08:55:41Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-45.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-620 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_22-debugsource-6-1.2 * kernel-livepatch-6_4_0-45-rt-debuginfo-6-1.2 * kernel-livepatch-6_4_0-45-rt-6-1.2 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 12:59:05 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 12:59:05 -0000 Subject: SUSE-SU-2026:23807-1: important: Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008194595.204.17779339062779965838@e7f4ad8d9866> # Security update for the Linux Kernel RT (Live Patch 21 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23807-1 Release Date: 2026-09-14T08:55:41Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-43.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-619 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_21-debugsource-6-1.1 * kernel-livepatch-6_4_0-43-rt-6-1.1 * kernel-livepatch-6_4_0-43-rt-debuginfo-6-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 13:00:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 13:00:00 -0000 Subject: SUSE-SU-2026:23806-1: important: Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008200052.204.8955376169503541485@e7f4ad8d9866> # Security update for the Linux Kernel RT (Live Patch 20 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23806-1 Release Date: 2026-09-14T08:55:41Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-42.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-618 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-MICRO-6-0-RT_Update_20-debugsource-7-1.1 * kernel-livepatch-6_4_0-42-rt-debuginfo-7-1.1 * kernel-livepatch-6_4_0-42-rt-7-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 13:00:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 13:00:55 -0000 Subject: SUSE-SU-2026:23805-1: important: Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008205540.204.12312436640905548777@e7f4ad8d9866> # Security update for the Linux Kernel RT (Live Patch 19 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23805-1 Release Date: 2026-09-14T08:55:41Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-41.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-617 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-41-rt-debuginfo-9-1.1 * kernel-livepatch-6_4_0-41-rt-9-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_19-debugsource-9-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 13:01:46 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 13:01:46 -0000 Subject: SUSE-SU-2026:23804-1: important: Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008210683.204.1014675862153360162@e7f4ad8d9866> # Security update for the Linux Kernel RT (Live Patch 18 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23804-1 Release Date: 2026-09-14T08:55:41Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-40.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-616 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-40-rt-debuginfo-10-1.1 * kernel-livepatch-6_4_0-40-rt-10-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_18-debugsource-10-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 13:02:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 13:02:36 -0000 Subject: SUSE-SU-2026:23803-1: important: Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Message-ID: <179008215680.204.13075671024868684773@e7f4ad8d9866> # Security update for the Linux Kernel RT (Live Patch 15 for SUSE Linux Enterprise Micro 6.0) Announcement ID: SUSE-SU-2026:23803-1 Release Date: 2026-09-14T08:55:41Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.0 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-39.1 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.0 zypper in -t patch SUSE-SLE-Micro-6.0-kernel-615 ## Package List: * SUSE Linux Micro 6.0 (x86_64) * kernel-livepatch-6_4_0-39-rt-debuginfo-11-1.1 * kernel-livepatch-6_4_0-39-rt-11-1.1 * kernel-livepatch-MICRO-6-0-RT_Update_15-debugsource-11-1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 16:30:33 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 16:30:33 -0000 Subject: SUSE-SU-2026:23849-1: important: Security update for gdb Message-ID: <179009463385.407.387966861416997644@32be4de442c6> # Security update for gdb Announcement ID: SUSE-SU-2026:23849-1 Release Date: 2026-09-20T14:02:11Z Rating: important References: * bsc#1277757 Cross-References: * CVE-2026-13732 CVSS scores: * CVE-2026-13732 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-13732 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-13732 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Micro 6.2 * SUSE Linux Micro Extras 6.2 An update that solves one vulnerability can now be installed. ## Description: This update for gdb fixes the following issue: * CVE-2026-13732: out-of-bounds write in STABS parser read_member_functions() via crafted ELF (bsc#1277757). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro Extras 6.2 zypper in -t patch SUSE-SLE-Micro-Extras-6.2-1717 ## Package List: * SUSE Linux Micro Extras 6.2 (aarch64 ppc64le s390x x86_64) * gdb-16.3-160000.6.1 * gdb-debuginfo-16.3-160000.6.1 * gdb-debugsource-16.3-160000.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13732.html * https://bugzilla.suse.com/show_bug.cgi?id=1277757 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 16:31:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 16:31:16 -0000 Subject: SUSE-SU-2026:23848-1: important: Security update for libsoup Message-ID: <179009467695.407.11652332029860403916@32be4de442c6> # Security update for libsoup Announcement ID: SUSE-SU-2026:23848-1 Release Date: 2026-09-21T12:43:30Z Rating: important References: * bsc#1279238 * bsc#1279239 Cross-References: * CVE-2026-85197 * CVE-2026-85534 CVSS scores: * CVE-2026-85197 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-85197 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-85197 ( NVD ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-85534 ( SUSE ): 9.2 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-85534 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-85534 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Micro 6.2 An update that solves two vulnerabilities can now be installed. ## Description: This update for libsoup fixes the following issues: * CVE-2026-85197: heap use-after-free in HTTP/2 `client on_data_read()` via `GOAWAY` during body upload (bsc#1279238). * CVE-2026-85534: heap buffer overflow in `SoupSession` through `on_data_source_read_callback()` via `SETTINGS` frame with crafted `INITIAL_WINDOW_SIZE` (bsc#1279239). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Micro 6.2 zypper in -t patch SUSE-SL-Micro-6.2-1729 ## Package List: * SUSE Linux Micro 6.2 (aarch64 ppc64le s390x x86_64) * libsoup-3_0-0-3.6.6-160000.4.1 * libsoup-debugsource-3.6.6-160000.4.1 * libsoup-3_0-0-debuginfo-3.6.6-160000.4.1 ## References: * https://www.suse.com/security/cve/CVE-2026-85197.html * https://www.suse.com/security/cve/CVE-2026-85534.html * https://bugzilla.suse.com/show_bug.cgi?id=1279238 * https://bugzilla.suse.com/show_bug.cgi?id=1279239 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 16:37:38 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 16:37:38 -0000 Subject: SUSE-SU-2026:4282-1: important: Security update for the Linux Kernel Message-ID: <179009505822.407.9016696959672485889@32be4de442c6> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:4282-1 Release Date: 2026-09-22T08:34:17Z Rating: important References: * bsc#1224586 * bsc#1251966 * bsc#1252682 * bsc#1254894 * bsc#1255225 * bsc#1257246 * bsc#1261679 * bsc#1262771 * bsc#1264296 * bsc#1264308 * bsc#1264541 * bsc#1264594 * bsc#1264619 * bsc#1264821 * bsc#1265068 * bsc#1265121 * bsc#1266920 * bsc#1267501 * bsc#1267612 * bsc#1267615 * bsc#1267643 * bsc#1268972 * bsc#1268987 * bsc#1269000 * bsc#1269013 * bsc#1269113 * bsc#1269114 * bsc#1269238 * bsc#1269256 * bsc#1269301 * bsc#1269306 * bsc#1269381 * bsc#1269412 * bsc#1269530 * bsc#1269655 * bsc#1269685 * bsc#1269686 * bsc#1269733 * bsc#1269734 * bsc#1269774 * bsc#1269783 * bsc#1269815 * bsc#1270264 * bsc#1271731 * bsc#1271825 * bsc#1271827 * bsc#1272182 * bsc#1272210 * bsc#1272262 * bsc#1272297 * bsc#1272385 * bsc#1272390 * bsc#1272426 * bsc#1272429 * bsc#1272482 * bsc#1272497 * bsc#1272591 * bsc#1272641 * bsc#1272643 * bsc#1272877 * bsc#1272891 * bsc#1273027 * bsc#1273105 * bsc#1273285 * bsc#1273303 * bsc#1273305 * bsc#1273316 * bsc#1273319 * bsc#1273327 * bsc#1273336 * bsc#1273463 * bsc#1273555 * bsc#1273557 * bsc#1273597 * bsc#1273734 * bsc#1273742 * bsc#1273745 * bsc#1273748 * bsc#1273749 * bsc#1273759 * bsc#1273762 * bsc#1273774 * bsc#1273778 * bsc#1273780 * bsc#1273813 * bsc#1273831 * bsc#1273860 * bsc#1273869 * bsc#1273882 * bsc#1273891 * bsc#1273892 * bsc#1273895 * bsc#1273930 * bsc#1273933 * bsc#1273936 * bsc#1273939 * bsc#1273940 * bsc#1273942 * bsc#1273944 * bsc#1273946 * bsc#1273957 * bsc#1273958 * bsc#1273968 * bsc#1273974 * bsc#1274003 * bsc#1274006 * bsc#1274019 * bsc#1274028 * bsc#1274040 * bsc#1274041 * bsc#1274077 * bsc#1274208 * bsc#1274274 * bsc#1274277 * bsc#1274278 * bsc#1274550 * bsc#1274581 * bsc#1274637 * bsc#1274645 * bsc#1274646 * bsc#1274651 * bsc#1274659 * bsc#1274662 * bsc#1274665 * bsc#1274678 * bsc#1274681 * bsc#1274699 * bsc#1274700 * bsc#1274705 * bsc#1274710 * bsc#1274725 * bsc#1274737 * bsc#1274800 * bsc#1274801 * bsc#1274803 * bsc#1274804 * bsc#1274834 * bsc#1274859 * bsc#1274873 * bsc#1274881 * bsc#1274888 * bsc#1274896 * bsc#1274898 * bsc#1274902 * bsc#1274908 * bsc#1274953 * bsc#1275083 * bsc#1275088 * bsc#1275094 * bsc#1275125 * bsc#1275161 * bsc#1275164 * bsc#1275169 * bsc#1275301 * bsc#1275303 * bsc#1275304 * bsc#1275305 * bsc#1275307 * bsc#1275470 * bsc#1275506 * bsc#1275517 * bsc#1275535 * bsc#1275540 * bsc#1275583 * bsc#1275650 * bsc#1275685 * bsc#1275687 * bsc#1275688 * bsc#1275695 * bsc#1275696 * bsc#1275704 * bsc#1275784 * bsc#1275810 * bsc#1275827 * bsc#1275864 * bsc#1275867 * bsc#1275870 * bsc#1275871 * bsc#1275923 * bsc#1275950 * bsc#1275970 * bsc#1275976 * bsc#1275985 * bsc#1276006 * bsc#1276343 * bsc#1276346 * bsc#1276350 * bsc#1276354 * bsc#1276363 * bsc#1276395 * bsc#1276445 * bsc#1276446 * bsc#1276452 * bsc#1276479 * bsc#1276502 * bsc#1276517 * bsc#1276528 * bsc#1276542 * bsc#1276547 * bsc#1276665 * bsc#1276767 * bsc#1276840 * bsc#1276922 * bsc#1277022 * bsc#1277023 * bsc#1277034 * bsc#1277057 * bsc#1277066 * bsc#1277073 * bsc#1277089 * bsc#1277095 * bsc#1277179 * bsc#1277235 * bsc#1277275 * bsc#1277329 * bsc#1277350 * bsc#1277391 * bsc#1277522 * bsc#1277553 * bsc#1277561 * bsc#1277571 * bsc#1277637 * bsc#1277728 * bsc#1277730 * bsc#1277738 * bsc#1277893 * bsc#1277908 * bsc#1278113 * bsc#1278132 * bsc#1278233 * bsc#1278236 * bsc#1278240 * bsc#1278253 * bsc#1278293 * bsc#1278294 * bsc#1278334 * bsc#1279422 * bsc#1279487 * bsc#1279499 * bsc#1279607 * bsc#1279813 Cross-References: * CVE-2024-35973 * CVE-2025-39964 * CVE-2025-40022 * CVE-2025-40277 * CVE-2025-68214 * CVE-2026-23003 * CVE-2026-23443 * CVE-2026-31483 * CVE-2026-43116 * CVE-2026-43125 * CVE-2026-43134 * CVE-2026-43257 * CVE-2026-43277 * CVE-2026-43363 * CVE-2026-43416 * CVE-2026-45941 * CVE-2026-46070 * CVE-2026-46107 * CVE-2026-46108 * CVE-2026-46128 * CVE-2026-52912 * CVE-2026-52920 * CVE-2026-52925 * CVE-2026-52939 * CVE-2026-52946 * CVE-2026-53001 * CVE-2026-53059 * CVE-2026-53061 * CVE-2026-53077 * CVE-2026-53089 * CVE-2026-53091 * CVE-2026-53149 * CVE-2026-53163 * CVE-2026-53219 * CVE-2026-53220 * CVE-2026-53223 * CVE-2026-53228 * CVE-2026-53238 * CVE-2026-53264 * CVE-2026-53265 * CVE-2026-53309 * CVE-2026-53374 * CVE-2026-53388 * CVE-2026-53403 * CVE-2026-63810 * CVE-2026-63823 * CVE-2026-63860 * CVE-2026-63868 * CVE-2026-63887 * CVE-2026-63888 * CVE-2026-63890 * CVE-2026-63891 * CVE-2026-63892 * CVE-2026-63898 * CVE-2026-63920 * CVE-2026-63928 * CVE-2026-63962 * CVE-2026-63990 * CVE-2026-64001 * CVE-2026-64002 * CVE-2026-64005 * CVE-2026-64007 * CVE-2026-64010 * CVE-2026-64011 * CVE-2026-64015 * CVE-2026-64088 * CVE-2026-64103 * CVE-2026-64109 * CVE-2026-64113 * CVE-2026-64114 * CVE-2026-64115 * CVE-2026-64118 * CVE-2026-64164 * CVE-2026-64178 * CVE-2026-64190 * CVE-2026-64266 * CVE-2026-64304 * CVE-2026-64306 * CVE-2026-64312 * CVE-2026-64313 * CVE-2026-64315 * CVE-2026-64317 * CVE-2026-64322 * CVE-2026-64323 * CVE-2026-64332 * CVE-2026-64333 * CVE-2026-64334 * CVE-2026-64340 * CVE-2026-64341 * CVE-2026-64343 * CVE-2026-64344 * CVE-2026-64380 * CVE-2026-64381 * CVE-2026-64408 * CVE-2026-64411 * CVE-2026-64412 * CVE-2026-64423 * CVE-2026-64436 * CVE-2026-64470 * CVE-2026-64471 * CVE-2026-64512 * CVE-2026-64513 * CVE-2026-64541 * CVE-2026-64544 * CVE-2026-64547 * CVE-2026-64551 * CVE-2026-64553 * CVE-2026-64562 * CVE-2026-64567 * CVE-2026-64581 * CVE-2026-64582 * CVE-2026-68082 * CVE-2026-68093 * CVE-2026-68111 * CVE-2026-68117 * CVE-2026-68121 * CVE-2026-68123 * CVE-2026-68129 * CVE-2026-68141 * CVE-2026-68143 * CVE-2026-68153 * CVE-2026-68154 * CVE-2026-68155 * CVE-2026-68156 * CVE-2026-68158 * CVE-2026-68159 * CVE-2026-68188 * CVE-2026-68197 * CVE-2026-68198 * CVE-2026-68202 * CVE-2026-68234 * CVE-2026-68238 * CVE-2026-68277 * CVE-2026-68278 * CVE-2026-68279 * CVE-2026-68284 * CVE-2026-68289 * CVE-2026-68299 * CVE-2026-68300 * CVE-2026-68313 * CVE-2026-68315 * CVE-2026-68320 * CVE-2026-68325 * CVE-2026-68328 * CVE-2026-68329 * CVE-2026-68338 * CVE-2026-68349 * CVE-2026-68351 * CVE-2026-68357 * CVE-2026-68363 * CVE-2026-68397 * CVE-2026-68398 * CVE-2026-68405 * CVE-2026-68410 * CVE-2026-68425 * CVE-2026-68426 * CVE-2026-68428 * CVE-2026-68432 * CVE-2026-68433 * CVE-2026-68450 * CVE-2026-68480 * CVE-2026-72017 * CVE-2026-72020 * CVE-2026-72036 * CVE-2026-72083 * CVE-2026-72084 * CVE-2026-72086 * CVE-2026-72108 * CVE-2026-72135 * CVE-2026-72138 * CVE-2026-72142 * CVE-2026-72164 * CVE-2026-72251 * CVE-2026-72282 * CVE-2026-72284 * CVE-2026-72296 * CVE-2026-72297 * CVE-2026-72323 * CVE-2026-72339 * CVE-2026-72389 * CVE-2026-72421 * CVE-2026-72450 * CVE-2026-72466 * CVE-2026-72487 * CVE-2026-72502 * CVE-2026-74255 * CVE-2026-74261 * CVE-2026-74265 * CVE-2026-74271 * CVE-2026-74278 * CVE-2026-74279 * CVE-2026-74296 * CVE-2026-74297 * CVE-2026-74302 * CVE-2026-74334 * CVE-2026-74341 * CVE-2026-74377 * CVE-2026-74378 * CVE-2026-74382 * CVE-2026-74388 * CVE-2026-74406 * CVE-2026-74416 * CVE-2026-74417 * CVE-2026-74454 * CVE-2026-74479 * CVE-2026-74482 * CVE-2026-74488 * CVE-2026-74495 * CVE-2026-74496 * CVE-2026-74508 * CVE-2026-74510 * CVE-2026-74519 * CVE-2026-74537 * CVE-2026-74548 * CVE-2026-74550 * CVE-2026-74556 * CVE-2026-74557 * CVE-2026-74582 * CVE-2026-74584 * CVE-2026-74669 * CVE-2026-74673 * CVE-2026-74705 * CVE-2026-74743 * CVE-2026-80534 * CVE-2026-80574 * CVE-2026-80580 * CVE-2026-80590 * CVE-2026-80603 * CVE-2026-80609 * CVE-2026-80714 * CVE-2026-80737 * CVE-2026-80765 * CVE-2026-80819 * CVE-2026-80909 CVSS scores: * CVE-2024-35973 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-35973 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39964 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-39964 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-39964 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-39964 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-40022 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2025-40022 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2025-40277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-40277 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2025-68214 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2025-68214 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23003 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23003 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-23003 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23003 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23443 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-23443 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-23443 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31483 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-31483 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-31483 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43116 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43116 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43125 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43125 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43134 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43134 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-43257 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43257 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43277 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43363 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-43416 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45941 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-45941 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45941 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46070 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-46070 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-46107 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-46107 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-46107 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-46108 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46108 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46128 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-46128 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52912 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52912 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52912 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52920 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L * CVE-2026-52920 ( NVD ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-52925 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-52925 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52925 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52939 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52939 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52946 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53001 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53059 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53059 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53059 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53061 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N * CVE-2026-53061 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53077 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53077 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53077 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53089 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53089 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53089 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53091 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53091 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-53091 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:H * CVE-2026-53091 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53149 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53149 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53219 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53220 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53223 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53228 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53228 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53238 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53238 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53238 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53265 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53265 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53309 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-53309 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-53309 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53374 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53374 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53374 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53403 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-53403 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53403 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63810 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63810 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63823 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63823 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63823 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63860 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63860 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L * CVE-2026-63860 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63868 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-63868 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-63887 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63887 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63887 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63888 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63888 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63888 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63890 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63890 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63891 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63891 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-63892 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63892 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63898 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63898 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63920 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63920 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63920 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63928 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63928 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63962 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63962 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63990 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63990 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64001 ( SUSE ): 5.6 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64001 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64002 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64002 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64002 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64005 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-64005 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:H * CVE-2026-64005 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64007 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64007 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64007 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64010 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64011 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64015 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64015 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64088 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64088 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64088 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64103 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64103 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64103 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64113 ( SUSE ): 5.3 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64113 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64114 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64115 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64118 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64118 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64118 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64164 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64164 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64164 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64178 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-64178 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64178 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64190 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64190 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64190 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64266 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64266 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64304 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64306 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-64306 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-64306 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64312 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64313 ( SUSE ): 7.4 CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-64313 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64313 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64315 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64317 ( SUSE ): 5.2 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64317 ( SUSE ): 6.1 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64317 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64322 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64322 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64322 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64323 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64323 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64332 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64332 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64333 ( SUSE ): 7.0 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64333 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64333 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64334 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64334 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64334 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64340 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64340 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64340 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64341 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64343 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64343 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( SUSE ): 5.4 CVSS:4.0/AV:P/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64344 ( SUSE ): 6.3 CVSS:3.1/AV:P/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64344 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64380 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64380 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64381 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64381 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64408 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64408 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64411 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64411 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64411 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64412 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64412 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64412 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64436 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64436 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64470 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64471 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64512 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64513 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64541 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64541 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64541 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64544 ( SUSE ): 6.7 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64544 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64547 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64547 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64547 ( NVD ): 8.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64551 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-64551 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64553 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64562 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64562 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64567 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64567 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64567 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64581 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64581 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64581 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64582 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68082 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68082 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68082 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68093 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:H/SC:L/SI:L/SA:H * CVE-2026-68093 ( SUSE ): 6.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:H * CVE-2026-68111 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68111 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68117 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68117 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68121 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68121 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68123 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68123 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68123 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68129 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68129 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68129 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68141 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68141 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68141 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68143 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68143 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68143 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68153 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68153 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68153 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68154 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68154 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68154 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68155 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68155 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68155 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68156 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68156 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68156 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68158 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68158 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68158 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68159 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68159 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68159 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68188 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68197 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68198 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68198 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68202 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68234 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68238 ( SUSE ): 1.8 CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68238 ( SUSE ): 1.9 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68277 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68278 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68278 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68279 ( SUSE ): 2.4 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-68279 ( SUSE ): 2.4 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-68284 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68284 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68284 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68289 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-68289 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L * CVE-2026-68299 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68299 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68300 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68313 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68315 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68320 ( NVD ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-68325 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68328 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68329 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68338 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68338 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68349 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68351 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68357 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68363 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68397 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68405 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68410 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68425 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68425 ( NVD ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68426 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68426 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68428 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68432 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68432 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-68433 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68433 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H * CVE-2026-68450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68480 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-72017 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-72017 ( SUSE ): 2.3 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L * CVE-2026-72020 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72020 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72020 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72036 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72036 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72036 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72083 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72084 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72086 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72108 ( SUSE ): 4.6 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N * CVE-2026-72108 ( SUSE ): 3.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L * CVE-2026-72108 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72135 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72135 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72135 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72138 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72138 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72142 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72164 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72164 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72251 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72251 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72251 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72282 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72282 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72284 ( SUSE ): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-72284 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-72296 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72296 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72296 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-72297 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-72297 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-72323 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-72323 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72323 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72339 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72339 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72339 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72389 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72421 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72421 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72421 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-72450 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72450 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72450 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72466 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72466 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72487 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72487 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-72502 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72502 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74255 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74255 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74261 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74265 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74271 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74278 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-74278 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-74279 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74279 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74296 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74296 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74297 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74297 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74302 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74302 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74334 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74334 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74341 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74341 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74377 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74377 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74377 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74378 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74378 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74378 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74382 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74382 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74388 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74388 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74406 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74406 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74416 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74417 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74417 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74454 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74454 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-74454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74479 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74479 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74482 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74482 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74488 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74488 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74495 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74495 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74508 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74508 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74508 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74510 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74519 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74519 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74537 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74537 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74548 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74550 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74550 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74556 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-74556 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74557 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N * CVE-2026-74557 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-74582 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74582 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74584 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-74584 ( SUSE ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:L * CVE-2026-74584 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-74669 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74673 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74673 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-74705 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74705 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74743 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74743 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74743 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80534 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80534 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80574 ( SUSE ): 6.8 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80574 ( NVD ): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80580 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80580 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80580 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80590 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80590 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80590 ( NVD ): 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H * CVE-2026-80603 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-80603 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-80603 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-80609 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80609 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80714 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80714 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80714 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80737 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80737 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80737 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80765 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80765 ( SUSE ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-80819 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80819 ( SUSE ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80909 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80909 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 234 vulnerabilities and has seven security fixes can now be installed. ## Description: The SUSE Linux Enterprise 12 SP5 kernel was updated to fix various security issues: The following security issues were fixed: * CVE-2025-40277: drm/vmwgfx: Validate command header size against (bsc#1254894). * CVE-2025-68214: timers: Fix NULL function pointer race in timer_shutdown_sync() (bsc#1255225). * CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack (bsc#1264619). * CVE-2026-43125: dlm: validate length in dlm_search_rsb_tree (bsc#1264541). * CVE-2026-43134: Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ (bsc#1264308). * CVE-2026-43257: media: cx88: Add missing unmap in snd_cx88_hw_params() (bsc#1264296). * CVE-2026-43277: ACPI / APEI: Make GHES estatus header validation more user friendly (bsc#1264594). * CVE-2026-43363: x86/apic: Disable x2apic on resume if the kernel expects so (bsc#1265068). * CVE-2026-43416: powerpc, perf: Check that current->mm is alive before getting user callchain (bsc#1265121). * CVE-2026-45941: tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure (bsc#1266920). * CVE-2026-46070: md/raid5: validate payload size before accessing journal metadata (bsc#1267501). * CVE-2026-46107: dm-thin: fix metadata refcount underflow (bsc#1267612). * CVE-2026-46108: ipmi:si: Return state to normal if message allocation fails (bsc#1267615). * CVE-2026-46128: ipmi: Check event message buffer response for bad data (bsc#1267643). * CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued (bsc#1269000). * CVE-2026-52920: netfilter: xt_policy: fix strict mode inbound policy matching (bsc#1269013). * CVE-2026-52925: vrf: Fix a potential NPD when removing a port from a VRF (bsc#1268987). * CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion (bsc#1268972). * CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (bsc#1269113). * CVE-2026-53001: netfilter: xtables: restrict several matches to inet family (bsc#1269114). * CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). * CVE-2026-53061: dm cache: fix dirty mapping checking in passthrough mode switching (bsc#1269685). * CVE-2026-53077: net/rds: Restrict use of RDS/IB to the initial network namespace (bsc#1269412). * CVE-2026-53089: bpf: Fix use-after-free in offloaded map/prog info fill (bsc#1269783). * CVE-2026-53091: net: do not use skb_mac_header() in qdisc_pkt_len_init() (bsc#1269530). * CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). * CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers (bsc#1269686). * CVE-2026-53220: netfilter: revalidate bridge ports (bsc#1269381). * CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs (bsc#1269301). * CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads (bsc#1269256). * CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths (bsc#1269774). * CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). * CVE-2026-53309: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (bsc#1269815). * CVE-2026-53403: fbdev: Fix fb_new_modelist to prevent null-ptr-deref in (bsc#1271731). * CVE-2026-63810: block: Avoid mounting the bdev pseudo-filesystem in userspace (bsc#1272297). * CVE-2026-63823: security: don't use RCU accessors for cred->session_keyring (bsc#1272182). * CVE-2026-63860: RDMA/core: Prefer NLA_NUL_STRING (bsc#1272429). * CVE-2026-63868: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (bsc#1272497). * CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). * CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). * CVE-2026-63890: scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (bsc#1272426). * CVE-2026-63891: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (bsc#1272641). * CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). * CVE-2026-63962: usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() (bsc#1272482). * CVE-2026-63990: bonding: refuse to enslave CAN devices (bsc#1273027). * CVE-2026-64001: ALSA: pcm: oss: Fix setup list UAF on proc write error (bsc#1273734). * CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). * CVE-2026-64005: net/smc: Do not re-initialize smc hashtables (bsc#1273831). * CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). * CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882). * CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891). * CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762). * CVE-2026-64088: batman-adv: tt: fix negative tt_buff_len (bsc#1273463). * CVE-2026-64103: scsi: isci: Fix use-after-free in device removal path (bsc#1273759). * CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748). * CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning (bsc#1272262). * CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). * CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). * CVE-2026-64118: qed: fix double free in qed_cxt_tables_alloc() (bsc#1273749). * CVE-2026-64178: Bluetooth: bnep: Fix UAF read of dev->name (bsc#1273946). * CVE-2026-64190: net: team: fix NULL pointer dereference in team_xmit during mode change (bsc#1272210). * CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944). * CVE-2026-64306: crypto: drbg - Fix returning success on failure in CTR_DRBG (bsc#1273939). * CVE-2026-64312: crypto: pcrypt - restore callback for non-parallel fallback (bsc#1273968). * CVE-2026-64313: crypto: ecc - Fix carry overflow in vli multiplication (bsc#1273940). * CVE-2026-64315: printk: add print_hex_dump_devel() (bsc#1274028). * CVE-2026-64317: isofs: bound Rock Ridge symlink components to the SL record (bsc#1273936). * CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count (bsc#1273958). * CVE-2026-64323: udf: validate VAT header length against the VAT inode size (bsc#1273305). * CVE-2026-64332: USB: ulpi: fix memory leak on registration failure (bsc#1273285). * CVE-2026-64333: USB: serial: digi_acceleport: fix write buffer corruption (bsc#1273933). * CVE-2026-64334: USB: serial: digi_acceleport: fix hard lockup on disconnect (bsc#1273942). * CVE-2026-64340: USB: legousbtower: fix use-after-free on disconnect race (bsc#1274003). * CVE-2026-64341: USB: iowarrior: fix use-after-free on disconnect race (bsc#1273895). * CVE-2026-64343: USB: ldusb: fix use-after-free on disconnect race (bsc#1273974). * CVE-2026-64344: USB: idmouse: simplify disconnect handling (bsc#1274019). * CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard() (bsc#1273860). * CVE-2026-64408: Bluetooth: bnep: pin L2CAP connection during netdev registration (bsc#1273778). * CVE-2026-64411: netfilter: ebtables: terminate table name before find_table_lock() (bsc#1274077). * CVE-2026-64412: netfilter: ebtables: module names must be null-terminated (bsc#1273780). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). * CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states (bsc#1274277). * CVE-2026-64470: Bluetooth: btusb: fix use-after-free on marvell probe failure (bsc#1273892). * CVE-2026-64471: Bluetooth: btusb: fix use-after-free on registration failure (bsc#1274278). * CVE-2026-64512: ACPI: CPPC: Suppress UBSAN warning caused by field misuse (bsc#1273597). * CVE-2026-64513: KVM: x86: Move update_cr8_intercept() to lapic.c (bsc#1273327). * CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). * CVE-2026-64544: crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (bsc#1273316). * CVE-2026-64547: net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (bsc#1273319). * CVE-2026-64551: sctp: validate STALE_COOKIE cause length before reading staleness (bsc#1273813). * CVE-2026-64553: net: psample: fix info leak in PSAMPLE_ATTR_DATA (bsc#1273336). * CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930). * CVE-2026-64567: btrfs: reject free space cache with more entries than pages (bsc#1274006). * CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). * CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (bsc#1274040). * CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers() (bsc#1274581). * CVE-2026-68093: KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug (bsc#1274725). * CVE-2026-68111: drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (bsc#1274873). * CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (bsc#1274881). * CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). * CVE-2026-68123: net: openvswitch: don't call pad_packet if not necessary (bsc#1275169). * CVE-2026-68129: gve: fix Rx queue stall on alloc failure (bsc#1275517). * CVE-2026-68141: net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() (bsc#1275094). * CVE-2026-68143: net: slip: serialize receive against buffer reallocation (bsc#1275583). * CVE-2026-68153: libceph: remove debugfs files before client teardown (bsc#1275301). * CVE-2026-68154: libceph: reject zero bucket types in crush_decode (bsc#1275303). * CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). * CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after authorizer update (bsc#1275305). * CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). * CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). * CVE-2026-68188: Bluetooth: RFCOMM: Fix session UAF in set_termios (bsc#1274953). * CVE-2026-68197: wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper (bsc#1274804). * CVE-2026-68198: wifi: ath6kl: fix use-after-free in aggr_reset_state() (bsc#1274803). * CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). * CVE-2026-68234: drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved (bsc#1275650). * CVE-2026-68238: drm/amdgpu: Release VFCT ACPI table reference (bsc#1275704). * CVE-2026-68277: drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (bsc#1275125). * CVE-2026-68278: drm/dp/mst: fix buffer overflows in sideband chunk accumulation (bsc#1275870). * CVE-2026-68279: drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (bsc#1275871). * CVE-2026-68284: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (bsc#1275970). * CVE-2026-68289: tipc: keep the skb in rcv queue until the whole data is read (bsc#1275976). * CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (bsc#1275088). * CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL (bsc#1275083). * CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit (bsc#1274665). * CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq() (bsc#1274662). * CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (bsc#1274659). * CVE-2026-68325: iommu/amd: Bound the early ACPI HID map (bsc#1274651). * CVE-2026-68328: nfp: Check resource mutex allocation (bsc#1274646). * CVE-2026-68329: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (bsc#1274645). * CVE-2026-68338: net/packet: avoid fanout hook re-registration after unregister (bsc#1274637). * CVE-2026-68349: wifi: carl9170: fix buffer overflow in rx_stream failover path (bsc#1274681). * CVE-2026-68351: wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read (bsc#1274678). * CVE-2026-68357: watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() (bsc#1274737). * CVE-2026-68363: wifi: ath9k: hif_usb: don't dereference hif_dev after re- arming firmware request (bsc#1275164). * CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). * CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). * CVE-2026-68405: wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (bsc#1274896). * CVE-2026-68410: wifi: libertas: fix memory leak in helper_firmware_cb() (bsc#1274710). * CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1274700). * CVE-2026-68426: esp: remove the skb from the chain when it's enqueued in cryptd_wq (bsc#1274705). * CVE-2026-68428: KVM: x86/mmu: Fix use-after-free on vendor module reload (bsc#1274699). * CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink (bsc#1274800). * CVE-2026-68433: libceph: bound get_version reply decode to front len (bsc#1274801). * CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert (bsc#1274834). * CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). * CVE-2026-72017: net: macb: drop in-flight Tx SKBs on close (bsc#1276840). * CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). * CVE-2026-72036: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1277034). * CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). * CVE-2026-72084: scsi: target: Write NULL to *port_nexus_ptr if no ISID (bsc#1275540). * CVE-2026-72086: scsi: xen: scsiback: Free unsubmitted command instead of double-putting it (bsc#1277179). * CVE-2026-72108: dm thin metadata: fix metadata snapshot consistency on commit failure (bsc#1277350). * CVE-2026-72135: tpm: Make the TPM character devices non-seekable (bsc#1277571). * CVE-2026-72138: xen/gntdev: fix error handling in ioctl (bsc#1277235). * CVE-2026-72142: i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (bsc#1277522). * CVE-2026-72164: ocfs2: avoid moving extents to occupied clusters (bsc#1277553). * CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). * CVE-2026-72282: KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers (bsc#1277728). * CVE-2026-72284: KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs (bsc#1277730). * CVE-2026-72296: net: ife: require ETH_HLEN to be pullable in ife_decode() (bsc#1275923). * CVE-2026-72297: net: atm: reject out-of-range traffic classes in QoS validation (bsc#1277738). * CVE-2026-72323: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() (bsc#1275985). * CVE-2026-72339: qede: fix off-by-one in BD ring consumption on build_skb failure (bsc#1276006). * CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). * CVE-2026-72421: ipv4: fib: Don't ignore error route in local/main tables (bsc#1277023). * CVE-2026-72450: xfrm: validate selector family and prefixlen during match (bsc#1278113). * CVE-2026-72466: xprtrdma: Fix bcall rep leak and unbounded peek (bsc#1277057). * CVE-2026-72487: PCI: Introduce named defines for PCI ROM (bsc#1276767). * CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (bsc#1276542). * CVE-2026-74255: tipc: fix UAF in tipc_l2_send_msg() (bsc#1276547). * CVE-2026-74261: ALSA: seq: avoid stale FIFO cells during resize (bsc#1276528). * CVE-2026-74265: net: mana: initialize gdma queue id to INVALID_QUEUE_ID (bsc#1276517). * CVE-2026-74271: power: supply: core: Delete two error messages for a failed memory allocation in power_supply_check_supplies() (bsc#1276502). * CVE-2026-74278: ALSA: seq: Fix kernel heap address leak in bounce_error_event() (bsc#1278132). * CVE-2026-74279: crypto: cavium/cpt - fix DMA cleanup using wrong loop index (bsc#1276479). * CVE-2026-74296: RDMA/mlx5: Release the HW-provided UAR index rather than the SW one (bsc#1276452). * CVE-2026-74297: RDMA/mlx5: Fix undefined shift of user RQ WQE size (bsc#1276446). * CVE-2026-74302: Bluetooth: hci_core: Fix UAF in hci_unregister_dev() (bsc#1276445). * CVE-2026-74334: RDMA/nldev: Fix locking when accessing mr->pd (bsc#1277095). * CVE-2026-74341: wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (bsc#1277089). * CVE-2026-74377: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path (bsc#1278236). * CVE-2026-74378: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (bsc#1278233). * CVE-2026-74382: net/sched: cls_bpf: prevent unbounded recursion in offload rollback (bsc#1278240). * CVE-2026-74388: ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data (bsc#1278253). * CVE-2026-74406: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive() (bsc#1276395). * CVE-2026-74416: drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (bsc#1276343). * CVE-2026-74417: drm/radeon: fix integer overflow in radeon_align_pitch() (bsc#1276363). * CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073). * CVE-2026-74479: net: pktgen: fix proc entry use-after-free (bsc#1276354). * CVE-2026-74482: mm/huge_memory: unlock i_mmap_rwsem before releasing after- split folios (bsc#1276346). * CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350). * CVE-2026-74495: igbvf: Fix leak in TX DMA error cleanup (bsc#1275864). * CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). * CVE-2026-74508: Bluetooth: HIDP: reject frames without a transaction header (bsc#1277893). * CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation (bsc#1275950). * CVE-2026-74519: pinctrl: devicetree: don't free uninitialized dev_name on error path (bsc#1275810). * CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). * CVE-2026-74548: forcedeth: fix UAF of txrx_stats in nv_remove (bsc#1275695). * CVE-2026-74550: net: do not send ICMP/NDISC Redirects when peer allocation fails (bsc#1275688). * CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). * CVE-2026-74557: scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer (bsc#1275685). * CVE-2026-74582: af_packet: fix raw sockets over 6in4 tunnel (bsc#1275784). * CVE-2026-74584: RDMA/bnxt_re: zero shared page before exposing to userspace (bsc#1277066). * CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). * CVE-2026-74673: Input: evdev - fix information leak in evdev_pass_values() (bsc#1277637). * CVE-2026-74705: udp: fix potential use-after-free in tunnel segmentation (bsc#1276922). * CVE-2026-74743: macvlan: inherit needed_headroom and needed_tailroom from lowerdev (bsc#1277908). * CVE-2026-80534: xfs: fix ilock leak on error in xfs_dq_get_next_id (bsc#1277022). * CVE-2026-80574: Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (bsc#1277329). * CVE-2026-80580: fbdev: bound mode sysfs output to the sysfs buffer (bsc#1278294). * CVE-2026-80590: inet: frags: strip GSO state from fragments before reassembly (bsc#1277275). * CVE-2026-80603: netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read (bsc#1278293). * CVE-2026-80609: qede: fix out-of-bounds check for cqe->len_list (bsc#1278334). * CVE-2026-80714: ipvs: do not propagate one-packet flag to synced conns (bsc#1277561). * CVE-2026-80737: serial: amba-pl011: synchronize DMA teardown (bsc#1279487). * CVE-2026-80765: HID: hyperv: validate initial device info bounds (bsc#1279499). * CVE-2026-80819: Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (bsc#1279607). * CVE-2026-80909: drm/amdgpu: Reject UVD message with invalid number of h265 refs (bsc#1279422). The following non security issues were fixed: * fcntl: Fix potential deadlock in send_sig{io, urg}() (bsc#1269113). * mkspec-dtb: Move DTS prefix into package list. * mkspec-dtb: Move provides-obsoletes to package list. * mkspec-dtb: Put per-architecture package lists into a hash. * mkspec-dtb: re-indent. * net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). * RDMA/mlx5: Fix integer overflow of user QP buffer size (git-fixes). * s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1270264). * s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1270264). * smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). * smb: client: harden POSIX SID length parsing (bsc#1273557). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-4282 * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4282 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4282 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (nosrc) * kernel-default-4.12.14-122.328.1 * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kernel-default-debugsource-4.12.14-122.328.1 * kernel-default-kgraft-devel-4.12.14-122.328.1 * kernel-default-debuginfo-4.12.14-122.328.1 * kernel-default-kgraft-4.12.14-122.328.1 * kgraft-patch-4_12_14-122_328-default-1-8.5.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * kernel-default-debugsource-4.12.14-122.328.1 * kernel-syms-4.12.14-122.328.1 * cluster-md-kmp-default-debuginfo-4.12.14-122.328.1 * dlm-kmp-default-debuginfo-4.12.14-122.328.1 * kernel-default-base-debuginfo-4.12.14-122.328.1 * kernel-default-debuginfo-4.12.14-122.328.1 * ocfs2-kmp-default-4.12.14-122.328.1 * dlm-kmp-default-4.12.14-122.328.1 * gfs2-kmp-default-debuginfo-4.12.14-122.328.1 * ocfs2-kmp-default-debuginfo-4.12.14-122.328.1 * gfs2-kmp-default-4.12.14-122.328.1 * cluster-md-kmp-default-4.12.14-122.328.1 * kernel-default-devel-4.12.14-122.328.1 * kernel-default-base-4.12.14-122.328.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-4.12.14-122.328.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (x86_64) * kernel-default-devel-debuginfo-4.12.14-122.328.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * kernel-source-4.12.14-122.328.1 * kernel-devel-4.12.14-122.328.1 * kernel-macros-4.12.14-122.328.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x) * kernel-default-man-4.12.14-122.328.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * kernel-default-debugsource-4.12.14-122.328.1 * kernel-syms-4.12.14-122.328.1 * cluster-md-kmp-default-debuginfo-4.12.14-122.328.1 * dlm-kmp-default-debuginfo-4.12.14-122.328.1 * kernel-default-base-debuginfo-4.12.14-122.328.1 * kernel-default-debuginfo-4.12.14-122.328.1 * ocfs2-kmp-default-4.12.14-122.328.1 * dlm-kmp-default-4.12.14-122.328.1 * gfs2-kmp-default-debuginfo-4.12.14-122.328.1 * ocfs2-kmp-default-debuginfo-4.12.14-122.328.1 * gfs2-kmp-default-4.12.14-122.328.1 * cluster-md-kmp-default-4.12.14-122.328.1 * kernel-default-devel-4.12.14-122.328.1 * kernel-default-base-4.12.14-122.328.1 * kernel-default-devel-debuginfo-4.12.14-122.328.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (nosrc x86_64) * kernel-default-4.12.14-122.328.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * kernel-source-4.12.14-122.328.1 * kernel-devel-4.12.14-122.328.1 * kernel-macros-4.12.14-122.328.1 ## References: * https://www.suse.com/security/cve/CVE-2024-35973.html * https://www.suse.com/security/cve/CVE-2025-39964.html * https://www.suse.com/security/cve/CVE-2025-40022.html * https://www.suse.com/security/cve/CVE-2025-40277.html * https://www.suse.com/security/cve/CVE-2025-68214.html * https://www.suse.com/security/cve/CVE-2026-23003.html * https://www.suse.com/security/cve/CVE-2026-23443.html * https://www.suse.com/security/cve/CVE-2026-31483.html * https://www.suse.com/security/cve/CVE-2026-43116.html * https://www.suse.com/security/cve/CVE-2026-43125.html * https://www.suse.com/security/cve/CVE-2026-43134.html * https://www.suse.com/security/cve/CVE-2026-43257.html * https://www.suse.com/security/cve/CVE-2026-43277.html * https://www.suse.com/security/cve/CVE-2026-43363.html * https://www.suse.com/security/cve/CVE-2026-43416.html * https://www.suse.com/security/cve/CVE-2026-45941.html * https://www.suse.com/security/cve/CVE-2026-46070.html * https://www.suse.com/security/cve/CVE-2026-46107.html * https://www.suse.com/security/cve/CVE-2026-46108.html * https://www.suse.com/security/cve/CVE-2026-46128.html * https://www.suse.com/security/cve/CVE-2026-52912.html * https://www.suse.com/security/cve/CVE-2026-52920.html * https://www.suse.com/security/cve/CVE-2026-52925.html * https://www.suse.com/security/cve/CVE-2026-52939.html * https://www.suse.com/security/cve/CVE-2026-52946.html * https://www.suse.com/security/cve/CVE-2026-53001.html * https://www.suse.com/security/cve/CVE-2026-53059.html * https://www.suse.com/security/cve/CVE-2026-53061.html * https://www.suse.com/security/cve/CVE-2026-53077.html * https://www.suse.com/security/cve/CVE-2026-53089.html * https://www.suse.com/security/cve/CVE-2026-53091.html * https://www.suse.com/security/cve/CVE-2026-53149.html * https://www.suse.com/security/cve/CVE-2026-53163.html * https://www.suse.com/security/cve/CVE-2026-53219.html * https://www.suse.com/security/cve/CVE-2026-53220.html * https://www.suse.com/security/cve/CVE-2026-53223.html * https://www.suse.com/security/cve/CVE-2026-53228.html * https://www.suse.com/security/cve/CVE-2026-53238.html * https://www.suse.com/security/cve/CVE-2026-53264.html * https://www.suse.com/security/cve/CVE-2026-53265.html * https://www.suse.com/security/cve/CVE-2026-53309.html * https://www.suse.com/security/cve/CVE-2026-53374.html * https://www.suse.com/security/cve/CVE-2026-53388.html * https://www.suse.com/security/cve/CVE-2026-53403.html * https://www.suse.com/security/cve/CVE-2026-63810.html * https://www.suse.com/security/cve/CVE-2026-63823.html * https://www.suse.com/security/cve/CVE-2026-63860.html * https://www.suse.com/security/cve/CVE-2026-63868.html * https://www.suse.com/security/cve/CVE-2026-63887.html * https://www.suse.com/security/cve/CVE-2026-63888.html * https://www.suse.com/security/cve/CVE-2026-63890.html * https://www.suse.com/security/cve/CVE-2026-63891.html * https://www.suse.com/security/cve/CVE-2026-63892.html * https://www.suse.com/security/cve/CVE-2026-63898.html * https://www.suse.com/security/cve/CVE-2026-63920.html * https://www.suse.com/security/cve/CVE-2026-63928.html * https://www.suse.com/security/cve/CVE-2026-63962.html * https://www.suse.com/security/cve/CVE-2026-63990.html * https://www.suse.com/security/cve/CVE-2026-64001.html * https://www.suse.com/security/cve/CVE-2026-64002.html * https://www.suse.com/security/cve/CVE-2026-64005.html * https://www.suse.com/security/cve/CVE-2026-64007.html * https://www.suse.com/security/cve/CVE-2026-64010.html * https://www.suse.com/security/cve/CVE-2026-64011.html * https://www.suse.com/security/cve/CVE-2026-64015.html * https://www.suse.com/security/cve/CVE-2026-64088.html * https://www.suse.com/security/cve/CVE-2026-64103.html * https://www.suse.com/security/cve/CVE-2026-64109.html * https://www.suse.com/security/cve/CVE-2026-64113.html * https://www.suse.com/security/cve/CVE-2026-64114.html * https://www.suse.com/security/cve/CVE-2026-64115.html * https://www.suse.com/security/cve/CVE-2026-64118.html * https://www.suse.com/security/cve/CVE-2026-64164.html * https://www.suse.com/security/cve/CVE-2026-64178.html * https://www.suse.com/security/cve/CVE-2026-64190.html * https://www.suse.com/security/cve/CVE-2026-64266.html * https://www.suse.com/security/cve/CVE-2026-64304.html * https://www.suse.com/security/cve/CVE-2026-64306.html * https://www.suse.com/security/cve/CVE-2026-64312.html * https://www.suse.com/security/cve/CVE-2026-64313.html * https://www.suse.com/security/cve/CVE-2026-64315.html * https://www.suse.com/security/cve/CVE-2026-64317.html * https://www.suse.com/security/cve/CVE-2026-64322.html * https://www.suse.com/security/cve/CVE-2026-64323.html * https://www.suse.com/security/cve/CVE-2026-64332.html * https://www.suse.com/security/cve/CVE-2026-64333.html * https://www.suse.com/security/cve/CVE-2026-64334.html * https://www.suse.com/security/cve/CVE-2026-64340.html * https://www.suse.com/security/cve/CVE-2026-64341.html * https://www.suse.com/security/cve/CVE-2026-64343.html * https://www.suse.com/security/cve/CVE-2026-64344.html * https://www.suse.com/security/cve/CVE-2026-64380.html * https://www.suse.com/security/cve/CVE-2026-64381.html * https://www.suse.com/security/cve/CVE-2026-64408.html * https://www.suse.com/security/cve/CVE-2026-64411.html * https://www.suse.com/security/cve/CVE-2026-64412.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64436.html * https://www.suse.com/security/cve/CVE-2026-64470.html * https://www.suse.com/security/cve/CVE-2026-64471.html * https://www.suse.com/security/cve/CVE-2026-64512.html * https://www.suse.com/security/cve/CVE-2026-64513.html * https://www.suse.com/security/cve/CVE-2026-64541.html * https://www.suse.com/security/cve/CVE-2026-64544.html * https://www.suse.com/security/cve/CVE-2026-64547.html * https://www.suse.com/security/cve/CVE-2026-64551.html * https://www.suse.com/security/cve/CVE-2026-64553.html * https://www.suse.com/security/cve/CVE-2026-64562.html * https://www.suse.com/security/cve/CVE-2026-64567.html * https://www.suse.com/security/cve/CVE-2026-64581.html * https://www.suse.com/security/cve/CVE-2026-64582.html * https://www.suse.com/security/cve/CVE-2026-68082.html * https://www.suse.com/security/cve/CVE-2026-68093.html * https://www.suse.com/security/cve/CVE-2026-68111.html * https://www.suse.com/security/cve/CVE-2026-68117.html * https://www.suse.com/security/cve/CVE-2026-68121.html * https://www.suse.com/security/cve/CVE-2026-68123.html * https://www.suse.com/security/cve/CVE-2026-68129.html * https://www.suse.com/security/cve/CVE-2026-68141.html * https://www.suse.com/security/cve/CVE-2026-68143.html * https://www.suse.com/security/cve/CVE-2026-68153.html * https://www.suse.com/security/cve/CVE-2026-68154.html * https://www.suse.com/security/cve/CVE-2026-68155.html * https://www.suse.com/security/cve/CVE-2026-68156.html * https://www.suse.com/security/cve/CVE-2026-68158.html * https://www.suse.com/security/cve/CVE-2026-68159.html * https://www.suse.com/security/cve/CVE-2026-68188.html * https://www.suse.com/security/cve/CVE-2026-68197.html * https://www.suse.com/security/cve/CVE-2026-68198.html * https://www.suse.com/security/cve/CVE-2026-68202.html * https://www.suse.com/security/cve/CVE-2026-68234.html * https://www.suse.com/security/cve/CVE-2026-68238.html * https://www.suse.com/security/cve/CVE-2026-68277.html * https://www.suse.com/security/cve/CVE-2026-68278.html * https://www.suse.com/security/cve/CVE-2026-68279.html * https://www.suse.com/security/cve/CVE-2026-68284.html * https://www.suse.com/security/cve/CVE-2026-68289.html * https://www.suse.com/security/cve/CVE-2026-68299.html * https://www.suse.com/security/cve/CVE-2026-68300.html * https://www.suse.com/security/cve/CVE-2026-68313.html * https://www.suse.com/security/cve/CVE-2026-68315.html * https://www.suse.com/security/cve/CVE-2026-68320.html * https://www.suse.com/security/cve/CVE-2026-68325.html * https://www.suse.com/security/cve/CVE-2026-68328.html * https://www.suse.com/security/cve/CVE-2026-68329.html * https://www.suse.com/security/cve/CVE-2026-68338.html * https://www.suse.com/security/cve/CVE-2026-68349.html * https://www.suse.com/security/cve/CVE-2026-68351.html * https://www.suse.com/security/cve/CVE-2026-68357.html * https://www.suse.com/security/cve/CVE-2026-68363.html * https://www.suse.com/security/cve/CVE-2026-68397.html * https://www.suse.com/security/cve/CVE-2026-68398.html * https://www.suse.com/security/cve/CVE-2026-68405.html * https://www.suse.com/security/cve/CVE-2026-68410.html * https://www.suse.com/security/cve/CVE-2026-68425.html * https://www.suse.com/security/cve/CVE-2026-68426.html * https://www.suse.com/security/cve/CVE-2026-68428.html * https://www.suse.com/security/cve/CVE-2026-68432.html * https://www.suse.com/security/cve/CVE-2026-68433.html * https://www.suse.com/security/cve/CVE-2026-68450.html * https://www.suse.com/security/cve/CVE-2026-68480.html * https://www.suse.com/security/cve/CVE-2026-72017.html * https://www.suse.com/security/cve/CVE-2026-72020.html * https://www.suse.com/security/cve/CVE-2026-72036.html * https://www.suse.com/security/cve/CVE-2026-72083.html * https://www.suse.com/security/cve/CVE-2026-72084.html * https://www.suse.com/security/cve/CVE-2026-72086.html * https://www.suse.com/security/cve/CVE-2026-72108.html * https://www.suse.com/security/cve/CVE-2026-72135.html * https://www.suse.com/security/cve/CVE-2026-72138.html * https://www.suse.com/security/cve/CVE-2026-72142.html * https://www.suse.com/security/cve/CVE-2026-72164.html * https://www.suse.com/security/cve/CVE-2026-72251.html * https://www.suse.com/security/cve/CVE-2026-72282.html * https://www.suse.com/security/cve/CVE-2026-72284.html * https://www.suse.com/security/cve/CVE-2026-72296.html * https://www.suse.com/security/cve/CVE-2026-72297.html * https://www.suse.com/security/cve/CVE-2026-72323.html * https://www.suse.com/security/cve/CVE-2026-72339.html * https://www.suse.com/security/cve/CVE-2026-72389.html * https://www.suse.com/security/cve/CVE-2026-72421.html * https://www.suse.com/security/cve/CVE-2026-72450.html * https://www.suse.com/security/cve/CVE-2026-72466.html * https://www.suse.com/security/cve/CVE-2026-72487.html * https://www.suse.com/security/cve/CVE-2026-72502.html * https://www.suse.com/security/cve/CVE-2026-74255.html * https://www.suse.com/security/cve/CVE-2026-74261.html * https://www.suse.com/security/cve/CVE-2026-74265.html * https://www.suse.com/security/cve/CVE-2026-74271.html * https://www.suse.com/security/cve/CVE-2026-74278.html * https://www.suse.com/security/cve/CVE-2026-74279.html * https://www.suse.com/security/cve/CVE-2026-74296.html * https://www.suse.com/security/cve/CVE-2026-74297.html * https://www.suse.com/security/cve/CVE-2026-74302.html * https://www.suse.com/security/cve/CVE-2026-74334.html * https://www.suse.com/security/cve/CVE-2026-74341.html * https://www.suse.com/security/cve/CVE-2026-74377.html * https://www.suse.com/security/cve/CVE-2026-74378.html * https://www.suse.com/security/cve/CVE-2026-74382.html * https://www.suse.com/security/cve/CVE-2026-74388.html * https://www.suse.com/security/cve/CVE-2026-74406.html * https://www.suse.com/security/cve/CVE-2026-74416.html * https://www.suse.com/security/cve/CVE-2026-74417.html * https://www.suse.com/security/cve/CVE-2026-74454.html * https://www.suse.com/security/cve/CVE-2026-74479.html * https://www.suse.com/security/cve/CVE-2026-74482.html * https://www.suse.com/security/cve/CVE-2026-74488.html * https://www.suse.com/security/cve/CVE-2026-74495.html * https://www.suse.com/security/cve/CVE-2026-74496.html * https://www.suse.com/security/cve/CVE-2026-74508.html * https://www.suse.com/security/cve/CVE-2026-74510.html * https://www.suse.com/security/cve/CVE-2026-74519.html * https://www.suse.com/security/cve/CVE-2026-74537.html * https://www.suse.com/security/cve/CVE-2026-74548.html * https://www.suse.com/security/cve/CVE-2026-74550.html * https://www.suse.com/security/cve/CVE-2026-74556.html * https://www.suse.com/security/cve/CVE-2026-74557.html * https://www.suse.com/security/cve/CVE-2026-74582.html * https://www.suse.com/security/cve/CVE-2026-74584.html * https://www.suse.com/security/cve/CVE-2026-74669.html * https://www.suse.com/security/cve/CVE-2026-74673.html * https://www.suse.com/security/cve/CVE-2026-74705.html * https://www.suse.com/security/cve/CVE-2026-74743.html * https://www.suse.com/security/cve/CVE-2026-80534.html * https://www.suse.com/security/cve/CVE-2026-80574.html * https://www.suse.com/security/cve/CVE-2026-80580.html * https://www.suse.com/security/cve/CVE-2026-80590.html * https://www.suse.com/security/cve/CVE-2026-80603.html * https://www.suse.com/security/cve/CVE-2026-80609.html * https://www.suse.com/security/cve/CVE-2026-80714.html * https://www.suse.com/security/cve/CVE-2026-80737.html * https://www.suse.com/security/cve/CVE-2026-80765.html * https://www.suse.com/security/cve/CVE-2026-80819.html * https://www.suse.com/security/cve/CVE-2026-80909.html * https://bugzilla.suse.com/show_bug.cgi?id=1224586 * https://bugzilla.suse.com/show_bug.cgi?id=1251966 * https://bugzilla.suse.com/show_bug.cgi?id=1252682 * https://bugzilla.suse.com/show_bug.cgi?id=1254894 * https://bugzilla.suse.com/show_bug.cgi?id=1255225 * https://bugzilla.suse.com/show_bug.cgi?id=1257246 * https://bugzilla.suse.com/show_bug.cgi?id=1261679 * https://bugzilla.suse.com/show_bug.cgi?id=1262771 * https://bugzilla.suse.com/show_bug.cgi?id=1264296 * https://bugzilla.suse.com/show_bug.cgi?id=1264308 * https://bugzilla.suse.com/show_bug.cgi?id=1264541 * https://bugzilla.suse.com/show_bug.cgi?id=1264594 * https://bugzilla.suse.com/show_bug.cgi?id=1264619 * https://bugzilla.suse.com/show_bug.cgi?id=1264821 * https://bugzilla.suse.com/show_bug.cgi?id=1265068 * https://bugzilla.suse.com/show_bug.cgi?id=1265121 * https://bugzilla.suse.com/show_bug.cgi?id=1266920 * https://bugzilla.suse.com/show_bug.cgi?id=1267501 * https://bugzilla.suse.com/show_bug.cgi?id=1267612 * https://bugzilla.suse.com/show_bug.cgi?id=1267615 * https://bugzilla.suse.com/show_bug.cgi?id=1267643 * https://bugzilla.suse.com/show_bug.cgi?id=1268972 * https://bugzilla.suse.com/show_bug.cgi?id=1268987 * https://bugzilla.suse.com/show_bug.cgi?id=1269000 * https://bugzilla.suse.com/show_bug.cgi?id=1269013 * https://bugzilla.suse.com/show_bug.cgi?id=1269113 * https://bugzilla.suse.com/show_bug.cgi?id=1269114 * https://bugzilla.suse.com/show_bug.cgi?id=1269238 * https://bugzilla.suse.com/show_bug.cgi?id=1269256 * https://bugzilla.suse.com/show_bug.cgi?id=1269301 * https://bugzilla.suse.com/show_bug.cgi?id=1269306 * https://bugzilla.suse.com/show_bug.cgi?id=1269381 * https://bugzilla.suse.com/show_bug.cgi?id=1269412 * https://bugzilla.suse.com/show_bug.cgi?id=1269530 * https://bugzilla.suse.com/show_bug.cgi?id=1269655 * https://bugzilla.suse.com/show_bug.cgi?id=1269685 * https://bugzilla.suse.com/show_bug.cgi?id=1269686 * https://bugzilla.suse.com/show_bug.cgi?id=1269733 * https://bugzilla.suse.com/show_bug.cgi?id=1269734 * https://bugzilla.suse.com/show_bug.cgi?id=1269774 * https://bugzilla.suse.com/show_bug.cgi?id=1269783 * https://bugzilla.suse.com/show_bug.cgi?id=1269815 * https://bugzilla.suse.com/show_bug.cgi?id=1270264 * https://bugzilla.suse.com/show_bug.cgi?id=1271731 * https://bugzilla.suse.com/show_bug.cgi?id=1271825 * https://bugzilla.suse.com/show_bug.cgi?id=1271827 * https://bugzilla.suse.com/show_bug.cgi?id=1272182 * https://bugzilla.suse.com/show_bug.cgi?id=1272210 * https://bugzilla.suse.com/show_bug.cgi?id=1272262 * https://bugzilla.suse.com/show_bug.cgi?id=1272297 * https://bugzilla.suse.com/show_bug.cgi?id=1272385 * https://bugzilla.suse.com/show_bug.cgi?id=1272390 * https://bugzilla.suse.com/show_bug.cgi?id=1272426 * https://bugzilla.suse.com/show_bug.cgi?id=1272429 * https://bugzilla.suse.com/show_bug.cgi?id=1272482 * https://bugzilla.suse.com/show_bug.cgi?id=1272497 * https://bugzilla.suse.com/show_bug.cgi?id=1272591 * https://bugzilla.suse.com/show_bug.cgi?id=1272641 * https://bugzilla.suse.com/show_bug.cgi?id=1272643 * https://bugzilla.suse.com/show_bug.cgi?id=1272877 * https://bugzilla.suse.com/show_bug.cgi?id=1272891 * https://bugzilla.suse.com/show_bug.cgi?id=1273027 * https://bugzilla.suse.com/show_bug.cgi?id=1273105 * https://bugzilla.suse.com/show_bug.cgi?id=1273285 * https://bugzilla.suse.com/show_bug.cgi?id=1273303 * https://bugzilla.suse.com/show_bug.cgi?id=1273305 * https://bugzilla.suse.com/show_bug.cgi?id=1273316 * https://bugzilla.suse.com/show_bug.cgi?id=1273319 * https://bugzilla.suse.com/show_bug.cgi?id=1273327 * https://bugzilla.suse.com/show_bug.cgi?id=1273336 * https://bugzilla.suse.com/show_bug.cgi?id=1273463 * https://bugzilla.suse.com/show_bug.cgi?id=1273555 * https://bugzilla.suse.com/show_bug.cgi?id=1273557 * https://bugzilla.suse.com/show_bug.cgi?id=1273597 * https://bugzilla.suse.com/show_bug.cgi?id=1273734 * https://bugzilla.suse.com/show_bug.cgi?id=1273742 * https://bugzilla.suse.com/show_bug.cgi?id=1273745 * https://bugzilla.suse.com/show_bug.cgi?id=1273748 * https://bugzilla.suse.com/show_bug.cgi?id=1273749 * https://bugzilla.suse.com/show_bug.cgi?id=1273759 * https://bugzilla.suse.com/show_bug.cgi?id=1273762 * https://bugzilla.suse.com/show_bug.cgi?id=1273774 * https://bugzilla.suse.com/show_bug.cgi?id=1273778 * https://bugzilla.suse.com/show_bug.cgi?id=1273780 * https://bugzilla.suse.com/show_bug.cgi?id=1273813 * https://bugzilla.suse.com/show_bug.cgi?id=1273831 * https://bugzilla.suse.com/show_bug.cgi?id=1273860 * https://bugzilla.suse.com/show_bug.cgi?id=1273869 * https://bugzilla.suse.com/show_bug.cgi?id=1273882 * https://bugzilla.suse.com/show_bug.cgi?id=1273891 * https://bugzilla.suse.com/show_bug.cgi?id=1273892 * https://bugzilla.suse.com/show_bug.cgi?id=1273895 * https://bugzilla.suse.com/show_bug.cgi?id=1273930 * https://bugzilla.suse.com/show_bug.cgi?id=1273933 * https://bugzilla.suse.com/show_bug.cgi?id=1273936 * https://bugzilla.suse.com/show_bug.cgi?id=1273939 * https://bugzilla.suse.com/show_bug.cgi?id=1273940 * https://bugzilla.suse.com/show_bug.cgi?id=1273942 * https://bugzilla.suse.com/show_bug.cgi?id=1273944 * https://bugzilla.suse.com/show_bug.cgi?id=1273946 * https://bugzilla.suse.com/show_bug.cgi?id=1273957 * https://bugzilla.suse.com/show_bug.cgi?id=1273958 * https://bugzilla.suse.com/show_bug.cgi?id=1273968 * https://bugzilla.suse.com/show_bug.cgi?id=1273974 * https://bugzilla.suse.com/show_bug.cgi?id=1274003 * https://bugzilla.suse.com/show_bug.cgi?id=1274006 * https://bugzilla.suse.com/show_bug.cgi?id=1274019 * https://bugzilla.suse.com/show_bug.cgi?id=1274028 * https://bugzilla.suse.com/show_bug.cgi?id=1274040 * https://bugzilla.suse.com/show_bug.cgi?id=1274041 * https://bugzilla.suse.com/show_bug.cgi?id=1274077 * https://bugzilla.suse.com/show_bug.cgi?id=1274208 * https://bugzilla.suse.com/show_bug.cgi?id=1274274 * https://bugzilla.suse.com/show_bug.cgi?id=1274277 * https://bugzilla.suse.com/show_bug.cgi?id=1274278 * https://bugzilla.suse.com/show_bug.cgi?id=1274550 * https://bugzilla.suse.com/show_bug.cgi?id=1274581 * https://bugzilla.suse.com/show_bug.cgi?id=1274637 * https://bugzilla.suse.com/show_bug.cgi?id=1274645 * https://bugzilla.suse.com/show_bug.cgi?id=1274646 * https://bugzilla.suse.com/show_bug.cgi?id=1274651 * https://bugzilla.suse.com/show_bug.cgi?id=1274659 * https://bugzilla.suse.com/show_bug.cgi?id=1274662 * https://bugzilla.suse.com/show_bug.cgi?id=1274665 * https://bugzilla.suse.com/show_bug.cgi?id=1274678 * https://bugzilla.suse.com/show_bug.cgi?id=1274681 * https://bugzilla.suse.com/show_bug.cgi?id=1274699 * https://bugzilla.suse.com/show_bug.cgi?id=1274700 * https://bugzilla.suse.com/show_bug.cgi?id=1274705 * https://bugzilla.suse.com/show_bug.cgi?id=1274710 * https://bugzilla.suse.com/show_bug.cgi?id=1274725 * https://bugzilla.suse.com/show_bug.cgi?id=1274737 * https://bugzilla.suse.com/show_bug.cgi?id=1274800 * https://bugzilla.suse.com/show_bug.cgi?id=1274801 * https://bugzilla.suse.com/show_bug.cgi?id=1274803 * https://bugzilla.suse.com/show_bug.cgi?id=1274804 * https://bugzilla.suse.com/show_bug.cgi?id=1274834 * https://bugzilla.suse.com/show_bug.cgi?id=1274859 * https://bugzilla.suse.com/show_bug.cgi?id=1274873 * https://bugzilla.suse.com/show_bug.cgi?id=1274881 * https://bugzilla.suse.com/show_bug.cgi?id=1274888 * https://bugzilla.suse.com/show_bug.cgi?id=1274896 * https://bugzilla.suse.com/show_bug.cgi?id=1274898 * https://bugzilla.suse.com/show_bug.cgi?id=1274902 * https://bugzilla.suse.com/show_bug.cgi?id=1274908 * https://bugzilla.suse.com/show_bug.cgi?id=1274953 * https://bugzilla.suse.com/show_bug.cgi?id=1275083 * https://bugzilla.suse.com/show_bug.cgi?id=1275088 * https://bugzilla.suse.com/show_bug.cgi?id=1275094 * https://bugzilla.suse.com/show_bug.cgi?id=1275125 * https://bugzilla.suse.com/show_bug.cgi?id=1275161 * https://bugzilla.suse.com/show_bug.cgi?id=1275164 * https://bugzilla.suse.com/show_bug.cgi?id=1275169 * https://bugzilla.suse.com/show_bug.cgi?id=1275301 * https://bugzilla.suse.com/show_bug.cgi?id=1275303 * https://bugzilla.suse.com/show_bug.cgi?id=1275304 * https://bugzilla.suse.com/show_bug.cgi?id=1275305 * https://bugzilla.suse.com/show_bug.cgi?id=1275307 * https://bugzilla.suse.com/show_bug.cgi?id=1275470 * https://bugzilla.suse.com/show_bug.cgi?id=1275506 * https://bugzilla.suse.com/show_bug.cgi?id=1275517 * https://bugzilla.suse.com/show_bug.cgi?id=1275535 * https://bugzilla.suse.com/show_bug.cgi?id=1275540 * https://bugzilla.suse.com/show_bug.cgi?id=1275583 * https://bugzilla.suse.com/show_bug.cgi?id=1275650 * https://bugzilla.suse.com/show_bug.cgi?id=1275685 * https://bugzilla.suse.com/show_bug.cgi?id=1275687 * https://bugzilla.suse.com/show_bug.cgi?id=1275688 * https://bugzilla.suse.com/show_bug.cgi?id=1275695 * https://bugzilla.suse.com/show_bug.cgi?id=1275696 * https://bugzilla.suse.com/show_bug.cgi?id=1275704 * https://bugzilla.suse.com/show_bug.cgi?id=1275784 * https://bugzilla.suse.com/show_bug.cgi?id=1275810 * https://bugzilla.suse.com/show_bug.cgi?id=1275827 * https://bugzilla.suse.com/show_bug.cgi?id=1275864 * https://bugzilla.suse.com/show_bug.cgi?id=1275867 * https://bugzilla.suse.com/show_bug.cgi?id=1275870 * https://bugzilla.suse.com/show_bug.cgi?id=1275871 * https://bugzilla.suse.com/show_bug.cgi?id=1275923 * https://bugzilla.suse.com/show_bug.cgi?id=1275950 * https://bugzilla.suse.com/show_bug.cgi?id=1275970 * https://bugzilla.suse.com/show_bug.cgi?id=1275976 * https://bugzilla.suse.com/show_bug.cgi?id=1275985 * https://bugzilla.suse.com/show_bug.cgi?id=1276006 * https://bugzilla.suse.com/show_bug.cgi?id=1276343 * https://bugzilla.suse.com/show_bug.cgi?id=1276346 * https://bugzilla.suse.com/show_bug.cgi?id=1276350 * https://bugzilla.suse.com/show_bug.cgi?id=1276354 * https://bugzilla.suse.com/show_bug.cgi?id=1276363 * https://bugzilla.suse.com/show_bug.cgi?id=1276395 * https://bugzilla.suse.com/show_bug.cgi?id=1276445 * https://bugzilla.suse.com/show_bug.cgi?id=1276446 * https://bugzilla.suse.com/show_bug.cgi?id=1276452 * https://bugzilla.suse.com/show_bug.cgi?id=1276479 * https://bugzilla.suse.com/show_bug.cgi?id=1276502 * https://bugzilla.suse.com/show_bug.cgi?id=1276517 * https://bugzilla.suse.com/show_bug.cgi?id=1276528 * https://bugzilla.suse.com/show_bug.cgi?id=1276542 * https://bugzilla.suse.com/show_bug.cgi?id=1276547 * https://bugzilla.suse.com/show_bug.cgi?id=1276665 * https://bugzilla.suse.com/show_bug.cgi?id=1276767 * https://bugzilla.suse.com/show_bug.cgi?id=1276840 * https://bugzilla.suse.com/show_bug.cgi?id=1276922 * https://bugzilla.suse.com/show_bug.cgi?id=1277022 * https://bugzilla.suse.com/show_bug.cgi?id=1277023 * https://bugzilla.suse.com/show_bug.cgi?id=1277034 * https://bugzilla.suse.com/show_bug.cgi?id=1277057 * https://bugzilla.suse.com/show_bug.cgi?id=1277066 * https://bugzilla.suse.com/show_bug.cgi?id=1277073 * https://bugzilla.suse.com/show_bug.cgi?id=1277089 * https://bugzilla.suse.com/show_bug.cgi?id=1277095 * https://bugzilla.suse.com/show_bug.cgi?id=1277179 * https://bugzilla.suse.com/show_bug.cgi?id=1277235 * https://bugzilla.suse.com/show_bug.cgi?id=1277275 * https://bugzilla.suse.com/show_bug.cgi?id=1277329 * https://bugzilla.suse.com/show_bug.cgi?id=1277350 * https://bugzilla.suse.com/show_bug.cgi?id=1277391 * https://bugzilla.suse.com/show_bug.cgi?id=1277522 * https://bugzilla.suse.com/show_bug.cgi?id=1277553 * https://bugzilla.suse.com/show_bug.cgi?id=1277561 * https://bugzilla.suse.com/show_bug.cgi?id=1277571 * https://bugzilla.suse.com/show_bug.cgi?id=1277637 * https://bugzilla.suse.com/show_bug.cgi?id=1277728 * https://bugzilla.suse.com/show_bug.cgi?id=1277730 * https://bugzilla.suse.com/show_bug.cgi?id=1277738 * https://bugzilla.suse.com/show_bug.cgi?id=1277893 * https://bugzilla.suse.com/show_bug.cgi?id=1277908 * https://bugzilla.suse.com/show_bug.cgi?id=1278113 * https://bugzilla.suse.com/show_bug.cgi?id=1278132 * https://bugzilla.suse.com/show_bug.cgi?id=1278233 * https://bugzilla.suse.com/show_bug.cgi?id=1278236 * https://bugzilla.suse.com/show_bug.cgi?id=1278240 * https://bugzilla.suse.com/show_bug.cgi?id=1278253 * https://bugzilla.suse.com/show_bug.cgi?id=1278293 * https://bugzilla.suse.com/show_bug.cgi?id=1278294 * https://bugzilla.suse.com/show_bug.cgi?id=1278334 * https://bugzilla.suse.com/show_bug.cgi?id=1279422 * https://bugzilla.suse.com/show_bug.cgi?id=1279487 * https://bugzilla.suse.com/show_bug.cgi?id=1279499 * https://bugzilla.suse.com/show_bug.cgi?id=1279607 * https://bugzilla.suse.com/show_bug.cgi?id=1279813 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 16:38:25 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 16:38:25 -0000 Subject: SUSE-SU-2026:4283-1: important: Security update for php-composer2 Message-ID: <179009510519.407.12835335115681355576@32be4de442c6> # Security update for php-composer2 Announcement ID: SUSE-SU-2026:4283-1 Release Date: 2026-09-22T08:35:37Z Rating: important References: * bsc#1271123 * bsc#1271130 * bsc#1271152 * bsc#1271504 * bsc#1271729 * bsc#1278257 * bsc#1279898 Cross-References: * CVE-2026-45793 * CVE-2026-59944 * CVE-2026-59946 * CVE-2026-59947 * CVE-2026-59948 * CVE-2026-84361 CVSS scores: * CVE-2026-45793 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-45793 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59944 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-59944 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2026-59944 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2026-59946 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-59946 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-59946 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2026-59947 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-59947 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59947 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59948 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59948 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-59948 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84361 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H * CVE-2026-84361 ( NVD ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves six vulnerabilities and has one security fix can now be installed. ## Description: This update for php-composer2 fixes the following issues: * CVE-2026-45793: GitHub OAuth tokens failing regex validation can cause credential disclosure (bsc#1271504). * CVE-2026-59944: path traversal and link following issue can make files world readable and executable (bsc#1279898). * CVE-2026-59946: package bin entries with path segments can cause unintended host file permission modifications (bsc#1271152). * CVE-2026-59947: unsanitized URL credential handling in debug output within Composer can allow sensitive token disclosure (bsc#1271130). * CVE-2026-59948: missing package name validation during dependency resolution in Composer can allow path traversal (bsc#1271123). * CVE-2026-84361: arbitrary code execution via malicious Perforce source URL (bsc#1278257). Changes for php-composer2: * version update to 2.2.30: * Fixed command injection via malicious Perforce url (GHSA-rvx4-ffvw-m9q3) * Sanitize URL-embedded usernames/token in a few more places (#13045) * Fixed matching of gitlab URLs to avoid possible credential leak to the wrong domain (#13042) * fix a regression on s390x due last change (bsc#1271729). * version update to 2.2.29: * Validate package names (GHSA-499r-g7pc-vmp9) * Validate package bin paths against path traversal (GHSA-gjfg-22fp-rrxx) * Sanitize URL-embedded usernames/token in verbose output (GHSA-g6xq-892h-64w3) * Only follow HTTP redirects from HTTP responses (#12948) * Prevent phar metadata unserialization on unsafe PHP versions (#12946) * Sanitize JSON parse errors in http responses to avoid leaking response body data (#12959) * Fixed GitHub token validation to be even more relaxed (#12856) * version update to 2.2.28. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4283 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4283 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4283 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4283 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4283 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4283 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4283 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4283 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4283 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * php-composer2-2.2.30-150400.3.21.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * php-composer2-2.2.30-150400.3.21.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * php-composer2-2.2.30-150400.3.21.1 * openSUSE Leap 15.4 (noarch) * php-composer2-2.2.30-150400.3.21.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * php-composer2-2.2.30-150400.3.21.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * php-composer2-2.2.30-150400.3.21.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * php-composer2-2.2.30-150400.3.21.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * php-composer2-2.2.30-150400.3.21.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * php-composer2-2.2.30-150400.3.21.1 ## References: * https://www.suse.com/security/cve/CVE-2026-45793.html * https://www.suse.com/security/cve/CVE-2026-59944.html * https://www.suse.com/security/cve/CVE-2026-59946.html * https://www.suse.com/security/cve/CVE-2026-59947.html * https://www.suse.com/security/cve/CVE-2026-59948.html * https://www.suse.com/security/cve/CVE-2026-84361.html * https://bugzilla.suse.com/show_bug.cgi?id=1271123 * https://bugzilla.suse.com/show_bug.cgi?id=1271130 * https://bugzilla.suse.com/show_bug.cgi?id=1271152 * https://bugzilla.suse.com/show_bug.cgi?id=1271504 * https://bugzilla.suse.com/show_bug.cgi?id=1271729 * https://bugzilla.suse.com/show_bug.cgi?id=1278257 * https://bugzilla.suse.com/show_bug.cgi?id=1279898 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 16:39:22 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 16:39:22 -0000 Subject: SUSE-SU-2026:4281-1: moderate: Security update for cups Message-ID: <179009516213.407.6253376244762353705@32be4de442c6> # Security update for cups Announcement ID: SUSE-SU-2026:4281-1 Release Date: 2026-09-22T08:33:20Z Rating: moderate References: * bsc#1279945 Cross-References: * CVE-2026-87875 CVSS scores: * CVE-2026-87875 ( SUSE ): 5.3 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-87875 ( SUSE ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-87875 ( NVD ): 4.3 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Affected Products: * Basesystem Module 15-SP7 * Desktop Applications Module 15-SP7 * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for cups fixes the following issue: * CVE-2026-87875,GHSA-559w-7676-3xrq: heap out-of-bounds read in `cupsUTF32ToUTF8()` due to missing source-length bound can be reached via the SNMP supply-description parsing (bsc#1279945). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4281 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4281 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4281 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4281 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4281 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4281 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4281 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-4281 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * cups-debugsource-2.2.7-150000.3.96.1 * cups-debuginfo-2.2.7-150000.3.96.1 * libcups2-2.2.7-150000.3.96.1 * cups-config-2.2.7-150000.3.96.1 * libcups2-debuginfo-2.2.7-150000.3.96.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * cups-debugsource-2.2.7-150000.3.96.1 * cups-debuginfo-2.2.7-150000.3.96.1 * libcups2-2.2.7-150000.3.96.1 * cups-config-2.2.7-150000.3.96.1 * libcups2-debuginfo-2.2.7-150000.3.96.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * cups-debugsource-2.2.7-150000.3.96.1 * cups-debuginfo-2.2.7-150000.3.96.1 * libcups2-2.2.7-150000.3.96.1 * cups-config-2.2.7-150000.3.96.1 * libcups2-debuginfo-2.2.7-150000.3.96.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * cups-debugsource-2.2.7-150000.3.96.1 * cups-debuginfo-2.2.7-150000.3.96.1 * libcups2-2.2.7-150000.3.96.1 * cups-config-2.2.7-150000.3.96.1 * libcups2-debuginfo-2.2.7-150000.3.96.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * cups-debugsource-2.2.7-150000.3.96.1 * cups-debuginfo-2.2.7-150000.3.96.1 * libcups2-2.2.7-150000.3.96.1 * cups-config-2.2.7-150000.3.96.1 * libcups2-debuginfo-2.2.7-150000.3.96.1 * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * libcupsmime1-2.2.7-150000.3.96.1 * cups-debugsource-2.2.7-150000.3.96.1 * cups-debuginfo-2.2.7-150000.3.96.1 * cups-devel-2.2.7-150000.3.96.1 * libcupscgi1-2.2.7-150000.3.96.1 * libcupscgi1-debuginfo-2.2.7-150000.3.96.1 * libcups2-debuginfo-2.2.7-150000.3.96.1 * cups-2.2.7-150000.3.96.1 * libcupsimage2-2.2.7-150000.3.96.1 * libcupsppdc1-debuginfo-2.2.7-150000.3.96.1 * libcupsimage2-debuginfo-2.2.7-150000.3.96.1 * libcups2-2.2.7-150000.3.96.1 * cups-client-2.2.7-150000.3.96.1 * cups-config-2.2.7-150000.3.96.1 * libcupsmime1-debuginfo-2.2.7-150000.3.96.1 * libcupsppdc1-2.2.7-150000.3.96.1 * cups-client-debuginfo-2.2.7-150000.3.96.1 * Desktop Applications Module 15-SP7 (x86_64) * libcups2-32bit-debuginfo-2.2.7-150000.3.96.1 * libcups2-32bit-2.2.7-150000.3.96.1 * Development Tools Module 15-SP7 (aarch64 ppc64le s390x x86_64) * cups-debugsource-2.2.7-150000.3.96.1 * cups-ddk-2.2.7-150000.3.96.1 * cups-debuginfo-2.2.7-150000.3.96.1 * cups-ddk-debuginfo-2.2.7-150000.3.96.1 ## References: * https://www.suse.com/security/cve/CVE-2026-87875.html * https://bugzilla.suse.com/show_bug.cgi?id=1279945 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 16:40:01 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 16:40:01 -0000 Subject: SUSE-SU-2026:4280-1: important: Security update for perl-Authen-SASL Message-ID: <179009520124.407.8165505907237078891@32be4de442c6> # Security update for perl-Authen-SASL Announcement ID: SUSE-SU-2026:4280-1 Release Date: 2026-09-22T08:32:21Z Rating: important References: * bsc#1279806 Cross-References: * CVE-2026-86219 CVSS scores: * CVE-2026-86219 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-86219 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-86219 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for perl-Authen-SASL fixes the following issue: * CVE-2026-86219: replayed authentication responses accepted due to unverified nonce in `server_step` (bsc#1279806). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4280 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4280 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * perl-Authen-SASL-2.16-5.6.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * perl-Authen-SASL-2.16-5.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-86219.html * https://bugzilla.suse.com/show_bug.cgi?id=1279806 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 16:43:02 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 16:43:02 -0000 Subject: SUSE-SU-2026:4279-1: important: Security update for the Linux Kernel Message-ID: <179009538213.407.17760805415478147740@32be4de442c6> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:4279-1 Release Date: 2026-09-22T08:32:06Z Rating: important References: * bsc#1235944 * bsc#1242405 * bsc#1261604 * bsc#1263072 * bsc#1264734 * bsc#1266008 * bsc#1267023 * bsc#1268659 * bsc#1269000 * bsc#1269004 * bsc#1269238 * bsc#1269242 * bsc#1269306 * bsc#1269655 * bsc#1269731 * bsc#1271825 * bsc#1271830 * bsc#1272179 * bsc#1272182 * bsc#1272230 * bsc#1272385 * bsc#1272390 * bsc#1272868 * bsc#1272877 * bsc#1273060 * bsc#1273105 * bsc#1273251 * bsc#1273276 * bsc#1273303 * bsc#1273311 * bsc#1273422 * bsc#1273484 * bsc#1273488 * bsc#1273523 * bsc#1273555 * bsc#1273742 * bsc#1273745 * bsc#1273748 * bsc#1273762 * bsc#1273774 * bsc#1273869 * bsc#1273882 * bsc#1273891 * bsc#1273930 * bsc#1273944 * bsc#1273966 * bsc#1273995 * bsc#1274014 * bsc#1274041 * bsc#1274208 * bsc#1274274 * bsc#1274497 * bsc#1274547 * bsc#1274550 * bsc#1274696 * bsc#1274705 * bsc#1274752 * bsc#1274753 * bsc#1274754 * bsc#1274859 * bsc#1274888 * bsc#1274898 * bsc#1274902 * bsc#1274908 * bsc#1274941 * bsc#1275161 * bsc#1275304 * bsc#1275307 * bsc#1275470 * bsc#1275472 * bsc#1275474 * bsc#1275506 * bsc#1275528 * bsc#1275535 * bsc#1275540 * bsc#1275687 * bsc#1275696 * bsc#1275784 * bsc#1275798 * bsc#1275827 * bsc#1275867 * bsc#1275886 * bsc#1275905 * bsc#1275985 * bsc#1276006 * bsc#1276350 * bsc#1276395 * bsc#1276665 * bsc#1276931 * bsc#1277073 * bsc#1277285 * bsc#1277391 * bsc#1277408 * bsc#1277523 * bsc#1277553 * bsc#1277561 * bsc#1277571 * bsc#1277813 * bsc#1277837 * bsc#1277901 * bsc#1277908 * bsc#1278088 * bsc#1278233 * bsc#1278236 * bsc#1278253 * bsc#1278294 * bsc#1279422 * bsc#1279487 * bsc#1279813 * jsc#PED-16892 Cross-References: * CVE-2023-53109 * CVE-2024-57841 * CVE-2026-23451 * CVE-2026-31502 * CVE-2026-43456 * CVE-2026-43502 * CVE-2026-45968 * CVE-2026-52910 * CVE-2026-52912 * CVE-2026-52929 * CVE-2026-52977 * CVE-2026-53059 * CVE-2026-53163 * CVE-2026-53260 * CVE-2026-53264 * CVE-2026-53381 * CVE-2026-53388 * CVE-2026-63801 * CVE-2026-63823 * CVE-2026-63827 * CVE-2026-63887 * CVE-2026-63888 * CVE-2026-63920 * CVE-2026-63992 * CVE-2026-64002 * CVE-2026-64007 * CVE-2026-64010 * CVE-2026-64011 * CVE-2026-64015 * CVE-2026-64047 * CVE-2026-64048 * CVE-2026-64098 * CVE-2026-64109 * CVE-2026-64114 * CVE-2026-64115 * CVE-2026-64137 * CVE-2026-64266 * CVE-2026-64268 * CVE-2026-64304 * CVE-2026-64355 * CVE-2026-64423 * CVE-2026-64450 * CVE-2026-64481 * CVE-2026-64541 * CVE-2026-64543 * CVE-2026-64556 * CVE-2026-64562 * CVE-2026-64563 * CVE-2026-64572 * CVE-2026-64581 * CVE-2026-64593 * CVE-2026-68121 * CVE-2026-68136 * CVE-2026-68138 * CVE-2026-68155 * CVE-2026-68158 * CVE-2026-68159 * CVE-2026-68160 * CVE-2026-68202 * CVE-2026-68397 * CVE-2026-68398 * CVE-2026-68417 * CVE-2026-68426 * CVE-2026-68480 * CVE-2026-72020 * CVE-2026-72069 * CVE-2026-72083 * CVE-2026-72084 * CVE-2026-72123 * CVE-2026-72135 * CVE-2026-72164 * CVE-2026-72251 * CVE-2026-72288 * CVE-2026-72289 * CVE-2026-72323 * CVE-2026-72339 * CVE-2026-72389 * CVE-2026-74345 * CVE-2026-74377 * CVE-2026-74378 * CVE-2026-74388 * CVE-2026-74390 * CVE-2026-74394 * CVE-2026-74406 * CVE-2026-74454 * CVE-2026-74488 * CVE-2026-74496 * CVE-2026-74518 * CVE-2026-74537 * CVE-2026-74556 * CVE-2026-74582 * CVE-2026-74615 * CVE-2026-74616 * CVE-2026-74669 * CVE-2026-74695 * CVE-2026-74743 * CVE-2026-80580 * CVE-2026-80714 * CVE-2026-80716 * CVE-2026-80737 * CVE-2026-80909 CVSS scores: * CVE-2023-53109 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-53109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-57841 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43456 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43502 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45968 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52910 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52910 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52910 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52910 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52912 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52912 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52912 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52929 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52977 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52977 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53059 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53059 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53059 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53381 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63801 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63801 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63801 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63823 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63823 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63823 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63827 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63887 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63887 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63887 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63888 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63888 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63888 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63920 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63920 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63920 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63992 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63992 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63992 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64002 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64002 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64002 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64007 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64007 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64007 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64010 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64011 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64015 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64015 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64047 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64047 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64048 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64048 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64048 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64098 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64098 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64114 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64114 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64115 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64137 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64137 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64137 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64266 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64266 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64268 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64304 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64355 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64355 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64450 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64450 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64481 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64481 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64541 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64541 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64541 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64556 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64556 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64562 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64562 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64563 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64563 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64572 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64572 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64581 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64581 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64581 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64593 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64593 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68121 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68121 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68136 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68136 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68155 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68155 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68155 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68158 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68158 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68158 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68159 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68159 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68159 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68160 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68160 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68160 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68202 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68426 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68426 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68480 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-72020 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72020 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72020 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72069 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72083 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72084 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72123 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72135 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72135 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72135 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72164 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72164 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72251 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72251 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72251 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72288 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72289 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72289 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72289 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72323 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-72323 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72323 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72339 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72339 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72339 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72389 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74345 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74345 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74345 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74377 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74377 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74377 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74378 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74378 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74378 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74388 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74388 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74390 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74390 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74394 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74406 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74406 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74454 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74454 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-74454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74488 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74488 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74518 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74518 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74537 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74537 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74556 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-74556 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74582 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74615 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74615 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74615 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74616 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74616 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74616 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74695 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74695 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74743 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74743 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74743 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80580 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80580 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80580 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80714 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80714 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80714 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80716 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80716 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80716 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80737 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80737 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80737 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80909 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80909 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves 101 vulnerabilities, contains one feature and has eight security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP4 RT kernel was updated to fix various security issues: The following security issues were fixed: * CVE-2023-53109: net: tunnels: annotate lockless accesses to dev->needed_headroom (bsc#1242405 bsc#1275784). * CVE-2024-57841: net: fix memory leak in tcp_conn_request() (bsc#1235944). * CVE-2026-53260: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req() (bsc#1269731). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). * CVE-2026-52910: bpf: Free reuseport cBPF prog after RCU grace period (bsc#1268659). * CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued (bsc#1269000). * CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). * CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). * CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). * CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). * CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). * CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). * CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). * CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). * CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179). * CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). * CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). * CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). * CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). * CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). * CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). * CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882). * CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891). * CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762). * CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). * CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). * CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488). * CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748). * CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). * CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). * CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). * CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944). * CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). * CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). * CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547). * CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). * CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). * CVE-2026-64556: perf/core: Detach event groups during remove_on_exec (bsc#1273251). * CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930). * CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). * CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). * CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). * CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497). * CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). * CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). * CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). * CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). * CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). * CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472). * CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). * CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). * CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). * CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). * CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). * CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). * CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). * CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). * CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). * CVE-2026-72084: scsi: target: core: Generate correct identifiers for PR OUT transport IDs (bsc#1275540). * CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523). * CVE-2026-72135: tpm: Make the TPM character devices non-seekable (bsc#1277571). * CVE-2026-72164: ocfs2: avoid moving extents to occupied clusters (bsc#1277553). * CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). * CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). * CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). * CVE-2026-72323: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() (bsc#1275985). * CVE-2026-72339: qede: fix off-by-one in BD ring consumption on build_skb failure (bsc#1276006). * CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). * CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). * CVE-2026-74377: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path (bsc#1278236). * CVE-2026-74378: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (bsc#1278233). * CVE-2026-74388: ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data (bsc#1278253). * CVE-2026-74390: RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (bsc#1278088). * CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). * CVE-2026-74406: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive() (bsc#1276395). * CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073). * CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350). * CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). * CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). * CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). * CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). * CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). * CVE-2026-74615: vxlan: do not arm the ageing timer on a device that is down (bsc#1277901). * CVE-2026-74616: xdp: reject clones that overrun skb_shared_info tailroom (bsc#1277813). * CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). * CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). * CVE-2026-74743: macvlan: inherit needed_headroom and needed_tailroom from lowerdev (bsc#1277908). * CVE-2026-80580: fbdev: bound mode sysfs output to the sysfs buffer (bsc#1278294). * CVE-2026-80714: ipvs: do not propagate one-packet flag to synced conns (bsc#1277561). * CVE-2026-80716: ALSA: pcm: wake linked drain waiters on unlink (bsc#1277837). * CVE-2026-80737: serial: amba-pl011: synchronize DMA teardown (bsc#1279487). * CVE-2026-80909: drm/amdgpu: Reject UVD message with invalid number of h265 refs (bsc#1279422). The following non security issues were fixed: * mkspec-dtb: Move DTS prefix into package list. * mkspec-dtb: Move provides-obsoletes to package list. * mkspec-dtb: Put per-architecture package lists into a hash. * mkspec-dtb: re-indent. * net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). * perf: Reject exited events as group leaders (git-fixes). * powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). * RDMA/siw: Introduce siw_cep_set_free_and_put (git-fixes). * RDMA/siw: Introduce siw_destroy_cep_sock (git-fixes). * RDMA/siw: Introduce siw_free_cm_id (git-fixes). * RDMA/siw: Only check attrs->cap.max_send_wr in siw_create_qp (git-fixes). * smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). * smb: client: require net admin for CIFS SWN netlink (bsc#1273966). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4279 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4279 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4279 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4279 ## Package List: * SUSE Linux Enterprise Micro for Rancher 5.3 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.186.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.186.1 * kernel-rt-debugsource-5.14.21-150400.15.186.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * kernel-source-rt-5.14.21-150400.15.186.1 * SUSE Linux Enterprise Micro 5.3 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.186.1 * SUSE Linux Enterprise Micro 5.3 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.186.1 * kernel-rt-debugsource-5.14.21-150400.15.186.1 * SUSE Linux Enterprise Micro 5.3 (noarch) * kernel-source-rt-5.14.21-150400.15.186.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.186.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.186.1 * kernel-rt-debugsource-5.14.21-150400.15.186.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * kernel-source-rt-5.14.21-150400.15.186.1 * SUSE Linux Enterprise Micro 5.4 (nosrc x86_64) * kernel-rt-5.14.21-150400.15.186.1 * SUSE Linux Enterprise Micro 5.4 (x86_64) * kernel-rt-debuginfo-5.14.21-150400.15.186.1 * kernel-rt-debugsource-5.14.21-150400.15.186.1 * SUSE Linux Enterprise Micro 5.4 (noarch) * kernel-source-rt-5.14.21-150400.15.186.1 ## References: * https://www.suse.com/security/cve/CVE-2023-53109.html * https://www.suse.com/security/cve/CVE-2024-57841.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45968.html * https://www.suse.com/security/cve/CVE-2026-52910.html * https://www.suse.com/security/cve/CVE-2026-52912.html * https://www.suse.com/security/cve/CVE-2026-52929.html * https://www.suse.com/security/cve/CVE-2026-52977.html * https://www.suse.com/security/cve/CVE-2026-53059.html * https://www.suse.com/security/cve/CVE-2026-53163.html * https://www.suse.com/security/cve/CVE-2026-53260.html * https://www.suse.com/security/cve/CVE-2026-53264.html * https://www.suse.com/security/cve/CVE-2026-53381.html * https://www.suse.com/security/cve/CVE-2026-53388.html * https://www.suse.com/security/cve/CVE-2026-63801.html * https://www.suse.com/security/cve/CVE-2026-63823.html * https://www.suse.com/security/cve/CVE-2026-63827.html * https://www.suse.com/security/cve/CVE-2026-63887.html * https://www.suse.com/security/cve/CVE-2026-63888.html * https://www.suse.com/security/cve/CVE-2026-63920.html * https://www.suse.com/security/cve/CVE-2026-63992.html * https://www.suse.com/security/cve/CVE-2026-64002.html * https://www.suse.com/security/cve/CVE-2026-64007.html * https://www.suse.com/security/cve/CVE-2026-64010.html * https://www.suse.com/security/cve/CVE-2026-64011.html * https://www.suse.com/security/cve/CVE-2026-64015.html * https://www.suse.com/security/cve/CVE-2026-64047.html * https://www.suse.com/security/cve/CVE-2026-64048.html * https://www.suse.com/security/cve/CVE-2026-64098.html * https://www.suse.com/security/cve/CVE-2026-64109.html * https://www.suse.com/security/cve/CVE-2026-64114.html * https://www.suse.com/security/cve/CVE-2026-64115.html * https://www.suse.com/security/cve/CVE-2026-64137.html * https://www.suse.com/security/cve/CVE-2026-64266.html * https://www.suse.com/security/cve/CVE-2026-64268.html * https://www.suse.com/security/cve/CVE-2026-64304.html * https://www.suse.com/security/cve/CVE-2026-64355.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64450.html * https://www.suse.com/security/cve/CVE-2026-64481.html * https://www.suse.com/security/cve/CVE-2026-64541.html * https://www.suse.com/security/cve/CVE-2026-64543.html * https://www.suse.com/security/cve/CVE-2026-64556.html * https://www.suse.com/security/cve/CVE-2026-64562.html * https://www.suse.com/security/cve/CVE-2026-64563.html * https://www.suse.com/security/cve/CVE-2026-64572.html * https://www.suse.com/security/cve/CVE-2026-64581.html * https://www.suse.com/security/cve/CVE-2026-64593.html * https://www.suse.com/security/cve/CVE-2026-68121.html * https://www.suse.com/security/cve/CVE-2026-68136.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://www.suse.com/security/cve/CVE-2026-68155.html * https://www.suse.com/security/cve/CVE-2026-68158.html * https://www.suse.com/security/cve/CVE-2026-68159.html * https://www.suse.com/security/cve/CVE-2026-68160.html * https://www.suse.com/security/cve/CVE-2026-68202.html * https://www.suse.com/security/cve/CVE-2026-68397.html * https://www.suse.com/security/cve/CVE-2026-68398.html * https://www.suse.com/security/cve/CVE-2026-68417.html * https://www.suse.com/security/cve/CVE-2026-68426.html * https://www.suse.com/security/cve/CVE-2026-68480.html * https://www.suse.com/security/cve/CVE-2026-72020.html * https://www.suse.com/security/cve/CVE-2026-72069.html * https://www.suse.com/security/cve/CVE-2026-72083.html * https://www.suse.com/security/cve/CVE-2026-72084.html * https://www.suse.com/security/cve/CVE-2026-72123.html * https://www.suse.com/security/cve/CVE-2026-72135.html * https://www.suse.com/security/cve/CVE-2026-72164.html * https://www.suse.com/security/cve/CVE-2026-72251.html * https://www.suse.com/security/cve/CVE-2026-72288.html * https://www.suse.com/security/cve/CVE-2026-72289.html * https://www.suse.com/security/cve/CVE-2026-72323.html * https://www.suse.com/security/cve/CVE-2026-72339.html * https://www.suse.com/security/cve/CVE-2026-72389.html * https://www.suse.com/security/cve/CVE-2026-74345.html * https://www.suse.com/security/cve/CVE-2026-74377.html * https://www.suse.com/security/cve/CVE-2026-74378.html * https://www.suse.com/security/cve/CVE-2026-74388.html * https://www.suse.com/security/cve/CVE-2026-74390.html * https://www.suse.com/security/cve/CVE-2026-74394.html * https://www.suse.com/security/cve/CVE-2026-74406.html * https://www.suse.com/security/cve/CVE-2026-74454.html * https://www.suse.com/security/cve/CVE-2026-74488.html * https://www.suse.com/security/cve/CVE-2026-74496.html * https://www.suse.com/security/cve/CVE-2026-74518.html * https://www.suse.com/security/cve/CVE-2026-74537.html * https://www.suse.com/security/cve/CVE-2026-74556.html * https://www.suse.com/security/cve/CVE-2026-74582.html * https://www.suse.com/security/cve/CVE-2026-74615.html * https://www.suse.com/security/cve/CVE-2026-74616.html * https://www.suse.com/security/cve/CVE-2026-74669.html * https://www.suse.com/security/cve/CVE-2026-74695.html * https://www.suse.com/security/cve/CVE-2026-74743.html * https://www.suse.com/security/cve/CVE-2026-80580.html * https://www.suse.com/security/cve/CVE-2026-80714.html * https://www.suse.com/security/cve/CVE-2026-80716.html * https://www.suse.com/security/cve/CVE-2026-80737.html * https://www.suse.com/security/cve/CVE-2026-80909.html * https://bugzilla.suse.com/show_bug.cgi?id=1235944 * https://bugzilla.suse.com/show_bug.cgi?id=1242405 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1267023 * https://bugzilla.suse.com/show_bug.cgi?id=1268659 * https://bugzilla.suse.com/show_bug.cgi?id=1269000 * https://bugzilla.suse.com/show_bug.cgi?id=1269004 * https://bugzilla.suse.com/show_bug.cgi?id=1269238 * https://bugzilla.suse.com/show_bug.cgi?id=1269242 * https://bugzilla.suse.com/show_bug.cgi?id=1269306 * https://bugzilla.suse.com/show_bug.cgi?id=1269655 * https://bugzilla.suse.com/show_bug.cgi?id=1269731 * https://bugzilla.suse.com/show_bug.cgi?id=1271825 * https://bugzilla.suse.com/show_bug.cgi?id=1271830 * https://bugzilla.suse.com/show_bug.cgi?id=1272179 * https://bugzilla.suse.com/show_bug.cgi?id=1272182 * https://bugzilla.suse.com/show_bug.cgi?id=1272230 * https://bugzilla.suse.com/show_bug.cgi?id=1272385 * https://bugzilla.suse.com/show_bug.cgi?id=1272390 * https://bugzilla.suse.com/show_bug.cgi?id=1272868 * https://bugzilla.suse.com/show_bug.cgi?id=1272877 * https://bugzilla.suse.com/show_bug.cgi?id=1273060 * https://bugzilla.suse.com/show_bug.cgi?id=1273105 * https://bugzilla.suse.com/show_bug.cgi?id=1273251 * https://bugzilla.suse.com/show_bug.cgi?id=1273276 * https://bugzilla.suse.com/show_bug.cgi?id=1273303 * https://bugzilla.suse.com/show_bug.cgi?id=1273311 * https://bugzilla.suse.com/show_bug.cgi?id=1273422 * https://bugzilla.suse.com/show_bug.cgi?id=1273484 * https://bugzilla.suse.com/show_bug.cgi?id=1273488 * https://bugzilla.suse.com/show_bug.cgi?id=1273523 * https://bugzilla.suse.com/show_bug.cgi?id=1273555 * https://bugzilla.suse.com/show_bug.cgi?id=1273742 * https://bugzilla.suse.com/show_bug.cgi?id=1273745 * https://bugzilla.suse.com/show_bug.cgi?id=1273748 * https://bugzilla.suse.com/show_bug.cgi?id=1273762 * https://bugzilla.suse.com/show_bug.cgi?id=1273774 * https://bugzilla.suse.com/show_bug.cgi?id=1273869 * https://bugzilla.suse.com/show_bug.cgi?id=1273882 * https://bugzilla.suse.com/show_bug.cgi?id=1273891 * https://bugzilla.suse.com/show_bug.cgi?id=1273930 * https://bugzilla.suse.com/show_bug.cgi?id=1273944 * https://bugzilla.suse.com/show_bug.cgi?id=1273966 * https://bugzilla.suse.com/show_bug.cgi?id=1273995 * https://bugzilla.suse.com/show_bug.cgi?id=1274014 * https://bugzilla.suse.com/show_bug.cgi?id=1274041 * https://bugzilla.suse.com/show_bug.cgi?id=1274208 * https://bugzilla.suse.com/show_bug.cgi?id=1274274 * https://bugzilla.suse.com/show_bug.cgi?id=1274497 * https://bugzilla.suse.com/show_bug.cgi?id=1274547 * https://bugzilla.suse.com/show_bug.cgi?id=1274550 * https://bugzilla.suse.com/show_bug.cgi?id=1274696 * https://bugzilla.suse.com/show_bug.cgi?id=1274705 * https://bugzilla.suse.com/show_bug.cgi?id=1274752 * https://bugzilla.suse.com/show_bug.cgi?id=1274753 * https://bugzilla.suse.com/show_bug.cgi?id=1274754 * https://bugzilla.suse.com/show_bug.cgi?id=1274859 * https://bugzilla.suse.com/show_bug.cgi?id=1274888 * https://bugzilla.suse.com/show_bug.cgi?id=1274898 * https://bugzilla.suse.com/show_bug.cgi?id=1274902 * https://bugzilla.suse.com/show_bug.cgi?id=1274908 * https://bugzilla.suse.com/show_bug.cgi?id=1274941 * https://bugzilla.suse.com/show_bug.cgi?id=1275161 * https://bugzilla.suse.com/show_bug.cgi?id=1275304 * https://bugzilla.suse.com/show_bug.cgi?id=1275307 * https://bugzilla.suse.com/show_bug.cgi?id=1275470 * https://bugzilla.suse.com/show_bug.cgi?id=1275472 * https://bugzilla.suse.com/show_bug.cgi?id=1275474 * https://bugzilla.suse.com/show_bug.cgi?id=1275506 * https://bugzilla.suse.com/show_bug.cgi?id=1275528 * https://bugzilla.suse.com/show_bug.cgi?id=1275535 * https://bugzilla.suse.com/show_bug.cgi?id=1275540 * https://bugzilla.suse.com/show_bug.cgi?id=1275687 * https://bugzilla.suse.com/show_bug.cgi?id=1275696 * https://bugzilla.suse.com/show_bug.cgi?id=1275784 * https://bugzilla.suse.com/show_bug.cgi?id=1275798 * https://bugzilla.suse.com/show_bug.cgi?id=1275827 * https://bugzilla.suse.com/show_bug.cgi?id=1275867 * https://bugzilla.suse.com/show_bug.cgi?id=1275886 * https://bugzilla.suse.com/show_bug.cgi?id=1275905 * https://bugzilla.suse.com/show_bug.cgi?id=1275985 * https://bugzilla.suse.com/show_bug.cgi?id=1276006 * https://bugzilla.suse.com/show_bug.cgi?id=1276350 * https://bugzilla.suse.com/show_bug.cgi?id=1276395 * https://bugzilla.suse.com/show_bug.cgi?id=1276665 * https://bugzilla.suse.com/show_bug.cgi?id=1276931 * https://bugzilla.suse.com/show_bug.cgi?id=1277073 * https://bugzilla.suse.com/show_bug.cgi?id=1277285 * https://bugzilla.suse.com/show_bug.cgi?id=1277391 * https://bugzilla.suse.com/show_bug.cgi?id=1277408 * https://bugzilla.suse.com/show_bug.cgi?id=1277523 * https://bugzilla.suse.com/show_bug.cgi?id=1277553 * https://bugzilla.suse.com/show_bug.cgi?id=1277561 * https://bugzilla.suse.com/show_bug.cgi?id=1277571 * https://bugzilla.suse.com/show_bug.cgi?id=1277813 * https://bugzilla.suse.com/show_bug.cgi?id=1277837 * https://bugzilla.suse.com/show_bug.cgi?id=1277901 * https://bugzilla.suse.com/show_bug.cgi?id=1277908 * https://bugzilla.suse.com/show_bug.cgi?id=1278088 * https://bugzilla.suse.com/show_bug.cgi?id=1278233 * https://bugzilla.suse.com/show_bug.cgi?id=1278236 * https://bugzilla.suse.com/show_bug.cgi?id=1278253 * https://bugzilla.suse.com/show_bug.cgi?id=1278294 * https://bugzilla.suse.com/show_bug.cgi?id=1279422 * https://bugzilla.suse.com/show_bug.cgi?id=1279487 * https://bugzilla.suse.com/show_bug.cgi?id=1279813 * https://jira.suse.com/browse/PED-16892 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 16:43:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 16:43:43 -0000 Subject: SUSE-SU-2026:4278-1: moderate: Security update for libtpms Message-ID: <179009542308.407.5826596429945231924@32be4de442c6> # Security update for libtpms Announcement ID: SUSE-SU-2026:4278-1 Release Date: 2026-09-22T08:31:52Z Rating: moderate References: * bsc#1244528 * bsc#1279628 Cross-References: * CVE-2025-49133 * CVE-2026-85769 CVSS scores: * CVE-2025-49133 ( SUSE ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2025-49133 ( NVD ): 5.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H * CVE-2025-49133 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-85769 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-85769 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-85769 ( NVD ): 6.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 An update that solves two vulnerabilities can now be installed. ## Description: This update for libtpms fixes the following issues: * CVE-2025-49133: inconsistent parameter handling can cause out-of-bounds reads (bsc#1244528). * CVE-2026-85769: heap out-of-bounds read in TPM2 state unmarshalling via unchecked block_skip_read() blocksize (bsc#1279628). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-4278 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4278 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4278 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4278 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4278 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4278 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * libtpms0-0.8.2-150300.3.12.1 * libtpms-devel-0.8.2-150300.3.12.1 * libtpms-debugsource-0.8.2-150300.3.12.1 * libtpms0-debuginfo-0.8.2-150300.3.12.1 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * libtpms0-0.8.2-150300.3.12.1 * libtpms-debugsource-0.8.2-150300.3.12.1 * libtpms0-debuginfo-0.8.2-150300.3.12.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * libtpms0-0.8.2-150300.3.12.1 * libtpms-debugsource-0.8.2-150300.3.12.1 * libtpms0-debuginfo-0.8.2-150300.3.12.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * libtpms0-0.8.2-150300.3.12.1 * libtpms-debugsource-0.8.2-150300.3.12.1 * libtpms0-debuginfo-0.8.2-150300.3.12.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * libtpms0-0.8.2-150300.3.12.1 * libtpms-debugsource-0.8.2-150300.3.12.1 * libtpms0-debuginfo-0.8.2-150300.3.12.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * libtpms0-0.8.2-150300.3.12.1 * libtpms-debugsource-0.8.2-150300.3.12.1 * libtpms0-debuginfo-0.8.2-150300.3.12.1 ## References: * https://www.suse.com/security/cve/CVE-2025-49133.html * https://www.suse.com/security/cve/CVE-2026-85769.html * https://bugzilla.suse.com/show_bug.cgi?id=1244528 * https://bugzilla.suse.com/show_bug.cgi?id=1279628 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 16:44:47 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 16:44:47 -0000 Subject: SUSE-SU-2026:4277-1: important: Security update for freeipmi Message-ID: <179009548797.407.6443584947879871007@32be4de442c6> # Security update for freeipmi Announcement ID: SUSE-SU-2026:4277-1 Release Date: 2026-09-22T08:31:22Z Rating: important References: * bsc#1267605 * bsc#1278719 * bsc#1278721 * bsc#1278722 * bsc#1278724 * bsc#1278726 * bsc#1278727 Cross-References: * CVE-2026-50031 * CVE-2026-85504 * CVE-2026-85505 * CVE-2026-85506 * CVE-2026-85507 * CVE-2026-85508 * CVE-2026-85509 CVSS scores: * CVE-2026-50031 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-50031 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-85504 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-85504 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-85504 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-85505 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-85505 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-85505 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-85506 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-85506 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-85506 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-85507 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-85507 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-85507 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-85508 ( SUSE ): 7.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-85508 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-85508 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-85509 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-85509 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-85509 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Basesystem Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves seven vulnerabilities can now be installed. ## Description: This update for freeipmi fixes the following issues: * CVE-2026-50031: Denial of service via buffer overflow in ipmi-oem client (bsc#1267605). * CVE-2026-85504: stack-based buffer overflow via malformed Fujitsu SEL long- text responses (bsc#1278719). * CVE-2026-85505: Denial of Service via stack-based buffer over-read in ipmi- oem (bsc#1278722). * CVE-2026-85506: Arbitrary code execution via stack-based buffer overflow in ipmi-oem (bsc#1278721). * CVE-2026-85507: stack-based buffer overflow in _output_dell_system_info_cmc_info (bsc#1278724). * CVE-2026-85508: stack-based buffer overflow in _output_dell_system_info_cmc_ipv6_info (bsc#1278726). * CVE-2026-85509: stack-based buffer overflow when a BMC returns more bytes than requested (bsc#1278727). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4277 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4277 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4277 * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4277 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4277 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4277 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4277 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4277 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4277 * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4277 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4277 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4277 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (x86_64) * freeipmi-debugsource-1.6.8-150400.3.6.1 * libfreeipmi17-debuginfo-1.6.8-150400.3.6.1 * libipmiconsole2-debuginfo-1.6.8-150400.3.6.1 * libfreeipmi17-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-1.6.8-150400.3.6.1 * libipmiconsole2-1.6.8-150400.3.6.1 * libipmimonitoring6-debuginfo-1.6.8-150400.3.6.1 * libipmimonitoring6-1.6.8-150400.3.6.1 * freeipmi-1.6.8-150400.3.6.1 * freeipmi-devel-1.6.8-150400.3.6.1 * freeipmi-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-debuginfo-1.6.8-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * freeipmi-debugsource-1.6.8-150400.3.6.1 * libfreeipmi17-debuginfo-1.6.8-150400.3.6.1 * libipmiconsole2-debuginfo-1.6.8-150400.3.6.1 * libfreeipmi17-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-1.6.8-150400.3.6.1 * libipmiconsole2-1.6.8-150400.3.6.1 * libipmimonitoring6-debuginfo-1.6.8-150400.3.6.1 * libipmimonitoring6-1.6.8-150400.3.6.1 * freeipmi-1.6.8-150400.3.6.1 * freeipmi-devel-1.6.8-150400.3.6.1 * freeipmi-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-debuginfo-1.6.8-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * freeipmi-debugsource-1.6.8-150400.3.6.1 * libfreeipmi17-debuginfo-1.6.8-150400.3.6.1 * libipmiconsole2-debuginfo-1.6.8-150400.3.6.1 * libfreeipmi17-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-1.6.8-150400.3.6.1 * libipmiconsole2-1.6.8-150400.3.6.1 * libipmimonitoring6-debuginfo-1.6.8-150400.3.6.1 * libipmimonitoring6-1.6.8-150400.3.6.1 * freeipmi-1.6.8-150400.3.6.1 * freeipmi-devel-1.6.8-150400.3.6.1 * freeipmi-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-debuginfo-1.6.8-150400.3.6.1 * openSUSE Leap 15.4 (aarch64 i586 x86_64) * freeipmi-debugsource-1.6.8-150400.3.6.1 * freeipmi-bmc-watchdog-1.6.8-150400.3.6.1 * libfreeipmi17-debuginfo-1.6.8-150400.3.6.1 * libipmiconsole2-debuginfo-1.6.8-150400.3.6.1 * libfreeipmi17-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-1.6.8-150400.3.6.1 * libipmiconsole2-1.6.8-150400.3.6.1 * libipmidetect0-debuginfo-1.6.8-150400.3.6.1 * libipmimonitoring6-debuginfo-1.6.8-150400.3.6.1 * freeipmi-ipmidetectd-1.6.8-150400.3.6.1 * libipmimonitoring6-1.6.8-150400.3.6.1 * freeipmi-1.6.8-150400.3.6.1 * freeipmi-devel-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-debuginfo-1.6.8-150400.3.6.1 * freeipmi-debuginfo-1.6.8-150400.3.6.1 * freeipmi-bmc-watchdog-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-1.6.8-150400.3.6.1 * freeipmi-ipmidetectd-debuginfo-1.6.8-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (x86_64) * freeipmi-debugsource-1.6.8-150400.3.6.1 * libfreeipmi17-debuginfo-1.6.8-150400.3.6.1 * libipmiconsole2-debuginfo-1.6.8-150400.3.6.1 * libfreeipmi17-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-1.6.8-150400.3.6.1 * libipmiconsole2-1.6.8-150400.3.6.1 * libipmimonitoring6-debuginfo-1.6.8-150400.3.6.1 * libipmimonitoring6-1.6.8-150400.3.6.1 * freeipmi-1.6.8-150400.3.6.1 * freeipmi-devel-1.6.8-150400.3.6.1 * freeipmi-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-debuginfo-1.6.8-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * freeipmi-debugsource-1.6.8-150400.3.6.1 * libfreeipmi17-debuginfo-1.6.8-150400.3.6.1 * libipmiconsole2-debuginfo-1.6.8-150400.3.6.1 * libfreeipmi17-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-1.6.8-150400.3.6.1 * libipmiconsole2-1.6.8-150400.3.6.1 * libipmimonitoring6-debuginfo-1.6.8-150400.3.6.1 * libipmimonitoring6-1.6.8-150400.3.6.1 * freeipmi-1.6.8-150400.3.6.1 * freeipmi-devel-1.6.8-150400.3.6.1 * freeipmi-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-debuginfo-1.6.8-150400.3.6.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * freeipmi-debugsource-1.6.8-150400.3.6.1 * libfreeipmi17-debuginfo-1.6.8-150400.3.6.1 * libipmiconsole2-debuginfo-1.6.8-150400.3.6.1 * libfreeipmi17-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-1.6.8-150400.3.6.1 * libipmiconsole2-1.6.8-150400.3.6.1 * libipmimonitoring6-debuginfo-1.6.8-150400.3.6.1 * libipmimonitoring6-1.6.8-150400.3.6.1 * freeipmi-1.6.8-150400.3.6.1 * freeipmi-devel-1.6.8-150400.3.6.1 * freeipmi-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-debuginfo-1.6.8-150400.3.6.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (x86_64) * freeipmi-debugsource-1.6.8-150400.3.6.1 * libfreeipmi17-debuginfo-1.6.8-150400.3.6.1 * libipmiconsole2-debuginfo-1.6.8-150400.3.6.1 * libfreeipmi17-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-1.6.8-150400.3.6.1 * libipmiconsole2-1.6.8-150400.3.6.1 * libipmimonitoring6-debuginfo-1.6.8-150400.3.6.1 * libipmimonitoring6-1.6.8-150400.3.6.1 * freeipmi-1.6.8-150400.3.6.1 * freeipmi-devel-1.6.8-150400.3.6.1 * freeipmi-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-debuginfo-1.6.8-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 x86_64) * freeipmi-debugsource-1.6.8-150400.3.6.1 * libfreeipmi17-debuginfo-1.6.8-150400.3.6.1 * libipmiconsole2-debuginfo-1.6.8-150400.3.6.1 * libfreeipmi17-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-1.6.8-150400.3.6.1 * libipmiconsole2-1.6.8-150400.3.6.1 * libipmimonitoring6-debuginfo-1.6.8-150400.3.6.1 * libipmimonitoring6-1.6.8-150400.3.6.1 * freeipmi-1.6.8-150400.3.6.1 * freeipmi-devel-1.6.8-150400.3.6.1 * freeipmi-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-debuginfo-1.6.8-150400.3.6.1 * Basesystem Module 15-SP7 (aarch64 x86_64) * freeipmi-debugsource-1.6.8-150400.3.6.1 * libfreeipmi17-debuginfo-1.6.8-150400.3.6.1 * libipmiconsole2-debuginfo-1.6.8-150400.3.6.1 * libfreeipmi17-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-1.6.8-150400.3.6.1 * libipmiconsole2-1.6.8-150400.3.6.1 * libipmimonitoring6-debuginfo-1.6.8-150400.3.6.1 * libipmimonitoring6-1.6.8-150400.3.6.1 * freeipmi-1.6.8-150400.3.6.1 * freeipmi-devel-1.6.8-150400.3.6.1 * freeipmi-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-debuginfo-1.6.8-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 x86_64) * freeipmi-debugsource-1.6.8-150400.3.6.1 * libfreeipmi17-debuginfo-1.6.8-150400.3.6.1 * libipmiconsole2-debuginfo-1.6.8-150400.3.6.1 * libfreeipmi17-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-1.6.8-150400.3.6.1 * libipmiconsole2-1.6.8-150400.3.6.1 * libipmimonitoring6-debuginfo-1.6.8-150400.3.6.1 * libipmimonitoring6-1.6.8-150400.3.6.1 * freeipmi-1.6.8-150400.3.6.1 * freeipmi-devel-1.6.8-150400.3.6.1 * freeipmi-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-debuginfo-1.6.8-150400.3.6.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * freeipmi-debugsource-1.6.8-150400.3.6.1 * libfreeipmi17-debuginfo-1.6.8-150400.3.6.1 * libipmiconsole2-debuginfo-1.6.8-150400.3.6.1 * libfreeipmi17-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-1.6.8-150400.3.6.1 * libipmiconsole2-1.6.8-150400.3.6.1 * libipmimonitoring6-debuginfo-1.6.8-150400.3.6.1 * libipmimonitoring6-1.6.8-150400.3.6.1 * freeipmi-1.6.8-150400.3.6.1 * freeipmi-devel-1.6.8-150400.3.6.1 * freeipmi-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-debuginfo-1.6.8-150400.3.6.1 * libipmidetect0-1.6.8-150400.3.6.1 * freeipmi-ipmiseld-debuginfo-1.6.8-150400.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2026-50031.html * https://www.suse.com/security/cve/CVE-2026-85504.html * https://www.suse.com/security/cve/CVE-2026-85505.html * https://www.suse.com/security/cve/CVE-2026-85506.html * https://www.suse.com/security/cve/CVE-2026-85507.html * https://www.suse.com/security/cve/CVE-2026-85508.html * https://www.suse.com/security/cve/CVE-2026-85509.html * https://bugzilla.suse.com/show_bug.cgi?id=1267605 * https://bugzilla.suse.com/show_bug.cgi?id=1278719 * https://bugzilla.suse.com/show_bug.cgi?id=1278721 * https://bugzilla.suse.com/show_bug.cgi?id=1278722 * https://bugzilla.suse.com/show_bug.cgi?id=1278724 * https://bugzilla.suse.com/show_bug.cgi?id=1278726 * https://bugzilla.suse.com/show_bug.cgi?id=1278727 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 20:30:34 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 20:30:34 -0000 Subject: SUSE-SU-2026:4288-1: moderate: Security update for php-composer2 Message-ID: <179010903401.20921.9801804909264279125@af273d3f1972> # Security update for php-composer2 Announcement ID: SUSE-SU-2026:4288-1 Release Date: 2026-09-22T16:09:53Z Rating: moderate References: * bsc#1279898 * bsc#1280019 Cross-References: * CVE-2026-45793 * CVE-2026-59944 * CVE-2026-59947 CVSS scores: * CVE-2026-45793 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N * CVE-2026-45793 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59944 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-59944 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2026-59944 ( NVD ): 6.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N * CVE-2026-59947 ( SUSE ): 5.7 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-59947 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-59947 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * Web and Scripting Module 15-SP7 An update that solves three vulnerabilities can now be installed. ## Description: This update for php-composer2 fixes the following issues: * CVE-2026-59944: path traversal and link following issue can make files world readable and executable (bsc#1279898). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4288 * Web and Scripting Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Web-Scripting-15-SP7-2026-4288 ## Package List: * openSUSE Leap 15.6 (noarch) * php-composer2-2.6.4-150600.3.23.1 * Web and Scripting Module 15-SP7 (noarch) * php-composer2-2.6.4-150600.3.23.1 ## References: * https://www.suse.com/security/cve/CVE-2026-45793.html * https://www.suse.com/security/cve/CVE-2026-59944.html * https://www.suse.com/security/cve/CVE-2026-59947.html * https://bugzilla.suse.com/show_bug.cgi?id=1279898 * https://bugzilla.suse.com/show_bug.cgi?id=1280019 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 20:31:31 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 20:31:31 -0000 Subject: SUSE-SU-2026:4287-1: moderate: Security update for openssl-certs Message-ID: <179010909135.20921.375588463831699711@af273d3f1972> # Security update for openssl-certs Announcement ID: SUSE-SU-2026:4287-1 Release Date: 2026-09-22T16:08:58Z Rating: moderate References: * bsc#1279961 Affected Products: * SUSE Linux Enterprise Server 11 SP4 * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE An update that has one security fix can now be installed. ## Description: This update for openssl-certs fixes the following issue: * Updated to 2.90 state (bsc#1279961): * Removed: * AffirmTrust Commercial * AffirmTrust Networking * AffirmTrust Premium * AffirmTrust Premium ECC * certSIGN ROOT CA * Entrust Root Certification Authority * PKI Root Certification Authority * FIRMAPROFESIONAL CA ROOT-A WEB * GLOBALTRUST 2020 * Secure Global CA * SecureSign Root CA12 * SecureTrust CA * TeliaSonera Root CA v1 * Trustwave Global Certification Authority * Trustwave Global ECC P256 Certification Authority * Trustwave Global ECC P384 Certification Authority * XRamp Global Certification Authority * Added: * SECOM SMIME RSA Root CA 2024 * SECOM TLS ECC Root CA 2024 * SECOM TLS RSA Root CA 2024 * SecureSign Root CA16 * Telia EC Email Root CA v3 * Telia EC TLS Root CA v3 * Telia RSA Email Root CA v3 * Telia RSA TLS Root CA v3 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2026-4287 * SUSE Linux Enterprise Server 11 SP4 zypper in -t patch SUSE-SLE-SERVER-11-SP4-LTSS-EXTREME-CORE-2026-4287 ## Package List: * SUSE Linux Enterprise Server 11 SP4 LTSS EXTREME CORE (noarch) * openssl-certs-2.90-0.7.36.1 * SUSE Linux Enterprise Server 11 SP4 (noarch) * openssl-certs-2.90-0.7.36.1 ## References: * https://bugzilla.suse.com/show_bug.cgi?id=1279961 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 20:32:13 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 20:32:13 -0000 Subject: SUSE-SU-2026:4286-1: important: Security update for amazon-ssm-agent Message-ID: <179010913304.20921.8902660363154891323@af273d3f1972> # Security update for amazon-ssm-agent Announcement ID: SUSE-SU-2026:4286-1 Release Date: 2026-09-22T16:08:49Z Rating: important References: * bsc#1276981 * bsc#1276994 * bsc#1278681 Cross-References: * CVE-2026-56854 * CVE-2026-56855 * CVE-2026-71556 * CVE-2026-71557 * CVE-2026-78662 CVSS scores: * CVE-2026-56854 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56854 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56854 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56855 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-71556 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L * CVE-2026-71556 ( NVD ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L * CVE-2026-71557 ( SUSE ): 5.4 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L * CVE-2026-71557 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:L * CVE-2026-78662 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78662 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78662 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves five vulnerabilities can now be installed. ## Description: This update for amazon-ssm-agent fixes the following issues: * CVE-2026-56854: golang.org/x/crypto/ssh: source-address restriction bypassed in 5 callback families (bsc#1278681) * CVE-2026-56855: golang.org/x/crypto/ssh: prevent DoS on deadlocked established channel (bsc#1278681) * CVE-2026-78662: golang.org/x/crypto/ssh: prevent DoS on deadlocked undecided channel (bsc#1278681). * CVE-2026-71556: github.com/go-git/go-git/v5: Arbitrary file read/write via symbolic link resolution (bsc#1276981). * CVE-2026-71557: github.com/go-git/go-git/v5: Malicious reference names may modify files outside the reference storage (bsc#1276994). Changes for amazon-ssm-agent: * Update to version 3.3.5390.0 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2026-4286 ## Package List: * Public Cloud Module 12 (aarch64 x86_64) * amazon-ssm-agent-3.3.5390.0-4.52.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56854.html * https://www.suse.com/security/cve/CVE-2026-56855.html * https://www.suse.com/security/cve/CVE-2026-71556.html * https://www.suse.com/security/cve/CVE-2026-71557.html * https://www.suse.com/security/cve/CVE-2026-78662.html * https://bugzilla.suse.com/show_bug.cgi?id=1276981 * https://bugzilla.suse.com/show_bug.cgi?id=1276994 * https://bugzilla.suse.com/show_bug.cgi?id=1278681 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 20:33:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 20:33:09 -0000 Subject: SUSE-SU-2026:4285-1: important: Security update for bind Message-ID: <179010918949.20921.3005928518994618494@af273d3f1972> # Security update for bind Announcement ID: SUSE-SU-2026:4285-1 Release Date: 2026-09-22T16:08:34Z Rating: important References: * bsc#1280430 * bsc#1280432 * bsc#1280433 * bsc#1280435 * bsc#1280436 * bsc#1280437 * bsc#1280438 * bsc#1280439 * bsc#1280440 * bsc#1280441 * bsc#1280442 * bsc#1280443 * bsc#1280444 * bsc#1280445 Cross-References: * CVE-2026-19033 * CVE-2026-19662 * CVE-2026-19666 * CVE-2026-19667 * CVE-2026-19668 * CVE-2026-19941 * CVE-2026-75029 * CVE-2026-76163 * CVE-2026-77119 * CVE-2026-77692 * CVE-2026-78301 * CVE-2026-80274 * CVE-2026-81563 * CVE-2026-81736 CVSS scores: * CVE-2026-19033 ( SUSE ): 8.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-19033 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-19033 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:L * CVE-2026-19662 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-19662 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-19662 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-19666 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-19666 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-19666 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-19667 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-19667 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-19667 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-19668 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-19668 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-19668 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-19941 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-19941 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-19941 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-75029 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-75029 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-75029 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-76163 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-76163 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-76163 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-77119 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-77119 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-77119 ( NVD ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N * CVE-2026-77692 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-77692 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-77692 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78301 ( SUSE ): 8.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N * CVE-2026-78301 ( SUSE ): 5.8 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N * CVE-2026-78301 ( NVD ): 5.8 CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N * CVE-2026-80274 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-80274 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-80274 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-81563 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-81563 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-81563 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-81736 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-81736 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-81736 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * Basesystem Module 15-SP7 * Server Applications Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves 14 vulnerabilities can now be installed. ## Description: This update for bind fixes the following issues: * CVE-2026-19033: Unauthenticated IXFR deltas are applied to the live zone before TSIG verification (bsc#1280430). * CVE-2026-19662: qpcache NOQNAME proof use-after-free crashes recursive resolver (bsc#1280432). * CVE-2026-19666: Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path (bsc#1280433). * CVE-2026-19667: Remote assertion failure via 16-bit length truncation in dns_ncache_add() (bsc#1280435). * CVE-2026-19668: Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching (bsc#1280436). * CVE-2026-19941: checkwildcard() accepts an out-of-zone NSEC as a wildcard- nonexistence proof (bsc#1280437). * CVE-2026-75029: Message parser retains every identical singleton RDATA, enabling wire-to-work amplification (bsc#1280438). * CVE-2026-76163: named aborts on a TKEY query when the user configuration has no global options statement (bsc#1280439). * CVE-2026-77119: NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets (bsc#1280440). * CVE-2026-77692: Unauthenticated remote crash of named via a single DoH SIG(0) request (bsc#1280441). * CVE-2026-78301: Out-of-zone database nodes can become authoritative zone cuts (bsc#1280442). * CVE-2026-80274: Validating resolver can abort while caching a mismatched NOQNAME proof (bsc#1280443). * CVE-2026-81563: SVCB AliasMode additional-data error leaks qpcache references (bsc#1280444). * CVE-2026-81736: Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees (bsc#1280445). Changes for bind: Upgrade to release 9.20.29 New Features: * Disclose active Negative Trust Anchors with Extended DNS Error 33\. Feature Changes: * Reject oversized and malformed DNSKEY records up front. * Speed up RPZ policy zone updates. Bug Fixes: * Prevent a crash when using both dns64 and filter-a. * Stop passing UDP client addresses to update-policy external helpers. * Missing required NSEC3 for delegation not detected. * Tighten EUI48 and EUI64 text parsing. * GeoIP ACL state could be stale or wrong after reload. * Honor DNSSEC policy key tag ranges. * Fix a double free in mdig when EDNS options are specified. * Fix a crash when an IXFR falls back to AXFR with updates still pending. * Fix DS requests to parental agents over TLS. * Fix the rndc-confgen -q (quiet) option. * Enforce query ACLs for redirect zones and searched DLZs. * Check asnum validity in GeoIP ACLs. * Fix a crash on remote- servers lists that reference themselves. * A record from outside a response policy zone could crash named. * Invalid key-store configuration could abort the DNSSEC tools. * NSEC signature set could bypass the secure-delegation check. * Fix a possible nsupdate issue when using GSS-TSIG. * Fix a crash with a single- element geoip sortlist. * Prevent out-of-bailiwick CNAMEs from evicting cached records. * Restore periodic cleanup of stale resolver address data. * Fix named- checkconf/named crash with malformed key name. * Prevent resolver crashes while processing DNS over TCP. * Ensure NSEC authority does not cross zonecut boundary. * Treat an unusable NSEC3 chain as a verification failure. * Treat non-canonical RPZ prefixes as any other failure. * Negative caching stopped working with stale-answer-client-timeout set to 0. * An unterminated OpenSSL private-key Label: field could be read past its parser buffer. * Restore SMF support on Solaris and illumos. * Fix compilation on GNU/Hurd. * dig +yaml was producing invalid YAML when a lookup failed. * Properly prevent TSIG generation command line injection attacks. * Fix a potential heap bounds overflow write in dnssec-signzone. * Fix crashes on invalid DNSTAP input in dnstap-read. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Basesystem Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP7-2026-4285 * Server Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP7-2026-4285 ## Package List: * Basesystem Module 15-SP7 (aarch64 ppc64le s390x x86_64) * bind-utils-9.20.29-150700.3.32.2 * bind-debuginfo-9.20.29-150700.3.32.2 * bind-utils-debuginfo-9.20.29-150700.3.32.2 * bind-debugsource-9.20.29-150700.3.32.2 * Server Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * bind-debuginfo-9.20.29-150700.3.32.2 * bind-9.20.29-150700.3.32.2 * bind-debugsource-9.20.29-150700.3.32.2 * Server Applications Module 15-SP7 (noarch) * bind-doc-9.20.29-150700.3.32.2 ## References: * https://www.suse.com/security/cve/CVE-2026-19033.html * https://www.suse.com/security/cve/CVE-2026-19662.html * https://www.suse.com/security/cve/CVE-2026-19666.html * https://www.suse.com/security/cve/CVE-2026-19667.html * https://www.suse.com/security/cve/CVE-2026-19668.html * https://www.suse.com/security/cve/CVE-2026-19941.html * https://www.suse.com/security/cve/CVE-2026-75029.html * https://www.suse.com/security/cve/CVE-2026-76163.html * https://www.suse.com/security/cve/CVE-2026-77119.html * https://www.suse.com/security/cve/CVE-2026-77692.html * https://www.suse.com/security/cve/CVE-2026-78301.html * https://www.suse.com/security/cve/CVE-2026-80274.html * https://www.suse.com/security/cve/CVE-2026-81563.html * https://www.suse.com/security/cve/CVE-2026-81736.html * https://bugzilla.suse.com/show_bug.cgi?id=1280430 * https://bugzilla.suse.com/show_bug.cgi?id=1280432 * https://bugzilla.suse.com/show_bug.cgi?id=1280433 * https://bugzilla.suse.com/show_bug.cgi?id=1280435 * https://bugzilla.suse.com/show_bug.cgi?id=1280436 * https://bugzilla.suse.com/show_bug.cgi?id=1280437 * https://bugzilla.suse.com/show_bug.cgi?id=1280438 * https://bugzilla.suse.com/show_bug.cgi?id=1280439 * https://bugzilla.suse.com/show_bug.cgi?id=1280440 * https://bugzilla.suse.com/show_bug.cgi?id=1280441 * https://bugzilla.suse.com/show_bug.cgi?id=1280442 * https://bugzilla.suse.com/show_bug.cgi?id=1280443 * https://bugzilla.suse.com/show_bug.cgi?id=1280444 * https://bugzilla.suse.com/show_bug.cgi?id=1280445 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Tue Sep 22 20:36:09 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Tue, 22 Sep 2026 20:36:09 -0000 Subject: SUSE-SU-2026:4284-1: important: Security update for the Linux Kernel Message-ID: <179010936980.20921.11975715241124083113@af273d3f1972> # Security update for the Linux Kernel Announcement ID: SUSE-SU-2026:4284-1 Release Date: 2026-09-22T16:08:14Z Rating: important References: * bsc#1235944 * bsc#1242405 * bsc#1261604 * bsc#1263072 * bsc#1264734 * bsc#1266008 * bsc#1267023 * bsc#1268659 * bsc#1269000 * bsc#1269004 * bsc#1269238 * bsc#1269242 * bsc#1269306 * bsc#1269655 * bsc#1269731 * bsc#1271825 * bsc#1271830 * bsc#1272179 * bsc#1272182 * bsc#1272230 * bsc#1272385 * bsc#1272390 * bsc#1272868 * bsc#1272877 * bsc#1273060 * bsc#1273105 * bsc#1273251 * bsc#1273276 * bsc#1273303 * bsc#1273311 * bsc#1273422 * bsc#1273484 * bsc#1273488 * bsc#1273523 * bsc#1273555 * bsc#1273742 * bsc#1273745 * bsc#1273748 * bsc#1273762 * bsc#1273774 * bsc#1273869 * bsc#1273882 * bsc#1273891 * bsc#1273930 * bsc#1273944 * bsc#1273966 * bsc#1273995 * bsc#1274014 * bsc#1274041 * bsc#1274208 * bsc#1274274 * bsc#1274497 * bsc#1274547 * bsc#1274550 * bsc#1274696 * bsc#1274705 * bsc#1274752 * bsc#1274753 * bsc#1274754 * bsc#1274859 * bsc#1274888 * bsc#1274898 * bsc#1274902 * bsc#1274908 * bsc#1274941 * bsc#1275161 * bsc#1275304 * bsc#1275307 * bsc#1275470 * bsc#1275472 * bsc#1275474 * bsc#1275506 * bsc#1275528 * bsc#1275535 * bsc#1275540 * bsc#1275687 * bsc#1275696 * bsc#1275784 * bsc#1275798 * bsc#1275827 * bsc#1275867 * bsc#1275886 * bsc#1275905 * bsc#1275985 * bsc#1276006 * bsc#1276350 * bsc#1276395 * bsc#1276665 * bsc#1276931 * bsc#1277073 * bsc#1277285 * bsc#1277391 * bsc#1277408 * bsc#1277523 * bsc#1277553 * bsc#1277561 * bsc#1277571 * bsc#1277813 * bsc#1277837 * bsc#1277901 * bsc#1277908 * bsc#1278088 * bsc#1278233 * bsc#1278236 * bsc#1278253 * bsc#1278294 * bsc#1279422 * bsc#1279487 * bsc#1279813 * jsc#PED-16892 Cross-References: * CVE-2023-53109 * CVE-2024-57841 * CVE-2026-23451 * CVE-2026-31502 * CVE-2026-43456 * CVE-2026-43502 * CVE-2026-45968 * CVE-2026-52910 * CVE-2026-52912 * CVE-2026-52929 * CVE-2026-52977 * CVE-2026-53059 * CVE-2026-53163 * CVE-2026-53260 * CVE-2026-53264 * CVE-2026-53381 * CVE-2026-53388 * CVE-2026-63801 * CVE-2026-63823 * CVE-2026-63827 * CVE-2026-63887 * CVE-2026-63888 * CVE-2026-63920 * CVE-2026-63992 * CVE-2026-64002 * CVE-2026-64007 * CVE-2026-64010 * CVE-2026-64011 * CVE-2026-64015 * CVE-2026-64047 * CVE-2026-64048 * CVE-2026-64098 * CVE-2026-64109 * CVE-2026-64114 * CVE-2026-64115 * CVE-2026-64137 * CVE-2026-64266 * CVE-2026-64268 * CVE-2026-64304 * CVE-2026-64355 * CVE-2026-64423 * CVE-2026-64450 * CVE-2026-64481 * CVE-2026-64541 * CVE-2026-64543 * CVE-2026-64556 * CVE-2026-64562 * CVE-2026-64563 * CVE-2026-64572 * CVE-2026-64581 * CVE-2026-64593 * CVE-2026-68121 * CVE-2026-68136 * CVE-2026-68138 * CVE-2026-68155 * CVE-2026-68158 * CVE-2026-68159 * CVE-2026-68160 * CVE-2026-68202 * CVE-2026-68397 * CVE-2026-68398 * CVE-2026-68417 * CVE-2026-68426 * CVE-2026-68480 * CVE-2026-72020 * CVE-2026-72069 * CVE-2026-72083 * CVE-2026-72084 * CVE-2026-72123 * CVE-2026-72135 * CVE-2026-72164 * CVE-2026-72251 * CVE-2026-72288 * CVE-2026-72289 * CVE-2026-72323 * CVE-2026-72339 * CVE-2026-72389 * CVE-2026-74345 * CVE-2026-74377 * CVE-2026-74378 * CVE-2026-74388 * CVE-2026-74390 * CVE-2026-74394 * CVE-2026-74406 * CVE-2026-74454 * CVE-2026-74488 * CVE-2026-74496 * CVE-2026-74518 * CVE-2026-74537 * CVE-2026-74556 * CVE-2026-74582 * CVE-2026-74615 * CVE-2026-74616 * CVE-2026-74669 * CVE-2026-74695 * CVE-2026-74743 * CVE-2026-80580 * CVE-2026-80714 * CVE-2026-80716 * CVE-2026-80737 * CVE-2026-80909 CVSS scores: * CVE-2023-53109 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2023-53109 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2024-57841 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2024-57841 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-23451 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-23451 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-31502 ( SUSE ): 7.1 CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-31502 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-31502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43456 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43456 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43502 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-43502 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-43502 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-45968 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-45968 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52910 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52910 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52910 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52910 ( NVD ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52912 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-52912 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52912 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-52929 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52929 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52977 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-52977 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53059 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-53059 ( NVD ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-53059 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53163 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53163 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-53260 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53264 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53381 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53381 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63801 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63801 ( SUSE ): 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63801 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63823 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63823 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63823 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63827 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63827 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63887 ( SUSE ): 7.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63887 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63887 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63888 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63888 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:H/A:H * CVE-2026-63888 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63920 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-63920 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63920 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H * CVE-2026-63992 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-63992 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-63992 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64002 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64002 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64002 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64007 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64007 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64007 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64010 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64010 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( SUSE ): 7.5 CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64011 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64011 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64015 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64015 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64015 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64047 ( SUSE ): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64047 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64048 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64048 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64048 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64098 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64098 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64098 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64109 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64109 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64114 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64114 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64114 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64115 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64115 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64137 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64137 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64137 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64266 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-64266 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64268 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64268 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64304 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64304 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64355 ( SUSE ): 7.7 CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64355 ( SUSE ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64355 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64450 ( SUSE ): 7.1 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64450 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-64450 ( NVD ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H * CVE-2026-64481 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64481 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64481 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64541 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64541 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64541 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64543 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64556 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64556 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64562 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64562 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64563 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64563 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64563 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64572 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64572 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64581 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64581 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64581 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64593 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-64593 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68121 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:H * CVE-2026-68121 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68136 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68136 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68136 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68155 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68155 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68155 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-68158 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68158 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68158 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68159 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-68159 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H * CVE-2026-68159 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68160 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68160 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-68160 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68202 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68202 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68397 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68398 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68417 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68426 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68426 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68480 ( SUSE ): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N * CVE-2026-72020 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-72020 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72020 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72069 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72069 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72083 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72083 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72084 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72084 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72123 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72123 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72135 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72135 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72135 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72164 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72164 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72251 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72251 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-72251 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72288 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72288 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72289 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72289 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72289 ( NVD ): 9.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-72323 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-72323 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72323 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72339 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72339 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72339 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-72389 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-72389 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74345 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74345 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74345 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74377 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74377 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74377 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74378 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74378 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74378 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74388 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74388 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74388 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74390 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74390 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-74394 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74394 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74406 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74406 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74454 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74454 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H * CVE-2026-74454 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74488 ( SUSE ): 7.1 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-74488 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74496 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74518 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74518 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74537 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74537 ( NVD ): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74556 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H * CVE-2026-74556 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74582 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74582 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74615 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74615 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74615 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-74616 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74616 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74616 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74669 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74695 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74695 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-74743 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-74743 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-74743 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80580 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80580 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80580 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80714 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80714 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80714 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80716 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80716 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80716 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80737 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80737 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80737 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-80909 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-80909 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Availability Extension 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise Live Patching 15-SP4 * SUSE Linux Enterprise Micro 5.3 * SUSE Linux Enterprise Micro 5.4 * SUSE Linux Enterprise Micro for Rancher 5.3 * SUSE Linux Enterprise Micro for Rancher 5.4 * SUSE Linux Enterprise Real Time 15 SP4 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves 101 vulnerabilities, contains one feature and has eight security fixes can now be installed. ## Description: The SUSE Linux Enterprise 15 SP4 kernel was updated to fix various security issues: The following security issues were fixed: * CVE-2023-53109: net: tunnels: annotate lockless accesses to dev->needed_headroom (bsc#1242405 bsc#1275784). * CVE-2024-57841: net: fix memory leak in tcp_conn_request() (bsc#1235944). * CVE-2026-53260: tcp: Add preempt_{disable,enable}_nested() in reqsk_queue_hash_req() (bsc#1269731). * CVE-2026-23451: bonding: prevent potential infinite loop in bond_header_parse() (bsc#1261604). * CVE-2026-31502: team: fix header_ops type confusion with non-Ethernet ports (bsc#1263072). * CVE-2026-43456: bonding: fix type confusion in bond_setup_by_slave() (bsc#1264734). * CVE-2026-43502: net/rds: handle zerocopy send cleanup before the message is queued (bsc#1266008). * CVE-2026-45968: cpuidle: Skip governor when only one idle state is available (bsc#1267023). * CVE-2026-52910: bpf: Free reuseport cBPF prog after RCU grace period (bsc#1268659). * CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued (bsc#1269000). * CVE-2026-52929: sctp: stream: fully roll back denied add-stream state (bsc#1269004). * CVE-2026-52977: futex: Prevent lockup in requeue-PI during signal/ timeout wakeup (bsc#1269242). * CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655). * CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306). * CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238). * CVE-2026-53381: virtiofs: fix UAF on submount umount (bsc#1271830). * CVE-2026-63801: tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done (bsc#1272230). * CVE-2026-63823: keys: Pin request_key_auth payload in instantiate paths (bsc#1272182). * CVE-2026-63827: apparmor: fix use-after-free in rawdata dedup loop (bsc#1272179). * CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385). * CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390). * CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877). * CVE-2026-63992: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() (bsc#1272868). * CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774). * CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105). * CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882). * CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891). * CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762). * CVE-2026-64047: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring (bsc#1273060). * CVE-2026-64048: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot (bsc#1273484). * CVE-2026-64098: drm/virtio: use uninterruptible resv lock for plane updates (bsc#1273488). * CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748). * CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742). * CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745). * CVE-2026-64268: RDMA/siw: bound Read Response placement to the RREAD length (bsc#1273276). * CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944). * CVE-2026-64355: bpf: Reject fragmented frames in devmap (bsc#1273422). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274). * CVE-2026-64450: tipc: fix out-of-bounds read in broadcast Gap ACK blocks (bsc#1273523). * CVE-2026-64481: ALSA: hda/cs35l41: Fix firmware load work teardown (bsc#1274547). * CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303). * CVE-2026-64543: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() (bsc#1273311). * CVE-2026-64556: perf/core: Detach event groups during remove_on_exec (bsc#1273251). * CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930). * CVE-2026-64563: rhashtable: clear stale iter->p on table restart (bsc#1273995). * CVE-2026-64572: ipv4: fib: free fib_alias with kfree_rcu() on insert error path (bsc#1274014). * CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041). * CVE-2026-64593: btrfs: do not trim a device which is not writeable (bsc#1274497). * CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888). * CVE-2026-68136: net: gro: fix double aggregation of flush-marked skbs (bsc#1275474). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274941). * CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304). * CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307). * CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470). * CVE-2026-68160: ceph: fix pre-auth out-of-bounds read on snaptrace in ceph_handle_caps() (bsc#1275472). * CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161). * CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898). * CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908). * CVE-2026-68417: RDMA/siw: publish QP after initialization (bsc#1274696). * CVE-2026-68426: xfrm: fix stale skb->prev after async crypto steals a GSO segment (bsc#1274705). * CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208). * CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506). * CVE-2026-72069: locking/rt: Fix the incorrect RCU protection in rt_spin_unlock() (bsc#1275528). * CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535). * CVE-2026-72084: scsi: target: core: Generate correct identifiers for PR OUT transport IDs (bsc#1275540). * CVE-2026-72123: can: bcm: defer rx_op deallocation to workqueue to fix thrtimer UAF (bsc#1277523). * CVE-2026-72135: tpm: Make the TPM character devices non-seekable (bsc#1277571). * CVE-2026-72164: ocfs2: avoid moving extents to occupied clusters (bsc#1277553). * CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827). * CVE-2026-72288: KVM: arm64: vgic: Handle race between interrupt affinity change and LPI disabling (bsc#1275886). * CVE-2026-72289: KVM: arm64: vgic: Check the interrupt is still ours before migrating it (bsc#1275905). * CVE-2026-72323: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() (bsc#1275985). * CVE-2026-72339: qede: fix off-by-one in BD ring consumption on build_skb failure (bsc#1276006). * CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869). * CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling (bsc#1277285). * CVE-2026-74377: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path (bsc#1278236). * CVE-2026-74378: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (bsc#1278233). * CVE-2026-74388: ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data (bsc#1278253). * CVE-2026-74390: RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs (bsc#1278088). * CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check (bsc#1277408). * CVE-2026-74406: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive() (bsc#1276395). * CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073). * CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350). * CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867). * CVE-2026-74518: mm/hugetlb: fix list corruption in allocate_file_region_entries() (bsc#1275798). * CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687). * CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696). * CVE-2026-74582: packet: use consistent hard_header_len in non-ring send paths (bsc#1275784). * CVE-2026-74615: vxlan: do not arm the ageing timer on a device that is down (bsc#1277901). * CVE-2026-74616: xdp: reject clones that overrun skb_shared_info tailroom (bsc#1277813). * CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391). * CVE-2026-74695: netfilter: nf_flow_table: drop existing skb dst before skb_dst_set_noref() (bsc#1276931). * CVE-2026-74743: macvlan: inherit needed_headroom and needed_tailroom from lowerdev (bsc#1277908). * CVE-2026-80580: fbdev: bound mode sysfs output to the sysfs buffer (bsc#1278294). * CVE-2026-80714: ipvs: do not propagate one-packet flag to synced conns (bsc#1277561). * CVE-2026-80716: ALSA: pcm: wake linked drain waiters on unlink (bsc#1277837). * CVE-2026-80737: serial: amba-pl011: synchronize DMA teardown (bsc#1279487). * CVE-2026-80909: drm/amdgpu: Reject UVD message with invalid number of h265 refs (bsc#1279422). The following non security issues were fixed: * mkspec-dtb: Move DTS prefix into package list. * mkspec-dtb: Move provides-obsoletes to package list. * mkspec-dtb: Put per-architecture package lists into a hash. * mkspec-dtb: re-indent. * net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550). * perf: Reject exited events as group leaders (git-fixes). * powerpc/pseries: lparcfg - fix kbuf[] underflow (bsc#1274753 ltc#221289 bsc#1274754 ltc#221288 bsc#1274752 ltc#221290). * RDMA/siw: Introduce siw_cep_set_free_and_put (git-fixes). * RDMA/siw: Introduce siw_destroy_cep_sock (git-fixes). * RDMA/siw: Introduce siw_free_cm_id (git-fixes). * RDMA/siw: Only check attrs->cap.max_send_wr in siw_create_qp (git-fixes). * smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902). * smb: client: require net admin for CIFS SWN netlink (bsc#1273966). ## Special Instructions and Notes: * Please reboot the system after installing this update. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4284 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4284 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4284 * SUSE Linux Enterprise High Availability Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2026-4284 * SUSE Linux Enterprise Live Patching 15-SP4 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP4-2026-4284 * SUSE Linux Enterprise Micro for Rancher 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4284 * SUSE Linux Enterprise Micro 5.3 zypper in -t patch SUSE-SLE-Micro-5.3-2026-4284 * SUSE Linux Enterprise Micro for Rancher 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4284 * SUSE Linux Enterprise Micro 5.4 zypper in -t patch SUSE-SLE-Micro-5.4-2026-4284 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4284 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (nosrc ppc64le x86_64) * kernel-default-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * kernel-obs-build-5.14.21-150400.24.240.1 * kernel-syms-5.14.21-150400.24.240.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.240.2 * kernel-default-debugsource-5.14.21-150400.24.240.2 * kernel-default-debuginfo-5.14.21-150400.24.240.2 * kernel-obs-build-debugsource-5.14.21-150400.24.240.1 * kernel-default-devel-5.14.21-150400.24.240.2 * reiserfs-kmp-default-5.14.21-150400.24.240.2 * kernel-default-base-5.14.21-150400.24.240.2.150400.24.120.2 * kernel-default-devel-debuginfo-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * kernel-source-5.14.21-150400.24.240.1 * kernel-macros-5.14.21-150400.24.240.1 * kernel-devel-5.14.21-150400.24.240.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch nosrc) * kernel-docs-5.14.21-150400.24.240.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 nosrc) * kernel-64kb-5.14.21-150400.24.240.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64) * kernel-64kb-debugsource-5.14.21-150400.24.240.2 * kernel-64kb-devel-5.14.21-150400.24.240.2 * kernel-64kb-devel-debuginfo-5.14.21-150400.24.240.2 * kernel-64kb-debuginfo-5.14.21-150400.24.240.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 nosrc x86_64) * kernel-default-5.14.21-150400.24.240.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * kernel-obs-build-5.14.21-150400.24.240.1 * kernel-syms-5.14.21-150400.24.240.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.240.2 * kernel-default-debugsource-5.14.21-150400.24.240.2 * kernel-default-debuginfo-5.14.21-150400.24.240.2 * kernel-obs-build-debugsource-5.14.21-150400.24.240.1 * kernel-default-devel-5.14.21-150400.24.240.2 * reiserfs-kmp-default-5.14.21-150400.24.240.2 * kernel-default-base-5.14.21-150400.24.240.2.150400.24.120.2 * kernel-default-devel-debuginfo-5.14.21-150400.24.240.2 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * kernel-source-5.14.21-150400.24.240.1 * kernel-macros-5.14.21-150400.24.240.1 * kernel-devel-5.14.21-150400.24.240.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch nosrc) * kernel-docs-5.14.21-150400.24.240.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 nosrc x86_64) * kernel-default-5.14.21-150400.24.240.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * kernel-obs-build-5.14.21-150400.24.240.1 * kernel-syms-5.14.21-150400.24.240.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.240.2 * kernel-default-debugsource-5.14.21-150400.24.240.2 * kernel-default-debuginfo-5.14.21-150400.24.240.2 * kernel-obs-build-debugsource-5.14.21-150400.24.240.1 * kernel-default-devel-5.14.21-150400.24.240.2 * reiserfs-kmp-default-5.14.21-150400.24.240.2 * kernel-default-base-5.14.21-150400.24.240.2.150400.24.120.2 * kernel-default-devel-debuginfo-5.14.21-150400.24.240.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * kernel-source-5.14.21-150400.24.240.1 * kernel-macros-5.14.21-150400.24.240.1 * kernel-devel-5.14.21-150400.24.240.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch nosrc) * kernel-docs-5.14.21-150400.24.240.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 nosrc) * kernel-64kb-5.14.21-150400.24.240.2 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64) * kernel-64kb-debugsource-5.14.21-150400.24.240.2 * kernel-64kb-devel-5.14.21-150400.24.240.2 * kernel-64kb-devel-debuginfo-5.14.21-150400.24.240.2 * kernel-64kb-debuginfo-5.14.21-150400.24.240.2 * SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le s390x x86_64) * ocfs2-kmp-default-5.14.21-150400.24.240.2 * kernel-default-debugsource-5.14.21-150400.24.240.2 * kernel-default-debuginfo-5.14.21-150400.24.240.2 * dlm-kmp-default-5.14.21-150400.24.240.2 * cluster-md-kmp-default-5.14.21-150400.24.240.2 * dlm-kmp-default-debuginfo-5.14.21-150400.24.240.2 * gfs2-kmp-default-debuginfo-5.14.21-150400.24.240.2 * ocfs2-kmp-default-debuginfo-5.14.21-150400.24.240.2 * gfs2-kmp-default-5.14.21-150400.24.240.2 * cluster-md-kmp-default-debuginfo-5.14.21-150400.24.240.2 * SUSE Linux Enterprise High Availability Extension 15 SP4 (nosrc) * kernel-default-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Live Patching 15-SP4 (nosrc) * kernel-default-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Live Patching 15-SP4 (ppc64le s390x x86_64) * kernel-default-livepatch-5.14.21-150400.24.240.2 * kernel-livepatch-SLE15-SP4_Update_59-debugsource-1-150400.9.5.1 * kernel-default-debugsource-5.14.21-150400.24.240.2 * kernel-default-debuginfo-5.14.21-150400.24.240.2 * kernel-livepatch-5_14_21-150400_24_240-default-1-150400.9.5.1 * kernel-livepatch-5_14_21-150400_24_240-default-debuginfo-1-150400.9.5.1 * kernel-default-livepatch-devel-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 nosrc s390x x86_64) * kernel-default-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 x86_64) * kernel-default-base-5.14.21-150400.24.240.2.150400.24.120.2 * SUSE Linux Enterprise Micro for Rancher 5.3 (aarch64 s390x x86_64) * kernel-default-debugsource-5.14.21-150400.24.240.2 * kernel-default-debuginfo-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Micro for Rancher 5.3 (noarch) * kernel-source-5.14.21-150400.24.240.1 * kernel-macros-5.14.21-150400.24.240.1 * SUSE Linux Enterprise Micro 5.3 (aarch64 nosrc s390x x86_64) * kernel-default-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Micro 5.3 (aarch64 x86_64) * kernel-default-base-5.14.21-150400.24.240.2.150400.24.120.2 * SUSE Linux Enterprise Micro 5.3 (aarch64 s390x x86_64) * kernel-default-debugsource-5.14.21-150400.24.240.2 * kernel-default-debuginfo-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Micro 5.3 (noarch) * kernel-source-5.14.21-150400.24.240.1 * kernel-macros-5.14.21-150400.24.240.1 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 nosrc s390x x86_64) * kernel-default-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 x86_64) * kernel-default-base-5.14.21-150400.24.240.2.150400.24.120.2 * SUSE Linux Enterprise Micro for Rancher 5.4 (aarch64 s390x x86_64) * kernel-default-debugsource-5.14.21-150400.24.240.2 * kernel-default-debuginfo-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Micro for Rancher 5.4 (noarch) * kernel-source-5.14.21-150400.24.240.1 * kernel-macros-5.14.21-150400.24.240.1 * SUSE Linux Enterprise Micro 5.4 (aarch64 nosrc s390x x86_64) * kernel-default-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Micro 5.4 (aarch64 x86_64) * kernel-default-base-5.14.21-150400.24.240.2.150400.24.120.2 * SUSE Linux Enterprise Micro 5.4 (aarch64 s390x x86_64) * kernel-default-debugsource-5.14.21-150400.24.240.2 * kernel-default-debuginfo-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Micro 5.4 (noarch) * kernel-source-5.14.21-150400.24.240.1 * kernel-macros-5.14.21-150400.24.240.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 nosrc ppc64le s390x x86_64) * kernel-default-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le x86_64) * kernel-default-base-5.14.21-150400.24.240.2.150400.24.120.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * kernel-obs-build-5.14.21-150400.24.240.1 * kernel-syms-5.14.21-150400.24.240.1 * reiserfs-kmp-default-debuginfo-5.14.21-150400.24.240.2 * kernel-default-debugsource-5.14.21-150400.24.240.2 * kernel-default-debuginfo-5.14.21-150400.24.240.2 * kernel-obs-build-debugsource-5.14.21-150400.24.240.1 * reiserfs-kmp-default-5.14.21-150400.24.240.2 * kernel-default-devel-5.14.21-150400.24.240.2 * kernel-default-devel-debuginfo-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * kernel-source-5.14.21-150400.24.240.1 * kernel-macros-5.14.21-150400.24.240.1 * kernel-devel-5.14.21-150400.24.240.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch nosrc) * kernel-docs-5.14.21-150400.24.240.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (nosrc s390x) * kernel-zfcpdump-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (s390x) * kernel-zfcpdump-debuginfo-5.14.21-150400.24.240.2 * kernel-zfcpdump-debugsource-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 nosrc) * kernel-64kb-5.14.21-150400.24.240.2 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64) * kernel-64kb-debugsource-5.14.21-150400.24.240.2 * kernel-64kb-devel-5.14.21-150400.24.240.2 * kernel-64kb-devel-debuginfo-5.14.21-150400.24.240.2 * kernel-64kb-debuginfo-5.14.21-150400.24.240.2 ## References: * https://www.suse.com/security/cve/CVE-2023-53109.html * https://www.suse.com/security/cve/CVE-2024-57841.html * https://www.suse.com/security/cve/CVE-2026-23451.html * https://www.suse.com/security/cve/CVE-2026-31502.html * https://www.suse.com/security/cve/CVE-2026-43456.html * https://www.suse.com/security/cve/CVE-2026-43502.html * https://www.suse.com/security/cve/CVE-2026-45968.html * https://www.suse.com/security/cve/CVE-2026-52910.html * https://www.suse.com/security/cve/CVE-2026-52912.html * https://www.suse.com/security/cve/CVE-2026-52929.html * https://www.suse.com/security/cve/CVE-2026-52977.html * https://www.suse.com/security/cve/CVE-2026-53059.html * https://www.suse.com/security/cve/CVE-2026-53163.html * https://www.suse.com/security/cve/CVE-2026-53260.html * https://www.suse.com/security/cve/CVE-2026-53264.html * https://www.suse.com/security/cve/CVE-2026-53381.html * https://www.suse.com/security/cve/CVE-2026-53388.html * https://www.suse.com/security/cve/CVE-2026-63801.html * https://www.suse.com/security/cve/CVE-2026-63823.html * https://www.suse.com/security/cve/CVE-2026-63827.html * https://www.suse.com/security/cve/CVE-2026-63887.html * https://www.suse.com/security/cve/CVE-2026-63888.html * https://www.suse.com/security/cve/CVE-2026-63920.html * https://www.suse.com/security/cve/CVE-2026-63992.html * https://www.suse.com/security/cve/CVE-2026-64002.html * https://www.suse.com/security/cve/CVE-2026-64007.html * https://www.suse.com/security/cve/CVE-2026-64010.html * https://www.suse.com/security/cve/CVE-2026-64011.html * https://www.suse.com/security/cve/CVE-2026-64015.html * https://www.suse.com/security/cve/CVE-2026-64047.html * https://www.suse.com/security/cve/CVE-2026-64048.html * https://www.suse.com/security/cve/CVE-2026-64098.html * https://www.suse.com/security/cve/CVE-2026-64109.html * https://www.suse.com/security/cve/CVE-2026-64114.html * https://www.suse.com/security/cve/CVE-2026-64115.html * https://www.suse.com/security/cve/CVE-2026-64137.html * https://www.suse.com/security/cve/CVE-2026-64266.html * https://www.suse.com/security/cve/CVE-2026-64268.html * https://www.suse.com/security/cve/CVE-2026-64304.html * https://www.suse.com/security/cve/CVE-2026-64355.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64450.html * https://www.suse.com/security/cve/CVE-2026-64481.html * https://www.suse.com/security/cve/CVE-2026-64541.html * https://www.suse.com/security/cve/CVE-2026-64543.html * https://www.suse.com/security/cve/CVE-2026-64556.html * https://www.suse.com/security/cve/CVE-2026-64562.html * https://www.suse.com/security/cve/CVE-2026-64563.html * https://www.suse.com/security/cve/CVE-2026-64572.html * https://www.suse.com/security/cve/CVE-2026-64581.html * https://www.suse.com/security/cve/CVE-2026-64593.html * https://www.suse.com/security/cve/CVE-2026-68121.html * https://www.suse.com/security/cve/CVE-2026-68136.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://www.suse.com/security/cve/CVE-2026-68155.html * https://www.suse.com/security/cve/CVE-2026-68158.html * https://www.suse.com/security/cve/CVE-2026-68159.html * https://www.suse.com/security/cve/CVE-2026-68160.html * https://www.suse.com/security/cve/CVE-2026-68202.html * https://www.suse.com/security/cve/CVE-2026-68397.html * https://www.suse.com/security/cve/CVE-2026-68398.html * https://www.suse.com/security/cve/CVE-2026-68417.html * https://www.suse.com/security/cve/CVE-2026-68426.html * https://www.suse.com/security/cve/CVE-2026-68480.html * https://www.suse.com/security/cve/CVE-2026-72020.html * https://www.suse.com/security/cve/CVE-2026-72069.html * https://www.suse.com/security/cve/CVE-2026-72083.html * https://www.suse.com/security/cve/CVE-2026-72084.html * https://www.suse.com/security/cve/CVE-2026-72123.html * https://www.suse.com/security/cve/CVE-2026-72135.html * https://www.suse.com/security/cve/CVE-2026-72164.html * https://www.suse.com/security/cve/CVE-2026-72251.html * https://www.suse.com/security/cve/CVE-2026-72288.html * https://www.suse.com/security/cve/CVE-2026-72289.html * https://www.suse.com/security/cve/CVE-2026-72323.html * https://www.suse.com/security/cve/CVE-2026-72339.html * https://www.suse.com/security/cve/CVE-2026-72389.html * https://www.suse.com/security/cve/CVE-2026-74345.html * https://www.suse.com/security/cve/CVE-2026-74377.html * https://www.suse.com/security/cve/CVE-2026-74378.html * https://www.suse.com/security/cve/CVE-2026-74388.html * https://www.suse.com/security/cve/CVE-2026-74390.html * https://www.suse.com/security/cve/CVE-2026-74394.html * https://www.suse.com/security/cve/CVE-2026-74406.html * https://www.suse.com/security/cve/CVE-2026-74454.html * https://www.suse.com/security/cve/CVE-2026-74488.html * https://www.suse.com/security/cve/CVE-2026-74496.html * https://www.suse.com/security/cve/CVE-2026-74518.html * https://www.suse.com/security/cve/CVE-2026-74537.html * https://www.suse.com/security/cve/CVE-2026-74556.html * https://www.suse.com/security/cve/CVE-2026-74582.html * https://www.suse.com/security/cve/CVE-2026-74615.html * https://www.suse.com/security/cve/CVE-2026-74616.html * https://www.suse.com/security/cve/CVE-2026-74669.html * https://www.suse.com/security/cve/CVE-2026-74695.html * https://www.suse.com/security/cve/CVE-2026-74743.html * https://www.suse.com/security/cve/CVE-2026-80580.html * https://www.suse.com/security/cve/CVE-2026-80714.html * https://www.suse.com/security/cve/CVE-2026-80716.html * https://www.suse.com/security/cve/CVE-2026-80737.html * https://www.suse.com/security/cve/CVE-2026-80909.html * https://bugzilla.suse.com/show_bug.cgi?id=1235944 * https://bugzilla.suse.com/show_bug.cgi?id=1242405 * https://bugzilla.suse.com/show_bug.cgi?id=1261604 * https://bugzilla.suse.com/show_bug.cgi?id=1263072 * https://bugzilla.suse.com/show_bug.cgi?id=1264734 * https://bugzilla.suse.com/show_bug.cgi?id=1266008 * https://bugzilla.suse.com/show_bug.cgi?id=1267023 * https://bugzilla.suse.com/show_bug.cgi?id=1268659 * https://bugzilla.suse.com/show_bug.cgi?id=1269000 * https://bugzilla.suse.com/show_bug.cgi?id=1269004 * https://bugzilla.suse.com/show_bug.cgi?id=1269238 * https://bugzilla.suse.com/show_bug.cgi?id=1269242 * https://bugzilla.suse.com/show_bug.cgi?id=1269306 * https://bugzilla.suse.com/show_bug.cgi?id=1269655 * https://bugzilla.suse.com/show_bug.cgi?id=1269731 * https://bugzilla.suse.com/show_bug.cgi?id=1271825 * https://bugzilla.suse.com/show_bug.cgi?id=1271830 * https://bugzilla.suse.com/show_bug.cgi?id=1272179 * https://bugzilla.suse.com/show_bug.cgi?id=1272182 * https://bugzilla.suse.com/show_bug.cgi?id=1272230 * https://bugzilla.suse.com/show_bug.cgi?id=1272385 * https://bugzilla.suse.com/show_bug.cgi?id=1272390 * https://bugzilla.suse.com/show_bug.cgi?id=1272868 * https://bugzilla.suse.com/show_bug.cgi?id=1272877 * https://bugzilla.suse.com/show_bug.cgi?id=1273060 * https://bugzilla.suse.com/show_bug.cgi?id=1273105 * https://bugzilla.suse.com/show_bug.cgi?id=1273251 * https://bugzilla.suse.com/show_bug.cgi?id=1273276 * https://bugzilla.suse.com/show_bug.cgi?id=1273303 * https://bugzilla.suse.com/show_bug.cgi?id=1273311 * https://bugzilla.suse.com/show_bug.cgi?id=1273422 * https://bugzilla.suse.com/show_bug.cgi?id=1273484 * https://bugzilla.suse.com/show_bug.cgi?id=1273488 * https://bugzilla.suse.com/show_bug.cgi?id=1273523 * https://bugzilla.suse.com/show_bug.cgi?id=1273555 * https://bugzilla.suse.com/show_bug.cgi?id=1273742 * https://bugzilla.suse.com/show_bug.cgi?id=1273745 * https://bugzilla.suse.com/show_bug.cgi?id=1273748 * https://bugzilla.suse.com/show_bug.cgi?id=1273762 * https://bugzilla.suse.com/show_bug.cgi?id=1273774 * https://bugzilla.suse.com/show_bug.cgi?id=1273869 * https://bugzilla.suse.com/show_bug.cgi?id=1273882 * https://bugzilla.suse.com/show_bug.cgi?id=1273891 * https://bugzilla.suse.com/show_bug.cgi?id=1273930 * https://bugzilla.suse.com/show_bug.cgi?id=1273944 * https://bugzilla.suse.com/show_bug.cgi?id=1273966 * https://bugzilla.suse.com/show_bug.cgi?id=1273995 * https://bugzilla.suse.com/show_bug.cgi?id=1274014 * https://bugzilla.suse.com/show_bug.cgi?id=1274041 * https://bugzilla.suse.com/show_bug.cgi?id=1274208 * https://bugzilla.suse.com/show_bug.cgi?id=1274274 * https://bugzilla.suse.com/show_bug.cgi?id=1274497 * https://bugzilla.suse.com/show_bug.cgi?id=1274547 * https://bugzilla.suse.com/show_bug.cgi?id=1274550 * https://bugzilla.suse.com/show_bug.cgi?id=1274696 * https://bugzilla.suse.com/show_bug.cgi?id=1274705 * https://bugzilla.suse.com/show_bug.cgi?id=1274752 * https://bugzilla.suse.com/show_bug.cgi?id=1274753 * https://bugzilla.suse.com/show_bug.cgi?id=1274754 * https://bugzilla.suse.com/show_bug.cgi?id=1274859 * https://bugzilla.suse.com/show_bug.cgi?id=1274888 * https://bugzilla.suse.com/show_bug.cgi?id=1274898 * https://bugzilla.suse.com/show_bug.cgi?id=1274902 * https://bugzilla.suse.com/show_bug.cgi?id=1274908 * https://bugzilla.suse.com/show_bug.cgi?id=1274941 * https://bugzilla.suse.com/show_bug.cgi?id=1275161 * https://bugzilla.suse.com/show_bug.cgi?id=1275304 * https://bugzilla.suse.com/show_bug.cgi?id=1275307 * https://bugzilla.suse.com/show_bug.cgi?id=1275470 * https://bugzilla.suse.com/show_bug.cgi?id=1275472 * https://bugzilla.suse.com/show_bug.cgi?id=1275474 * https://bugzilla.suse.com/show_bug.cgi?id=1275506 * https://bugzilla.suse.com/show_bug.cgi?id=1275528 * https://bugzilla.suse.com/show_bug.cgi?id=1275535 * https://bugzilla.suse.com/show_bug.cgi?id=1275540 * https://bugzilla.suse.com/show_bug.cgi?id=1275687 * https://bugzilla.suse.com/show_bug.cgi?id=1275696 * https://bugzilla.suse.com/show_bug.cgi?id=1275784 * https://bugzilla.suse.com/show_bug.cgi?id=1275798 * https://bugzilla.suse.com/show_bug.cgi?id=1275827 * https://bugzilla.suse.com/show_bug.cgi?id=1275867 * https://bugzilla.suse.com/show_bug.cgi?id=1275886 * https://bugzilla.suse.com/show_bug.cgi?id=1275905 * https://bugzilla.suse.com/show_bug.cgi?id=1275985 * https://bugzilla.suse.com/show_bug.cgi?id=1276006 * https://bugzilla.suse.com/show_bug.cgi?id=1276350 * https://bugzilla.suse.com/show_bug.cgi?id=1276395 * https://bugzilla.suse.com/show_bug.cgi?id=1276665 * https://bugzilla.suse.com/show_bug.cgi?id=1276931 * https://bugzilla.suse.com/show_bug.cgi?id=1277073 * https://bugzilla.suse.com/show_bug.cgi?id=1277285 * https://bugzilla.suse.com/show_bug.cgi?id=1277391 * https://bugzilla.suse.com/show_bug.cgi?id=1277408 * https://bugzilla.suse.com/show_bug.cgi?id=1277523 * https://bugzilla.suse.com/show_bug.cgi?id=1277553 * https://bugzilla.suse.com/show_bug.cgi?id=1277561 * https://bugzilla.suse.com/show_bug.cgi?id=1277571 * https://bugzilla.suse.com/show_bug.cgi?id=1277813 * https://bugzilla.suse.com/show_bug.cgi?id=1277837 * https://bugzilla.suse.com/show_bug.cgi?id=1277901 * https://bugzilla.suse.com/show_bug.cgi?id=1277908 * https://bugzilla.suse.com/show_bug.cgi?id=1278088 * https://bugzilla.suse.com/show_bug.cgi?id=1278233 * https://bugzilla.suse.com/show_bug.cgi?id=1278236 * https://bugzilla.suse.com/show_bug.cgi?id=1278253 * https://bugzilla.suse.com/show_bug.cgi?id=1278294 * https://bugzilla.suse.com/show_bug.cgi?id=1279422 * https://bugzilla.suse.com/show_bug.cgi?id=1279487 * https://bugzilla.suse.com/show_bug.cgi?id=1279813 * https://jira.suse.com/browse/PED-16892 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 23 12:30:50 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 23 Sep 2026 12:30:50 -0000 Subject: SUSE-SU-2026:4296-1: important: Security update for util-linux Message-ID: <179016665043.13743.1554226682008241986@c47cdf24d69a> # Security update for util-linux Announcement ID: SUSE-SU-2026:4296-1 Release Date: 2026-09-23T07:56:55Z Rating: important References: * bsc#1261606 * bsc#1268886 * bsc#1269583 Cross-References: * CVE-2026-13595 * CVE-2026-27456 * CVE-2026-53613 CVSS scores: * CVE-2026-13595 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-13595 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-13595 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-13595 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-27456 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-27456 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53613 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for util-linux fixes the following issues: * CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). * CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). * CVE-2026-53613: Local Privilege Escalation via TOCTOU in mount(8) ? Target Path Redirection (bsc#1268886) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4296 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4296 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * libsmartcols-devel-2.33.2-4.57.1 * python-libmount-debugsource-2.33.2-4.57.1 * util-linux-debugsource-2.33.2-4.57.1 * uuidd-debuginfo-2.33.2-4.57.1 * util-linux-systemd-debugsource-2.33.2-4.57.1 * libfdisk1-debuginfo-2.33.2-4.57.1 * uuidd-2.33.2-4.57.1 * libuuid1-2.33.2-4.57.1 * python-libmount-2.33.2-4.57.1 * libuuid1-debuginfo-2.33.2-4.57.1 * libsmartcols1-debuginfo-2.33.2-4.57.1 * util-linux-debuginfo-2.33.2-4.57.1 * util-linux-systemd-debuginfo-2.33.2-4.57.1 * libblkid-devel-2.33.2-4.57.1 * libblkid1-debuginfo-2.33.2-4.57.1 * libmount-devel-2.33.2-4.57.1 * libuuid-devel-2.33.2-4.57.1 * libmount1-debuginfo-2.33.2-4.57.1 * libsmartcols1-2.33.2-4.57.1 * libfdisk1-2.33.2-4.57.1 * util-linux-2.33.2-4.57.1 * libblkid1-2.33.2-4.57.1 * libmount1-2.33.2-4.57.1 * python-libmount-debuginfo-2.33.2-4.57.1 * util-linux-systemd-2.33.2-4.57.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (s390x x86_64) * libmount1-32bit-2.33.2-4.57.1 * libblkid1-debuginfo-32bit-2.33.2-4.57.1 * libmount1-debuginfo-32bit-2.33.2-4.57.1 * libuuid1-32bit-2.33.2-4.57.1 * libuuid1-debuginfo-32bit-2.33.2-4.57.1 * libblkid1-32bit-2.33.2-4.57.1 * SUSE Linux Enterprise Server 12 SP5 LTSS (noarch) * util-linux-lang-2.33.2-4.57.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * libsmartcols-devel-2.33.2-4.57.1 * python-libmount-debugsource-2.33.2-4.57.1 * util-linux-debugsource-2.33.2-4.57.1 * uuidd-debuginfo-2.33.2-4.57.1 * libmount1-debuginfo-32bit-2.33.2-4.57.1 * util-linux-systemd-debugsource-2.33.2-4.57.1 * libfdisk1-debuginfo-2.33.2-4.57.1 * libblkid1-32bit-2.33.2-4.57.1 * uuidd-2.33.2-4.57.1 * libuuid1-2.33.2-4.57.1 * python-libmount-2.33.2-4.57.1 * libuuid1-debuginfo-2.33.2-4.57.1 * libblkid1-debuginfo-32bit-2.33.2-4.57.1 * libsmartcols1-debuginfo-2.33.2-4.57.1 * libuuid1-32bit-2.33.2-4.57.1 * util-linux-debuginfo-2.33.2-4.57.1 * util-linux-systemd-debuginfo-2.33.2-4.57.1 * libblkid-devel-2.33.2-4.57.1 * libblkid1-debuginfo-2.33.2-4.57.1 * libmount1-32bit-2.33.2-4.57.1 * libmount-devel-2.33.2-4.57.1 * libuuid-devel-2.33.2-4.57.1 * libmount1-debuginfo-2.33.2-4.57.1 * libsmartcols1-2.33.2-4.57.1 * libfdisk1-2.33.2-4.57.1 * util-linux-2.33.2-4.57.1 * libblkid1-2.33.2-4.57.1 * libmount1-2.33.2-4.57.1 * python-libmount-debuginfo-2.33.2-4.57.1 * libuuid1-debuginfo-32bit-2.33.2-4.57.1 * util-linux-systemd-2.33.2-4.57.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (noarch) * util-linux-lang-2.33.2-4.57.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13595.html * https://www.suse.com/security/cve/CVE-2026-27456.html * https://www.suse.com/security/cve/CVE-2026-53613.html * https://bugzilla.suse.com/show_bug.cgi?id=1261606 * https://bugzilla.suse.com/show_bug.cgi?id=1268886 * https://bugzilla.suse.com/show_bug.cgi?id=1269583 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 23 12:31:30 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 23 Sep 2026 12:31:30 -0000 Subject: SUSE-SU-2026:4294-1: important: Security update for gdb Message-ID: <179016669015.13743.10192960336609350801@c47cdf24d69a> # Security update for gdb Announcement ID: SUSE-SU-2026:4294-1 Release Date: 2026-09-23T07:56:27Z Rating: important References: * bsc#1277757 Cross-References: * CVE-2026-13732 CVSS scores: * CVE-2026-13732 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-13732 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-13732 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves one vulnerability can now be installed. ## Description: This update for gdb fixes the following issue: * CVE-2026-13732: Out-of-bounds write in STABS parser read_member_functions() via crafted ELF (bsc#1277757). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4294 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4294 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * gdb-debuginfo-13.2-2.29.1 * gdb-debugsource-13.2-2.29.1 * gdb-13.2-2.29.1 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * gdb-debuginfo-13.2-2.29.1 * gdb-debugsource-13.2-2.29.1 * gdb-13.2-2.29.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13732.html * https://bugzilla.suse.com/show_bug.cgi?id=1277757 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 23 12:32:16 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 23 Sep 2026 12:32:16 -0000 Subject: SUSE-SU-2026:4293-1: important: Security update for google-osconfig-agent Message-ID: <179016673659.13743.1148258588497307994@c47cdf24d69a> # Security update for google-osconfig-agent Announcement ID: SUSE-SU-2026:4293-1 Release Date: 2026-09-23T07:56:13Z Rating: important References: * bsc#1272118 * bsc#1276722 * bsc#1278597 * bsc#1278967 * bsc#1279297 * bsc#1279414 Cross-References: * CVE-2026-41178 * CVE-2026-56852 * CVE-2026-56854 * CVE-2026-56855 * CVE-2026-78662 * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56854 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56854 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56854 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56855 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78662 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78662 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78662 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84445 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Public Cloud Module 15-SP4 * Public Cloud Module 15-SP5 * Public Cloud Module 15-SP6 * Public Cloud Module 15-SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.3 An update that solves eight vulnerabilities can now be installed. ## Description: This update for google-osconfig-agent fixes the following issues: * CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276722). * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272118). * CVE-2026-56854: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). * CVE-2026-56855: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). * CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). * CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279297). * CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279414). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278967). Changes for google-osconfig-agent: * Update to version 20260908.00 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 15-SP4 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP4-2026-4293 * Public Cloud Module 15-SP5 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP5-2026-4293 * Public Cloud Module 15-SP6 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP6-2026-4293 * SUSE Linux Enterprise Micro 5.5 zypper in -t patch SUSE-SLE-Micro-5.5-2026-4293 * Public Cloud Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP7-2026-4293 ## Package List: * Public Cloud Module 15-SP4 (aarch64 ppc64le s390x x86_64) * google-osconfig-agent-20260911.00-150000.1.67.1 * Public Cloud Module 15-SP5 (aarch64 ppc64le s390x x86_64) * google-osconfig-agent-20260911.00-150000.1.67.1 * Public Cloud Module 15-SP6 (aarch64 ppc64le s390x x86_64) * google-osconfig-agent-20260911.00-150000.1.67.1 * SUSE Linux Enterprise Micro 5.5 (aarch64 ppc64le s390x x86_64) * google-osconfig-agent-20260911.00-150000.1.67.1 * Public Cloud Module 15-SP7 (aarch64 ppc64le s390x x86_64) * google-osconfig-agent-20260911.00-150000.1.67.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41178.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://www.suse.com/security/cve/CVE-2026-56854.html * https://www.suse.com/security/cve/CVE-2026-56855.html * https://www.suse.com/security/cve/CVE-2026-78662.html * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1272118 * https://bugzilla.suse.com/show_bug.cgi?id=1276722 * https://bugzilla.suse.com/show_bug.cgi?id=1278597 * https://bugzilla.suse.com/show_bug.cgi?id=1278967 * https://bugzilla.suse.com/show_bug.cgi?id=1279297 * https://bugzilla.suse.com/show_bug.cgi?id=1279414 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 23 12:32:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 23 Sep 2026 12:32:53 -0000 Subject: SUSE-SU-2026:4292-1: important: Security update for google-osconfig-agent Message-ID: <179016677380.13743.13104516969949734602@c47cdf24d69a> # Security update for google-osconfig-agent Announcement ID: SUSE-SU-2026:4292-1 Release Date: 2026-09-23T07:55:28Z Rating: important References: * bsc#1272118 * bsc#1276722 * bsc#1278597 * bsc#1278967 * bsc#1279297 * bsc#1279414 Cross-References: * CVE-2026-41178 * CVE-2026-56852 * CVE-2026-56854 * CVE-2026-56855 * CVE-2026-78662 * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-41178 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-41178 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-56852 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56852 ( SUSE ): 5.9 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56852 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56854 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56854 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56854 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56855 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78662 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78662 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78662 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84445 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * Public Cloud Module 12 * SUSE Linux Enterprise High Performance Computing 12 SP2 * SUSE Linux Enterprise High Performance Computing 12 SP3 * SUSE Linux Enterprise High Performance Computing 12 SP4 * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 * SUSE Linux Enterprise Server 12 SP1 * SUSE Linux Enterprise Server 12 SP2 * SUSE Linux Enterprise Server 12 SP3 * SUSE Linux Enterprise Server 12 SP4 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 * SUSE Linux Enterprise Server for SAP Applications 12 SP1 * SUSE Linux Enterprise Server for SAP Applications 12 SP2 * SUSE Linux Enterprise Server for SAP Applications 12 SP3 * SUSE Linux Enterprise Server for SAP Applications 12 SP4 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves eight vulnerabilities can now be installed. ## Description: This update for google-osconfig-agent fixes the following issues: * CVE-2026-41178: go.opentelemetry.io/otel/baggage: no rejection of raw-length headers in baggage parsing allows for DoS via oversized inputs (bsc#1276722). * CVE-2026-56852: golang.org/x/text/unicode/norm: infinite loop on truncated/invalid UTF-8 input (bsc#1272118). * CVE-2026-56854: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). * CVE-2026-56855: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). * CVE-2026-78662: golang.org/x/crypto/ssh: authentication bypass and deadlocks in the crypto/ssh library (bsc#1278597). * CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279297). * CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279414). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1278967). Changes for google-osconfig-agent: * Update to version 20260908.00 ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * Public Cloud Module 12 zypper in -t patch SUSE-SLE-Module-Public-Cloud-12-2026-4292 ## Package List: * Public Cloud Module 12 (aarch64 ppc64le s390x x86_64) * google-osconfig-agent-20260911.00-1.60.1 ## References: * https://www.suse.com/security/cve/CVE-2026-41178.html * https://www.suse.com/security/cve/CVE-2026-56852.html * https://www.suse.com/security/cve/CVE-2026-56854.html * https://www.suse.com/security/cve/CVE-2026-56855.html * https://www.suse.com/security/cve/CVE-2026-78662.html * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1272118 * https://bugzilla.suse.com/show_bug.cgi?id=1276722 * https://bugzilla.suse.com/show_bug.cgi?id=1278597 * https://bugzilla.suse.com/show_bug.cgi?id=1278967 * https://bugzilla.suse.com/show_bug.cgi?id=1279297 * https://bugzilla.suse.com/show_bug.cgi?id=1279414 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 23 16:31:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 23 Sep 2026 16:31:03 -0000 Subject: SUSE-SU-2026:4299-1: important: Security update for the Linux Kernel (Live Patch 77 for SUSE Linux Enterprise 12 SP5) Message-ID: <179018106394.1955.14136582175047836931@cc827fc6be87> # Security update for the Linux Kernel (Live Patch 77 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:4299-1 Release Date: 2026-09-23T12:09:41Z Rating: important References: * bsc#1267388 * bsc#1274074 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64564 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.293 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-4299 SUSE-SLE-Live- Patching-12-SP5-2026-4304 SUSE-SLE-Live-Patching-12-SP5-2026-4297 SUSE-SLE-Live- Patching-12-SP5-2026-4300 SUSE-SLE-Live-Patching-12-SP5-2026-4305 SUSE-SLE-Live- Patching-12-SP5-2026-4306 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_269-default-18-2.1 * kgraft-patch-4_12_14-122_275-default-15-2.1 * kgraft-patch-4_12_14-122_293-default-12-2.1 * kgraft-patch-4_12_14-122_280-default-13-2.1 * kgraft-patch-4_12_14-122_283-default-13-2.1 * kgraft-patch-4_12_14-122_290-default-13-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 23 16:32:05 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 23 Sep 2026 16:32:05 -0000 Subject: SUSE-SU-2026:4302-1: important: Security update for perl-Authen-SASL Message-ID: <179018112551.1955.514907140621598072@cc827fc6be87> # Security update for perl-Authen-SASL Announcement ID: SUSE-SU-2026:4302-1 Release Date: 2026-09-23T11:37:23Z Rating: important References: * bsc#1279806 Cross-References: * CVE-2026-86219 CVSS scores: * CVE-2026-86219 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-86219 ( SUSE ): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-86219 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * Development Tools Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves one vulnerability can now be installed. ## Description: This update for perl-Authen-SASL fixes the following issue: * CVE-2026-86219: replayed authentication responses accepted due to unverified nonce in `server_step` (bsc#1279806). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4302 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4302 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4302 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4302 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4302 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4302 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4302 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4302 * Development Tools Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Development-Tools-15-SP7-2026-4302 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4302 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4302 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (noarch) * perl-Authen-SASL-2.16-150000.1.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (noarch) * perl-Authen-SASL-2.16-150000.1.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (noarch) * perl-Authen-SASL-2.16-150000.1.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (noarch) * perl-Authen-SASL-2.16-150000.1.9.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (noarch) * perl-Authen-SASL-2.16-150000.1.9.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (noarch) * perl-Authen-SASL-2.16-150000.1.9.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch) * perl-Authen-SASL-2.16-150000.1.9.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (noarch) * perl-Authen-SASL-2.16-150000.1.9.1 * Development Tools Module 15-SP7 (noarch) * perl-Authen-SASL-2.16-150000.1.9.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (noarch) * perl-Authen-SASL-2.16-150000.1.9.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * perl-Authen-SASL-2.16-150000.1.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-86219.html * https://bugzilla.suse.com/show_bug.cgi?id=1279806 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 23 16:33:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 23 Sep 2026 16:33:55 -0000 Subject: SUSE-SU-2026:4298-1: moderate: Security update for python-WebOb Message-ID: <179018123564.1955.2267280391388607757@cc827fc6be87> # Security update for python-WebOb Announcement ID: SUSE-SU-2026:4298-1 Release Date: 2026-09-23T10:17:45Z Rating: moderate References: * bsc#1275917 Cross-References: * CVE-2026-54770 CVSS scores: * CVE-2026-54770 ( SUSE ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N * CVE-2026-54770 ( NVD ): 6.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Affected Products: * openSUSE Leap 15.4 An update that solves one vulnerability can now be installed. ## Description: This update for python-WebOb fixes the following issues: * CVE-2026-54770: an unauthenticated attacker who can influence an application's redirect target can send users to an attacker-controlled host for phishing or OAuth and SSO token theft (bsc#1275917). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4298 ## Package List: * openSUSE Leap 15.4 (noarch) * python311-WebOb-1.8.7-150400.11.9.1 ## References: * https://www.suse.com/security/cve/CVE-2026-54770.html * https://bugzilla.suse.com/show_bug.cgi?id=1275917 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 23 20:30:53 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 23 Sep 2026 20:30:53 -0000 Subject: SUSE-SU-2026:4312-1: important: Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise 15 SP5) Message-ID: <179019545379.16895.11884541587669570541@af273d3f1972> # Security update for the Linux Kernel (Live Patch 40 for SUSE Linux Enterprise 15 SP5) Announcement ID: SUSE-SU-2026:4312-1 Release Date: 2026-09-23T16:04:39Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 5.14.21-150500.55.166 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-4312 SUSE-SLE- Module-Live-Patching-15-SP5-2026-4313 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-4312 SUSE-2026-4313 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_166-default-5-150500.2.1 * kernel-livepatch-5_14_21-150500_55_149-default-8-150500.2.1 * kernel-livepatch-5_14_21-150500_55_149-default-debuginfo-8-150500.2.1 * kernel-livepatch-5_14_21-150500_55_166-default-debuginfo-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_40-debugsource-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_38-debugsource-8-150500.2.1 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_166-default-5-150500.2.1 * kernel-livepatch-5_14_21-150500_55_149-default-8-150500.2.1 * kernel-livepatch-5_14_21-150500_55_149-default-debuginfo-8-150500.2.1 * kernel-livepatch-5_14_21-150500_55_166-default-debuginfo-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_40-debugsource-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_38-debugsource-8-150500.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 23 20:32:03 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 23 Sep 2026 20:32:03 -0000 Subject: SUSE-SU-2026:4310-1: important: Security update for the Linux Kernel (Live Patch 82 for SUSE Linux Enterprise 12 SP5) Message-ID: <179019552324.16895.7952911790652221843@af273d3f1972> # Security update for the Linux Kernel (Live Patch 82 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:4310-1 Release Date: 2026-09-23T14:04:06Z Rating: important References: * bsc#1267388 * bsc#1274074 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64564 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.307 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-4310 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_307-default-6-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 23 20:32:55 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 23 Sep 2026 20:32:55 -0000 Subject: SUSE-SU-2026:4311-1: important: Security update for podofo Message-ID: <179019557507.16895.6773309113779131513@af273d3f1972> # Security update for podofo Announcement ID: SUSE-SU-2026:4311-1 Release Date: 2026-09-23T15:58:05Z Rating: important References: * bsc#1084891 * bsc#1184645 * bsc#1186588 * bsc#1190178 Cross-References: * CVE-2018-8002 * CVE-2020-18971 * CVE-2021-30470 * CVE-2021-30471 CVSS scores: * CVE-2018-8002 ( SUSE ): 3.3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2018-8002 ( NVD ): 8.8 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2020-18971 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2021-30470 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2021-30470 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2021-30471 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2021-30471 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * openSUSE Leap 15.3 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for podofo fixes the following issues: * CVE-2018-8002: infinite loop vulnerability in ParseFileComplete() (bsc#1084891). * CVE-2020-18971: stack-based buffer overflow in src/base/PdfDictionary.cpp (bsc#1190178). * CVE-2021-30470: uncontrolled recursive call of funtions in src/base/PdfTokenizer.cpp can lead to a stack overflow (bsc#1186588). * CVE-2021-30471: uncontrolled recursive call in PdfNamesTree:AddToDictionary function in src/podofo/doc/PdfNamesTree.cpp (bsc#1184645). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.3 zypper in -t patch SUSE-2026-4311 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4311 ## Package List: * openSUSE Leap 15.3 (aarch64 i586 ppc64le s390x x86_64) * podofo-debuginfo-0.9.6-150300.3.18.1 * podofo-0.9.6-150300.3.18.1 * libpodofo0_9_6-debuginfo-0.9.6-150300.3.18.1 * libpodofo0_9_6-0.9.6-150300.3.18.1 * podofo-debugsource-0.9.6-150300.3.18.1 * libpodofo-devel-0.9.6-150300.3.18.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x x86_64) * podofo-debuginfo-0.9.6-150300.3.18.1 * libpodofo0_9_6-0.9.6-150300.3.18.1 * libpodofo0_9_6-debuginfo-0.9.6-150300.3.18.1 * podofo-debugsource-0.9.6-150300.3.18.1 ## References: * https://www.suse.com/security/cve/CVE-2018-8002.html * https://www.suse.com/security/cve/CVE-2020-18971.html * https://www.suse.com/security/cve/CVE-2021-30470.html * https://www.suse.com/security/cve/CVE-2021-30471.html * https://bugzilla.suse.com/show_bug.cgi?id=1084891 * https://bugzilla.suse.com/show_bug.cgi?id=1184645 * https://bugzilla.suse.com/show_bug.cgi?id=1186588 * https://bugzilla.suse.com/show_bug.cgi?id=1190178 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 23 20:33:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 23 Sep 2026 20:33:49 -0000 Subject: SUSE-SU-2026:4309-1: important: Security update for gimp Message-ID: <179019562928.16895.9707808255625047045@af273d3f1972> # Security update for gimp Announcement ID: SUSE-SU-2026:4309-1 Release Date: 2026-09-23T13:18:47Z Rating: important References: * bsc#1273151 * bsc#1274837 * bsc#1274840 * bsc#1276911 * bsc#1277378 * bsc#1279838 * bsc#1279839 Cross-References: * CVE-2026-59088 * CVE-2026-59090 * CVE-2026-66757 * CVE-2026-78465 * CVE-2026-80101 CVSS scores: * CVE-2026-59088 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-59088 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59088 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59088 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-59090 ( SUSE ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-59090 ( SUSE ): 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H * CVE-2026-59090 ( NVD ): 9.9 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-59090 ( NVD ): 8.4 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:H * CVE-2026-66757 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-66757 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-66757 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-78465 ( SUSE ): 5.8 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-78465 ( SUSE ): 5.8 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H * CVE-2026-78465 ( NVD ): 7.0 CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-80101 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-80101 ( SUSE ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L * CVE-2026-80101 ( NVD ): 4.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L Affected Products: * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Linux Enterprise Workstation Extension 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves five vulnerabilities and has two security fixes can now be installed. ## Description: This update for gimp fixes the following issues: Security issues fixed: * CVE-2026-59088: denial of service via signed integer overflow in FLI file processing (bsc#1274837). * CVE-2026-59090: arbitrary code execution in PSD plugin due to unsigned underflow (bsc#1274840). * CVE-2026-66757: signed integer overflow in `file-sgi` causes the plugin to crash when RLE-compressed SGI images are processed (bsc#1273151). * CVE-2026-78465: 32-bit integer overflow in PCX image memory calculations can cause undersized heap allocations (bsc#1277378). * CVE-2026-80101: independent header field validation in the XWD loader can cause heap out-of-bounds reads (bsc#1276911). Non security issues fixed: * RLE-compressed SGI files are written with a bad offset table and 57 of 144 scanlines fail to decode, on the patched and the released build alike (bsc#1279838). * XWD bytes-per-line guard can never fire, and load_xwd_f1_d24_b1() still allocates the unchecked header field (bsc#1279839). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4309 * SUSE Linux Enterprise Workstation Extension 15 SP7 zypper in -t patch SUSE-SLE-Product-WE-15-SP7-2026-4309 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4309 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * gimp-plugin-aa-debuginfo-2.10.30-150400.3.74.1 * libgimpui-2_0-0-debuginfo-2.10.30-150400.3.74.1 * gimp-2.10.30-150400.3.74.1 * libgimp-2_0-0-2.10.30-150400.3.74.1 * libgimpui-2_0-0-2.10.30-150400.3.74.1 * gimp-devel-2.10.30-150400.3.74.1 * libgimp-2_0-0-debuginfo-2.10.30-150400.3.74.1 * gimp-debuginfo-2.10.30-150400.3.74.1 * gimp-plugin-aa-2.10.30-150400.3.74.1 * gimp-devel-debuginfo-2.10.30-150400.3.74.1 * gimp-debugsource-2.10.30-150400.3.74.1 * openSUSE Leap 15.4 (noarch) * gimp-lang-2.10.30-150400.3.74.1 * openSUSE Leap 15.4 (x86_64) * libgimpui-2_0-0-32bit-2.10.30-150400.3.74.1 * libgimp-2_0-0-32bit-2.10.30-150400.3.74.1 * libgimp-2_0-0-32bit-debuginfo-2.10.30-150400.3.74.1 * libgimpui-2_0-0-32bit-debuginfo-2.10.30-150400.3.74.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libgimpui-2_0-0-64bit-debuginfo-2.10.30-150400.3.74.1 * libgimp-2_0-0-64bit-debuginfo-2.10.30-150400.3.74.1 * libgimp-2_0-0-64bit-2.10.30-150400.3.74.1 * libgimpui-2_0-0-64bit-2.10.30-150400.3.74.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (x86_64) * libgimpui-2_0-0-debuginfo-2.10.30-150400.3.74.1 * gimp-2.10.30-150400.3.74.1 * libgimp-2_0-0-2.10.30-150400.3.74.1 * libgimpui-2_0-0-2.10.30-150400.3.74.1 * gimp-devel-2.10.30-150400.3.74.1 * libgimp-2_0-0-debuginfo-2.10.30-150400.3.74.1 * gimp-debuginfo-2.10.30-150400.3.74.1 * gimp-devel-debuginfo-2.10.30-150400.3.74.1 * gimp-debugsource-2.10.30-150400.3.74.1 * SUSE Linux Enterprise Workstation Extension 15 SP7 (noarch) * gimp-lang-2.10.30-150400.3.74.1 * SUSE Package Hub 15 15-SP7 (aarch64 ppc64le s390x) * libgimpui-2_0-0-debuginfo-2.10.30-150400.3.74.1 * libgimpui-2_0-0-2.10.30-150400.3.74.1 * gimp-debugsource-2.10.30-150400.3.74.1 * libgimp-2_0-0-debuginfo-2.10.30-150400.3.74.1 * gimp-debuginfo-2.10.30-150400.3.74.1 * libgimp-2_0-0-2.10.30-150400.3.74.1 * SUSE Package Hub 15 15-SP7 (aarch64) * gimp-plugin-aa-debuginfo-2.10.30-150400.3.74.1 * gimp-2.10.30-150400.3.74.1 * gimp-devel-2.10.30-150400.3.74.1 * gimp-plugin-aa-2.10.30-150400.3.74.1 * gimp-devel-debuginfo-2.10.30-150400.3.74.1 * SUSE Package Hub 15 15-SP7 (noarch) * gimp-lang-2.10.30-150400.3.74.1 ## References: * https://www.suse.com/security/cve/CVE-2026-59088.html * https://www.suse.com/security/cve/CVE-2026-59090.html * https://www.suse.com/security/cve/CVE-2026-66757.html * https://www.suse.com/security/cve/CVE-2026-78465.html * https://www.suse.com/security/cve/CVE-2026-80101.html * https://bugzilla.suse.com/show_bug.cgi?id=1273151 * https://bugzilla.suse.com/show_bug.cgi?id=1274837 * https://bugzilla.suse.com/show_bug.cgi?id=1274840 * https://bugzilla.suse.com/show_bug.cgi?id=1276911 * https://bugzilla.suse.com/show_bug.cgi?id=1277378 * https://bugzilla.suse.com/show_bug.cgi?id=1279838 * https://bugzilla.suse.com/show_bug.cgi?id=1279839 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Wed Sep 23 20:34:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Wed, 23 Sep 2026 20:34:49 -0000 Subject: SUSE-SU-2026:4308-1: important: Security update for apptainer Message-ID: <179019568970.16895.5915592023472220399@af273d3f1972> # Security update for apptainer Announcement ID: SUSE-SU-2026:4308-1 Release Date: 2026-09-23T13:18:26Z Rating: important References: * bsc#1278666 * bsc#1279033 * bsc#1279236 * bsc#1279333 Cross-References: * CVE-2026-56854 * CVE-2026-56855 * CVE-2026-78662 * CVE-2026-84303 * CVE-2026-84304 * CVE-2026-84445 CVSS scores: * CVE-2026-56854 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-56854 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-56854 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-56855 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-56855 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-56855 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-78662 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-78662 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-78662 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-84303 ( SUSE ): 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N * CVE-2026-84303 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84304 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84304 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84304 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-84445 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-84445 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-84445 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * HPC Module 15-SP7 * openSUSE Leap 15.6 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for apptainer fixes the following issues: * CVE-2026-56854: golang.org/x/crypto/ssh: source-address restriction bypassed in 5 callback families (bsc#1278666). * CVE-2026-56855: golang.org/x/crypto/ssh: prevent DoS on deadlocked established channel (bsc#1278666). * CVE-2026-78662: golang.org/x/crypto/ssh: prevent DoS on deadlocked undecided channel (bsc#1278666). * CVE-2026-84303: google.golang.org/grpc: xDS RBAC HTTP filter implementation issue allows for bypass of authorization policies via mixed-case or canonical-case header matches (bsc#1279333). * CVE-2026-84304: google.golang.org/grpc: heap memory exhaustion via HTTP/2 DATA frame fragmentation (bsc#1279236). * CVE-2026-84445: google.golang.org/grpc: DoS via crash due to missing ':authority' and 'Host' headers in gRPC-Go xDS servers (bsc#1279033). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4308 * HPC Module 15-SP7 zypper in -t patch SUSE-SLE-Module-HPC-15-SP7-2026-4308 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4308 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4308 ## Package List: * openSUSE Leap 15.6 (aarch64 x86_64) * apptainer-suid-1.5.3-150600.4.43.1 * apptainer-debuginfo-1.5.3-150600.4.43.1 * apptainer-1.5.3-150600.4.43.1 * apptainer-suid-debuginfo-1.5.3-150600.4.43.1 * openSUSE Leap 15.6 (noarch) * apptainer-sle15_6-1.5.3-150600.4.43.1 * apptainer-leap-1.5.3-150600.4.43.1 * apptainer-sle16-1.5.3-150600.4.43.1 * apptainer-sle15_7-1.5.3-150600.4.43.1 * HPC Module 15-SP7 (aarch64 x86_64) * apptainer-debuginfo-1.5.3-150600.4.43.1 * apptainer-1.5.3-150600.4.43.1 * HPC Module 15-SP7 (noarch) * apptainer-sle15_7-1.5.3-150600.4.43.1 * SUSE Package Hub 15 15-SP7 (aarch64 x86_64) * apptainer-suid-1.5.3-150600.4.43.1 * apptainer-1.5.3-150600.4.43.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 x86_64) * apptainer-debuginfo-1.5.3-150600.4.43.1 * apptainer-1.5.3-150600.4.43.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (noarch) * apptainer-sle15_6-1.5.3-150600.4.43.1 ## References: * https://www.suse.com/security/cve/CVE-2026-56854.html * https://www.suse.com/security/cve/CVE-2026-56855.html * https://www.suse.com/security/cve/CVE-2026-78662.html * https://www.suse.com/security/cve/CVE-2026-84303.html * https://www.suse.com/security/cve/CVE-2026-84304.html * https://www.suse.com/security/cve/CVE-2026-84445.html * https://bugzilla.suse.com/show_bug.cgi?id=1278666 * https://bugzilla.suse.com/show_bug.cgi?id=1279033 * https://bugzilla.suse.com/show_bug.cgi?id=1279236 * https://bugzilla.suse.com/show_bug.cgi?id=1279333 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 24 08:30:49 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 24 Sep 2026 08:30:49 -0000 Subject: SUSE-SU-2026:4315-1: important: Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise 15 SP6) Message-ID: <179023864999.2776.18111465232816393275@32be4de442c6> # Security update for the Linux Kernel (Live Patch 19 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:4315-1 Release Date: 2026-09-23T19:34:20Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.5 * openSUSE Leap 15.6 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Live Patching 15-SP5 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Micro 5.5 * SUSE Linux Enterprise Real Time 15 SP5 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.84 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP5 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP5-2026-4315 * openSUSE Leap 15.5 zypper in -t patch SUSE-2026-4315 * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-4318 SUSE-SLE- Module-Live-Patching-15-SP6-2026-4319 SUSE-SLE-Module-Live- Patching-15-SP6-2026-4314 SUSE-SLE-Module-Live-Patching-15-SP6-2026-4316 SUSE- SLE-Module-Live-Patching-15-SP6-2026-4317 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4319 SUSE-2026-4314 SUSE-2026-4316 SUSE-2026-4317 SUSE-2026-4318 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_169-default-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_41-debugsource-5-150500.2.1 * kernel-livepatch-5_14_21-150500_55_169-default-debuginfo-5-150500.2.1 * openSUSE Leap 15.5 (ppc64le s390x x86_64) * kernel-livepatch-5_14_21-150500_55_169-default-5-150500.2.1 * kernel-livepatch-SLE15-SP5_Update_41-debugsource-5-150500.2.1 * kernel-livepatch-5_14_21-150500_55_169-default-debuginfo-5-150500.2.1 * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-17-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_15-debugsource-17-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-17-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_17-debugsource-12-150600.2.1 * kernel-livepatch-6_4_0-150600_23_84-default-debuginfo-12-150600.2.1 * kernel-livepatch-6_4_0-150600_23_81-default-12-150600.2.1 * kernel-livepatch-6_4_0-150600_23_84-default-12-150600.2.1 * kernel-livepatch-6_4_0-150600_23_70-default-17-150600.2.1 * kernel-livepatch-6_4_0-150600_23_78-default-12-150600.2.1 * kernel-livepatch-6_4_0-150600_23_81-default-debuginfo-12-150600.2.1 * kernel-livepatch-6_4_0-150600_23_78-default-debuginfo-12-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_18-debugsource-12-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_14-debugsource-17-150600.2.1 * kernel-livepatch-6_4_0-150600_23_70-default-debuginfo-17-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_19-debugsource-12-150600.2.1 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_65-default-debuginfo-17-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_15-debugsource-17-150600.2.1 * kernel-livepatch-6_4_0-150600_23_65-default-17-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_17-debugsource-12-150600.2.1 * kernel-livepatch-6_4_0-150600_23_84-default-debuginfo-12-150600.2.1 * kernel-livepatch-6_4_0-150600_23_81-default-12-150600.2.1 * kernel-livepatch-6_4_0-150600_23_84-default-12-150600.2.1 * kernel-livepatch-6_4_0-150600_23_70-default-17-150600.2.1 * kernel-livepatch-6_4_0-150600_23_78-default-12-150600.2.1 * kernel-livepatch-6_4_0-150600_23_81-default-debuginfo-12-150600.2.1 * kernel-livepatch-6_4_0-150600_23_78-default-debuginfo-12-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_18-debugsource-12-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_14-debugsource-17-150600.2.1 * kernel-livepatch-6_4_0-150600_23_70-default-debuginfo-17-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_19-debugsource-12-150600.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 24 12:30:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 24 Sep 2026 12:30:51 -0000 Subject: SUSE-SU-2026:4328-1: important: Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 15 SP7) Message-ID: <179025305190.9651.14499006012276816169@c47cdf24d69a> # Security update for the Linux Kernel (Live Patch 8 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:4328-1 Release Date: 2026-09-24T06:33:43Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.28 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-4328 SUSE-SLE- Module-Live-Patching-15-SP7-2026-4329 SUSE-SLE-Module-Live- Patching-15-SP7-2026-4330 SUSE-SLE-Module-Live-Patching-15-SP7-2026-4331 SUSE- SLE-Module-Live-Patching-15-SP7-2026-4332 SUSE-SLE-Module-Live- Patching-15-SP7-2026-4333 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP7_Update_8-debugsource-12-150700.2.1 * kernel-livepatch-6_4_0-150700_53_11-default-debuginfo-17-150700.2.1 * kernel-livepatch-6_4_0-150700_53_22-default-debuginfo-12-150700.2.1 * kernel-livepatch-6_4_0-150700_53_28-default-12-150700.2.1 * kernel-livepatch-6_4_0-150700_53_16-default-debuginfo-17-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_3-debugsource-17-150700.2.1 * kernel-livepatch-6_4_0-150700_53_16-default-17-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_7-debugsource-12-150700.2.1 * kernel-livepatch-6_4_0-150700_53_11-default-17-150700.2.1 * kernel-livepatch-6_4_0-150700_53_22-default-12-150700.2.1 * kernel-livepatch-6_4_0-150700_53_25-default-debuginfo-12-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_4-debugsource-17-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_6-debugsource-12-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_5-debugsource-14-150700.2.1 * kernel-livepatch-6_4_0-150700_53_19-default-debuginfo-14-150700.2.1 * kernel-livepatch-6_4_0-150700_53_19-default-14-150700.2.1 * kernel-livepatch-6_4_0-150700_53_25-default-12-150700.2.1 * kernel-livepatch-6_4_0-150700_53_28-default-debuginfo-12-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 24 12:31:37 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 24 Sep 2026 12:31:37 -0000 Subject: SUSE-SU-2026:4320-1: important: Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise 15 SP6) Message-ID: <179025309747.9651.1521823126455693314@c47cdf24d69a> # Security update for the Linux Kernel (Live Patch 27 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:4320-1 Release Date: 2026-09-24T03:04:27Z Rating: important References: * bsc#1267388 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves five vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.115 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-4320 SUSE-SLE- Module-Live-Patching-15-SP6-2026-4321 SUSE-SLE-Module-Live- Patching-15-SP6-2026-4322 SUSE-SLE-Module-Live-Patching-15-SP6-2026-4323 SUSE- SLE-Module-Live-Patching-15-SP6-2026-4324 SUSE-SLE-Module-Live- Patching-15-SP6-2026-4325 SUSE-SLE-Module-Live-Patching-15-SP6-2026-4326 SUSE- SLE-Module-Live-Patching-15-SP6-2026-4327 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4320 SUSE-2026-4321 SUSE-2026-4322 SUSE-2026-4323 SUSE-2026-4324 SUSE-2026-4325 SUSE-2026-4326 SUSE-2026-4327 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_95-default-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_115-default-debuginfo-5-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_27-debugsource-5-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_24-debugsource-7-150600.2.1 * kernel-livepatch-6_4_0-150600_23_87-default-debuginfo-11-150600.2.1 * kernel-livepatch-6_4_0-150600_23_100-default-debuginfo-8-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_20-debugsource-11-150600.2.1 * kernel-livepatch-6_4_0-150600_23_95-default-debuginfo-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_112-default-debuginfo-6-150600.2.1 * kernel-livepatch-6_4_0-150600_23_103-default-debuginfo-7-150600.2.1 * kernel-livepatch-6_4_0-150600_23_109-default-debuginfo-6-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_25-debugsource-6-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_22-debugsource-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_112-default-6-150600.2.1 * kernel-livepatch-6_4_0-150600_23_87-default-11-150600.2.1 * kernel-livepatch-6_4_0-150600_23_109-default-6-150600.2.1 * kernel-livepatch-6_4_0-150600_23_115-default-5-150600.2.1 * kernel-livepatch-6_4_0-150600_23_100-default-8-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_26-debugsource-6-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_23-debugsource-8-150600.2.1 * kernel-livepatch-6_4_0-150600_23_103-default-7-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_21-debugsource-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_92-default-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_92-default-debuginfo-9-150600.2.1 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150600_23_95-default-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_115-default-debuginfo-5-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_27-debugsource-5-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_24-debugsource-7-150600.2.1 * kernel-livepatch-6_4_0-150600_23_87-default-debuginfo-11-150600.2.1 * kernel-livepatch-6_4_0-150600_23_100-default-debuginfo-8-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_20-debugsource-11-150600.2.1 * kernel-livepatch-6_4_0-150600_23_95-default-debuginfo-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_112-default-debuginfo-6-150600.2.1 * kernel-livepatch-6_4_0-150600_23_103-default-debuginfo-7-150600.2.1 * kernel-livepatch-6_4_0-150600_23_109-default-debuginfo-6-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_25-debugsource-6-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_22-debugsource-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_112-default-6-150600.2.1 * kernel-livepatch-6_4_0-150600_23_87-default-11-150600.2.1 * kernel-livepatch-6_4_0-150600_23_109-default-6-150600.2.1 * kernel-livepatch-6_4_0-150600_23_115-default-5-150600.2.1 * kernel-livepatch-6_4_0-150600_23_100-default-8-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_26-debugsource-6-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_23-debugsource-8-150600.2.1 * kernel-livepatch-6_4_0-150600_23_103-default-7-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_21-debugsource-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_92-default-9-150600.2.1 * kernel-livepatch-6_4_0-150600_23_92-default-debuginfo-9-150600.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 24 16:30:43 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 24 Sep 2026 16:30:43 -0000 Subject: SUSE-SU-2026:4342-1: important: Security update for the Linux Kernel (Live Patch 29 for SUSE Linux Enterprise 15 SP6) Message-ID: <179026744301.3607.9041373031934621822@cc827fc6be87> # Security update for the Linux Kernel (Live Patch 29 for SUSE Linux Enterprise 15 SP6) Announcement ID: SUSE-SU-2026:4342-1 Release Date: 2026-09-24T11:04:33Z Rating: important References: * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise Live Patching 15-SP6 * SUSE Linux Enterprise Real Time 15 SP6 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 An update that solves four vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150600.23.125 fixes various security issues: The following security issues were fixed: * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP6 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP6-2026-4342 SUSE-SLE- Module-Live-Patching-15-SP6-2026-4343 * openSUSE Leap 15.6 zypper in -t patch SUSE-2026-4343 SUSE-2026-4342 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_29-debugsource-3-150600.2.1 * kernel-livepatch-6_4_0-150600_23_125-default-3-150600.2.1 * kernel-livepatch-6_4_0-150600_23_118-default-debuginfo-5-150600.2.1 * kernel-livepatch-6_4_0-150600_23_125-default-debuginfo-3-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_28-debugsource-5-150600.2.1 * kernel-livepatch-6_4_0-150600_23_118-default-5-150600.2.1 * openSUSE Leap 15.6 (ppc64le s390x x86_64) * kernel-livepatch-SLE15-SP6_Update_29-debugsource-3-150600.2.1 * kernel-livepatch-6_4_0-150600_23_125-default-3-150600.2.1 * kernel-livepatch-6_4_0-150600_23_118-default-debuginfo-5-150600.2.1 * kernel-livepatch-6_4_0-150600_23_125-default-debuginfo-3-150600.2.1 * kernel-livepatch-SLE15-SP6_Update_28-debugsource-5-150600.2.1 * kernel-livepatch-6_4_0-150600_23_118-default-5-150600.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 24 16:31:45 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 24 Sep 2026 16:31:45 -0000 Subject: SUSE-SU-2026:4340-1: important: Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise 15 SP7) Message-ID: <179026750593.3607.10125203034320114658@cc827fc6be87> # Security update for the Linux Kernel (Live Patch 12 for SUSE Linux Enterprise 15 SP7) Announcement ID: SUSE-SU-2026:4340-1 Release Date: 2026-09-24T10:04:24Z Rating: important References: * bsc#1267388 * bsc#1270303 * bsc#1273232 * bsc#1274074 * bsc#1274942 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-53360 * CVE-2026-64423 * CVE-2026-64561 * CVE-2026-64564 * CVE-2026-68138 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-53360 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-53360 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-53360 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64561 ( SUSE ): 9.3 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H * CVE-2026-64561 ( SUSE ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64561 ( NVD ): 8.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( SUSE ): 7.3 CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68138 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-68138 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Live Patching 15-SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves six vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 6.4.0-150700.53.40 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-53360: KVM: SEV: Require in-GHCB scratch area if GHCB v2+ is in use (bsc#1270303). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64561: KVM: x86: Check for invalid/obsolete root _after_ making MMU pages available (Zapscape) (bsc#1273232). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). * CVE-2026-68138: net/sched: serialize qdisc_rtab_list against concurrent get/put (bsc#1274942). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 15-SP7 zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP7-2026-4340 SUSE-SLE- Module-Live-Patching-15-SP7-2026-4341 ## Package List: * SUSE Linux Enterprise Live Patching 15-SP7 (ppc64le s390x x86_64) * kernel-livepatch-6_4_0-150700_53_40-default-debuginfo-8-150700.2.1 * kernel-livepatch-6_4_0-150700_53_40-default-8-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_12-debugsource-8-150700.2.1 * kernel-livepatch-SLE15-SP7_Update_11-debugsource-9-150700.2.1 * kernel-livepatch-6_4_0-150700_53_37-default-debuginfo-9-150700.2.1 * kernel-livepatch-6_4_0-150700_53_37-default-9-150700.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-53360.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64561.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://www.suse.com/security/cve/CVE-2026-68138.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1270303 * https://bugzilla.suse.com/show_bug.cgi?id=1273232 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1274942 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 24 16:32:29 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 24 Sep 2026 16:32:29 -0000 Subject: SUSE-SU-2026:4336-1: important: Security update for the Linux Kernel (Live Patch 83 for SUSE Linux Enterprise 12 SP5) Message-ID: <179026754914.3607.8060146586715522429@cc827fc6be87> # Security update for the Linux Kernel (Live Patch 83 for SUSE Linux Enterprise 12 SP5) Announcement ID: SUSE-SU-2026:4336-1 Release Date: 2026-09-24T08:58:16Z Rating: important References: * bsc#1267388 * bsc#1274074 * bsc#1275458 Cross-References: * CVE-2026-46150 * CVE-2026-64423 * CVE-2026-64564 CVSS scores: * CVE-2026-46150 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-46150 ( SUSE ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-46150 ( NVD ): 7.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-64423 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64423 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-64564 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-64564 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Live Patching 12-SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves three vulnerabilities can now be installed. ## Description: This update for the SUSE Linux Enterprise Kernel 4.12.14-122.310 fixes various security issues: The following security issues were fixed: * CVE-2026-46150: fanotify: fix false positive on permission events (bsc#1267388). * CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1275458). * CVE-2026-64564: sctp: don't free the ASCONF's own transport in DEL-IP processing (SCTPhantom) (bsc#1274074). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Live Patching 12-SP5 zypper in -t patch SUSE-SLE-Live-Patching-12-SP5-2026-4336 SUSE-SLE-Live- Patching-12-SP5-2026-4337 SUSE-SLE-Live-Patching-12-SP5-2026-4338 ## Package List: * SUSE Linux Enterprise Live Patching 12-SP5 (ppc64le s390x x86_64) * kgraft-patch-4_12_14-122_299-default-9-2.1 * kgraft-patch-4_12_14-122_302-default-8-2.1 * kgraft-patch-4_12_14-122_310-default-6-2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-46150.html * https://www.suse.com/security/cve/CVE-2026-64423.html * https://www.suse.com/security/cve/CVE-2026-64564.html * https://bugzilla.suse.com/show_bug.cgi?id=1267388 * https://bugzilla.suse.com/show_bug.cgi?id=1274074 * https://bugzilla.suse.com/show_bug.cgi?id=1275458 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 24 16:33:36 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 24 Sep 2026 16:33:36 -0000 Subject: SUSE-SU-2026:4339-1: moderate: Security update for java-11-openjdk Message-ID: <179026761607.3607.12833063188435559235@cc827fc6be87> # Security update for java-11-openjdk Announcement ID: SUSE-SU-2026:4339-1 Release Date: 2026-09-24T09:12:43Z Rating: moderate References: * bsc#1275035 * bsc#1275764 * bsc#1275777 * bsc#1275778 Cross-References: * CVE-2026-60589 * CVE-2026-61308 * CVE-2026-70907 CVSS scores: * CVE-2026-60589 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-60589 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N * CVE-2026-61308 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-61308 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-70907 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-70907 ( NVD ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L Affected Products: * Legacy Module 15-SP7 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux Enterprise Server 15 SP4 LTSS * SUSE Linux Enterprise Server 15 SP5 * SUSE Linux Enterprise Server 15 SP5 LTSS * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server 15 SP6 LTSS * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 * SUSE Package Hub 15 15-SP7 An update that solves three vulnerabilities and has one security fix can now be installed. ## Description: This update for java-11-openjdk fixes the following issues: * CVE-2026-60589: OpenJDK: Improve Resource Resolving (bsc#1275777). * CVE-2026-61308: OpenJDK: Enhance HTTP Connections (bsc#1275778). * CVE-2026-70907: OpenJDK: Enhance TLS server (bsc#1275764). Changes for java-11-openjdk: * Upgrade to upstream tag jdk-11.0.32.1+1 (August 2026 CSPU) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP4-2026-4339 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-ESPOS-2026-4339 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 zypper in -t patch SUSE-SLE-Product-HPC-15-SP4-LTSS-2026-4339 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP5-2026-4339 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-ESPOS-2026-4339 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 zypper in -t patch SUSE-SLE-Product-HPC-15-SP5-LTSS-2026-4339 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-4339 * SUSE Linux Enterprise Server 15 SP4 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP4-LTSS-2026-4339 * Legacy Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Legacy-15-SP7-2026-4339 * SUSE Package Hub 15 15-SP7 zypper in -t patch SUSE-SLE-Module-Packagehub-Subpackages-15-SP7-2026-4339 * SUSE Linux Enterprise Server 15 SP5 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP5-LTSS-2026-4339 * SUSE Linux Enterprise Server 15 SP6 LTSS zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-4339 ## Package List: * SUSE Linux Enterprise Server for SAP Applications 15 SP4 (ppc64le x86_64) * java-11-openjdk-devel-11.0.32.1-150000.3.144.1 * java-11-openjdk-headless-11.0.32.1-150000.3.144.1 * java-11-openjdk-debugsource-11.0.32.1-150000.3.144.1 * java-11-openjdk-11.0.32.1-150000.3.144.1 * java-11-openjdk-demo-11.0.32.1-150000.3.144.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP4 (aarch64 x86_64) * java-11-openjdk-devel-11.0.32.1-150000.3.144.1 * java-11-openjdk-headless-11.0.32.1-150000.3.144.1 * java-11-openjdk-debugsource-11.0.32.1-150000.3.144.1 * java-11-openjdk-11.0.32.1-150000.3.144.1 * java-11-openjdk-demo-11.0.32.1-150000.3.144.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP4 (aarch64 x86_64) * java-11-openjdk-devel-11.0.32.1-150000.3.144.1 * java-11-openjdk-headless-11.0.32.1-150000.3.144.1 * java-11-openjdk-debugsource-11.0.32.1-150000.3.144.1 * java-11-openjdk-11.0.32.1-150000.3.144.1 * java-11-openjdk-demo-11.0.32.1-150000.3.144.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 (ppc64le x86_64) * java-11-openjdk-demo-11.0.32.1-150000.3.144.1 * java-11-openjdk-headless-11.0.32.1-150000.3.144.1 * java-11-openjdk-devel-11.0.32.1-150000.3.144.1 * java-11-openjdk-11.0.32.1-150000.3.144.1 * SUSE Linux Enterprise High Performance Computing ESPOS 15 SP5 (aarch64 x86_64) * java-11-openjdk-demo-11.0.32.1-150000.3.144.1 * java-11-openjdk-headless-11.0.32.1-150000.3.144.1 * java-11-openjdk-devel-11.0.32.1-150000.3.144.1 * java-11-openjdk-11.0.32.1-150000.3.144.1 * SUSE Linux Enterprise High Performance Computing LTSS 15 SP5 (aarch64 x86_64) * java-11-openjdk-demo-11.0.32.1-150000.3.144.1 * java-11-openjdk-headless-11.0.32.1-150000.3.144.1 * java-11-openjdk-devel-11.0.32.1-150000.3.144.1 * java-11-openjdk-11.0.32.1-150000.3.144.1 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64) * java-11-openjdk-debuginfo-11.0.32.1-150000.3.144.1 * java-11-openjdk-devel-11.0.32.1-150000.3.144.1 * java-11-openjdk-headless-11.0.32.1-150000.3.144.1 * java-11-openjdk-debugsource-11.0.32.1-150000.3.144.1 * java-11-openjdk-11.0.32.1-150000.3.144.1 * java-11-openjdk-demo-11.0.32.1-150000.3.144.1 * java-11-openjdk-devel-debuginfo-11.0.32.1-150000.3.144.1 * java-11-openjdk-headless-debuginfo-11.0.32.1-150000.3.144.1 * SUSE Linux Enterprise Server 15 SP4 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-devel-11.0.32.1-150000.3.144.1 * java-11-openjdk-headless-11.0.32.1-150000.3.144.1 * java-11-openjdk-debugsource-11.0.32.1-150000.3.144.1 * java-11-openjdk-11.0.32.1-150000.3.144.1 * java-11-openjdk-demo-11.0.32.1-150000.3.144.1 * Legacy Module 15-SP7 (aarch64 ppc64le s390x x86_64) * java-11-openjdk-debuginfo-11.0.32.1-150000.3.144.1 * java-11-openjdk-devel-11.0.32.1-150000.3.144.1 * java-11-openjdk-headless-11.0.32.1-150000.3.144.1 * java-11-openjdk-debugsource-11.0.32.1-150000.3.144.1 * java-11-openjdk-11.0.32.1-150000.3.144.1 * java-11-openjdk-demo-11.0.32.1-150000.3.144.1 * java-11-openjdk-devel-debuginfo-11.0.32.1-150000.3.144.1 * java-11-openjdk-headless-debuginfo-11.0.32.1-150000.3.144.1 * SUSE Package Hub 15 15-SP7 (noarch) * java-11-openjdk-javadoc-11.0.32.1-150000.3.144.1 * SUSE Linux Enterprise Server 15 SP5 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-demo-11.0.32.1-150000.3.144.1 * java-11-openjdk-headless-11.0.32.1-150000.3.144.1 * java-11-openjdk-devel-11.0.32.1-150000.3.144.1 * java-11-openjdk-11.0.32.1-150000.3.144.1 * SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64) * java-11-openjdk-debuginfo-11.0.32.1-150000.3.144.1 * java-11-openjdk-devel-11.0.32.1-150000.3.144.1 * java-11-openjdk-headless-11.0.32.1-150000.3.144.1 * java-11-openjdk-debugsource-11.0.32.1-150000.3.144.1 * java-11-openjdk-11.0.32.1-150000.3.144.1 * java-11-openjdk-demo-11.0.32.1-150000.3.144.1 * java-11-openjdk-devel-debuginfo-11.0.32.1-150000.3.144.1 * java-11-openjdk-headless-debuginfo-11.0.32.1-150000.3.144.1 ## References: * https://www.suse.com/security/cve/CVE-2026-60589.html * https://www.suse.com/security/cve/CVE-2026-61308.html * https://www.suse.com/security/cve/CVE-2026-70907.html * https://bugzilla.suse.com/show_bug.cgi?id=1275035 * https://bugzilla.suse.com/show_bug.cgi?id=1275764 * https://bugzilla.suse.com/show_bug.cgi?id=1275777 * https://bugzilla.suse.com/show_bug.cgi?id=1275778 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 24 16:34:28 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 24 Sep 2026 16:34:28 -0000 Subject: SUSE-SU-2026:4335-1: critical: Security update for hplip Message-ID: <179026766878.3607.12050845248391104285@cc827fc6be87> # Security update for hplip Announcement ID: SUSE-SU-2026:4335-1 Release Date: 2026-09-24T08:37:36Z Rating: critical References: * bsc#1281303 * bsc#1281304 * bsc#1281305 * bsc#1281306 * bsc#1281307 * bsc#1281308 * bsc#1281309 * bsc#1281310 * bsc#1281313 * bsc#1281314 * bsc#1282051 Cross-References: * CVE-2026-91097 * CVE-2026-91098 * CVE-2026-91099 * CVE-2026-91100 * CVE-2026-91101 * CVE-2026-91102 * CVE-2026-91103 * CVE-2026-91104 * CVE-2026-91105 * CVE-2026-91106 CVSS scores: * CVE-2026-91097 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-91097 ( SUSE ): 7.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L * CVE-2026-91097 ( NVD ): 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-91097 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-91098 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-91098 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-91098 ( NVD ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-91098 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-91099 ( SUSE ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-91099 ( SUSE ): 5.1 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N * CVE-2026-91099 ( NVD ): 5.1 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-91099 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-91100 ( SUSE ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N * CVE-2026-91100 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:L * CVE-2026-91100 ( NVD ): 6.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-91100 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-91101 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-91101 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-91101 ( NVD ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-91101 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-91102 ( SUSE ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-91102 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-91102 ( NVD ): 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-91102 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-91103 ( SUSE ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-91103 ( SUSE ): 4.6 CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-91103 ( NVD ): 5.1 CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-91103 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-91104 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-91104 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-91104 ( NVD ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-91104 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-91105 ( SUSE ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-91105 ( SUSE ): 8.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H * CVE-2026-91105 ( NVD ): 8.6 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-91105 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-91106 ( SUSE ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-91106 ( SUSE ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H * CVE-2026-91106 ( NVD ): 9.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-91106 ( NVD ): 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise High Performance Computing 12 SP5 * SUSE Linux Enterprise Server 12 SP5 * SUSE Linux Enterprise Server 12 SP5 LTSS * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security * SUSE Linux Enterprise Server for SAP Applications 12 SP5 An update that solves 10 vulnerabilities and has one security fix can now be installed. ## Description: This update for hplip fixes the following issues: * CVE-2026-91097: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281303). * CVE-2026-91098: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281304). * CVE-2026-91099: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281305). * CVE-2026-91100: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281306). * CVE-2026-91101: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281307). * CVE-2026-91102: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281308). * CVE-2026-91103: medium severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281309). * CVE-2026-91104: critical severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281313). * CVE-2026-91105: high severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281310). * CVE-2026-91106: critical severity issue - multiple vulnerabilities enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions (bsc#1281314 bsc#1282051). Changes for hplip: * Fix download of propietary plugin for 3.26.6 * Update to HPLIP 3.26.6 * Add support for the following new printers: * HP ScanJet Enterprise Flow N9000 sn1 * HP ScanJet Enterprise Flow 9000 s1 * HP ScanJet Pro 4200 s1 * HP LaserJet Pro 4006dn printer * HP LaserJet Pro 4006dw printer * HP LaserJet Pro 4006n printer * HP LaserJet Pro 4002d printer * HP LaserJet Pro 4007dw printer * HP LaserJet Pro 4007n printer * HP LaserJet Pro 4008d * HP LaserJet Pro 4008dn * HP LaserJet Pro 4008dw * HP LaserJet Pro MFP 4112dw printer * HP LaserJet Pro MFP 4112fdn printer * HP LaserJet Pro MFP 4112fdw printer * HP LaserJet Pro MFP 4113dw printer * HP LaserJet Pro MFP 4113dwg printer * HP LaserJet Pro MFP 4113fdn printer * HP LaserJet Pro MFP 4113fdng printer * HP LaserJet Pro MFP 4113fdw printer * HP LaserJet Pro MFP 4113fdwg printer * HP LaserJet Pro MFP 4114dw * HP LaserJet Pro MFP 4114fdn * HP LaserJet Pro MFP 4114fdw ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server 12 SP5 LTSS zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-2026-4335 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security zypper in -t patch SUSE-SLE-SERVER-12-SP5-LTSS-EXTENDED-SECURITY-2026-4335 ## Package List: * SUSE Linux Enterprise Server 12 SP5 LTSS (aarch64 ppc64le s390x x86_64) * hplip-udev-rules-3.26.6-3.14.2 * hplip-3.26.6-3.14.2 * hplip-debugsource-3.26.6-3.14.2 * hplip-sane-3.26.6-3.14.2 * hplip-debuginfo-3.26.6-3.14.2 * hplip-hpijs-debuginfo-3.26.6-3.14.2 * hplip-hpijs-3.26.6-3.14.2 * hplip-devel-3.26.6-3.14.2 * SUSE Linux Enterprise Server 12 SP5 LTSS (ppc64le s390x x86_64) * hplip-sane-debuginfo-3.26.6-3.14.2 * SUSE Linux Enterprise Server 12 SP5 LTSS Extended Security (x86_64) * hplip-udev-rules-3.26.6-3.14.2 * hplip-3.26.6-3.14.2 * hplip-sane-debuginfo-3.26.6-3.14.2 * hplip-debugsource-3.26.6-3.14.2 * hplip-sane-3.26.6-3.14.2 * hplip-debuginfo-3.26.6-3.14.2 * hplip-hpijs-debuginfo-3.26.6-3.14.2 * hplip-hpijs-3.26.6-3.14.2 * hplip-devel-3.26.6-3.14.2 ## References: * https://www.suse.com/security/cve/CVE-2026-91097.html * https://www.suse.com/security/cve/CVE-2026-91098.html * https://www.suse.com/security/cve/CVE-2026-91099.html * https://www.suse.com/security/cve/CVE-2026-91100.html * https://www.suse.com/security/cve/CVE-2026-91101.html * https://www.suse.com/security/cve/CVE-2026-91102.html * https://www.suse.com/security/cve/CVE-2026-91103.html * https://www.suse.com/security/cve/CVE-2026-91104.html * https://www.suse.com/security/cve/CVE-2026-91105.html * https://www.suse.com/security/cve/CVE-2026-91106.html * https://bugzilla.suse.com/show_bug.cgi?id=1281303 * https://bugzilla.suse.com/show_bug.cgi?id=1281304 * https://bugzilla.suse.com/show_bug.cgi?id=1281305 * https://bugzilla.suse.com/show_bug.cgi?id=1281306 * https://bugzilla.suse.com/show_bug.cgi?id=1281307 * https://bugzilla.suse.com/show_bug.cgi?id=1281308 * https://bugzilla.suse.com/show_bug.cgi?id=1281309 * https://bugzilla.suse.com/show_bug.cgi?id=1281310 * https://bugzilla.suse.com/show_bug.cgi?id=1281313 * https://bugzilla.suse.com/show_bug.cgi?id=1281314 * https://bugzilla.suse.com/show_bug.cgi?id=1282051 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 24 16:35:12 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 24 Sep 2026 16:35:12 -0000 Subject: SUSE-SU-2026:4334-1: low: Security update for ImageMagick Message-ID: <179026771270.3607.14904897331650713047@cc827fc6be87> # Security update for ImageMagick Announcement ID: SUSE-SU-2026:4334-1 Release Date: 2026-09-24T08:37:22Z Rating: low References: * bsc#1279696 * bsc#1279711 * bsc#1279794 * bsc#1279797 Cross-References: * CVE-2026-86420 * CVE-2026-86421 * CVE-2026-86423 * CVE-2026-86425 CVSS scores: * CVE-2026-86420 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-86420 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-86420 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-86420 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-86420 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-86421 ( SUSE ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N * CVE-2026-86421 ( SUSE ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-86421 ( NVD ): 6.3 CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-86421 ( NVD ): 3.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L * CVE-2026-86421 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-86423 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-86423 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-86423 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-86423 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H * CVE-2026-86423 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-86425 ( SUSE ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-86425 ( SUSE ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-86425 ( NVD ): 4.8 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-86425 ( NVD ): 3.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L * CVE-2026-86425 ( NVD ): 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H Affected Products: * Desktop Applications Module 15-SP7 * openSUSE Leap 15.4 * SUSE Linux Enterprise Desktop 15 SP7 * SUSE Linux Enterprise Real Time 15 SP7 * SUSE Linux Enterprise Server 15 SP7 * SUSE Linux Enterprise Server for SAP Applications 15 SP7 An update that solves four vulnerabilities can now be installed. ## Description: This update for ImageMagick fixes the following issues: * CVE-2026-86420: denial of Service due to memory budget exhaustion (bsc#1279696). * CVE-2026-86421: denial of Service via memory leak in MSL decoder (bsc#1279711). * CVE-2026-86423: denial of service via heap-use-after-free in PerlMagick's GetList method (bsc#1279794). * CVE-2026-86425: denial of Service due to heap-use-after-free vulnerability (bsc#1279797). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.4 zypper in -t patch SUSE-2026-4334 * Desktop Applications Module 15-SP7 zypper in -t patch SUSE-SLE-Module-Desktop-Applications-15-SP7-2026-4334 ## Package List: * openSUSE Leap 15.4 (aarch64 i586 ppc64le s390x x86_64) * libMagickWand-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.113.1 * libMagickWand-7_Q16HDRI10-7.1.0.9-150400.6.113.1 * libMagick++-devel-7.1.0.9-150400.6.113.1 * libMagick++-7_Q16HDRI5-debuginfo-7.1.0.9-150400.6.113.1 * perl-PerlMagick-7.1.0.9-150400.6.113.1 * ImageMagick-debugsource-7.1.0.9-150400.6.113.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.113.1 * perl-PerlMagick-debuginfo-7.1.0.9-150400.6.113.1 * libMagickCore-7_Q16HDRI10-debuginfo-7.1.0.9-150400.6.113.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.113.1 * ImageMagick-7.1.0.9-150400.6.113.1 * ImageMagick-extra-debuginfo-7.1.0.9-150400.6.113.1 * ImageMagick-extra-7.1.0.9-150400.6.113.1 * ImageMagick-config-7-SUSE-7.1.0.9-150400.6.113.1 * libMagick++-7_Q16HDRI5-7.1.0.9-150400.6.113.1 * libMagickCore-7_Q16HDRI10-7.1.0.9-150400.6.113.1 * ImageMagick-devel-7.1.0.9-150400.6.113.1 * openSUSE Leap 15.4 (x86_64) * libMagick++-devel-32bit-7.1.0.9-150400.6.113.1 * libMagick++-7_Q16HDRI5-32bit-debuginfo-7.1.0.9-150400.6.113.1 * libMagick++-7_Q16HDRI5-32bit-7.1.0.9-150400.6.113.1 * libMagickCore-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.113.1 * libMagickWand-7_Q16HDRI10-32bit-debuginfo-7.1.0.9-150400.6.113.1 * libMagickWand-7_Q16HDRI10-32bit-7.1.0.9-150400.6.113.1 * libMagickCore-7_Q16HDRI10-32bit-7.1.0.9-150400.6.113.1 * ImageMagick-devel-32bit-7.1.0.9-150400.6.113.1 * openSUSE Leap 15.4 (aarch64_ilp32) * libMagick++-7_Q16HDRI5-64bit-debuginfo-7.1.0.9-150400.6.113.1 * libMagick++-devel-64bit-7.1.0.9-150400.6.113.1 * libMagickWand-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.113.1 * libMagickWand-7_Q16HDRI10-64bit-7.1.0.9-150400.6.113.1 * ImageMagick-devel-64bit-7.1.0.9-150400.6.113.1 * libMagickCore-7_Q16HDRI10-64bit-debuginfo-7.1.0.9-150400.6.113.1 * libMagickCore-7_Q16HDRI10-64bit-7.1.0.9-150400.6.113.1 * libMagick++-7_Q16HDRI5-64bit-7.1.0.9-150400.6.113.1 * openSUSE Leap 15.4 (noarch) * ImageMagick-doc-7.1.0.9-150400.6.113.1 * Desktop Applications Module 15-SP7 (aarch64 ppc64le s390x x86_64) * ImageMagick-debugsource-7.1.0.9-150400.6.113.1 * ImageMagick-debuginfo-7.1.0.9-150400.6.113.1 * ImageMagick-config-7-upstream-7.1.0.9-150400.6.113.1 ## References: * https://www.suse.com/security/cve/CVE-2026-86420.html * https://www.suse.com/security/cve/CVE-2026-86421.html * https://www.suse.com/security/cve/CVE-2026-86423.html * https://www.suse.com/security/cve/CVE-2026-86425.html * https://bugzilla.suse.com/show_bug.cgi?id=1279696 * https://bugzilla.suse.com/show_bug.cgi?id=1279711 * https://bugzilla.suse.com/show_bug.cgi?id=1279794 * https://bugzilla.suse.com/show_bug.cgi?id=1279797 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 24 20:31:00 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 24 Sep 2026 20:31:00 -0000 Subject: SUSE-SU-2026:23871-1: important: Security update for exiv2 Message-ID: <179028186069.3757.4596946683508525531@e7f4ad8d9866> # Security update for exiv2 Announcement ID: SUSE-SU-2026:23871-1 Release Date: 2026-09-22T07:21:55Z Rating: important References: * bsc#1277579 * bsc#1277591 * bsc#1277791 Cross-References: * CVE-2026-49275 * CVE-2026-68546 * CVE-2026-68547 CVSS scores: * CVE-2026-49275 ( SUSE ): 4.4 CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:A/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N * CVE-2026-49275 ( SUSE ): 5.5 CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H * CVE-2026-68546 ( SUSE ): 6.1 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-68546 ( SUSE ): 8.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:H * CVE-2026-68547 ( SUSE ): 6.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-68547 ( SUSE ): 7.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves three vulnerabilities can now be installed. ## Description: This update for exiv2 fixes the following issues: * CVE-2026-49275: Out of bounds read in CrwMap::decodeBasic (bsc#1277791). * CVE-2026-68546: Heap out-of-bounds read in RemoteIo when reading block- aligned remote CRW files (bsc#1277579). * CVE-2026-68547: Heap out-of-bounds write in RemoteIo when reading from a malicious remote server (bsc#1277591). Changes for exiv2: * update to 0.28.9: * https://github.com/Exiv2/exiv2/security/advisories/GHSA-3695-mjv8-3r52 * https://github.com/Exiv2/exiv2/security/advisories/GHSA-jcgh-p9v3-pw6j * https://github.com/Exiv2/exiv2/security/advisories/GHSA-hxph-pv7w-8649 * https://github.com/Exiv2/exiv2/security/advisories/GHSA-vg6c-9f6h-4x5q * https://github.com/Exiv2/exiv2/security/advisories/GHSA-9v3x-mhg4-wwv2 * https://github.com/Exiv2/exiv2/security/advisories/GHSA-fgw8-p7pr-37cp * https://github.com/Exiv2/exiv2/security/advisories/GHSA-pwvq-9w4q-786w ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1732 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (x86_64) * libexiv2-28-0.28.9-160000.1.1 * libexiv2-28-x86-64-v3-0.28.9-160000.1.1 * exiv2-debuginfo-0.28.9-160000.1.1 * exiv2-debugsource-0.28.9-160000.1.1 * libexiv2-28-debuginfo-0.28.9-160000.1.1 * libexiv2-28-x86-64-v3-debuginfo-0.28.9-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-49275.html * https://www.suse.com/security/cve/CVE-2026-68546.html * https://www.suse.com/security/cve/CVE-2026-68547.html * https://bugzilla.suse.com/show_bug.cgi?id=1277579 * https://bugzilla.suse.com/show_bug.cgi?id=1277591 * https://bugzilla.suse.com/show_bug.cgi?id=1277791 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 24 20:31:51 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 24 Sep 2026 20:31:51 -0000 Subject: SUSE-SU-2026:23870-1: important: Security update for util-linux Message-ID: <179028191184.3757.427042206775789019@e7f4ad8d9866> # Security update for util-linux Announcement ID: SUSE-SU-2026:23870-1 Release Date: 2026-09-22T07:18:54Z Rating: important References: * bsc#1261606 * bsc#1268886 * bsc#1269583 * bsc#1270219 * bsc#1275441 * bsc#1278347 * bsc#1278348 * bsc#1278349 Cross-References: * CVE-2026-13595 * CVE-2026-27456 * CVE-2026-53612 * CVE-2026-53613 * CVE-2026-53614 * CVE-2026-76642 * CVE-2026-78408 * CVE-2026-78410 CVSS scores: * CVE-2026-13595 ( SUSE ): 6.9 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-13595 ( SUSE ): 6.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-13595 ( NVD ): 6.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-13595 ( NVD ): 5.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:H * CVE-2026-27456 ( SUSE ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-27456 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-53612 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53613 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-53614 ( SUSE ): 7.0 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-76642 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-76642 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-76642 ( NVD ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-76642 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-78408 ( SUSE ): 5.2 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:P/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-78408 ( SUSE ): 6.6 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H * CVE-2026-78408 ( NVD ): 7.9 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H * CVE-2026-78410 ( SUSE ): 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N * CVE-2026-78410 ( SUSE ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-78410 ( NVD ): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: * SUSE Linux Enterprise Server 16.0 * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves eight vulnerabilities can now be installed. ## Description: This update for util-linux fixes the following issues: * CVE-2026-13595: heap use-after-free in `libblkid` nested partition probing (bsc#1269583). * CVE-2026-27456: TOCTOU in the mount program when setting up loop devices (bsc#1261606). * CVE-2026-53612: local privilege escalation via TOCTOU in mount(8) hook_owner.c chmod/chown (bsc#1268886). * CVE-2026-53613: local privilege escalation via TOCTOU in mount(8) - Target Path Redirection (bsc#1268886). * CVE-2026-53614: local privilege escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8) (bsc#1268886). * CVE-2026-76642: failed external mount helper triggers privileged `X-mount` post-hooks, which enables local privilege escalation (bsc#1278349). * CVE-2026-78408: `nsenter --join-cgroup` leaks root `cgroup` migration authority, which allows for migration or termination of root processes (bsc#1278348). * CVE-2026-78410: restricted `bind` mounts do not pin the source, which allows for `X-mount.owner`/`group`/`mode` redirection (bsc#1278347). Changes for util-linux: * lib/fileutils: add ul_openat_resolve() openat2 wrapper (bsc#1275441) * lib/fileutils: fix RESOLVE_NO_SYMLINKS fallback value * lib/fileutils: fix unused parameter warnings without SYS_openat2 * libmount: add missing fileutils.h include to hook_idmap.c * libmount: add mnt_open_tree() helper for safe tree opening * libmount: pin source path with openat2() for restricted users (bsc#1275441, bsc#1278347, CVE-2026-78410) * libmount: restrict source path canonicalization for non-root users (bsc#1275441, bsc#1278347, CVE-2026-78410) * libmount: skip post-mount hooks after failed mount helper (bsc#1275441, bsc#1278349, CVE-2026-76642) * libmount: use USE_LIBMOUNT_MOUNTFD_SUPPORT for idmap hook * nsenter: close cgroup.procs fd after join to prevent authority leak (bsc#1275441, bsc#1278348, CVE-2026-78408) * nsenter, unshare: add O_CLOEXEC to all open() calls (bsc#1275441, bsc#1278348, CVE-2026-78408) * wall, write: sanitize hostname in banner header (bsc#1275441) * Add missing function. (bsc#1275441) * ipcutils: Prevent using uninitialized variable (bsc#1268886) * BREAKING CHANGE: Paths must always be canonicalized for unprivileged users to ensure safe target resolution. X-mount.nocanonicalize is ignored for them. * INCOMAPTIBLE CHANGE (linux < 6.15): X-mount.subdir: The safe detached subdirectory is no more supported for unprivileged users for safety reasons. * liblastlog2: Wait on busy SQLite connections (bsc#1268886). * libmount: Fix subvolid buffer overflow in get_btrfs_fs_root (bsc#1268886). * libblkid: Fix use-after-free in nested partition probing (bsc#1269583, bsc#1268886, CVE-2026-13595) * libmount: fix SUID bypass via LIBMOUNT_FORCE_MOUNT2 and legacy mount path (bsc#1268886, CVE-2026-53614, GHSA-67r7-8m5w-22wx). * fileutils: add ul_open_no_symlinks() needed by other patches (bsc#1268886). * libmount: add fd_target to context for TOCTOU race condition prevention (bsc#1268886, CVE-2026-53613, GHSA-8gj5-72r3-428g). * libmount: ignore X-mount.nocanonicalize for restricted users * libmount: use fd-based fchownat/chmod in hook_owner (bsc#1268886, CVE-2026-53612, GHSA-g8wm-75wr-g2vh). * libmount: restrict X-mount.subdir for non-root (bsc#1268886). * libmount: use fd_target in hook_idmap for move_mount() * libmount: add mount ID verification and man page TOCTOU note * loopdev: use openat2(RESOLVE_NO_SYMLINKS) for backing file (bsc#1268886#c2, bsc#1261606). * Ignore pam-config error that prevents update failure if common _pam configuration is not symlink to common-_ -pc (bsc#1270219). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1733 * SUSE Linux Enterprise Server 16.0 zypper in -t patch SUSE-SLES-16.0-1733 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * libblkid-devel-static-2.41.1-160000.5.1 * liblastlog2-devel-2.41.1-160000.5.1 * libsmartcols-devel-static-2.41.1-160000.5.1 * libuuid1-debuginfo-2.41.1-160000.5.1 * util-linux-tty-tools-2.41.1-160000.5.1 * util-linux-2.41.1-160000.5.1 * libsmartcols1-2.41.1-160000.5.1 * util-linux-systemd-debugsource-2.41.1-160000.5.1 * python313-libmount-debuginfo-2.41.1-160000.5.1 * python-libmount-debugsource-2.41.1-160000.5.1 * liblastlog2-2-2.41.1-160000.5.1 * libfdisk-devel-static-2.41.1-160000.5.1 * libsmartcols-devel-2.41.1-160000.5.1 * python313-libmount-2.41.1-160000.5.1 * util-linux-systemd-2.41.1-160000.5.1 * libfdisk1-2.41.1-160000.5.1 * liblastlog2-2-debuginfo-2.41.1-160000.5.1 * libuuid-devel-2.41.1-160000.5.1 * lastlog2-debuginfo-2.41.1-160000.5.1 * libmount1-2.41.1-160000.5.1 * libmount1-debuginfo-2.41.1-160000.5.1 * libuuid-devel-static-2.41.1-160000.5.1 * libfdisk-devel-2.41.1-160000.5.1 * util-linux-debuginfo-2.41.1-160000.5.1 * libblkid-devel-2.41.1-160000.5.1 * libblkid1-debuginfo-2.41.1-160000.5.1 * uuidd-debuginfo-2.41.1-160000.5.1 * libmount-devel-static-2.41.1-160000.5.1 * libsmartcols1-debuginfo-2.41.1-160000.5.1 * lastlog2-2.41.1-160000.5.1 * util-linux-tty-tools-debuginfo-2.41.1-160000.5.1 * libmount-devel-2.41.1-160000.5.1 * util-linux-debugsource-2.41.1-160000.5.1 * libfdisk1-debuginfo-2.41.1-160000.5.1 * libblkid1-2.41.1-160000.5.1 * libuuid1-2.41.1-160000.5.1 * util-linux-systemd-debuginfo-2.41.1-160000.5.1 * uuidd-2.41.1-160000.5.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * util-linux-lang-2.41.1-160000.5.1 * SUSE Linux Enterprise Server 16.0 (aarch64 ppc64le s390x) * libblkid-devel-static-2.41.1-160000.5.1 * liblastlog2-devel-2.41.1-160000.5.1 * libsmartcols-devel-static-2.41.1-160000.5.1 * libuuid1-debuginfo-2.41.1-160000.5.1 * util-linux-tty-tools-2.41.1-160000.5.1 * util-linux-2.41.1-160000.5.1 * libsmartcols1-2.41.1-160000.5.1 * util-linux-systemd-debugsource-2.41.1-160000.5.1 * python313-libmount-debuginfo-2.41.1-160000.5.1 * python-libmount-debugsource-2.41.1-160000.5.1 * liblastlog2-2-2.41.1-160000.5.1 * libfdisk-devel-static-2.41.1-160000.5.1 * libsmartcols-devel-2.41.1-160000.5.1 * python313-libmount-2.41.1-160000.5.1 * util-linux-systemd-2.41.1-160000.5.1 * libfdisk1-2.41.1-160000.5.1 * liblastlog2-2-debuginfo-2.41.1-160000.5.1 * libuuid-devel-2.41.1-160000.5.1 * lastlog2-debuginfo-2.41.1-160000.5.1 * libmount1-2.41.1-160000.5.1 * libmount1-debuginfo-2.41.1-160000.5.1 * libuuid-devel-static-2.41.1-160000.5.1 * libfdisk-devel-2.41.1-160000.5.1 * util-linux-debuginfo-2.41.1-160000.5.1 * libblkid-devel-2.41.1-160000.5.1 * libblkid1-debuginfo-2.41.1-160000.5.1 * uuidd-debuginfo-2.41.1-160000.5.1 * libmount-devel-static-2.41.1-160000.5.1 * libsmartcols1-debuginfo-2.41.1-160000.5.1 * lastlog2-2.41.1-160000.5.1 * util-linux-tty-tools-debuginfo-2.41.1-160000.5.1 * libmount-devel-2.41.1-160000.5.1 * util-linux-debugsource-2.41.1-160000.5.1 * libfdisk1-debuginfo-2.41.1-160000.5.1 * libblkid1-2.41.1-160000.5.1 * libuuid1-2.41.1-160000.5.1 * util-linux-systemd-debuginfo-2.41.1-160000.5.1 * uuidd-2.41.1-160000.5.1 * SUSE Linux Enterprise Server 16.0 (noarch) * util-linux-lang-2.41.1-160000.5.1 ## References: * https://www.suse.com/security/cve/CVE-2026-13595.html * https://www.suse.com/security/cve/CVE-2026-27456.html * https://www.suse.com/security/cve/CVE-2026-53612.html * https://www.suse.com/security/cve/CVE-2026-53613.html * https://www.suse.com/security/cve/CVE-2026-53614.html * https://www.suse.com/security/cve/CVE-2026-76642.html * https://www.suse.com/security/cve/CVE-2026-78408.html * https://www.suse.com/security/cve/CVE-2026-78410.html * https://bugzilla.suse.com/show_bug.cgi?id=1261606 * https://bugzilla.suse.com/show_bug.cgi?id=1268886 * https://bugzilla.suse.com/show_bug.cgi?id=1269583 * https://bugzilla.suse.com/show_bug.cgi?id=1270219 * https://bugzilla.suse.com/show_bug.cgi?id=1275441 * https://bugzilla.suse.com/show_bug.cgi?id=1278347 * https://bugzilla.suse.com/show_bug.cgi?id=1278348 * https://bugzilla.suse.com/show_bug.cgi?id=1278349 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 24 20:32:44 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 24 Sep 2026 20:32:44 -0000 Subject: SUSE-SU-2026:23869-1: important: Security update for rabbitmq-server Message-ID: <179028196448.3757.6314713536864491792@e7f4ad8d9866> # Security update for rabbitmq-server Announcement ID: SUSE-SU-2026:23869-1 Release Date: 2026-09-22T02:15:45Z Rating: important References: * bsc#1266465 * bsc#1271318 * bsc#1271336 * bsc#1271337 * bsc#1271338 * bsc#1271339 * bsc#1271340 * bsc#1271343 * bsc#1271344 * bsc#1271345 * bsc#1271346 * bsc#1279938 Cross-References: * CVE-2026-44839 * CVE-2026-57212 * CVE-2026-57213 * CVE-2026-57214 * CVE-2026-57215 * CVE-2026-57216 * CVE-2026-57217 * CVE-2026-57218 * CVE-2026-57219 * CVE-2026-57220 * CVE-2026-57221 CVSS scores: * CVE-2026-44839 ( SUSE ): 8.2 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-44839 ( SUSE ): 6.2 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N * CVE-2026-44839 ( NVD ): 5.6 CVSS:4.0/AV:N/AC:H/AT:N/PR:H/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-44839 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N * CVE-2026-57212 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-57212 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H * CVE-2026-57212 ( NVD ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-57212 ( NVD ): 7.7 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H * CVE-2026-57213 ( SUSE ): 4.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2026-57213 ( SUSE ): 3.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N * CVE-2026-57213 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-57213 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N * CVE-2026-57214 ( SUSE ): 4.6 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N * CVE-2026-57214 ( NVD ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-57214 ( NVD ): 5.4 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N * CVE-2026-57215 ( SUSE ): 7.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N * CVE-2026-57215 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-57215 ( NVD ): 7.0 CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-57215 ( NVD ): 8.8 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H * CVE-2026-57216 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-57216 ( NVD ): 10.0 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H * CVE-2026-57216 ( NVD ): 6.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N * CVE-2026-57217 ( SUSE ): 7.6 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N * CVE-2026-57217 ( SUSE ): 6.8 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N * CVE-2026-57217 ( NVD ): 7.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-57217 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-57218 ( SUSE ): 7.1 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-57218 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-57218 ( NVD ): 4.9 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-57218 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N * CVE-2026-57219 ( SUSE ): 8.8 CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N * CVE-2026-57219 ( SUSE ): 8.7 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N * CVE-2026-57219 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-57219 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2026-57220 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N * CVE-2026-57220 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-57220 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-57221 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2026-57221 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N * CVE-2026-57221 ( NVD ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-57221 ( NVD ): 5.0 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves 11 vulnerabilities and has one fix can now be installed. ## Description: This update for rabbitmq-server fixes the following issues: * CVE-2026-44839: XSS in management UI due to unsanitized vhost names (bsc#1266465). * CVE-2026-57212: The rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths (bsc#1271318). * CVE-2026-57213: stored XSS in RabbitMQ federation management plugin via unsanitized consumer_tag rendering (bsc#1271336). * CVE-2026-57214: stored XSS in RabbitMQ management UI (bsc#1271337). * CVE-2026-57215: direct-reply-to binding persistence can lead to unauthorized reply-channel injection and persistent phantom (bsc#1271338). * CVE-2026-57216: stream Protocol loopback enforcement can lead to remote guest sessions due to listener-address loopback checks (bsc#1271339). * CVE-2026-57217: topic authorization can lead to cross-tenant routing-key bypass (bsc#1271340). * CVE-2026-57218: consumer persistence can lead to post-revocation message disclosure in OAuth2 (bsc#1271343). * CVE-2026-57219: Unauthenticated disclosure of OAuth client credentials via an HTTP API endpoint with certain less common OAuth 2 configurations (bsc#1271344). * CVE-2026-57220: stream listener does not enforce configured frame-size limit during authentication, permitting unauth'd mem-exhaust DoS (bsc#1271345). * CVE-2026-57221: passive queue/exchange declaration bypasses authorization checks, leaking queue metadata to unprivileged users (bsc#1271346). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1731 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * rabbitmq-server-4.1.5-160000.2.1 * rabbitmq-server-plugins-4.1.5-160000.2.1 * erlang-rabbitmq-client-4.1.5-160000.2.1 * SUSE Linux Enterprise Server for SAP applications 16.0 (noarch) * rabbitmq-server-bash-completion-4.1.5-160000.2.1 * rabbitmq-server-zsh-completion-4.1.5-160000.2.1 ## References: * https://www.suse.com/security/cve/CVE-2026-44839.html * https://www.suse.com/security/cve/CVE-2026-57212.html * https://www.suse.com/security/cve/CVE-2026-57213.html * https://www.suse.com/security/cve/CVE-2026-57214.html * https://www.suse.com/security/cve/CVE-2026-57215.html * https://www.suse.com/security/cve/CVE-2026-57216.html * https://www.suse.com/security/cve/CVE-2026-57217.html * https://www.suse.com/security/cve/CVE-2026-57218.html * https://www.suse.com/security/cve/CVE-2026-57219.html * https://www.suse.com/security/cve/CVE-2026-57220.html * https://www.suse.com/security/cve/CVE-2026-57221.html * https://bugzilla.suse.com/show_bug.cgi?id=1266465 * https://bugzilla.suse.com/show_bug.cgi?id=1271318 * https://bugzilla.suse.com/show_bug.cgi?id=1271336 * https://bugzilla.suse.com/show_bug.cgi?id=1271337 * https://bugzilla.suse.com/show_bug.cgi?id=1271338 * https://bugzilla.suse.com/show_bug.cgi?id=1271339 * https://bugzilla.suse.com/show_bug.cgi?id=1271340 * https://bugzilla.suse.com/show_bug.cgi?id=1271343 * https://bugzilla.suse.com/show_bug.cgi?id=1271344 * https://bugzilla.suse.com/show_bug.cgi?id=1271345 * https://bugzilla.suse.com/show_bug.cgi?id=1271346 * https://bugzilla.suse.com/show_bug.cgi?id=1279938 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 24 20:33:26 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 24 Sep 2026 20:33:26 -0000 Subject: SUSE-SU-2026:23868-1: important: Security update for zstd-jni Message-ID: <179028200677.3757.10902905460223664124@e7f4ad8d9866> # Security update for zstd-jni Announcement ID: SUSE-SU-2026:23868-1 Release Date: 2026-09-21T17:43:40Z Rating: important References: * bsc#1279953 * bsc#1279954 * bsc#1279955 * bsc#1279956 Cross-References: * CVE-2026-87823 * CVE-2026-87824 * CVE-2026-87825 * CVE-2026-87877 CVSS scores: * CVE-2026-87823 ( SUSE ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-87823 ( NVD ): 8.8 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-87823 ( NVD ): 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H * CVE-2026-87824 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-87824 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-87824 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-87825 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-87825 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-87825 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-87877 ( SUSE ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H * CVE-2026-87877 ( NVD ): 7.0 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-87877 ( NVD ): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves four vulnerabilities can now be installed. ## Description: This update for zstd-jni fixes the following issues: * CVE-2026-87823: denial of Service or Information Disclosure via out-of- bounds read (bsc#1279953). * CVE-2026-87824: denial of Service (DoS) via out-of-bounds read in Zstd.trainFromBufferDirect (bsc#1279956). * CVE-2026-87825: use-after-free resulting in silent data corruption or JVM crashes (bsc#1279955). * CVE-2026-87877: use-After-Free vulnerability allows memory corruption and denial of service (bsc#1279954). Changes for zstd-jni: * update to version v1.5.7.16. ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise Server for SAP applications 16.0 zypper in -t patch SUSE-SLES-16.0-1730 ## Package List: * SUSE Linux Enterprise Server for SAP applications 16.0 (ppc64le x86_64) * zstd-jni-1.5.7.16-160000.1.1 ## References: * https://www.suse.com/security/cve/CVE-2026-87823.html * https://www.suse.com/security/cve/CVE-2026-87824.html * https://www.suse.com/security/cve/CVE-2026-87825.html * https://www.suse.com/security/cve/CVE-2026-87877.html * https://bugzilla.suse.com/show_bug.cgi?id=1279953 * https://bugzilla.suse.com/show_bug.cgi?id=1279954 * https://bugzilla.suse.com/show_bug.cgi?id=1279955 * https://bugzilla.suse.com/show_bug.cgi?id=1279956 -------------- next part -------------- An HTML attachment was scrubbed... URL: From null at suse.de Thu Sep 24 20:34:05 2026 From: null at suse.de (SLE-SECURITY-UPDATES) Date: Thu, 24 Sep 2026 20:34:05 -0000 Subject: SUSE-SU-2026:23867-1: important: Security update for jsoup, re2j Message-ID: <179028204579.3757.10643812983535521523@e7f4ad8d9866> # Security update for jsoup, re2j Announcement ID: SUSE-SU-2026:23867-1 Release Date: 2026-09-21T12:46:08Z Rating: important References: * bsc#1275912 Cross-References: * CVE-2026-75140 CVSS scores: * CVE-2026-75140 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H * CVE-2026-75140 ( NVD ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2026-75140 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Products: * SUSE Linux Enterprise Server for SAP applications 16.0 An update that solves one vulnerability can now be installed. ## Description: This update for jsoup, re2j fixes the following issue: * CVE-2026-75140: The builder copies the entire inherited namespace map on every start element, causing quadratic time and memory complexity, which attackers can exploit to trigger an OutOfMemoryError and terminate the application (bsc#1275912). Changes for jsoup: * Upgrade to upstream version 1.23.2 * Improvement: Improved consecutive StreamParser.selectFirst() calls during progressive parsing, so later matches are returned with their parsed contents when earlier selections had left them as parser lookahead. E.g., given One

Full

Next

, selecting title and then #hit now advances the partial lookahead and returns

Full

, rather than returning an empty

before its content is parsed. The updated readiness tracking follows StreamParser's normal emission order across implicit HTML structure and parser recovery. * Improvement: Improved XML parser performance and memory use for documents with many nested namespace declarations by recording namespace changes within each element scope (bsc#1275912, CVE-2026-75140). * Improvement: Improved W3CDom conversion performance for documents with many nested namespace declarations. The W3C converter now uses the same optimized namespace tracking as the XML parser. * Improvement: Improved W3CDom XML conversion to retain processing instructions, comments outside the root element, and CDATA sections, which were previously dropped or converted to text. * Improvement: DOM mutation methods, including child insertion and replacement, now reject operations that would create a cycle, such as making a node its own child or moving an ancestor beneath a descendant. * Improvement: Added Elements#before(Node), after(Node), prepend(Node), and append(Node) to match the existing HTML string methods. * Improvement: Large file-backed uploads through Connection.requestBodyStream(InputStream) now stream directly with the JDK HttpClient on Java 11+, rather than being loaded fully into memory first. * Improvement: Extended Java 11+ HTTP client reuse from requests sharing a Jsoup.newSession() to ordinary Jsoup.connect() calls, reducing transport thread and connection setup churn under sustained request loads. Sessions with custom authentication or SSL contexts continue to use their own client. * Change: Aligned the XML parser stack depth and lookups to the configured maximum, which now defaults to 512 for both HTML and XML. Use Parser#setMaxDepth(int) to configure. * Bugfix: Fixed W3CDom namespace conversion in several cases: * Namespace declarations and prefixed attributes now carry the correct namespace URI, so namespace-aware DOM lookups work as expected. * Attributes added after parsing, or included through subtree conversion, now use inherited prefix declarations. * Namespace declarations now apply regardless of attribute order, and an empty declaration shadows an inherited binding only within its scope. * With namespace awareness disabled, inherited and undeclared prefixes now receive the declarations needed for XML serialization. * Valid HTML names that are not XML QNames, such as a:b:c, are normalized. Attributes that still cannot be represented are skipped, and unrepresentable elements no longer change the surrounding tree. * Bugfix: Fixed W3CDom conversion of programmatically created or renamed elements whose names can be represented in a jsoup HTML DOM but are not valid XML names, such as 1abc. These names are now normalized (e.g. _1abc) instead of causing a NullPointerException. * Bugfix: Fixed XML doctype serialization when a system identifier contains a double quote, which could otherwise produce invalid XML. * Bugfix: XML serialization now repairs element and attribute names that start with an invalid character, rather than outputting null elements or dropping attributes. For example, an attribute named 1a is written as _1a. Additional leading underscores keep repaired attribute names unique if they conflict with another attribute. * Bugfix: Supplementary Unicode characters are now escaped correctly when serializing with non-UTF, non-ASCII output charsets such as ISO-8859-1. Previously, characters could be emitted unescaped when their low 16-bit value was representable by the configured charset, causing replacement or corruption when the output was encoded. * Bugfix: Fixed the JDK HttpClient implementation to accept responses missing a Content-Type header, matching the HttpURLConnection implementation. * Bugfix: Fixed HTTP response content-type matching to handle media types case-insensitively and recognize structured +xml suffixes, including vendor- specific media types. * Bugfix: HTTP request URL normalization now percent-encodes ASCII control characters, DEL, and embedded fragment delimiters, keeping normalized URLs valid for HTTP requests while preserving existing escapes. * Bugfix: Corrected multipart form encoding to percent-escape CR and LF in field names and filenames, matching the HTML form submission specification. Multipart file content-types containing CR or LF are now rejected with a ValidationException. * Bugfix: Aligned trailing comment placement with the HTML specification: comments after remain children of the html element, while comments after remain children of the document. * Bugfix: When using the optional re2j regular expression engine, memory allocation errors caused by complex selector patterns at match time are now normalized to a ValidationException with a Pattern complexity error message. * Bugfix: Fixed parsing of malformed SVG and MathML content so that breakout HTML tags are placed according to the HTML specification. * Bugfix: Fixed deeply nested malformed HTML parsing that could lose the document body because stack lookups did not align to the configured maximum parser depth. * Bugfix: Aligned RCDATA, RAWTEXT, and script-data parsing with the HTML specification: malformed end tags no longer consume following markup, unclosed title/textarea content stays text through EOF, and custom text tags match exact names. * Bugfix: Improved URL validation during HTTP/HTTPS URL resolution and cleaning; resolved URLs without a host are now rejected instead of being accepted based only on their scheme prefix, aligning to RFC 9110. Valid relative links and non-HTTP(S) schemes are unchanged. * Bugfix: Redirects with malformed single-slash HTTP locations now use standard URL resolution to align with browsers. * Bugfix: Template fragment parsing now handles unmatched tags without throwing a ValidationException. * Bugfix: Improved source tracking for adopted formatting elements and malformed markup ending at EOF. * Changes of 1.23.1 * Improvement: Reduced retained memory when parsing with source position tracking enabled (Parser#setTrackPosition(true)). Source ranges are now stored in compact parser-owned span records instead of node and attribute user data, and Position objects are created lazily when source ranges are read. This cuts tracked DOM retained size by about 50-60% on representative benchmark documents, while keeping Node#sourceRange(), Element#endSourceRange(), and Attribute#sourceRange() behavior intact. * Improvement: Added Element#classList(), an immutable snapshot of an element's class names in attribute order. Use hasClass() when you just need to test for one class, classList() when you want to read or iterate classes without needing a mutable result, and classNames() when you want the existing mutable, deduplicated set that can be written back with classNames(Set). The class APIs now share an HTML-whitespace scanner, which also makes classNames() faster and lighter on allocation, especially when walking many elements without class names. * Improvement: Aligned HTML parser scope classification with the current HTML spec for select, foreignObject, and template. * Improvement: Simplified the HTML tree builder's scope, implied-end-tag, and special-element checks by caching parser-only options on Tag. That improves HTML parser throughput by about 10% on small inputs and up to about 30% on larger inputs in the benchmark fixtures. * Improvement: Improved HTML parser throughput stability by making hot tokeniser scan paths compile more predictably. * Improvement: